课题基金 / 基金详情

TC-Small-Virtual Machine Introspection-based Live Forensics for Detection of Malicious Software

TC-Small-Virtual Machine Introspection-based Live Forensics for Detection of Malicious Software
用于检测恶意软件的基于 TC-Small-Virtual Machine Introspection 的实时取证
批准号:
1016807
负责人:
Golden Richard
金额:
$49.9万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2010
资助国家:
美国
项目状态:
已结题
起止时间:
2010-09-01 至 2015-12-31

项目摘要

项目成果

Golden Richard的其他基金

相似基金

相关文献

中文摘要
翻译
现代恶意软件被广泛用于计算机犯罪和网络战争,并对美国的军事,民用和企业层面的网络基础设施构成严重威胁。 恶意软件可以使用许多技术来获取所需的资源并阻止检测,包括挂钩或修改系统调用,添加新的系统调用,插入新的内核模块以及直接匹配内核代码。 此外,恶意软件越来越隐蔽,既难以检测又难以分析,并且当前一代的检测、分析和缓解方案将随着更多隐蔽性的趋势的增加而变得越来越无效,其中使用了更多深奥的感染媒介、复杂的打包方案、多态性和变质。创建强大的恶意软件检测和缓解技术。这些实时取证技术深入分析内存转储,并建立反映调查时机器状态的内核和应用程序结构的准确模型。 通过将实时取证技术集成到虚拟机监视器(VMM)中,并开发硬件支持的自省技术来分析恶意软件状态,可以创建恶意软件检测设施,防止恶意软件干扰检测和缓解策略。该提案讨论了支持这一研究议程的一些必要任务,包括设计和开发硬件辅助VMM自省架构,内核数据结构和其他来宾虚拟机状态(包括文件系统)的可移植建模。 这些建模技术可用于实时验证关键内核代码、交叉验证内核结构、应用程序状态分析和保护关键系统文件。该研究的一个新的方面是使用商品图形处理单元(GPU),受硬件直接I/O虚拟化保护,作为恶意软件检测加速器。该研究的智力价值是增加内省现场取证分析的深度,灵活性和能力,并将现场取证的范围扩展到检测复杂的恶意软件。 所提出的技术扩展了现场取证技术、虚拟机内省和内核级恶意软件检测的最新技术,并将为构建更强大的技术奠定基础。 拟议工作的更广泛影响触及社会的所有部门,因为公民个人以及执法,军队和企业社区都受益于部署更复杂的恶意软件检测机制。拟议的工作也增强了新奥尔良大学现有的信息保证课程,因为这项工作的研究成果将被纳入本科生和研究生课程,使学生接触到一个重要的研究领域,其中从业人员的供应远远低于需求。www.cs.uno.edu/~golden/live-forensics.html
英文摘要
Modern malware is used extensively in computer crime and cyber-warfareand poses a serious threat to the cyber-infrastructure of the UnitedStates, at the military, civil, and corporate levels. Malware canemploy a number of techniques to gain access to needed resources andto prevent detection, including hooking or modifying system calls,adding new system calls, inserting new kernel modules, and directlypatching kernel code. Furthermore, malware is increasingly stealthy,being both difficult to detect and to analyze, and current-generationschemes for detection, analysis, and mitigation will becomeincreasingly ineffective as the trend toward additional stealthincreases, with more esoteric infection vectors, complex packingschemes, polymorphism, and metamorphism being employed.This proposal leverages emerging live digital forensics techniques, tocreate powerful techniques for malware detection and mitigation. Theselive forensics techniques deeply analyze memory dumps and buildaccurate models of kernel and application structures that reflect thestate of the machine at the time of an investigation. By integratinglive forensics techniques into a virtual machine monitor (VMM) anddeveloping hardware-supported introspection techniques to analyzesystem state, malware detection facilities can be created that preventmalware from interfering with detection and mitigation strategies.The proposal discusses a number of necessary tasks to support thisresearch agenda, including the design of and development of ahardware-assisted VMM introspection architecture and deep, portablemodeling of kernel data structures and other guest VM state, includingthe filesystem. These modeling techniques can then be used forreal-time verification of critical kernel code, cross-verification ofkernel structures, application state analysis, and protection ofcritical system files. A novel aspect of the proposed research is theuse of commodity Graphics Processing Units (GPUs), protected byhardware directed-I/O virtualization, as malware detectionaccelerators.The intellectual merit of the proposed research is to increase thedepth, flexibility, and capabilities of introspected live forensicsanalysis and to expand the scope of live forensics to the detection ofsophisticated malware. The proposed techniques expandstate-of-the-art in live forensics techniques, virtual machineintrospection, and kernel-level malware detection and will provide afoundation on which to build even more powerful techniques. Thebroader impacts of the proposed work touch all sectors of society,since individual citizens, as well as the law enforcement, military,and corporate communities all benefit from the deployment of moresophisticated malware detection mechanisms. The proposed work alsoenhances the existing curriculum in information assurance at theUniversity of New Orleans, since research results from this effortwill be incorporated into both undergraduate and graduate courses,exposing students to an important area of study in which the supply ofpractitioners falls far short of the demand.For further information see the project web site at the URLhttp://www.cs.uno.edu/~golden/live-forensics.html.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
SFS: Applied Cybersecurity Training
  • 批准号:
    1946626
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $335.82万
  • 财政年份:
    2020
  • 负责人:
    Golden Richard
  • 依托单位:
SaTC: CORE: Medium: Robust Memory Forensics Techniques for Userland Malware Analysis
  • 批准号:
    1703683
  • 项目类别:
    Standard Grant
  • 资助金额:
    $111.34万
  • 财政年份:
    2017
  • 负责人:
    Golden Richard
  • 依托单位:
TWC: Medium: Collaborative: Towards a Binary-Centric Framework for Cyber Forensics in Enterprise Environments
  • 批准号:
    1732143
  • 项目类别:
    Standard Grant
  • 资助金额:
    $19.61万
  • 财政年份:
    2016
  • 负责人:
    Golden Richard
  • 依托单位:
TWC: Medium: Collaborative: Towards a Binary-Centric Framework for Cyber Forensics in Enterprise Environments
  • 批准号:
    1409534
  • 项目类别:
    Standard Grant
  • 资助金额:
    $39.98万
  • 财政年份:
    2014
  • 负责人:
    Golden Richard
  • 依托单位:
国内基金
海外基金
昼夜节律性small RNA在血斑形成时间推断中的法医学应用研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2024
  • 负责人:
  • 依托单位:
tRNA-derived small RNA上调YBX1/CCL5通路参与硼替佐米诱导慢性疼痛的机制研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    10.0万元
  • 批准年份:
    2022
  • 负责人:
    张祥忠
  • 依托单位:
Small RNA调控I-F型CRISPR-Cas适应性免疫性的应答及分子机制
Small RNAs调控解淀粉芽胞杆菌FZB42生防功能的机制研究
  • 批准号:
    31972324
  • 项目类别:
    面上项目
  • 资助金额:
    58.0万元
  • 批准年份:
    2019
  • 负责人:
    高学文
  • 依托单位: