课题基金 / 基金详情

CAREER: Language-based Security for Polymorphic Malware Protection

CAREER: Language-based Security for Polymorphic Malware Protection
职业:基于语言的多态恶意软件保护安全
批准号:
1054629
负责人:
Kevin Hamlen
金额:
$50.37万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2011
资助国家:
美国
项目状态:
已结题
起止时间:
2011-08-01 至 2017-07-31

项目摘要

项目成果

Kevin Hamlen的其他基金

相似基金

相关文献

中文摘要
翻译
病毒、蠕虫和其他自我传播的恶意软件仍然是国家网络基础设施几乎所有部门(包括政府、企业和家庭消费者)持续存在的重大安全威胁。新恶意软件出现的速度越来越快,威胁到国防社区维护有效检测系统的能力。这部分是因为许多恶意软件检测算法基于语法特征来识别恶意软件。多态恶意软件在传播过程中不断进化出新的语法,每天引入数百或数千种实现相同恶意行为的新语法。因此,发现实用的、可扩展的技术来可靠地检测新的多态恶意软件变体是当前计算机安全行业面临的最重大挑战之一。该项目开发了基于语义而非纯粹语法代码特征检测恶意软件的静态-动态混合技术。因此,恶意软件是根据其恶意编程的含义而不是实现它的语法来识别的。恶意负载是通过将传统的静态代码分析应用于在运行时动态截获的解密内存页来识别的。该项目的一个主要目标是开发可扩展的、适用于标准计算机硬件和操作系统的技术。这将允许大规模部署结果,并有助于保护国家免受分布式攻击,这些攻击会损害大量低优先级目标,从而攻击高优先级目标。研究结果将带来强大的新战略、概念和实用工具,使防御者在反病毒军备竞赛中获得重要的新优势,并提高国家网络基础设施抵御网络攻击的能力。
英文摘要
Viruses, worms, and other self-propagating malware remain significant ongoing security threats to almost all sectors of the nation's cyber-infrastructure, including government, business, and home consumers. The escalating rate of new malware appearances increasingly threatens to outpace the defense community's ability to maintain effective detection systems. This is in part because many malware detection algorithms identify malicious software based on syntactic features. Polymorphic malware continually evolves new syntaxes at it propagates, introducing hundreds or thousands of new syntaxes per day that implement the same malicious behavior. Discovering practical, scalable techniques for reliably detecting new polymorphic malware variants is therefore one of the most significant challenges currently facing the computer security industry.This project develops hybrid static-dynamic technologies that detect malware based on semantic rather than purely syntactic code features. Thus, malware is identified based on the meaning of its malicious programming rather than the syntax with which it implements it. Malicious payloads are identified by applying traditionally static code analyses to decrypted memory pages intercepted dynamically at runtime. A major goal of the project is to develop technologies that are scalable and practical for standard computer hardware and operating systems. This will allow wide-scale deployment of results, and help to protect the nation from distributed attacks that compromise large numbers of low-priority targets to attack higher-priority targets. Results from the research will lead to powerful new strategies, concepts, and practical tools that give defenders a significant new advantage in the virus-antivirus arms race, and improving the national cyber-infrastructure's resilience against cyber-attacks.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
TWC: TTP Option: Medium: Collaborative: ENCORE - ENhanced program protection through COmpiler-REwriter cooperation
  • 批准号:
    1513704
  • 项目类别:
    Standard Grant
  • 资助金额:
    $17.7万
  • 财政年份:
    2015
  • 负责人:
    Kevin Hamlen
  • 依托单位:
TC: Medium: Collaborative Research: Securing Web Advertisements: Fixing the Short-term Crisis and Addressing Long-term Challenges
  • 批准号:
    1065216
  • 项目类别:
    Standard Grant
  • 资助金额:
    $52.74万
  • 财政年份:
    2011
  • 负责人:
    Kevin Hamlen
  • 依托单位:
EAGER: Secure Peer-to-peer Data Management
  • 批准号:
    0959096
  • 项目类别:
    Standard Grant
  • 资助金额:
    $8.0万
  • 财政年份:
    2009
  • 负责人:
    Kevin Hamlen
  • 依托单位:
海外基金