课题基金 / 基金详情

SDCI Sec: Passive and Active DNS Monitoring Tools for Detecting and Tracking the Evolution of Malicious Domain Names

SDCI Sec: Passive and Active DNS Monitoring Tools for Detecting and Tracking the Evolution of Malicious Domain Names
SDCI Sec:用于检测和跟踪恶意域名演变的被动和主动 DNS 监控工具
批准号:
1127195
负责人:
Roberto Perdisci
金额:
$38.0万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2011
资助国家:
美国
项目状态:
已结题
起止时间:
2011-09-01 至 2019-08-31

项目摘要

项目成果

Roberto Perdisci的其他基金

相似基金

相关文献

中文摘要
翻译
最近,网络犯罪分子一直在利用域名系统(DNS)来构建敏捷的恶意网络基础设施,以支持其犯罪活动。例如,僵尸网络和其他类型的恶意软件通常使用DNS来定位其命令和控制(C C)服务器。这种恶意使用DNS的另一个例子是流量网络,它利用快速流量域,即,在这个项目中,PI将开发一套开源工具,使用被动和主动DNS流量监控来检测和跟踪恶意域名的演变。特别是,PI将开发并公开发布FluxBuster,这是一个能够通过ISC安全信息交换(ISC/SIE)框架被动监控从许多不同网络收集的DNS流量来检测“野外”流量网络的系统。沿着FluxBuster,PI将开发和发布DNS监控工具,这些工具利用被动和主动方法来检测和跟踪恶意软件相关(例如,PI计划部署所提议的工具,并将其结果提供给安全社区。因此,该项目可以广泛造福社会,因为它产生的结果可供安全研究人员、网络运营商和执法机构随时使用,以识别和阻止恶意域名并打击网络犯罪活动,从而有助于使互联网更加安全。
英文摘要
Recently cyber-criminals have been leveraging the domain name system (DNS) to build agile malicious network infrastructures in support of their criminal activities. For example, botnets and other types of malware typically use DNS to locate their command-and-control (C&C) servers. Another example of such malicious use of DNS is represented by flux networks, which make use of fast-flux domains, i.e., domains whose set of resolved IPs changes abnormally frequently, to support spam campaigns, phishing websites, browser exploits, etc.In this project, the PIs will develop a suite of open-source tools that use passive and active DNS traffic monitoring to detect and track the evolution in time of malicious domains. In particular, the PIs will develop and publicly release FluxBuster, a system that is able to detect flux networks "in the wild" by passively monitoring DNS traffic collected from many different networks through the ISC Security Information Exchange (ISC/SIE) framework. Along with FluxBuster, the PIs will develop and release DNS monitoring tools that leverage passive and active approaches to detect and track the evolution in time of malware-related (e.g., C&C) domain names.The PIs plan to deploy the proposed tools and make their results available to the security community. This project can therefore broadly benefit society, in that it produces results that are readily usable by security researchers, network operators, and law enforcement agencies to identify and block malicious domains and combat cyber-criminal activities, thus contributing to making the Internet more secure.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: SaTC: CORE: Medium: Defending Against Social Engineering Attacks with In-Browser AI
EAGER: Collaborative: Leveraging High-Density Internet Peering Hubs to Mitigate Large-Scale DDoS Attacks
TWC: Medium: Collaborative: Exposing and Mitigating Cross-Channel Attacks that Exploit the Convergence of Telephony and the Internet
CAREER: Automatic Learning of Adaptive Network-Centric Malware Detection Models
国内基金
海外基金
工业大麻内生菌SEC-024A高效抑菌VOCs的合成调控、诱变选育及其增效分子机制研究
蟾毒灵通过SEC13/HMGB1/TLR4/NF-κB轴调控转移生态位抑制乳腺癌骨转移的机制研究
SEC61A2调控EMT影响肺腺癌细胞侵袭和转移的机制研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2025
  • 负责人:
    徐磊
  • 依托单位:
膀胱癌细胞中TEAD4激活SEC61G通过糖酵解促进M2巨噬细胞极化的机制研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2025
  • 负责人:
    李朋
  • 依托单位: