课题基金 / 基金详情

CAREER: Automatic Learning of Adaptive Network-Centric Malware Detection Models

CAREER: Automatic Learning of Adaptive Network-Centric Malware Detection Models
职业:自适应网络中心恶意软件检测模型的自动学习
批准号:
1149051
负责人:
Roberto Perdisci
金额:
$40.26万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2012
资助国家:
美国
项目状态:
已结题
起止时间:
2012-06-01 至 2018-05-31

项目摘要

项目成果

Roberto Perdisci的其他基金

相似基金

相关文献

中文摘要
翻译
恶意软件(也称为恶意软件(恶意软件)是大多数网络犯罪活动的基础,造成了巨大的经济损失,并对国家安全构成了巨大的风险。该研究创建了新的基于网络中心行为的恶意软件检测系统,该系统自动学习如何识别网络中受恶意软件危害的计算机,并可以自我调整,以实现给定网络的恶意软件检测率和错误警报之间的最佳折衷。这种自调整属性是通过将恶意软件生成的网络流量模型与合法用户生成的网络活动的模型相结合来构建混合检测模型来实现的,该混合检测模型可以适应特定的网络环境并准确地检测跨网络边界的恶意软件生成的网络流量。这种新的恶意软件检测方法考虑了整个网络内发生的事件,而不是关注发生在每个单个主机上的事件,并且专注于对所有类型的恶意软件的自适应检测,而不是局限于特定的恶意软件类型(例如僵尸网络)。因此,本研究产生的检测系统将提供新的有效检测能力,可以补充现有的反恶意软件技术,并显著有助于更好地针对恶意软件的深度防御策略。
英文摘要
Malicious software (a.k.a. malware) is at the basis of most cyber-criminal operations, causing significant financial loss and posing great risks to national security.This research creates novel network-centric behavior-based malware detection systems that automatically learn how to identify malware-compromised machines within a network, and that can self-tune to achieve the best possible trade-off between malware detection rate and false alarms for a given network. This self-tuning property is achieved by combining models of malware-generated network traffic with models of legitimate user-generated network activities to build hybrid detection models that can adapt to a specific network environment and accurately detect malware-generated network traffic crossing the network perimeter.This new approach to malware detection takes into account events that occur within an entire network, rather than focusing on events that occur at each single host, and focuses on adaptive detection of all types of malware, rather than being limited to a specific malware type (e.g., botnets). Therefore, the detection systems resulting from this research will provide new effective detection capabilities that can complement current anti-malware technologies and significantly contribute to a better defense-in-depth strategy against malware.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: SaTC: CORE: Medium: Defending Against Social Engineering Attacks with In-Browser AI
EAGER: Collaborative: Leveraging High-Density Internet Peering Hubs to Mitigate Large-Scale DDoS Attacks
TWC: Medium: Collaborative: Exposing and Mitigating Cross-Channel Attacks that Exploit the Convergence of Telephony and the Internet
SDCI Sec: Passive and Active DNS Monitoring Tools for Detecting and Tracking the Evolution of Malicious Domain Names
海外基金