CAREER: Automated Forensic-in-the-Loop Cyber Defense Infrastructure
CAREER: Automated Forensic-in-the-Loop Cyber Defense Infrastructure
批准号:
2145616
负责人:
Yonghwi Kwon
金额:
$54.76万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2022
资助国家:
美国
项目状态:
未结题
起止时间:
2022-07-01 至 2027-06-30
中文摘要
网络攻击正变得越来越先进和复杂。高级攻击者会长时间监视他们的目标,以了解他们的漏洞和保护策略。这种先进的攻击是极其具有挑战性的,以防止和调查,因为他们的复杂和先进的战术和资源,并通过他们的战略,渗透系统在意想不到的/忽视的方式。更糟糕的是,攻击者使用复杂的策略,如混淆和逃避技术,以阻挠或延迟取证调查。攻击者还危害了广泛的系统组件和资源,使得恢复和加固系统变得非常困难。法医分析的延误或不完整使得难以及时妥善保护受害者的组织,从而导致重大损害和损失。为此,本项目开发了新技术,以(1)彻底防止各种攻击,(2)进行快速和全面的取证分析,(3)严格保护受害者的系统。该项目还包括教育活动,通过组织辅导讲习班和指导包括许多女学生在内的弗吉尼亚大学大学网络防御竞赛队,扩大了对计算的参与。该项目旨在开发一个自动化的取证在环网络防御基础设施,该基础设施将新颖的防御,取证分析和加固方法相结合。首先,研究者开发攻击向量不可知的保护和检测方法,通过扰动输入和运行时环境,是攻击的最薄弱环节。其次,调查人员开发新的自动化技术来检测和消除应用于恶意软件的反取证技术。此外,为了处理规避恶意软件,调查员介绍了自适应反事实执行技术,以发展的运行时环境和执行上下文。最后,调查人员开发了一种自动化的根本原因分析技术,可以诊断漏洞并确定潜在的修复方法(例如,该奖项反映了NSF的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Cyber-attacks are becoming increasingly advanced and sophisticated. Advanced attackers monitor their targets for a long time to find out about their vulnerabilities and protective strategies. Such advanced attacks are extremely challenging to prevent and investigate due to their sophisticated and advanced tactics and resources and by their strategy to penetrate the system in unexpected/overlooked ways. Worse, attackers use sophisticated tactics, such as obfuscation and evasive techniques, to thwart or delay forensics investigations. Attackers also compromise a wide range of system components and resources, making it extremely difficult to restore and harden the system. Delayed or incomplete forensic analysis makes it difficult to properly secure the victim’s organization on time, leading to significant damages and losses. To this end, this project develops novel techniques to (1) prevent diverse attacks thoroughly, (2) conduct rapid and comprehensive forensic analysis, and (3) protect the victim’s system rigorously. This project also involves educational activities that broadens participation in computing, by organizing mentoring workshops and coaching the University of Virginia’s Collegiate Cyber Defense Competition team, which includes many female students. This project aims to develop an automated forensic-in-the-loop cyber defense infrastructure that coherently integrates novel defenses, forensic analysis, and hardening approaches. First, the investigator develops attack vector agnostic protection and detection approaches by perturbing inputs and runtime environments that are the weakest links of the attacks. Second, the investigator develops novel automated techniques to detect and eliminate anti-forensic techniques applied to malware. Furthermore, to handle evasive malware, the investigator introduces the adaptive counterfactual execution technique to evolve the runtime environment and execution context. Finally, the investigator develops an automated root cause analysis technique that diagnoses loopholes and identifies potential fixes (e.g., secure configurations).This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(3)
专著(0)
科研奖励(0)
会议论文
DOI:
10.1109/icse48619.2023.00048
发表时间:
2023-05
期刊:
2023 IEEE/ACM 45th International Conference on Software Engineering (ICSE)
影响因子:
--
作者:
[I. L. Kim;Weihang Wang;Yonghwi Kwon;X. Zhang]
通讯作者:
I. L. Kim;Weihang Wang;Yonghwi Kwon;X. Zhang
PyFET: Forensically Equivalent Transformation for Python Binary Decompilation
PyFET:Python 二进制反编译的取证等效转换
DOI:
--
发表时间:
2023
期刊:
Proceedings IEEE Symposium on Security and Privacy
影响因子:
--
作者:
[Ahad, Ali, Jung, Chijung, Askar, Ammar, Kim, Doowon, Kim, Taesoo, Kwon, Yonghwi]
通讯作者:
Kwon, Yonghwi
DOI:
10.14722/ndss.2023.24632
发表时间:
2023
期刊:
Proceedings 2023 Network and Distributed System Security Symposium
影响因子:
--
作者:
[An Chen;Jiho Lee;Basanta Chaulagain;Yonghwi Kwon;K. H. Lee]
通讯作者:
An Chen;Jiho Lee;Basanta Chaulagain;Yonghwi Kwon;K. H. Lee
SaTC: CORE: Medium: Collaborative: Doctor WHO: Investigation and Prevention of Online Content Management System Abuse
-
批准号:2426653
-
项目类别:Standard Grant
-
资助金额:$38.77万
-
财政年份:2023
-
负责人:Yonghwi Kwon
-
依托单位:
OAC Core: Small: Collaborative Research: Data Provenance Infrastructure towards Robust andReliable Data Sharing and Analytics
-
批准号:1908021
-
项目类别:Standard Grant
-
资助金额:$25.0万
-
财政年份:2019
-
负责人:Yonghwi Kwon
-
依托单位:
SaTC: CORE: Medium: Collaborative: Doctor WHO: Investigation and Prevention of Online Content Management System Abuse
-
批准号:1916499
-
项目类别:Standard Grant
-
资助金额:$38.77万
-
财政年份:2019
-
负责人:Yonghwi Kwon
-
依托单位:
CRII: SaTC: Secure and Comprehensive Forensic Audit Infrastructure for Transparent Heterogeneous Computing
-
批准号:1850392
-
项目类别:Standard Grant
-
资助金额:$17.44万
-
财政年份:2019
-
负责人:Yonghwi Kwon
-
依托单位:
海外基金