课题基金 / 基金详情

The feasibility of using fuzzy hashing for malware detection

The feasibility of using fuzzy hashing for malware detection
使用模糊哈希进行恶意软件检测的可行性
批准号:
461282-2013
负责人:
ElKhatib, Khalil
金额:
$1.82万
依托单位国家:
加拿大
项目类别:
Engage Grants Program
财政年份:
2013
资助国家:
加拿大
项目状态:
已结题
起止时间:
2013-01-01 至 2014-12-31

项目摘要

项目成果

ElKhatib, Khalil的其他基金

相似基金

相关文献

中文摘要
翻译
在计算机安全的任何其他领域中,黑客试图开发新的计算机恶意软件变体,而安全专业人员试图开发和完善工具来识别和隔离这些恶意代码,这两者之间的竞争总是动态的。每当一种新的恶意软件变种被开发出来,安全专家就会创建一个“签名”来唯一地识别该恶意软件,并将其添加到已知恶意软件的参考数据库中。防病毒软件使用这些数据库来检测系统是否被感染,或者某些数据流量是否包含已知的这些恶意代码。目前,生成病毒签名的最简单方法是基于使用加密散列,例如消息摘要算法5 (MD5)或安全散列算法1 (SHA-1),其中文件的散列被认为是该文件的签名,因此用于确定它是已知恶意软件还是已知恶意软件的变体。本课题的研究目的是研究利用模糊哈希算法减少病毒检测过程中的假阴性次数,提高病毒检测速度的可行性。目前,这个项目的合作公司Red River Solutions Inc.有一个恶意软件检测产品,但该产品在通过更传统的方法、签名和签名更新来检测恶意软件变体方面的能力有限。这项研究的预期结果是提高该产品在识别攻击目标网络的多态病毒方面的能力。从公司的角度来看,结果将是一个更好的产品,将更有市场,并为公司的客户提供更多的价值。此外,它将通过一种新的、独特的方式来检测恶意软件,为公司在市场上提供竞争优势。这个功能将是有市场的,也是一个关键的卖点。
英文摘要
More than any other field in computer security, the race is always dynamic between hackers trying to develop new variants of computer malwares and security professionals trying to develop and perfect tools to identify and isolate these malicious codes. Every time a new variant of a malware is developed, security professionals create a "signature" that uniquely identifies the malware and adds it to the reference database of known malwares. Anti-virus software uses these databases when trying to detect whether a system in infected, or whether certain data traffic contains known strains of these malicious codes. Currently, the simplest methods to generate a signature for a virus are based on using cryptographic hashes such as the Message-Digest algorithm 5 (MD5) or the Secure Hash Algorithm 1 (SHA-1) where the hash of a file is considered as the signature for that file and is therefore used to determine whether it is a known malware or a variant of known malware. The purpose of the research project is to study the feasibility of using fuzzy hashing algorithms to reduce the number of false negatives during virus detection and to improve its detection speed. At this point of time, the collaborating company on this project, Red River Solutions Inc. has a malware detection product, but the product is limited in its capabilities in detecting variants to malware by more traditional means, signatures and updates to signatures. The expected outcome of this research is to advance the product's capabilities in the area of identifying polymorphic viruses as they attack a targeted network. From the company perspective, the outcome will be a better product that will be more marketable and provide more value to the company's clients. Further it will provide a competitive advantage to the company in the market place by having a new and unique manner to detect malware. This feature will be marketable and a key selling point.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
NexGenDFA: A Framework for Next Generation Digital Forensic Analysis
NexGenDFA: A Framework for Next Generation Digital Forensic Analysis
NexGenDFA: A Framework for Next Generation Digital Forensic Analysis
Risk Assessment of SkyX: An Advanced autonomous Drone Platform for Monitoring Critical Infrastructures****
国内基金
海外基金
Capture and Release of Droplets Using Advanced Materials for High Technology Applications
  • 批准号:
    52073127
  • 项目类别:
    面上项目
  • 资助金额:
    58.0万元
  • 批准年份:
    2020
  • 负责人:
    Alidad Amirfazli
  • 依托单位:
Molecular Interaction Reconstruction of Rheumatoid Arthritis Therapies Using Clinical Data