课题基金 / 基金详情

Computational tools for analyzing and detecting software supply chain attacks

Computational tools for analyzing and detecting software supply chain attacks
用于分析和检测软件供应链攻击的计算工具
批准号:
474601-2014
负责人:
Lie, David
金额:
$2.6万
依托单位:
依托单位国家:
加拿大
项目类别:
Collaborative Research and Development Grants
财政年份:
2015
资助国家:
加拿大
项目状态:
已结题
起止时间:
2015-01-01 至 2016-12-31

项目摘要

项目成果

Lie, David的其他基金

相似基金

相关文献

中文摘要
翻译
软件供应链攻击--恶意软件被秘密插入到客户开发和最终使用之间的链中某个地方的信誉良好的软件中的攻击,已经成为一个越来越令人担忧的问题。 供应链攻击有可能影响企业、公共组织和个人用户,对各种用户都构成威胁。 传统的防御措施,如防病毒扫描程序,在很大程度上是无效的,因为这些攻击所存放的恶意软件通常是定制的,并且可以悄悄地嵌入到最终用户通常高度信任的代码中。 在这个合作项目中,我们将通过研究和设计新的代码分析技术来解决这一威胁,这些技术可以检测和识别软件供应链攻击。 传统的恶意软件检测技术需要足够便宜才能在每台机器上运行,这将它们限制在相当便宜的语法,基于签名的检测机制上,这些机制几乎无法理解它正在扫描的代码的行为。 然而,在云计算服务中发现的大量容易获得的并行计算能力,与快速网络连接的广泛可用性相结合,激发了一种方法,其中代码分析技术可以集中应用,然后将结果传播到所有终端主机。 这为计算密集型但功能强大的静态和动态分析技术打开了大门,这些技术不仅仅是试图检测代码是否与某些先前已知的签名匹配,而是试图理解和分析不受信任的软件的潜在行为,以查看它是否包含任何恶意意图。
英文摘要
Software supply chain attacks -- attacks where malware is covertly inserted into reputable and otherwise benign software somewhere in the chain between development and final use by the customer have become a growing concern. With the potential to affect enterprises, public organizations and individual users, supply chain attacks are a threat to users of every kind. Traditional defenses, such as anti-virus scanners are largely ineffective as the malware deposited by these attacks are often custom crafted and can be stealthily embedded in code that is normally highly trusted by the end user. In this collaborative project, we will address this threat by investigating and designing new code analysis techniques that can detect and identify software supply chain attacks. Traditional malware detection techniques needed to be cheap enough to run on each machine, limiting them to fairly cheap syntactic, signature-based detection mechanisms that did little to try to understand the behavior of the code it was scanning. However, the large amounts of easily available parallel computing power found in cloud computing services, combined with the broad availability of fast network connectivity, motivates an approach where code analysis techniques can be applied centrally and then the results are disseminated to all end hosts. This opens the door to very computationally intensive, but powerful static and dynamic analysis techniques which, instead of merely seeking to detect if the code matches some a previously known signature, seeks instead to understand and analyze the potential behavior of an untrusted piece of software to see if it harbors any malicious intent.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
A Machine Learning Approach to Detecting Security Vulnerabilities in Software.
  • 批准号:
    RGPIN-2018-05931
  • 项目类别:
    Discovery Grants Program - Individual
  • 资助金额:
    $2.04万
  • 财政年份:
    2022
  • 负责人:
    Lie, David
  • 依托单位:
Secure and Reliable Systems
  • 批准号:
    CRC-2019-00242
  • 项目类别:
    Canada Research Chairs
  • 资助金额:
    $14.57万
  • 财政年份:
    2022
  • 负责人:
    Lie, David
  • 依托单位:
A Machine Learning Approach to Detecting Security Vulnerabilities in Software.
  • 批准号:
    RGPIN-2018-05931
  • 项目类别:
    Discovery Grants Program - Individual
  • 资助金额:
    $2.04万
  • 财政年份:
    2021
  • 负责人:
    Lie, David
  • 依托单位:
Tools and methods for detecting vulnerabilities in embedded devices
  • 批准号:
    535902-2018
  • 项目类别:
    Collaborative Research and Development Grants
  • 资助金额:
    $5.19万
  • 财政年份:
    2021
  • 负责人:
    Lie, David
  • 依托单位:
海外基金