课题基金 / 基金详情

Towards Malware Author Attribution

Towards Malware Author Attribution
走向恶意软件作者归属
批准号:
RGPIN-2015-04102
负责人:
Stakhanova, Natalia
金额:
$1.31万
依托单位:
依托单位国家:
加拿大
项目类别:
Discovery Grants Program - Individual
财政年份:
2016
资助国家:
加拿大
项目状态:
已结题
起止时间:
2016-01-01 至 2017-12-31

项目摘要

项目成果

Stakhanova, Natalia的其他基金

相似基金

相关文献

中文摘要
翻译
2008年,赛门铁克向其恶意软件数据库添加了160万个新的恶意软件签名。这一数字在2009年增加到290万。2010年,数据库的新成员构成了440万个新签名。这一趋势仍在继续,2011年恶意软件的增长达到了41%。传统的方法主要是基于识别记录良好的威胁(签名),难以应对每年恶意软件数量的这种增长速度。因此,大多数恶意软件菌株(其中许多是短暂的,即不到24小时)没有被检测到。传统防御方法的这种不足暴露了对替代防御的迫切需要。我们建议将注意力转向恶意软件来源,即恶意软件作者。这样的攻击策略的好处是显而易见的:我们可以有效地表征由其作者生成的所有恶意软件变体,而不是检测每个恶意软件菌株。我们建议对恶意软件作者归属背后的理论和实践进行研究。作者归属是一种根据作者以前作品中提取的作者写作风格的文本特征来确定文档作者的技术,虽然在社会科学中已经很成熟,但它在恶意软件检测领域提出了许多研究问题。例如,我们如何定义作者(例如,恶意软件生成引擎、恶意软件活动、个人),以便能够利用它进行自动和准确的检测,以及源代码和二进制代码在多大程度上嵌入了可追溯到其作者的不同功能。
英文摘要
In 2008 Symantec added 1.6 million new malware signatures to its malware database. This number increased to 2.9 million in 2009. In 2010, the new addition to the database constituted 4.4 million new signatures. This trend continued, and in 2011 an increase in malware has reached 41%. Traditional approaches predominantly based on recognizing well-documented threats (signatures) are struggling to cope with this rate of growth in malware numbers each year. Consequently, the majority of malware strains (many of which are short lived, i.e., less than 24 hours) go undetected. This inadequacy of traditional approaches exposes a dire need for alternative defences. We propose to turn our attention to malware source, i.e, malware authors. The benefit of such a strategy is clear: instead of detecting every malware strain, we could effectively characterize all malware variants generated by its author. We propose to study the theory and practice behind malware author attribution. Although authorship attribution, a technique aiming to determine an author of a document given some textual characteristics of the author’s writing style extracted from his previous works, is well established in social science, it raises many research questions in malware detection domain. For example, how can we define an author (e.g., malware generation engine, a malware campaign, an individual) so that it can be leveraged for automatic and accurate detection, and to what extend source and binary code embed distinct features traceable to its author.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Subverting adversarial attribution
  • 批准号:
    RGPIN-2020-06319
  • 项目类别:
    Discovery Grants Program - Individual
  • 资助金额:
    $2.11万
  • 财政年份:
    2022
  • 负责人:
    Stakhanova, Natalia
  • 依托单位:
Security and Privacy
  • 批准号:
    CRC-2018-00254
  • 项目类别:
    Canada Research Chairs
  • 资助金额:
    $8.74万
  • 财政年份:
    2022
  • 负责人:
    Stakhanova, Natalia
  • 依托单位:
Attribution of phishing email campaigns
  • 批准号:
    568654-2021
  • 项目类别:
    Alliance Grants
  • 资助金额:
    $2.91万
  • 财政年份:
    2021
  • 负责人:
    Stakhanova, Natalia
  • 依托单位:
Subverting adversarial attribution
  • 批准号:
    RGPIN-2020-06319
  • 项目类别:
    Discovery Grants Program - Individual
  • 资助金额:
    $2.11万
  • 财政年份:
    2021
  • 负责人:
    Stakhanova, Natalia
  • 依托单位:
海外基金