Intelligence-driven malware detection system
Intelligence-driven malware detection system
批准号:
RGPIN-2020-04701
负责人:
HabibiLAshkari, Arash
金额:
$2.11万
依托单位:
依托单位国家:
加拿大
项目类别:
Discovery Grants Program - Individual
财政年份:
2022
资助国家:
加拿大
项目状态:
已结题
起止时间:
2022-01-01 至 2023-12-31
中文摘要
在接下来的五年里,我将专注于推进智能驱动的恶意软件检测的研究,方法是识别和开发:恶意软件剖析分析:恶意软件编写者混淆恶意软件样本,以将恶意代码隐藏在合法可执行文件中,以逃避反恶意软件解决方案和篡改,而不更改其真实结构以利用目标计算机并保持完全未被检测到。由于本研究的主要贡献之一是设计自动的静态和动态恶意软件分析和检测,因此我在这一部分的研究工作将集中在以下几个方面:恶意软件分析、恶意软件归属、恶意软件作者归属、恶意软件行为模式创建和恶意软件表征。安全大数据分析:现代基础设施产生和发布的恶意软件数量每天都在爆炸式增长,导致产生的数据集太大、太复杂,而且变化太快,无法使用传统的分析和检测工具。在恶意软件检测领域,这些数据提供了丰富的信息来源,允许分析恶意软件的解剖结构,通常准确地指出薄弱环节和潜在的解决方案。在这一领域,我将专注于大规模系统上恶意软件的动态识别/构建和预测分析,目的是使用数据挖掘方法结合预测分析方法来设计不同基础设施上的恶意软件的综合行为模式。模式可视化技术:常见的可视化技术通常不是为恶意软件模式识别而设计的,因此我们需要微调的新技术来进行全面的恶意软件分析。恶意软件可视化应该具有优雅和视觉吸引力的设计,同时具有信息量大、交互和提供探索性功能。这些功能帮助分析人员首先掌握恶意软件行为的总体视图,使他们能够感知活动区域,然后允许进一步探索不正常的行为模式,帮助检测恶意软件或识别可能的威胁。因此,我将提供一种新的可视化技术,它将涵盖恶意软件分析器的位置、原因和方式。大量恶意软件数据集:现代恶意软件具有突变特征,如多态和变形,导致恶意软件家族和家族内部恶意软件变体的数量大幅增长。拥有一个可以从各个方面系统地表征恶意软件的恶意软件数据集,包括它们的安装方法、激活机制和恶意有效负载的性质,对于机器学习过程和模式定义至关重要。我将专注于收集大量可用的恶意软件并开发类似的恶意软件,以生成大量恶意软件库,以剖析、理解恶意代码并触发它,从而能够分析恶意软件的解剖结构并预测恶意软件家族的行为模式。
英文摘要
Over the next five years, I will focus on advancing research in intelligence-driven malware detection by identifying and developing: Malware anatomy analysis: Malware writers obfuscate malware samples to conceal malicious code inside a legitimate executable to evade antimalware solutions and tamper without changing its genuine structure to exploit target machines and remain fully undetected. Since one of the main contributions of this research is to design automated static and dynamic malware analysis and detection, my research activities in this part will focus on several areas: malware analysis, malware attribution, malware authorship attribution, malware behavior pattern creation and malware characterization. Security big data analytics: The amount of malware produced and published by modern infrastructures has been exploding daily, making the resulting data sets too large, too complex and too rapidly changing for traditional analysis and detection tools. In the malware detection domain, this data provides a rich source of information that allows for analysis of the anatomy of malware, often pinpointing weak spots and potential solutions. In this area, I will be concentrating on the dynamic recognition/structuring and predictive analysis of malware on large-scale systems with the aim of using data mining methods to incorporate predictive analytic methods to design a comprehensive behavioral pattern of malware on different infrastructure. A pattern visualization technique: Common visualization techniques are generally not designed for malware pattern recognition, so we require novel techniques fine-tuned for thorough malware analysis. Malware visualizations should have an elegant and visually appealing design, while being informative, interactive, and providing exploratory capabilities. These features assist an analyst to first grasp an overall view of the malware behavior, allowing them to perceive areas of activity, and second to permit further explorations of irregular behavioral patterns, assisting in the detection of malware or identification of possible threats. Therefore, I will provide a new visualization technique that will cover the where, why and how features for malware analyzer. A bank of malware datasets: Modern malware is designed with mutation characteristics, such as polymorphism and metamorphism, causing an enormous growth in the number of malware families, and malware variants inside the families. Having a malware dataset that can systematically characterize malware from various aspects, including their installation methods, activation mechanisms, and the nature of malicious payloads is vital to the machine learning process and pattern definition. I will focus to collect huge available malware and develop similar malware to generate a massive bank of malware to dissect, understand the malicious code, and trigger it, allowing for analysis of the anatomy of malware and prediction of behavior patterns for malware families.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Behaviour-Centric Cybersecurity
-
批准号:CRC-2021-00340
-
项目类别:Canada Research Chairs
-
资助金额:$6.92万
-
财政年份:2022
-
负责人:HabibiLAshkari, Arash
-
依托单位:
Intelligence-driven malware detection system
-
批准号:RGPIN-2020-04701
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.11万
-
财政年份:2021
-
负责人:HabibiLAshkari, Arash
-
依托单位:
国内基金
海外基金
Data-driven Recommendation System Construction of an Online Medical Platform Based on the Fusion of Information
-
批准号:--
-
项目类别:外国青年学者研究基金项目
-
资助金额:--
-
批准年份:2024
-
负责人:江洋子
-
依托单位:
基于Cache的远程计时攻击研究
-
批准号:60772082
-
项目类别:面上项目
-
资助金额:28.0万元
-
批准年份:2007
-
负责人:王韬
-
依托单位: