SBIR-STTR Award

Anti-Malcious Source Scanner
Award last edited on: 2/20/2007

Sponsored Program
SBIR
Awarding Agency
DOD : MDA
Total Award Amount
$100,000
Award Phase
1
Solicitation Topic Code
MDA04-092
Principal Investigator
Luis Lopez

Company Information

2LResearch Corporation

PO Box 18034
Huntsville, AL 35804
   (256) 656-9652
   luis@hiwaay.net
   www.2lresearch.com
Location: Single
Congr. District: 05
County: Madison

Phase I

Contract Number: ----------
Start Date: ----    Completed: ----
Phase I year
2005
Phase I Amount
$100,000
2LR proposes to develop a malicious source code scanner that can flag sections of potentially `bad' source code that is vulnerable to exploitation or may contain latent malicious content. This effort will evaluate and compare current methods for detecting malicious code with a novel method based on code-logic signature analysis and discrimination. It will develop pattern classes that are associated with patterns of logic instructions present within actual malcode specimens. We expect malcode control flow logic patterns to cluster in `pattern space' (i.e. revealing code logic pedigrees). This is because specific algorithmic logic must be used to effect specific behaviors. Specific exploits are achieved by specific behaviors. The logic that codes malicious (exploitive) behavior becomes the signature. If a group of malware specimens all use the same exploitive behavior, their signatures will all have similar traits. In some sense, this is akin to DNA patterns and how they also cluster for different pedigrees

Phase II

Contract Number: ----------
Start Date: ----    Completed: ----
Phase II year
----
Phase II Amount
----