| Item type |
Symposium(1) |
| 公開日 |
2015-10-14 |
| タイトル |
|
|
タイトル |
エキスパートによるマルウェア解析レポートと動的解析ログの相関分析 |
| タイトル |
|
|
言語 |
en |
|
タイトル |
Correlating Experts' Malware Analysis Reports and Dynamic Malware Analysis Logs |
| 言語 |
|
|
言語 |
jpn |
| キーワード |
|
|
主題Scheme |
Other |
|
主題 |
MWS,マルウェア |
| 資源タイプ |
|
|
資源タイプ識別子 |
http://purl.org/coar/resource_type/c_5794 |
|
資源タイプ |
conference paper |
| 著者所属 |
|
|
|
早稲田大学 |
| 著者所属 |
|
|
|
早稲田大学 |
| 著者所属(英) |
|
|
|
en |
|
|
School of Fundamental Science and Engineering, Waseda University |
| 著者所属(英) |
|
|
|
en |
|
|
School of Fundamental Science and Engineering, Waseda University |
| 著者名 |
藤野, 朗稚
森, 達哉
|
| 著者名(英) |
Akinori, Fujino
Tatsuya, Mori
|
| 論文抄録 |
|
|
内容記述タイプ |
Other |
|
内容記述 |
アンチウィルスベンダーは日々大量のマルウェアを解析し,その結果はマルウェア解析レポートとしてデータベースに蓄積されている.一般にマルウェア解析レポートは自然言語で記述されており,実際に使用された API や引数の詳細などは陽に書かれていない.また,解析レポートはマルウェア種別毎に独立しているため,同じ挙動を持つ他の種別を調べることは難しい.本論文では,マルウェア解析のエキスパートによる解析レポートと動的解析ログを対応付けるデータベースの作成を狙いとする.このデータベースを使うことにより,動的解析ログから悪性挙動を自動的に検出可能となることが期待される.実データを用いた解析の結果,異なるマルウェア種別や種別不明のマルウェアからも共通する悪性挙動が検出可能であることが明らかになった. |
| 論文抄録(英) |
|
|
内容記述タイプ |
Other |
|
内容記述 |
Anti-virus vendors analyze a huge number of malware samples. Their analysis reports are stored on a database. In general, malware analysis reports are written in natural languages and do not include details of API calls and their arguments. This work aims to develop a database which relates malicious behaviors and dyanmic analysis logs. Such database enables us to automatically detect malicious behaviors from dynamic analysis logs. Using actual dynamic analysis logs of malware samples, we verified that a common set of malicious behaviors can be extracted from multiple, distinct malware samples and even from unclassified malware samples. |
| 書誌情報 |
コンピュータセキュリティシンポジウム2015論文集
巻 2015,
号 3,
p. 702-709,
発行日 2015-10-14
|
| 出版者 |
|
|
言語 |
ja |
|
出版者 |
情報処理学会 |