ログイン 新規登録
言語:

WEKO3

  • トップ
  • ランキング
To
lat lon distance
To

Field does not validate



インデックスリンク

インデックスツリー

メールアドレスを入力してください。

WEKO

One fine body…

WEKO

One fine body…

アイテム

  1. シンポジウム
  2. シンポジウムシリーズ
  3. コンピュータセキュリティシンポジウム
  4. 2016

HTTPヘッダフィールドの可変性に基づくマルウェア感染端末の特定

https://ipsj.ixsq.nii.ac.jp/records/175793
https://ipsj.ixsq.nii.ac.jp/records/175793
615f2e9f-3e18-4514-ad12-463e5af43850
名前 / ファイル ライセンス アクション
IPSJCSS2016093.pdf IPSJCSS2016093.pdf (662.4 kB)
Copyright (c) 2016 by the Information Processing Society of Japan

WEKO

オープンアクセス
Item type Symposium(1)
公開日 2016-10-04
タイトル
タイトル HTTPヘッダフィールドの可変性に基づくマルウェア感染端末の特定
タイトル
言語 en
タイトル Detecting Malware-Infected Hosts Based on the Variability of HTTP Header Fields
言語
言語 jpn
キーワード
主題Scheme Other
主題 MWS,マルウェア,悪性通信,機械学習,テンプレート
資源タイプ
資源タイプ識別子 http://purl.org/coar/resource_type/c_5794
資源タイプ conference paper
著者所属
早稲田大学 基幹理工学研究科
著者所属
早稲田大学 基幹理工学研究科/NTT コミュニケーションズ株式会社
著者所属
早稲田大学 基幹理工学研究科
著者所属
早稲田大学 基幹理工学研究科
著者所属(英)
en
Graduate School of Fundamental Science and Engineering, Waseda University
著者所属(英)
en
Graduate School of Fundamental Science and Engineering, Waseda University / NTT Communications Corporation
著者所属(英)
en
Graduate School of Fundamental Science and Engineering, Waseda University
著者所属(英)
en
Graduate School of Fundamental Science and Engineering, Waseda University
著者名 水野, 翔

× 水野, 翔

水野, 翔

Search repository
畑田, 充弘

× 畑田, 充弘

畑田, 充弘

Search repository
森, 達哉

× 森, 達哉

森, 達哉

Search repository
後藤, 滋樹

× 後藤, 滋樹

後藤, 滋樹

Search repository
著者名(英) Sho, Mizuno

× Sho, Mizuno

en Sho, Mizuno

Search repository
Mitsuhiro, Hatada

× Mitsuhiro, Hatada

en Mitsuhiro, Hatada

Search repository
Tatsuya, Mori

× Tatsuya, Mori

en Tatsuya, Mori

Search repository
Shigeki, Goto

× Shigeki, Goto

en Shigeki, Goto

Search repository
論文抄録
内容記述タイプ Other
内容記述 マルウェアによる脅威は依然として顕著である.感染の対策を講じていても,日々現れる新種マルウェアによって端末が感染してしまう危険性は十分にある.本研究の目的は,マルウェアに感染している端末を特定することである.主要なアイデアは,HTTP パケットのヘッダに記録された膨大な情報の可変性に着目し,テンプレート化手法によって情報を集約する.その後に機械学習を適用することで,悪性通信と良性通信の弁別と,弁別に貢献した特徴の抽出を行う.評価実験では,90.5 % の高精度で悪性通信と良性通信の弁別が可能であることを示した.また,240,858 種類あった特徴量を最終的に 5,502 種類にまで削減することに成功した.
論文抄録(英)
内容記述タイプ Other
内容記述 Damage caused by malware has been a significant problem that needs to be addressed. Even if we take countermeasures for infection, there would be new malware which cannot be detected by known signatures. The purpose of this study is to identify devices that are likely infected with malware. It should cover new malware. Our key idea is to make use of various information in HTTP headers and aggregate the information by creating templates. We adopt a machine learning algorithm to classify observed traffic into two classes: legitimate and malicious. Through the extensive experiments, we demonstrate that our methodology can achieve up to 90.5% precision in discriminating between malicious traffic and legitimate one. We also succeeded in reducing the number of features from 240,858 to 5,502.
書誌レコードID
識別子タイプ NCID
関連識別子 ISSN 1882-0840
書誌情報 コンピュータセキュリティシンポジウム2016論文集

巻 2016, 号 2, p. 632-639, 発行日 2016-10-04
出版者
言語 ja
出版者 情報処理学会
戻る
0
views
See details
Views

Versions

Ver.1 2025-01-20 06:08:18.561605
Show All versions

Share

Mendeley Twitter Facebook Print Addthis

Cite as

エクスポート

OAI-PMH
  • OAI-PMH JPCOAR
  • OAI-PMH DublinCore
  • OAI-PMH DDI
Other Formats
  • JSON
  • BIBTEX

Confirm


Powered by WEKO3


Powered by WEKO3