| Item type |
Symposium(1) |
| 公開日 |
2016-10-04 |
| タイトル |
|
|
タイトル |
HTTPヘッダフィールドの可変性に基づくマルウェア感染端末の特定 |
| タイトル |
|
|
言語 |
en |
|
タイトル |
Detecting Malware-Infected Hosts Based on the Variability of HTTP Header Fields |
| 言語 |
|
|
言語 |
jpn |
| キーワード |
|
|
主題Scheme |
Other |
|
主題 |
MWS,マルウェア,悪性通信,機械学習,テンプレート |
| 資源タイプ |
|
|
資源タイプ識別子 |
http://purl.org/coar/resource_type/c_5794 |
|
資源タイプ |
conference paper |
| 著者所属 |
|
|
|
早稲田大学 基幹理工学研究科 |
| 著者所属 |
|
|
|
早稲田大学 基幹理工学研究科/NTT コミュニケーションズ株式会社 |
| 著者所属 |
|
|
|
早稲田大学 基幹理工学研究科 |
| 著者所属 |
|
|
|
早稲田大学 基幹理工学研究科 |
| 著者所属(英) |
|
|
|
en |
|
|
Graduate School of Fundamental Science and Engineering, Waseda University |
| 著者所属(英) |
|
|
|
en |
|
|
Graduate School of Fundamental Science and Engineering, Waseda University / NTT Communications Corporation |
| 著者所属(英) |
|
|
|
en |
|
|
Graduate School of Fundamental Science and Engineering, Waseda University |
| 著者所属(英) |
|
|
|
en |
|
|
Graduate School of Fundamental Science and Engineering, Waseda University |
| 著者名 |
水野, 翔
畑田, 充弘
森, 達哉
後藤, 滋樹
|
| 著者名(英) |
Sho, Mizuno
Mitsuhiro, Hatada
Tatsuya, Mori
Shigeki, Goto
|
| 論文抄録 |
|
|
内容記述タイプ |
Other |
|
内容記述 |
マルウェアによる脅威は依然として顕著である.感染の対策を講じていても,日々現れる新種マルウェアによって端末が感染してしまう危険性は十分にある.本研究の目的は,マルウェアに感染している端末を特定することである.主要なアイデアは,HTTP パケットのヘッダに記録された膨大な情報の可変性に着目し,テンプレート化手法によって情報を集約する.その後に機械学習を適用することで,悪性通信と良性通信の弁別と,弁別に貢献した特徴の抽出を行う.評価実験では,90.5 % の高精度で悪性通信と良性通信の弁別が可能であることを示した.また,240,858 種類あった特徴量を最終的に 5,502 種類にまで削減することに成功した. |
| 論文抄録(英) |
|
|
内容記述タイプ |
Other |
|
内容記述 |
Damage caused by malware has been a significant problem that needs to be addressed. Even if we take countermeasures for infection, there would be new malware which cannot be detected by known signatures. The purpose of this study is to identify devices that are likely infected with malware. It should cover new malware. Our key idea is to make use of various information in HTTP headers and aggregate the information by creating templates. We adopt a machine learning algorithm to classify observed traffic into two classes: legitimate and malicious. Through the extensive experiments, we demonstrate that our methodology can achieve up to 90.5% precision in discriminating between malicious traffic and legitimate one. We also succeeded in reducing the number of features from 240,858 to 5,502. |
| 書誌レコードID |
|
|
|
識別子タイプ |
NCID |
|
|
関連識別子 |
ISSN 1882-0840 |
| 書誌情報 |
コンピュータセキュリティシンポジウム2016論文集
巻 2016,
号 2,
p. 632-639,
発行日 2016-10-04
|
| 出版者 |
|
|
言語 |
ja |
|
出版者 |
情報処理学会 |