{"updated":"2025-01-20T04:02:15.846465+00:00","metadata":{"_oai":{"id":"oai:ipsj.ixsq.nii.ac.jp:00182561","sets":["1164:3925:9071:9205"]},"path":["9205"],"owner":"11","recid":"182561","title":["ドライブ・パイ・ダウンロード攻撃によるインシデントを再現するフォレンジック支援システム"],"pubdate":{"attribute_name":"公開日","attribute_value":"2017-07-07"},"_buckets":{"deposit":"ceacb5ef-c7c2-482f-bc4f-9b57755e8a86"},"_deposit":{"id":"182561","pid":{"type":"depid","value":"182561","revision_id":0},"owners":[11],"status":"published","created_by":11},"item_title":"ドライブ・パイ・ダウンロード攻撃によるインシデントを再現するフォレンジック支援システム","author_link":["397957","397955","397954","397950","397956","397952","397953","397951"],"item_titles":{"attribute_name":"タイトル","attribute_value_mlt":[{"subitem_title":"ドライブ・パイ・ダウンロード攻撃によるインシデントを再現するフォレンジック支援システム"},{"subitem_title":"A Forensic Support System for Reproduction of Incidents Caused by Drive-by Download","subitem_title_language":"en"}]},"item_type_id":"4","publish_date":"2017-07-07","item_4_text_3":{"attribute_name":"著者所属","attribute_value_mlt":[{"subitem_text_value":"近畿大学理工学部情報学科"},{"subitem_text_value":"近畿大学理工学部情報学科"},{"subitem_text_value":"神戸大学大学院工学研究科電気電子工学専攻"},{"subitem_text_value":"近畿大学理工学部情報学科"}]},"item_4_text_4":{"attribute_name":"著者所属(英)","attribute_value_mlt":[{"subitem_text_value":"Faculty of Science and Engineering, Kindai University","subitem_text_language":"en"},{"subitem_text_value":"Faculty of Science and Engineering, Kindai University","subitem_text_language":"en"},{"subitem_text_value":"Kobe University,","subitem_text_language":"en"},{"subitem_text_value":"Faculty of Science and Engineering, Kindai University","subitem_text_language":"en"}]},"item_language":{"attribute_name":"言語","attribute_value_mlt":[{"subitem_language":"jpn"}]},"item_publisher":{"attribute_name":"出版者","attribute_value_mlt":[{"subitem_publisher":"情報処理学会","subitem_publisher_language":"ja"}]},"publish_status":"0","weko_shared_id":-1,"item_file_price":{"attribute_name":"Billing file","attribute_type":"file","attribute_value_mlt":[{"url":{"url":"https://ipsj.ixsq.nii.ac.jp/record/182561/files/IPSJ-CSEC17078016.pdf","label":"IPSJ-CSEC17078016.pdf"},"format":"application/pdf","billing":["billing_file"],"filename":"IPSJ-CSEC17078016.pdf","filesize":[{"value":"1.7 MB"}],"mimetype":"application/pdf","priceinfo":[{"tax":["include_tax"],"price":"0","billingrole":"30"},{"tax":["include_tax"],"price":"0","billingrole":"44"}],"accessrole":"open_login","version_id":"4a035d3c-3594-4ca2-a5a1-5f3744792ca3","displaytype":"detail","licensetype":"license_note","license_note":"Copyright (c) 2017 by the Institute of Electronics, Information and Communication Engineers This SIG report is only available to those in membership of the SIG."}]},"item_4_creator_5":{"attribute_name":"著者名","attribute_type":"creator","attribute_value_mlt":[{"creatorNames":[{"creatorName":"奥田, 裕樹"}],"nameIdentifiers":[{}]},{"creatorNames":[{"creatorName":"福田, 洋治"}],"nameIdentifiers":[{}]},{"creatorNames":[{"creatorName":"白石, 善明"}],"nameIdentifiers":[{}]},{"creatorNames":[{"creatorName":"井口, 信和"}],"nameIdentifiers":[{}]}]},"item_4_creator_6":{"attribute_name":"著者名(英)","attribute_type":"creator","attribute_value_mlt":[{"creatorNames":[{"creatorName":"Yuki, Okuda","creatorNameLang":"en"}],"nameIdentifiers":[{}]},{"creatorNames":[{"creatorName":"Youji, Fukuta","creatorNameLang":"en"}],"nameIdentifiers":[{}]},{"creatorNames":[{"creatorName":"Yoshiaki, Shiraishi","creatorNameLang":"en"}],"nameIdentifiers":[{}]},{"creatorNames":[{"creatorName":"Nobukazu, Iguchi","creatorNameLang":"en"}],"nameIdentifiers":[{}]}]},"item_4_source_id_9":{"attribute_name":"書誌レコードID","attribute_value_mlt":[{"subitem_source_identifier":"AA11235941","subitem_source_identifier_type":"NCID"}]},"item_4_textarea_12":{"attribute_name":"Notice","attribute_value_mlt":[{"subitem_textarea_value":"SIG Technical Reports are nonrefereed and hence may later appear in any journals, conferences, symposia, etc."}]},"item_resource_type":{"attribute_name":"資源タイプ","attribute_value_mlt":[{"resourceuri":"http://purl.org/coar/resource_type/c_18gh","resourcetype":"technical report"}]},"item_4_source_id_11":{"attribute_name":"ISSN","attribute_value_mlt":[{"subitem_source_identifier":"2188-8655","subitem_source_identifier_type":"ISSN"}]},"item_4_description_7":{"attribute_name":"論文抄録","attribute_value_mlt":[{"subitem_description":"本研究では,端末にマルウェアを送る主要な手段の 1 つであるドライブ ・ パイ ・ ダウンロード攻撃 (DBD 攻撃) を含むインシデントを想定し,マルウェアの感染と活動の調査を支援するシステムを開発する.本システムは,インシデント発生時の通信パケットの記録から DBD 攻撃に関連する悪性 Web サイトへのリクエストとそのレスポンス,Web クライアントの動作を再現する.悪性 Web サイトは作られてから姿を消すまでの期間が短く,端末に設置されたマルウェアが活動後に消失,または攻撃者が痕跡を消去 ・ 攪乱すると,事後の調査が困難になる.インシデント対応の初動や調査の場面で本システムを用いることで DBD 攻撃によるマルウェア感染の過程が再現できる.これをインシデントが観測 ・ 記録できる環境で実施することでマルウェア感染の過程と活動の痕跡の収集と記録を支援する.","subitem_description_type":"Other"}]},"item_4_description_8":{"attribute_name":"論文抄録(英)","attribute_value_mlt":[{"subitem_description":"In this research, we have developed a system that supports investigation of malware infections and activities in Drive-by Download attack which is one of the dominant tool of sending malware to terminals. This system reproduces HTTP requests, responses and behavior of malicious website related to the Drive-by Download attack from the raw packets of the communication at the time of the incident occurs. As a malicious website is disappeared in a short period, when malware installed in the terminal disappears after the activity or an attacker erases / disturbs the evidence, it becomes difficult to investigation. By using this system at the initial stage and investigation of incident handling, the process of malware infection caused by Drive-by Download attack can be reproduced. Using of this system in an environment where the incident can observe and record, it supports to collect the malware infection process and its activity.","subitem_description_type":"Other"}]},"item_4_biblio_info_10":{"attribute_name":"書誌情報","attribute_value_mlt":[{"bibliographicPageEnd":"6","bibliographic_titles":[{"bibliographic_title":"研究報告コンピュータセキュリティ(CSEC)"}],"bibliographicPageStart":"1","bibliographicIssueDates":{"bibliographicIssueDate":"2017-07-07","bibliographicIssueDateType":"Issued"},"bibliographicIssueNumber":"16","bibliographicVolumeNumber":"2017-CSEC-78"}]},"relation_version_is_last":true,"weko_creator_id":"11"},"created":"2025-01-19T00:50:09.480825+00:00","id":182561,"links":{}}