@inproceedings{oai:ipsj.ixsq.nii.ac.jp:00201441, author = {レーナン, トゥアンアン and 大久保, 潤 and Tuan, Anh Le Nang and Jun, Ohkubo}, book = {コンピュータセキュリティシンポジウム2019論文集}, month = {Oct}, note = {クラスタリング手法のひとつに Expectation-Maximization (EM) アルゴリズムを用いたものがある.混合ガウス分布などを仮定したEMアルゴリズムがよく知られているが,同時期に収集できたデータ同士の類似度が高いという特徴を有するマルウェアデータに対して精度が悪くなる場合があること,年ごとに解析してしまうと全体のデータを有効活用できないこと,などの問題がある.これらの問題を解決するために,条件付き確率を利用した Conditional EM (CEM) アルゴリズムが提案されている.本研究では,時系列マルウェアデータに CEM アルゴリズムと EM アルゴリズムをそれぞれ適用し,クラスタリングの性能を比較する.その結果,特徴ベクトルの生成方法を表現力を高められるように工夫することにより,CEM アルゴリズムのほうが EM アルゴリズムよりも高い分類性能を示す可能性が示唆された., Expectation-Maximization (EM) algorithm is one of the famous methods for clustering. It is possible to use various probabilistic models in the EM algorithm, and a Gaussian mixture model is widely used. However, some of malware data sets collected in a similar time sometimes show high similarity, and a naive application of the EM algorithm gives sometimes a low accuracy in clustering. In addition, separate analysis for each year cannot use the entire data effectively. In order to solve these problems, the conditional EM (CEM) algorithm has been proposed, in which conditional probabilities are employed. In the present paper, the EM and CEM algorithms are applied to time-series data set of malware, and comparisons of the performance are given. The numerical results indicate that the CEM algorithm show higher classification performance than the EM algorithm by using adequate feature vectors with high-power of expression.}, pages = {1052--1058}, publisher = {情報処理学会}, title = {CEMアルゴリズムを用いたマルウェアのクラスタリング}, volume = {2019}, year = {2019} }