ログイン 新規登録
言語:

WEKO3

  • トップ
  • ランキング
To
lat lon distance
To

Field does not validate



インデックスリンク

インデックスツリー

メールアドレスを入力してください。

WEKO

One fine body…

WEKO

One fine body…

アイテム

  1. シンポジウム
  2. シンポジウムシリーズ
  3. コンピュータセキュリティシンポジウム
  4. 2023

標的型マルウェアの鮮度と攻撃観測成功率の関連性調査手法

https://ipsj.ixsq.nii.ac.jp/records/228622
https://ipsj.ixsq.nii.ac.jp/records/228622
ae0c7df2-7df8-4072-9d34-6c4b17fbdb5e
名前 / ファイル ライセンス アクション
IPSJ-CSS2023009.pdf IPSJ-CSS2023009.pdf (490.1 kB)
Copyright (c) 2023 by the Information Processing Society of Japan

WEKO

オープンアクセス
Item type Symposium(1)
公開日 2023-10-23
タイトル
タイトル 標的型マルウェアの鮮度と攻撃観測成功率の関連性調査手法
タイトル
言語 en
タイトル An Investigation Method for Revealing Relation between Targeted-Attack Malware Freshness and Attack Observation Success Rate
言語
言語 jpn
キーワード
主題Scheme Other
主題 生体認証 距離学習 カリキュラム学習 顔認証 公平性
資源タイプ
資源タイプ識別子 http://purl.org/coar/resource_type/c_5794
資源タイプ conference paper
著者所属
立命館大学
著者所属
Turnt Up Technologies株式会社/立命館大学
著者所属
立命館大学
著者所属
立命館大学
著者所属(英)
en
Ritsumeikan University
著者所属(英)
en
Turnt Up Technologies, Inc. / Ritsumeikan University
著者所属(英)
en
Ritsumeikan University
著者所属(英)
en
Ritsumeikan University
著者名 河原, 晃平

× 河原, 晃平

河原, 晃平

Search repository
津田, 侑

× 津田, 侑

津田, 侑

Search repository
金城, 聖

× 金城, 聖

金城, 聖

Search repository
毛利, 公一

× 毛利, 公一

毛利, 公一

Search repository
著者名(英) Kohei, Kawahara

× Kohei, Kawahara

en Kohei, Kawahara

Search repository
Yu, Tsuda

× Yu, Tsuda

en Yu, Tsuda

Search repository
Akira, Kanashiro

× Akira, Kanashiro

en Akira, Kanashiro

Search repository
Koichi, Mouri

× Koichi, Mouri

en Koichi, Mouri

Search repository
論文抄録
内容記述タイプ Other
内容記述 標的型攻撃の実態を把握するためには,攻撃者が使用する標的型マルウェアの機能を明らかにするだけでなく,攻撃者がC&C サーバを介して標的組織に侵入し行う活動を観測・分析することが重要となる.実態を把握する上で,標的型マルウェアを入手する必要があるが,一般的に,攻撃者が利用したマルウェアを標的組織から直接入手することは困難であるため,解析者はVirusTotal に代表されるマルウェア検査サービスに投稿されたマルウェアを入手・解析することになる.特に,攻撃に使用されるC&C サーバの活
動時間が極端に短い場合が多いことから,解析者はマルウェア検査サービスに投稿されたマルウェアのなかでも,投稿されて間もないマルウェアの解析を試みる.しかし,投稿されて間もないマルウェアを用いた解析がもたらす攻撃者の活動やその観測結果への影響については議論が乏しい.そこで,マルウェア検査サービスへマルウェアが投稿されてからの経過時間によって鮮度を定義し,鮮度が攻撃者の挙動観測に与える影響を調査する.本論文では,鮮度と攻撃観測成功確率の関連性を調査するための方法を提案する.
論文抄録(英)
内容記述タイプ Other
内容記述 In order to understand the real situation of targeted attacks, it is important to analyze the activities of RAT operators via C&C servers, not only to clarify the functions of targeted-attack malware. It is necessary to obtain targeted-attack malware for grasp the actual situation. In general, however, it is difficult to obtain malware used by attackers directly from the target organizations, so analysts obtain malware from malware scanning services such as VirusTotal. In particular, since the lifetime of the C&C servers used in attacks is often extremely short, analysts attempt to analyze malware that has been submitted to malware inspection services for a short period of time after it is submitted. However, there is little discussion aboutthe impact of the analysis using that malware on the observation results. Therefore, we use freshness that
is defined by the time elapsed since the malware was submitted to a malware inspection service. Then We investigate the impact of freshness on the observation of attacker behavior. In this paer, we propose an investigation method for revealing relationship between freshness and attack observation success rate.
書誌情報 コンピュータセキュリティシンポジウム2023論文集

p. 57-62, 発行日 2023-10-23
出版者
言語 ja
出版者 情報処理学会
戻る
0
views
See details
Views

Versions

Ver.1 2025-01-19 11:47:19.670565
Show All versions

Share

Mendeley Twitter Facebook Print Addthis

Cite as

エクスポート

OAI-PMH
  • OAI-PMH JPCOAR
  • OAI-PMH DublinCore
  • OAI-PMH DDI
Other Formats
  • JSON
  • BIBTEX

Confirm


Powered by WEKO3


Powered by WEKO3