| Item type |
Symposium(1) |
| 公開日 |
2011-10-12 |
| タイトル |
|
|
タイトル |
マルウェア感染検知のための経年変化を考慮した特徴量評価に関する一考察 |
| タイトル |
|
|
言語 |
en |
|
タイトル |
A study of feature evaluation considering effects of year for malware detection |
| 言語 |
|
|
言語 |
jpn |
| キーワード |
|
|
主題Scheme |
Other |
|
主題 |
攻撃通信データ |
| 資源タイプ |
|
|
資源タイプ識別子 |
http://purl.org/coar/resource_type/c_5794 |
|
資源タイプ |
conference paper |
| 著者所属 |
|
|
|
早稲田大学 基幹理工学研究科 情報理工学専攻 |
| 著者所属 |
|
|
|
早稲田大学 基幹理工学研究科 情報理工学専攻 |
| 著者所属 |
|
|
|
電気通信大学 大学院情報理工学研究科総合情報学専攻 |
| 著者所属 |
|
|
|
NTT コミュニケーションズ株式会社 |
| 著者所属 |
|
|
|
早稲田大学 基幹理工学研究科 情報理工学専攻 |
| 著者所属(英) |
|
|
|
en |
|
|
Graduate School of Fundamental Science and Engineering, Waseda University |
| 著者所属(英) |
|
|
|
en |
|
|
Graduate School of Fundamental Science and Engineering, Waseda University |
| 著者所属(英) |
|
|
|
en |
|
|
The University of Electro-Communications |
| 著者所属(英) |
|
|
|
en |
|
|
NTT communications Corporation |
| 著者所属(英) |
|
|
|
en |
|
|
Graduate School of Fundamental Science and Engineering, Waseda University |
| 著者名 |
川元, 研治
市田, 達也
市野, 正嗣
畑田, 充弘
小松, 尚久
|
| 著者名(英) |
Kenji, Kawamoto
Tatsuya, Ichida
Masatsugu, Ichino
Mitsuhiro, Hatada
Naohisa, Komatsu
|
| 論文抄録 |
|
|
内容記述タイプ |
Other |
|
内容記述 |
本研究では,マルウェア感染検知の既存研究でよく用いられている特徴量に対して,マルウェアに感染している感染トラヒックとマルウェアに感染していない正常トラヒックの識別実験により特徴量評価を行った.その際,特徴量毎にベクトル量子化で作成した正常時,感染時のコードブックとテストデータとの特徴空間上での距離を用いて識別を行った.本稿では,感染トラヒックデータとしてCCCDATAset,正常トラヒックデータとして同じデータ収集日におけるあるイントラネットのトラヒックデータを使用して,年によらずマルウェア感染検知において有効である特徴量について考察した結果を報告する. |
| 論文抄録(英) |
|
|
内容記述タイプ |
Other |
|
内容記述 |
In this paper, we evaluated features used in existing researches based on the experiment that showed how each features could discriminate anomaly traffic that was infected with malware from normal traffic that was not infected with malware. In this evaluation, we made discriminations using the distance between the normal or anomaly codebook made by each features using vector quantization and test data. In this paper, we used CCCDATAset as anomaly traffic data, some traffic data on an intranet which was the same date as anomaly traffic data as normal traffic. Then we report our consideration which features are effective for malware detection with no relation to year effects. |
| 書誌情報 |
コンピュータセキュリティシンポジウム2011 論文集
巻 2011,
号 3,
p. 277-282,
発行日 2011-10-12
|
| 出版者 |
|
|
言語 |
ja |
|
出版者 |
情報処理学会 |