| 講演抄録/キーワード |
| 講演名 |
2006-10-17 14:15
[招待講演]nicter: An Incident Analysis System for the Global Internet using Correlation between Network Monitoring and Malware Analysis Koji Nakao・○Katsunari Yoshioka・Masashi Eto・Daisuke Inoue・Kenji Rikitake(NICT) |
| 抄録 |
(和) |
As network security incidents are being more complex and serious, activities of network monitoring, incident analysis and response are becoming increasingly important. In this paper, we propose an incident analysis system called nicter. The nicter monitors wide range of networks by distributed sensors for detecting an incident candidate (IC), such as unseen attacking behaviors or a sudden increase of certain type of traffics, which may indicate the occurrence of incidents. The nicter also keeps collecting malware executables in the wild using various malware capturing techniques and analyzing their internal and external behaviors and characteristics. The macroscopic analysis results from network monitoring and microscopic analysis results from malware analysis are correlated so that the detected ICs are bound with their possible root causes, namely propagations of malwares. We describe the macro-micro correlation with an actual analysis case as well as explaining the role of each analysis method. |
| (英) |
As network security incidents are being more complex and serious, activities of network monitoring, incident analysis and response are becoming increasingly important. In this paper, we propose an incident analysis system called nicter. The nicter monitors wide range of networks by distributed sensors for detecting an incident candidate (IC), such as unseen attacking behaviors or a sudden increase of certain type of traffics, which may indicate the occurrence of incidents. The nicter also keeps collecting malware executables in the wild using various malware capturing techniques and analyzing their internal and external behaviors and characteristics. The macroscopic analysis results from network monitoring and microscopic analysis results from malware analysis are correlated so that the detected ICs are bound with their possible root causes, namely propagations of malwares. We describe the macro-micro correlation with an actual analysis case as well as explaining the role of each analysis method. |
| キーワード |
(和) |
ネットワークセキュリティ / インシデント分析システム / ネットワークモニタリング / マルウェア解析 / integrated incident handling and response / / / |
| (英) |
network security / incident analysis system / network monitoring / malware analysis / integrated incident handling and response / / / |
| 文献情報 |
信学技報, vol. 106, no. 292, DC2006-30, pp. 25-30, 2006年10月. |
| 資料番号 |
DC2006-30 |
| 発行日 |
2006-10-10 (DE, DC) |
| ISSN |
Print edition: ISSN 0913-5685 |
| PDFダウンロード |
|
|