| 講演抄録/キーワード |
| 講演名 |
2017-03-02 09:30
C&Cセッション分類によるボット感染PC検出手法 ○師井日向子・川原崎雅敏(筑波大) IN2016-99 |
| 抄録 |
(和) |
トラフィックの特性解析によるマルウェア検出では,汎用的な検出手法や特定のマルウェアに特化した手法が研究されている.本研究では,ボットネットを対象に,既存手法を組み合わせて検出精度を向上させる手法を提案し,実データに適用してその有効性を示す.ボットネットの検出は,踏み台となる端末を制御しているC&Cサーバを検出する方法が一般的である.本研究ではTCPトラフィックを監視し,その特徴を機械学習手法で分類することで,C&Cサーバとの通信をより高い精度で検出できることを示す. |
| (英) |
In malware detection by traffic characterization analysis, general-purpose detection and methods specialized to specific malware are being studied. In this paper, we propose a method for improving detection accuracy by combining existing methods for botnets, and apply it to actual data to show its effectiveness. Botnet detection is a method of detecting a C&C server in general. In this paper, by monitoring TCP traffic and classifying its characteristics by a machine learning method, we show that communication with C&C server can be detected with higher accuracy. |
| キーワード |
(和) |
C&Cサーバ / ボットネット / 異常検出 / / / / / |
| (英) |
C&C server / botnet / anomaly detection / / / / / |
| 文献情報 |
信学技報, vol. 116, no. 485, IN2016-99, pp. 13-18, 2017年3月. |
| 資料番号 |
IN2016-99 |
| 発行日 |
2017-02-23 (IN) |
| ISSN |
Print edition: ISSN 0913-5685 Online edition: ISSN 2432-6380 |
著作権に ついて |
技術研究報告に掲載された論文の著作権は電子情報通信学会に帰属します.(許諾番号:10GA0019/12GB0052/13GB0056/17GB0034/18GB0034) |
| PDFダウンロード |
IN2016-99 |