| 講演抄録/キーワード |
| 講演名 |
2018-03-08 09:20
IoTマルウェアに対する静的解析に基づいた類似度の有効性検証 ○伊沢亮一・班 涛(NICT)・鉄 穎(横浜国大)・吉岡克成(横浜国大/NICT)・井上大介(NICT) ICSS2017-69 |
| 抄録 |
(和) |
本稿では複数のIoT(Internet of Things)マルウェアを静的解析した結果から類似度行列を作成し,それがマルウェア分類に有効であるか否かを検証する.検証では逆アセンブルコードを基に作成した類似度行列をt-SNE(t-Distributed
Stochastic Neighbor Embedding)で2次元平面上に可視化し,同じマルウェア名をもつ検体同士が近くに配置されているかを確認する.ARMやMIPS,MIPSelで動作するIoTマルウェアそれぞれ5162検体,1904検体, 1595検体に対して検証した結果,作成した類似度行列が分類に有効であろうことが確認できた.従来のWindowsマルウェアの多くはパッキング(暗号化/圧縮)や難読化が施されており,静的解析では十分な情報が得られないことが知られている.これに対し,現状,IoTマルウェアには静的解析が有効であることを示した点に本稿の貢献がある. |
| (英) |
In this paper, we generate a similarity matrix between IoT (Internet of Things) malware samples based on their disassembly code. We then visualize the similarity matrix on a two dimensional plane with t-SNE (t-Distributed Stochastic Neighbor Embedding) to consider how the matrix will be working for malware classification. At this time, we use 5162, 1904, and 1595 IoT malware samples for ARM, MIPS, MIPSel architectures, respectively, and we conclude that the disassembly code was effective for generating similarity matrices. On the contrary, most Windows malware samples are packed (compressed and/or encrypted), and so static analysis including disassembly is not effective for them. Confirming that static analysis is still effective for IoT malware is a major contribution of ours in this paper. |
| キーワード |
(和) |
Internet of Things / マルウェア解析 / n-gram / Jaccard係数 / t-SNE / / / |
| (英) |
Internet of Things / Malware analysis / n-gram / Jaccard similarity / t-SNE / / / |
| 文献情報 |
信学技報, vol. 117, no. 481, ICSS2017-69, pp. 109-114, 2018年3月. |
| 資料番号 |
ICSS2017-69 |
| 発行日 |
2018-02-28 (ICSS) |
| ISSN |
Print edition: ISSN 0913-5685 Online edition: ISSN 2432-6380 |
著作権に ついて |
技術研究報告に掲載された論文の著作権は電子情報通信学会に帰属します.(許諾番号:10GA0019/12GB0052/13GB0056/17GB0034/18GB0034) |
| PDFダウンロード |
ICSS2017-69 |