| 講演抄録/キーワード |
| 講演名 |
2021-03-01 09:35
DNSトラフィックを用いた感染端末の検知手法 ○向後宗一郎・金井 敦(法政大) ICSS2020-27 |
| 抄録 |
(和) |
マルウェアによる被害は年々より顕著になっていくことが考えられる.しかし,ネットワークに接続されるすべての端末を管理するのは多大な労力が必要となる.そこで,端末側ではなくネットワークトラフィックを観察することで,不正トラフィックを検知する.端末依存ではないため,端末側に負担をかけることなく感染端末を特定でき,有効と考えられる.本論文では,感染した場合に変化が現れると想定されるDNSトラフィックを対象に分析することにより,BOT化した端末の検知手法を提案する.不正トラフィックの判定には,DNSパケットのAレコードから取得できる特徴量と機械学習としてRandom Forestを用い,実際に検証した.その結果,高い精度と高速な判定が可能であることを実証した. |
| (英) |
The damage caused by computer viruses is becoming a serious problem. However, it requires a lot of effort to manage all the terminals connected to the network. Therefore, we focus on the network traffic instead of the terminal side. Since it doesn't depend on the terminal, it is effective in identifying infected terminals without placing a burden on the terminal side. In this paper, we propose a method for detecting BOT by analyzing DNS traffic, which is assumed to change when infected. We used features obtained from A-records of DNS packets and Random Forest as a machine learning method to determine unauthorized traffic. As a result, we have demonstrated that it is possible to achieve high-accuracy and high-speed detection. |
| キーワード |
(和) |
機械学習 / 検知 / セキュリティ / マルウェア / ボット / BOT / DNS / IoT |
| (英) |
Machine Learning / Detection / Security / Malware / BOT / DNS / IoT / |
| 文献情報 |
信学技報, vol. 120, no. 384, ICSS2020-27, pp. 7-12, 2021年3月. |
| 資料番号 |
ICSS2020-27 |
| 発行日 |
2021-02-22 (ICSS) |
| ISSN |
Online edition: ISSN 2432-6380 |
著作権に ついて |
技術研究報告に掲載された論文の著作権は電子情報通信学会に帰属します.(許諾番号:10GA0019/12GB0052/13GB0056/17GB0034/18GB0034) |
| PDFダウンロード |
ICSS2020-27 |