ご案内 入会して研究会活動をもっとお得に!研究会参加費・年間登録費が会員価格になります。
お知らせ 【重要】研究会参加費の支払いおよび原稿アップロード手続きの変更に関するご案内
電子情報通信学会 研究会発表申込システム
講演論文 詳細
技報閲覧サービス
[ログイン]
技報アーカイブ
 トップに戻る 前のページに戻る   [Japanese] / [English] 

講演抄録/キーワード
講演名 2021-10-15 16:50
IPフロー情報を利用した確定時間でのマルウェアトラフィック検知
小松聖矢桂 祐成垣内正年新井イスマイル藤川和利奈良先端大IA2021-27
抄録 (和) ボットネットやランサムウェア等のマルウェアの活動による被害が社会問題となっている.マルウェアの活動を効率的に検知し被害を低減するため,その活動トラフィックをネットワーク上で検知する研究が提案されている.これらの研究で利用されるトラフィック情報には,パケット情報,IPフロー情報,Interfaceカウンタ情報の3種類がある.IPフロー情報を用いる場合,5タプルでトラフィックが集約され軽量だが,タイムアウトが発生するかコネクションが終了するまで情報が出力されず,スキャン活動や長期間継続するフローに対し早期の検知が困難である.
本研究では,これらのフローが終了する前に検知を行い,特徴量を変更することで,検知性能を従来のシステムと同等に保つことを目指す.本報告では,フローごとのコネクション状態とポート番号,トランスポート層プロトコルの遷移を特徴量として用いる既存の検知手法と,Zeekを用いてIPフロー情報に変換したISCX botnetデータセットを利用し,フロー継続時間の上限を設定しない場合(データセット中の最長フロー 240,418秒)と30秒とした場合で検知性能を調査した.結果,それぞれ98.1%と96.1%のF値で検知が可能であることを確認した.本調査から,30秒以内(確定時間)でのマルウェアトラフィック検知をわずかな検知性能の低下で実現可能なことを示した. 
(英) The damage caused by the activities of malware such as botnets and ransomware has become a social problem. In order to detect malware activity efficiently and reduce the damage, research on detecting malware activity traffic in the network has been proposed. There are three types of traffic information used in these research: packet information, IP flow information, and interface counters information. In the case of using IP flow information, traffic is aggregated in 5-tuples, which is lightweight, but the information is not output until a timeout occurs or the connection is terminated. Therefore, making it difficult to detect scanning activities or long-lasting flows at an early stage.
This research aims to maintain the same detection performance as conventional research by modifying the feature while detecting these flows before they terminate. In this paper, we experiment with existing methods that use connection status, port numbers, and transport layer protocols transition of each flow as features. We used the ISCX botnet dataset converted into IP flow information using Zeek to investigate the detection performance when the upper limit of flow duration is not set (the longest flow in the dataset: 240,418 seconds) and when the upper limit is set to 30 seconds. As a result, we confirmed that detection was possible with an F-measure of 98.1% and 96.1%, respectively. From this research, we showed that it is possible to detect malware traffic within 30 seconds (a certain time) with a slight decrease in detection performance.
キーワード (和) マルウェア / ボットネット / マルウェア検知 / 侵入検出・検知 / ネットワークセキュリティ / / /  
(英) Malware / Botnet / Malware Detection / Intrusion Detection / Network Security / / /  
文献情報 信学技報, vol. 121, no. 201, IA2021-27, pp. 6-11, 2021年10月.
資料番号 IA2021-27 
発行日 2021-10-08 (IA) 
ISSN Online edition: ISSN 2432-6380
著作権に
ついて
技術研究報告に掲載された論文の著作権は電子情報通信学会に帰属します.(許諾番号:10GA0019/12GB0052/13GB0056/17GB0034/18GB0034)
PDFダウンロード IA2021-27

研究会情報
研究会 IA  
開催期間 2021-10-15 - 2021-10-15 
開催地(和) オンライン開催 
開催地(英) Online 
テーマ(和) ネットワーク研究開発テストベッド運用・利用、一般(ADVNET共催) 
テーマ(英) Network R&D Testbed Operation and Utilization, etc. (cosponsored by ADVNET
講演論文情報の詳細
申込み研究会 IA 
会議コード 2021-10-IA 
本文の言語 日本語 
タイトル(和) IPフロー情報を利用した確定時間でのマルウェアトラフィック検知 
サブタイトル(和)  
タイトル(英) Malware Traffic Detection at Certain Time Using IP Flow Information 
サブタイトル(英)  
キーワード(1)(和/英) マルウェア / Malware  
キーワード(2)(和/英) ボットネット / Botnet  
キーワード(3)(和/英) マルウェア検知 / Malware Detection  
キーワード(4)(和/英) 侵入検出・検知 / Intrusion Detection  
キーワード(5)(和/英) ネットワークセキュリティ / Network Security  
キーワード(6)(和/英) /  
キーワード(7)(和/英) /  
キーワード(8)(和/英) /  
第1著者 氏名(和/英/ヨミ) 小松 聖矢 / Seiya Komatsu / コマツ セイヤ
第1著者 所属(和/英) 奈良先端科学技術大学院大学 (略称: 奈良先端大)
Nara Institute of Science and Technology (略称: NAIST)
第2著者 氏名(和/英/ヨミ) 桂 祐成 / Yusei Katsura / カツラ ユウセイ
第2著者 所属(和/英) 奈良先端科学技術大学院大学 (略称: 奈良先端大)
Nara Institute of Science and Technology (略称: NAIST)
第3著者 氏名(和/英/ヨミ) 垣内 正年 / Masatoshi Kakiuchi / カキウチ マサトシ
第3著者 所属(和/英) 奈良先端科学技術大学院大学 (略称: 奈良先端大)
Nara Institute of Science and Technology (略称: NAIST)
第4著者 氏名(和/英/ヨミ) 新井 イスマイル / Ismail Arai / アライ イスマイル
第4著者 所属(和/英) 奈良先端科学技術大学院大学 (略称: 奈良先端大)
Nara Institute of Science and Technology (略称: NAIST)
第5著者 氏名(和/英/ヨミ) 藤川 和利 / Kazutoshi Fujikawa / フジカワ カズトシ
第5著者 所属(和/英) 奈良先端科学技術大学院大学 (略称: 奈良先端大)
Nara Institute of Science and Technology (略称: NAIST)
第6著者 氏名(和/英/ヨミ) / /
第6著者 所属(和/英) (略称: )
(略称: )
第7著者 氏名(和/英/ヨミ) / /
第7著者 所属(和/英) (略称: )
(略称: )
第8著者 氏名(和/英/ヨミ) / /
第8著者 所属(和/英) (略称: )
(略称: )
第9著者 氏名(和/英/ヨミ) / /
第9著者 所属(和/英) (略称: )
(略称: )
第10著者 氏名(和/英/ヨミ) / /
第10著者 所属(和/英) (略称: )
(略称: )
第11著者 氏名(和/英/ヨミ) / /
第11著者 所属(和/英) (略称: )
(略称: )
第12著者 氏名(和/英/ヨミ) / /
第12著者 所属(和/英) (略称: )
(略称: )
第13著者 氏名(和/英/ヨミ) / /
第13著者 所属(和/英) (略称: )
(略称: )
第14著者 氏名(和/英/ヨミ) / /
第14著者 所属(和/英) (略称: )
(略称: )
第15著者 氏名(和/英/ヨミ) / /
第15著者 所属(和/英) (略称: )
(略称: )
第16著者 氏名(和/英/ヨミ) / /
第16著者 所属(和/英) (略称: )
(略称: )
第17著者 氏名(和/英/ヨミ) / /
第17著者 所属(和/英) (略称: )
(略称: )
第18著者 氏名(和/英/ヨミ) / /
第18著者 所属(和/英) (略称: )
(略称: )
第19著者 氏名(和/英/ヨミ) / /
第19著者 所属(和/英) (略称: )
(略称: )
第20著者 氏名(和/英/ヨミ) / /
第20著者 所属(和/英) (略称: )
(略称: )
第21著者 氏名(和/英/ヨミ) / /
第21著者 所属(和/英) (略称: )
(略称: )
第22著者 氏名(和/英/ヨミ) / /
第22著者 所属(和/英) (略称: )
(略称: )
第23著者 氏名(和/英/ヨミ) / /
第23著者 所属(和/英) (略称: )
(略称: )
第24著者 氏名(和/英/ヨミ) / /
第24著者 所属(和/英) (略称: )
(略称: )
第25著者 氏名(和/英/ヨミ) / /
第25著者 所属(和/英) (略称: )
(略称: )
第26著者 氏名(和/英/ヨミ) / /
第26著者 所属(和/英) (略称: )
(略称: )
第27著者 氏名(和/英/ヨミ) / /
第27著者 所属(和/英) (略称: )
(略称: )
第28著者 氏名(和/英/ヨミ) / /
第28著者 所属(和/英) (略称: )
(略称: )
第29著者 氏名(和/英/ヨミ) / /
第29著者 所属(和/英) (略称: )
(略称: )
第30著者 氏名(和/英/ヨミ) / /
第30著者 所属(和/英) (略称: )
(略称: )
第31著者 氏名(和/英/ヨミ) / /
第31著者 所属(和/英) (略称: )
(略称: )
第32著者 氏名(和/英/ヨミ) / /
第32著者 所属(和/英) (略称: )
(略称: )
第33著者 氏名(和/英/ヨミ) / /
第33著者 所属(和/英) (略称: )
(略称: )
第34著者 氏名(和/英/ヨミ) / /
第34著者 所属(和/英) (略称: )
(略称: )
第35著者 氏名(和/英/ヨミ) / /
第35著者 所属(和/英) (略称: )
(略称: )
第36著者 氏名(和/英/ヨミ) / /
第36著者 所属(和/英) (略称: )
(略称: )
講演者 第1著者 
発表日時 2021-10-15 16:50:00 
発表時間 25分 
申込先研究会 IA 
資料番号 IA2021-27 
巻番号(vol) vol.121 
号番号(no) no.201 
ページ範囲 pp.6-11 
ページ数
発行日 2021-10-08 (IA) 


[研究会発表申込システムのトップページに戻る]

[電子情報通信学会ホームページ]


IEICE / 電子情報通信学会