Paper Abstract and Keywords |
Presentation |
2007-07-20 11:10
Exploring the required condtions for malware to run for behavior analysis Yuji Hoshizawa, Kouichirou Okada, Motoaki Yamamura (SecureBrain Corp.), Takayoshi Shiigi (JPCERT) ISEC2007-53 |
Abstract |
(in Japanese) |
(See Japanese page) |
(in English) |
As a way of knowing host or behavior of malware on the network, we run malware in an isolated environment that doesn't affect other systems and monitor the behavior, which is called dynamic analysis. It is relatively easy to realize and get a certain level of results quickly, because there are many tools that record the access to the registry or files and capture the network traffic. However, it is far from easy to analyze malware that work under specific conditions, such as malware that change process depending on time and date or the day of the week, or work only when there are particular files. In this paper, we consider the way of exploring required conditions of malware automatically, to reduce the analyzing time and to improve the accuracy of the result of analysis using the dynamic analysis. |
Keyword |
(in Japanese) |
(See Japanese page) |
(in English) |
Malware / Bot / Required conditions / Automation / / / / |
Reference Info. |
IEICE Tech. Rep., vol. 107, no. 141, ISEC2007-53, pp. 57-61, July 2007. |
Paper # |
ISEC2007-53 |
Date of Issue |
2007-07-13 (ISEC) |
ISSN |
Print edition: ISSN 0913-5685 Online edition: ISSN 2432-6380 |
Copyright and reproduction |
All rights are reserved and no part of this publication may be reproduced or transmitted in any form or by any means, electronic or mechanical, including photocopy, recording, or any information storage and retrieval system, without permission in writing from the publisher. Notwithstanding, instructors are permitted to photocopy isolated articles for noncommercial classroom use without fee. (License No.: 10GA0019/12GB0052/13GB0056/17GB0034/18GB0034) |
Download PDF |
ISEC2007-53 |
Conference Information |
Committee |
ISEC SITE IPSJ-CSEC |
Conference Date |
2007-07-19 - 2007-07-20 |
Place (in Japanese) |
(See Japanese page) |
Place (in English) |
Future University-Hakodate |
Topics (in Japanese) |
(See Japanese page) |
Topics (in English) |
|
Paper Information |
Registration To |
ISEC |
Conference Code |
2007-07-ISEC-SITE-IPSJ-CSEC |
Language |
Japanese |
Title (in Japanese) |
(See Japanese page) |
Sub Title (in Japanese) |
(See Japanese page) |
Title (in English) |
Exploring the required condtions for malware to run for behavior analysis |
Sub Title (in English) |
|
Keyword(1) |
Malware |
Keyword(2) |
Bot |
Keyword(3) |
Required conditions |
Keyword(4) |
Automation |
Keyword(5) |
|
Keyword(6) |
|
Keyword(7) |
|
Keyword(8) |
|
1st Author's Name |
Yuji Hoshizawa |
1st Author's Affiliation |
SecureBrain Corporation (SecureBrain Corp.) |
2nd Author's Name |
Kouichirou Okada |
2nd Author's Affiliation |
SecureBrain Corporation (SecureBrain Corp.) |
3rd Author's Name |
Motoaki Yamamura |
3rd Author's Affiliation |
SecureBrain Corporation (SecureBrain Corp.) |
4th Author's Name |
Takayoshi Shiigi |
4th Author's Affiliation |
Japan Computer Emergency Response Team Coordination Center (JPCERT) |
5th Author's Name |
|
5th Author's Affiliation |
() |
6th Author's Name |
|
6th Author's Affiliation |
() |
7th Author's Name |
|
7th Author's Affiliation |
() |
8th Author's Name |
|
8th Author's Affiliation |
() |
9th Author's Name |
|
9th Author's Affiliation |
() |
10th Author's Name |
|
10th Author's Affiliation |
() |
11th Author's Name |
|
11th Author's Affiliation |
() |
12th Author's Name |
|
12th Author's Affiliation |
() |
13th Author's Name |
|
13th Author's Affiliation |
() |
14th Author's Name |
|
14th Author's Affiliation |
() |
15th Author's Name |
|
15th Author's Affiliation |
() |
16th Author's Name |
|
16th Author's Affiliation |
() |
17th Author's Name |
|
17th Author's Affiliation |
() |
18th Author's Name |
|
18th Author's Affiliation |
() |
19th Author's Name |
|
19th Author's Affiliation |
() |
20th Author's Name |
|
20th Author's Affiliation |
() |
Speaker |
Author-1 |
Date Time |
2007-07-20 11:10:00 |
Presentation Time |
25 minutes |
Registration for |
ISEC |
Paper # |
ISEC2007-53 |
Volume (vol) |
vol.107 |
Number (no) |
no.141 |
Page |
pp.57-61 |
#Pages |
5 |
Date of Issue |
2007-07-13 (ISEC) |
|