Paper Abstract and Keywords |
Presentation |
2018-03-07 13:00
A Study on Malware Activity Detection Based on Real-time Analysis of Darknet Data Using Graphical Lasso Chansu Han (Kyushu Univ.), Jumpei Shimamura (Clwit Inc.), Takeshi Takahashi, Daisuke Inoue (NICT), Masanori Kawakita, Jun'ichi Takeuchi (Kyushu Univ.), Koji Nakao (NICT) ICSS2017-51 |
Abstract |
(in Japanese) |
(See Japanese page) |
(in English) |
In this study, we considered a method to detect malignant activity (especially botnet) in cyber space automatically and in real-time from darknet traffic data. A method to grasp the cooperative relationship between the source hosts from the traffic data based on the graph density obtained by the Graphical Lasso algorithm, and to detect abnormality was studied. We developed the method and proposed a method to detect malignant activities in real-time by using a new alert judgment method. In our research, we implemented a tool to carry out the analysis using the proposed method against actual darknet traffic and confirmed that it operates in real-time. At the same time, we shortened the program calculation time and evaluated parameter tuning. Finally, we introduced examples of malicious activities detected in continuous operation. |
Keyword |
(in Japanese) |
(See Japanese page) |
(in English) |
Malware Activity Detection / Graphical Lasso / Graph Density / Online Processing / Real-time Analysis / / / |
Reference Info. |
IEICE Tech. Rep., vol. 117, no. 481, ICSS2017-51, pp. 1-6, March 2018. |
Paper # |
ICSS2017-51 |
Date of Issue |
2018-02-28 (ICSS) |
ISSN |
Print edition: ISSN 0913-5685 Online edition: ISSN 2432-6380 |
Copyright and reproduction |
All rights are reserved and no part of this publication may be reproduced or transmitted in any form or by any means, electronic or mechanical, including photocopy, recording, or any information storage and retrieval system, without permission in writing from the publisher. Notwithstanding, instructors are permitted to photocopy isolated articles for noncommercial classroom use without fee. (License No.: 10GA0019/12GB0052/13GB0056/17GB0034/18GB0034) |
Download PDF |
ICSS2017-51 |
|