Presentation 2003/7/10
Unknown Virus Detection System using Virtual Network
Masaki KAMIZONO, Yoshiaki SHIRAISHI, Masakatu MORII,
PDF Download Page PDF download Page Link
Abstract(in Japanese) (See Japanese page)
Abstract(in English) The spread of computer virus by E-mail is a social problem. In particular, unknown virus which can not be detected by a general virus detection scheme based on pattern matching tends to expand the damage. It is also necessary to find out a countermeasure against a metamorphic virus, which changes itself whenever it infects a computer, because a pattern matching-based virus detection scheme can not detect the virus. It is known that a dynamic heuristic scheme is effective to detect unknown or metamorphic viruses. In the scheme, after a doubtful target file is actually run on a computer and its behavior on the computer is monitored, we judge whether the file is a virus or not. In this paper, we propose a dynamic heuristic scheme-based system which runs a target file attached to E-mail on a virtual machine and a virtual network, and monitored its behavior pattern in the virtual environment. We describe an implementation of proposed system, and show some evaluation results.
Keyword(in Japanese) (See Japanese page)
Keyword(in English) computer virus / unknown virus / virus detection / virtual network / dynamic heuristic scheme
Paper # ISEC2003-27
Date of Issue

Conference Information
Committee ISEC
Conference Date 2003/7/10(1days)
Place (in Japanese) (See Japanese page)
Place (in English)
Topics (in Japanese) (See Japanese page)
Topics (in English)
Chair
Vice Chair
Secretary
Assistant

Paper Information
Registration To Information Security (ISEC)
Language JPN
Title (in Japanese) (See Japanese page)
Sub Title (in Japanese) (See Japanese page)
Title (in English) Unknown Virus Detection System using Virtual Network
Sub Title (in English)
Keyword(1) computer virus
Keyword(2) unknown virus
Keyword(3) virus detection
Keyword(4) virtual network
Keyword(5) dynamic heuristic scheme
1st Author's Name Masaki KAMIZONO
1st Author's Affiliation Department of Information Science and Intelligent Systems, The University of Tokushima()
2nd Author's Name Yoshiaki SHIRAISHI
2nd Author's Affiliation Department of Informatics, School of Science and Engineering, Kinki University
3rd Author's Name Masakatu MORII
3rd Author's Affiliation Department of Information Science and Intelligent Systems, The University of Tokushima
Date 2003/7/10
Paper # ISEC2003-27
Volume (vol) vol.103
Number (no) 195
Page pp.pp.-
#Pages 8
Date of Issue