Journal of Information Processing
Online ISSN : 1882-6652
ISSN-L : 1882-6652
Evaluating payload features for malware infection detection
Yusuke OtsukiMasatsugu IchinoSoichi KimuraMitsuhiro HatadaHiroshi Yoshiura
著者情報
ジャーナル フリー

2014 年 22 巻 2 号 p. 376-387

詳細
抄録
Analysis of malware-infected traffic data revealed the payload features that are the most effective for detecting infection. The traffic data was attack traffic using the D3M2012 dataset and CCC DATAsets 2009, 2010, and 2011. Traffic flowing on an intranet at two different sites was used as normal traffic data. Since the type of malware (worm, Internet connection confirmation, etc.) affects the type of traffic generated, the malware was divided into three types — worm, Trojan horse, and file-infected virus — and the most effective features were identified for each type.
著者関連情報
© 2014 by the Information Processing Society of Japan
前の記事 次の記事
feedback
Top