KMITL
Permanent URI for this communityhttps://dspace.kmitl.ac.th/handle/123456789/1
Browse
12 results
Search Results
- Some of the metrics are blocked by yourconsent settings
Item type:Publication, A Spatio-Temporal malware and country clustering algorithm: 2012 IIJ MITF case study(2017-10-01) ;Sisaat, Khamphao ;Kittitornkun, Surin ;Kikuchi, Hiroaki ;Yukonhiatou, ChaxiongTerada, MasatoA huge number of botnet malware variants can be downloaded by zombie personal computers as secondary injections and upgrades according to their botmasters to perform different distributed/coordinated cyber attacks such as phishing, spam e-mail, malicious Web sites, ransomware, DDoS. In order to generate a faster response to new threats and better understanding of botnet activities, grouping them based on their malicious behaviors has become extremely important. This paper presents a Spatio-Temporal malware clustering algorithm based on its (weekly-hourly-country) features. The dataset contains more than 32 million of malware download logs from 100 honeypots set up by Malware Investigation Task Force (MITF) of Internet Initiative Japan Inc. (IIJ) from 2011 to 2012. The Top-20 malware clustering results coincidentally correspond to Conficker.B and Conficker.C with relatively high precision and recall rates up to 100.0, 88.9 % and 91.7, 100.0 %, respectively. On the other hand, the resulting two clusters of Top-20 countries are comparable to those with high and low growth rates recently reported in 2015 by Asghari et al. Therefore, our approach can be validated and evaluated to yield precision and recall of up to 75.0 and 86.7 %, respectively. - Some of the metrics are blocked by yourconsent settings
Item type:Publication, Temporal behaviors of Top-10 malware download in 2010-2012(2014-10-15) ;Yukonhiatou, Chaxiong ;Kittitornkun, Surin ;Kikuchi, Hiroaki ;Sisaat, KhamphaoTerada, MasatoMalware can be widely downloaded over the Internet by the bot-infected computers according to their botmaster in order to form a botnet and eventually to perform cyber attacks. This paper analyzes and summarizes the malware download behaviors of Top-10 malware based on 2010 CCC, 2011 CCC and 2012 IIJ MITF datasets. The datasets contain millions of download logs collected from several Honeypots located in Japan observing malware/bot traffic and activities. These log data have been processed and analyzed in terms of daily and hourly downloads based on our Top-10 processing algorithm. As a result, both daily and hourly download patterns in each year are quite different due to different malware families and spreading protocols. - Some of the metrics are blocked by yourconsent settings
Item type:Publication, Temporal behavior analysis of malware/bot downloads using top-10 processing(2013-12-01) ;Yukonhiatou, Chaxiong ;Kittitornkun, Surin ;Kikuchi, Hiroaki ;Sisaat, KhamphaoTerada, MasatoNowadays malware can be spread over the Internet using botnets to download. This preliminary work presents temporal download behavior of Top-10 malware based on 2010 and 2011 CCC (Cyber Clean Center) datasets in terms of number of downloads per day and per hour. The datasets contain download logs of several independent honeypots in Japan to observe malware traffic and its activities. Our results show sequences and similar patterns of malware downloads in 2010. On the other hand, the behaviors in 2011 are quite different from those of 2010 that no obvious sequences and patterns can be detected. © 2013 IEEE. - Some of the metrics are blocked by yourconsent settings
Item type:Publication, Time zone correlation analysis of malware/bot downloads(2013-01-01) ;Sisaat, Khamphao ;Kikuchi, Hiroaki ;Matsuo, Shunji ;Terada, MasatoFujiwara, MasashiA botnet attacks any Victim Hosts via the multiple Command and Control (C and C) Servers, which are controlled by a botmaster. This makes it more difficult to detect the botnet attacks and harder to trace the source country of the botmaster due to the lack of the logged data about the attacks. To locate the C and C Servers during malware/bot downloading phase, we have analyzed the source IP addresses of downloads to more than 90 independent Honeypots in Japan in the CCC (Cyber Clean Center) dataset 2010 comprising over 1 million data records and almost 1 thousand malware names. Based on GeoIP services, a Time Zone Correlation model has been proposed to determine the correlation coefficient between bot downloads from Japan and other source countries. We found a strong correlation between active malware/bot downloads and time zone of the C and C Servers. As a result, our model confirms that malware/bot downloads are synchronized with time zone (country) of the corresponding C and C Servers so that the botmaster can be possibly traced. © 2013 The Institute of Electronics, Information and Communication Engineers. - Some of the metrics are blocked by yourconsent settings
Item type:Publication, Clustering Top-10 malware/bots based on download behavior(2013-01-01) ;Yukonhiatou, Chaxiong ;Kittitornkun, Surin ;Kikuchi, Hiroaki ;Sisaat, KhamphaoTerada, MasatoMalware can be spread over the Internet via especially download mechanism to the victim computers. This work tries to cluster malware/bots download behavior of Top-10 malware based on 2010 and 2011 CCC (Cyber Clean Center) datasets. The datasets contain more than one million download logs collected from several independent honeypots in Japan to observe malware/bot traffic and activities. Although the daily and hourly patterns are quite similar in 2010, those of 2011 are quite different. As a result, the proposed Integral Correlation Coefficient can cluster 3 and 4 groups of Top-10 malware/bots in 2010 and 2011, respectively. © 2013 IEEE. - Some of the metrics are blocked by yourconsent settings
Item type:Publication, Geographical visualization of malware download for anomaly detection(2012-11-06) ;Hiroguchi, Naoki ;Sisaat, Khamphao ;Kikuchi, HiroakiKittitornkun, SurinWe study a linkage between attacks in cyberspace and incidents in our real world. For example, the Internet had been closed down in Egypt for preventing protests against President Hosni Mubarak. Meanwhile, for more than two weeks we have observed that no port-scan packet were sent from Egypt to Japan. This motivates us for this study to find any incident between botnet attacks which were involved many vulnerable servers and the real events occurred in the world. For this purpose, we developed the virtualization system on Google Earth service for plotting source IP addresses of botnet communications. We investigated the actual malware downloading events observed by more than 70 distributed honey pots in the Japanese backbone network. In order to automate the detection process, we study some anomaly detection schemes base on the entropy of honey pot activities. Our analysis shows some evidences that botnet attacks are involved in our real world. © 2012 IEEE. - Some of the metrics are blocked by yourconsent settings
Item type:Publication, Apriori-PrefixSpan hybrid approach for automated detection of botnet coordinated attacks(2011-11-09) ;Ohrui, Masayuki ;Kikuchi, Hiroaki ;Terada, MasatoRosyid, Nur RohmanThis paper aims to detect features of coordinated attacks by applying data mining techniques, Apriori and PrefixSpan, to the CCC DATAset 2008-2010 which consists of the captured packets data and the downloading logs. Data mining algorithms allow us to automate detecting characteristics from large amount of data, which the conventional heuristics could not apply. Apriori achives high recall but with false positive, while PrefixSpan has high precision but low recall. Hence, we propose hybriding these algorithms. Our analysis shows the change in behavior of malware over the past 3 years. © 2011 IEEE. - Some of the metrics are blocked by yourconsent settings
Item type:Publication, Analysis on the sequential behavior of malware attacks(2011-01-01) ;Rosyid, Nur Rohman ;Ohrui, Masayuki ;Kikuchi, Hiroaki ;Sooraksa, PitikhateTerada, MasatoOvercoming the highly organized and coordinated malware threats by botnets on the Internet is becoming increasingly difficult. A honeypot is a powerful tool for observing and catching malware and virulent activity in Internet traffic. Because botnets use systematic attack methods, the sequences of malware downloaded by honeypots have particular forms of coordinated pattern. This paper aims to discover new frequent sequential attack patterns in malware automatically. One problem is the difficulty in identifying particular patterns from full yearlong logs because the dataset is too large for individual investigations. This paper proposes the use of a data-mining algorithm to overcome this problem. We implement the PrefixSpan algorithm to analyze malware-attack logs and then show some experimental results. Analysis of these results indicates that botnet attacks can be characterized either by the download times or by the source addresses of the bots. Finally, we use entropy analysis to reveal how frequent sequential patterns are involved in coordinated attacks. Copyright © 2011 The Institute of Electronics, Information and Communication Engineers. - Some of the metrics are blocked by yourconsent settings
Item type:Publication, A discovery of sequential attack patterns of malware in botnets(2010-12-01) ;Rosyid, Nur Rohman ;Ohrui, Masayuki ;Kikuchi, Hiroaki ;Sooraksa, PitikhateTerada, MasatoMore than 90 independent honeypots have observed malware traffic at the Japanese tier-1 backbone. Typical attacks were made by multiple servers, coordinating to send many kinds of malware. T his paper aims to discover some frequent new sequential attack patterns of malware. It is not easy to identify particular patterns logs of one year because the volume of dataset is too large to investigate one by one. To overcome the problem, this paper proposes data mining algorithm, the PrejixSpan method. We implement the PrejixSpan algorithm to analyze the malware footprints and show the experimental result. The result of analysis shows that the attacks are performed by multiple sequential attack patterns within a short amount of time. ©2010 IEEE. - Some of the metrics are blocked by yourconsent settings
Item type:Publication, Privacy-preserving collaborative filtering protocol based on similarity between items(2010-07-12) ;Tada, Minako ;Kikuchi, HiroakiPuntheeranurak, SutheeraA recommendation system enables us to take information from huge datasets about tastes effectively. Many cryptographical protocols for computing privacy-preserving recommendation without leaking the privacy of users are proposed. However, the current issue is the large computational overhead depending the number of users. Hence, the application of the protocol is limited within small communities. In this paper, we address the issue of scalability by replacing the similarity between users by that of between items. Since the similarities between items can be publicly available, the recommendation steps are processed without dealing with confidential information such as the similarities between users. We propose an efficient scheme by using item-item similarities for providing a prediction of arbitrary values of rating. We show the performance and the accuracy evaluation of our proposed scheme based on a numerical experiment. © 2010 IEEE.
