KMITL
Permanent URI for this communityhttps://dspace.kmitl.ac.th/handle/123456789/1
Browse
6 results
Search Results
- Some of the metrics are blocked by yourconsent settings
Item type:Publication, A Spatio-Temporal malware and country clustering algorithm: 2012 IIJ MITF case study(2017-10-01) ;Sisaat, Khamphao ;Kittitornkun, Surin ;Kikuchi, Hiroaki ;Yukonhiatou, ChaxiongTerada, MasatoA huge number of botnet malware variants can be downloaded by zombie personal computers as secondary injections and upgrades according to their botmasters to perform different distributed/coordinated cyber attacks such as phishing, spam e-mail, malicious Web sites, ransomware, DDoS. In order to generate a faster response to new threats and better understanding of botnet activities, grouping them based on their malicious behaviors has become extremely important. This paper presents a Spatio-Temporal malware clustering algorithm based on its (weekly-hourly-country) features. The dataset contains more than 32 million of malware download logs from 100 honeypots set up by Malware Investigation Task Force (MITF) of Internet Initiative Japan Inc. (IIJ) from 2011 to 2012. The Top-20 malware clustering results coincidentally correspond to Conficker.B and Conficker.C with relatively high precision and recall rates up to 100.0, 88.9 % and 91.7, 100.0 %, respectively. On the other hand, the resulting two clusters of Top-20 countries are comparable to those with high and low growth rates recently reported in 2015 by Asghari et al. Therefore, our approach can be validated and evaluated to yield precision and recall of up to 75.0 and 86.7 %, respectively. - Some of the metrics are blocked by yourconsent settings
Item type:Publication, Temporal behaviors of Top-10 malware download in 2010-2012(2014-10-15) ;Yukonhiatou, Chaxiong ;Kittitornkun, Surin ;Kikuchi, Hiroaki ;Sisaat, KhamphaoTerada, MasatoMalware can be widely downloaded over the Internet by the bot-infected computers according to their botmaster in order to form a botnet and eventually to perform cyber attacks. This paper analyzes and summarizes the malware download behaviors of Top-10 malware based on 2010 CCC, 2011 CCC and 2012 IIJ MITF datasets. The datasets contain millions of download logs collected from several Honeypots located in Japan observing malware/bot traffic and activities. These log data have been processed and analyzed in terms of daily and hourly downloads based on our Top-10 processing algorithm. As a result, both daily and hourly download patterns in each year are quite different due to different malware families and spreading protocols. - Some of the metrics are blocked by yourconsent settings
Item type:Publication, Temporal behavior analysis of malware/bot downloads using top-10 processing(2013-12-01) ;Yukonhiatou, Chaxiong ;Kittitornkun, Surin ;Kikuchi, Hiroaki ;Sisaat, KhamphaoTerada, MasatoNowadays malware can be spread over the Internet using botnets to download. This preliminary work presents temporal download behavior of Top-10 malware based on 2010 and 2011 CCC (Cyber Clean Center) datasets in terms of number of downloads per day and per hour. The datasets contain download logs of several independent honeypots in Japan to observe malware traffic and its activities. Our results show sequences and similar patterns of malware downloads in 2010. On the other hand, the behaviors in 2011 are quite different from those of 2010 that no obvious sequences and patterns can be detected. © 2013 IEEE. - Some of the metrics are blocked by yourconsent settings
Item type:Publication, Time zone correlation analysis of malware/bot downloads(2013-01-01) ;Sisaat, Khamphao ;Kikuchi, Hiroaki ;Matsuo, Shunji ;Terada, MasatoFujiwara, MasashiA botnet attacks any Victim Hosts via the multiple Command and Control (C and C) Servers, which are controlled by a botmaster. This makes it more difficult to detect the botnet attacks and harder to trace the source country of the botmaster due to the lack of the logged data about the attacks. To locate the C and C Servers during malware/bot downloading phase, we have analyzed the source IP addresses of downloads to more than 90 independent Honeypots in Japan in the CCC (Cyber Clean Center) dataset 2010 comprising over 1 million data records and almost 1 thousand malware names. Based on GeoIP services, a Time Zone Correlation model has been proposed to determine the correlation coefficient between bot downloads from Japan and other source countries. We found a strong correlation between active malware/bot downloads and time zone of the C and C Servers. As a result, our model confirms that malware/bot downloads are synchronized with time zone (country) of the corresponding C and C Servers so that the botmaster can be possibly traced. © 2013 The Institute of Electronics, Information and Communication Engineers. - Some of the metrics are blocked by yourconsent settings
Item type:Publication, Clustering Top-10 malware/bots based on download behavior(2013-01-01) ;Yukonhiatou, Chaxiong ;Kittitornkun, Surin ;Kikuchi, Hiroaki ;Sisaat, KhamphaoTerada, MasatoMalware can be spread over the Internet via especially download mechanism to the victim computers. This work tries to cluster malware/bots download behavior of Top-10 malware based on 2010 and 2011 CCC (Cyber Clean Center) datasets. The datasets contain more than one million download logs collected from several independent honeypots in Japan to observe malware/bot traffic and activities. Although the daily and hourly patterns are quite similar in 2010, those of 2011 are quite different. As a result, the proposed Integral Correlation Coefficient can cluster 3 and 4 groups of Top-10 malware/bots in 2010 and 2011, respectively. © 2013 IEEE. - Some of the metrics are blocked by yourconsent settings
Item type:Publication, Geographical visualization of malware download for anomaly detection(2012-11-06) ;Hiroguchi, Naoki ;Sisaat, Khamphao ;Kikuchi, HiroakiKittitornkun, SurinWe study a linkage between attacks in cyberspace and incidents in our real world. For example, the Internet had been closed down in Egypt for preventing protests against President Hosni Mubarak. Meanwhile, for more than two weeks we have observed that no port-scan packet were sent from Egypt to Japan. This motivates us for this study to find any incident between botnet attacks which were involved many vulnerable servers and the real events occurred in the world. For this purpose, we developed the virtualization system on Google Earth service for plotting source IP addresses of botnet communications. We investigated the actual malware downloading events observed by more than 70 distributed honey pots in the Japanese backbone network. In order to automate the detection process, we study some anomaly detection schemes base on the entropy of honey pot activities. Our analysis shows some evidences that botnet attacks are involved in our real world. © 2012 IEEE.
