KMITL
Permanent URI for this communityhttps://dspace.kmitl.ac.th/handle/123456789/1
Browse
2 results
Search Results
- Some of the metrics are blocked by yourconsent settings
Item type:Publication, A Spatio-Temporal malware and country clustering algorithm: 2012 IIJ MITF case study(2017-10-01) ;Sisaat, Khamphao ;Kittitornkun, Surin ;Kikuchi, Hiroaki ;Yukonhiatou, ChaxiongTerada, MasatoA huge number of botnet malware variants can be downloaded by zombie personal computers as secondary injections and upgrades according to their botmasters to perform different distributed/coordinated cyber attacks such as phishing, spam e-mail, malicious Web sites, ransomware, DDoS. In order to generate a faster response to new threats and better understanding of botnet activities, grouping them based on their malicious behaviors has become extremely important. This paper presents a Spatio-Temporal malware clustering algorithm based on its (weekly-hourly-country) features. The dataset contains more than 32 million of malware download logs from 100 honeypots set up by Malware Investigation Task Force (MITF) of Internet Initiative Japan Inc. (IIJ) from 2011 to 2012. The Top-20 malware clustering results coincidentally correspond to Conficker.B and Conficker.C with relatively high precision and recall rates up to 100.0, 88.9 % and 91.7, 100.0 %, respectively. On the other hand, the resulting two clusters of Top-20 countries are comparable to those with high and low growth rates recently reported in 2015 by Asghari et al. Therefore, our approach can be validated and evaluated to yield precision and recall of up to 75.0 and 86.7 %, respectively. - Some of the metrics are blocked by yourconsent settings
Item type:Publication, Time zone correlation analysis of malware/bot downloads(2013-01-01) ;Sisaat, Khamphao ;Kikuchi, Hiroaki ;Matsuo, Shunji ;Terada, MasatoFujiwara, MasashiA botnet attacks any Victim Hosts via the multiple Command and Control (C and C) Servers, which are controlled by a botmaster. This makes it more difficult to detect the botnet attacks and harder to trace the source country of the botmaster due to the lack of the logged data about the attacks. To locate the C and C Servers during malware/bot downloading phase, we have analyzed the source IP addresses of downloads to more than 90 independent Honeypots in Japan in the CCC (Cyber Clean Center) dataset 2010 comprising over 1 million data records and almost 1 thousand malware names. Based on GeoIP services, a Time Zone Correlation model has been proposed to determine the correlation coefficient between bot downloads from Japan and other source countries. We found a strong correlation between active malware/bot downloads and time zone of the C and C Servers. As a result, our model confirms that malware/bot downloads are synchronized with time zone (country) of the corresponding C and C Servers so that the botmaster can be possibly traced. © 2013 The Institute of Electronics, Information and Communication Engineers.
