Kittitornkun, Surin
Loading...
Preferred name
Kittitornkun, Surin
Alternative Name
Kittitornkun, S.
Main Affiliation
Email
surin.ki@kmitl.ac.th
2 results
Now showing 1 - 2 of 2
- Some of the metrics are blocked by yourconsent settings
Item type:Publication, Temporal behaviors of Top-10 malware download in 2010-2012(2014-10-15) ;Yukonhiatou, Chaxiong; ;Kikuchi, Hiroaki ;Sisaat, KhamphaoTerada, MasatoMalware can be widely downloaded over the Internet by the bot-infected computers according to their botmaster in order to form a botnet and eventually to perform cyber attacks. This paper analyzes and summarizes the malware download behaviors of Top-10 malware based on 2010 CCC, 2011 CCC and 2012 IIJ MITF datasets. The datasets contain millions of download logs collected from several Honeypots located in Japan observing malware/bot traffic and activities. These log data have been processed and analyzed in terms of daily and hourly downloads based on our Top-10 processing algorithm. As a result, both daily and hourly download patterns in each year are quite different due to different malware families and spreading protocols. - Some of the metrics are blocked by yourconsent settings
Item type:Publication, Time zone correlation analysis of malware/bot downloads(2013-01-01) ;Sisaat, Khamphao ;Kikuchi, Hiroaki ;Matsuo, Shunji ;Terada, MasatoFujiwara, MasashiA botnet attacks any Victim Hosts via the multiple Command and Control (C and C) Servers, which are controlled by a botmaster. This makes it more difficult to detect the botnet attacks and harder to trace the source country of the botmaster due to the lack of the logged data about the attacks. To locate the C and C Servers during malware/bot downloading phase, we have analyzed the source IP addresses of downloads to more than 90 independent Honeypots in Japan in the CCC (Cyber Clean Center) dataset 2010 comprising over 1 million data records and almost 1 thousand malware names. Based on GeoIP services, a Time Zone Correlation model has been proposed to determine the correlation coefficient between bot downloads from Japan and other source countries. We found a strong correlation between active malware/bot downloads and time zone of the C and C Servers. As a result, our model confirms that malware/bot downloads are synchronized with time zone (country) of the corresponding C and C Servers so that the botmaster can be possibly traced. © 2013 The Institute of Electronics, Information and Communication Engineers.
