ログイン
Language:

WEKO3

  • トップ
  • ランキング
To
lat lon distance
To

Field does not validate



インデックスリンク

インデックスツリー

メールアドレスを入力してください。

WEKO

One fine body…

WEKO

One fine body…

アイテム

  1. 学術雑誌論文
  2. 5 技術(工学)

A Cause-Based Classification Approach for Malicious DNS Queries Detected Through Blacklists

http://hdl.handle.net/10228/00007631
http://hdl.handle.net/10228/00007631
886e29e9-64dc-4e2f-be60-e5e4fe7bade8
名前 / ファイル ライセンス アクション
ACCESS.2019.2944203.pdf ACCESS.2019.2944203.pdf (7.8 MB)
アイテムタイプ 学術雑誌論文 = Journal Article(1)
公開日 2020-03-02
資源タイプ
資源タイプ識別子 http://purl.org/coar/resource_type/c_6501
資源タイプ journal article
タイトル
タイトル A Cause-Based Classification Approach for Malicious DNS Queries Detected Through Blacklists
言語 en
言語
言語 eng
著者 佐藤, 彰洋

× 佐藤, 彰洋

WEKO 27948
e-Rad 30609376
Scopus著者ID 55437344000
ORCiD 0000-0003-3178-1041
九工大研究者情報 100000049

en Sato, Akihiro

ja 佐藤, 彰洋

ja-Kana サトウ, アキヒロ


Search repository
中村, 豊

× 中村, 豊

WEKO 8847
e-Rad 40346317
Scopus著者ID 56393278900
九工大研究者情報 367

en Nakamura, Yutaka

ja 中村, 豊

ja-Kana ナカムラ, ユタカ


Search repository
福田, 豊

× 福田, 豊

WEKO 24131
e-Rad 90372763
Scopus著者ID 35811871400
ORCiD 0000-0003-0430-0871
九工大研究者情報 371

en Fukuda, Yutaka

ja 福田, 豊

ja-Kana フクダ, ユタカ


Search repository
Sasai, Kazuto

× Sasai, Kazuto

WEKO 26910

en Sasai, Kazuto
Sasai, K.

Search repository
Kitagata, Gen

× Kitagata, Gen

WEKO 26911

en Kitagata, Gen
Kitagata, G.

Search repository
抄録
内容記述タイプ Abstract
内容記述 Some of the most serious security threats facing computer networks involve malware. To prevent this threat, administrators need to swiftly remove the infected machines from their networks. One common way to detect infected machines in a network is by monitoring communications based on blacklists. However, detection using this method has the following two problems: no blacklist is completely reliable, and blacklists do not provide sufficient evidence to allow administrators to determine the validity and accuracy of the detection results. Therefore, simply matching communications with blacklist entries is insufficient, and administrators should pursue their detection causes by investigating the communications themselves. In this paper, we propose an approach for classifying malicious DNS queries detected through blacklists by their causes. This approach is motivated by the following observation: a malware communication is divided into several transactions, each of which generates queries related to the malware; thus, surrounding queries that occur before and after a malicious query detected through blacklists help in estimating the cause of the malicious query. Our cause-based classification drastically reduces the number of malicious queries to be investigated because the investigation scope is limited to only representative queries in the classification results. In experiments, we have confirmed that our approach could group 388 malicious queries into 3 clusters, each consisting of queries with a common cause. These results indicate that administrators can briefly pursue all the causes by investigating only representative queries of each cluster, and thereby swiftly address the problem of infected machines in the network.
言語 en
書誌情報 en : IEEE Access

巻 7, p. 142991-143001, 発行日 2019-09-27
出版社
出版者 IEEE
DOI
関連タイプ isIdenticalTo
識別子タイプ DOI
関連識別子 https://doi.org/10.1109/ACCESS.2019.2944203
日本十進分類法
主題Scheme NDC
主題 547
ISSN
収録物識別子タイプ EISSN
収録物識別子 2169-3536
著作権関連情報
権利情報Resource http://creativecommons.org/licenses/by/4.0/
権利情報 This work is licensed under a Creative Commons Attribution 4.0 License. http://creativecommons.org/licenses/by/4.0/
出版タイプ
出版タイプ VoR
出版タイプResource http://purl.org/coar/version/c_970fb48d4fbd8a85
査読の有無
値 yes
研究者情報
URL https://hyokadb02.jimu.kyutech.ac.jp/html/371_ja.html
論文ID(連携)
値 10350174
連携ID
値 8133
戻る
0
views
See details
Views

Versions

Ver.1 2023-05-15 12:54:33.918611
Show All versions

Share

Share
tweet

Cite as

Other

print

エクスポート

OAI-PMH
  • OAI-PMH JPCOAR 2.0
  • OAI-PMH JPCOAR 1.0
  • OAI-PMH DublinCore
  • OAI-PMH DDI
Other Formats
  • JSON
  • BIBTEX
  • ZIP

コミュニティ

確認

確認

確認


Powered by WEKO3


Powered by WEKO3