DocumentCode :
2565118
Title :
Design and prototyping of framework for automated continuous malware collection and analysis
Author :
Takeda, Keiji ; Mizutani, Masayoshi
Author_Institution :
Keio Univ., Fujisawa, Japan
fYear :
2011
fDate :
18-21 Oct. 2011
Firstpage :
1
Lastpage :
6
Abstract :
In this paper, design of a framework for malware collection and analysis is described. The framework enables researchers to collect malware samples for analysis continuously, to develop counter measures and to generate pattern signatures for detection. By using this framework security analysts and operators are able to minimize their workload. Five components of malware collection unit, malware database, dynamic analysis unit, static analysis unit, signature generation and response unit have been developed and with certain level of manual operation these units are functional and are able to reduce workload of analysts for counter malware activities. Functionality to manage resources for integrated units such as virtual machines, virtual networks etc is being developed. Development of automated generation of signature would be key for this solution. An approach which compare network traffic generated by machines with malicious executable running and innocent network traffic collected from network used in daily operation which is assumed not to include malicious traffic is proposed. Under the situation with increasing number of newly created malware development of automation and continuity of counter malware scheme has been significant issues. This proposed framework is considered possible solution for such problem in the area of computer and network security.
Keywords :
computer network security; digital signatures; invasive software; virtual machines; computer security; counter malware activity; dynamic analysis unit; malware analysis; malware collection; malware collection unit; malware database; network security; pattern signature; signature generation unit; signature response unit; static analysis unit; virtual machines; virtual networks; Databases; Malware; Operating systems; Servers; Virtual machining; Cyber security; malware protection;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Security Technology (ICCST), 2011 IEEE International Carnahan Conference on
Conference_Location :
Barcelona
ISSN :
1071-6572
Print_ISBN :
978-1-4577-0902-9
Type :
conf
DOI :
10.1109/CCST.2011.6095922
Filename :
6095922
Link To Document :
بازگشت