• Search Research Projects
  • Search Researchers
  • How to Use
  1. Back to previous page

A Study on a Framework of Detection of Malicious Behavior Patterns

Research Project

Project/Area Number 15500025
Research Category

Grant-in-Aid for Scientific Research (C)

Allocation TypeSingle-year Grants
Section一般
Research Field Software
Research InstitutionShibaura Institute of Technology

Principal Investigator

MATSUURA Saeko  Shibaura Institute of Technology, Faculty of System Engieering, Department of Electronic & Information Systems, Assistant Professor, システム工学部, 助教授 (10348906)

Project Period (FY) 2003 – 2005
Project Status Completed (Fiscal Year 2005)
Budget Amount *help
¥3,000,000 (Direct Cost: ¥3,000,000)
Fiscal Year 2005: ¥700,000 (Direct Cost: ¥700,000)
Fiscal Year 2004: ¥900,000 (Direct Cost: ¥900,000)
Fiscal Year 2003: ¥1,400,000 (Direct Cost: ¥1,400,000)
KeywordsDetection of Computer Virus / Framework / Behavioral Pattern / Object Oriented Model / Aspect Oriented / Detection Model / Data Movement Tracking / APISPY / 振舞いパターン / コンピュータ・ウィルスの検出 / フローズン・スポット / ホット・スポット
Research Abstract

We studied a framework of the program that detects malicious behavioral patterns from the program that performs some malicious behavior which was not intended by the user. This framework was built based on a method which judges whether a program was a computer virus including unknown viruses. Computer virus is a typical malicious behavioral program. Moreover, we developed a program that collects behavioral data of the target program. In 2003, the unknown virus detection program was redesigned the model from both viewpoints of object-oriented development and meta-modeling. First, the program structure was analyzed based on the graphical model of the specification of behavioral patterns and the detection program by UML which is a unified modeling language in object-oriented development. The detection program consists of the following three parts. (1)An abstract model of the program execution environment. (2)The definition of behavioral patterns of virus. (3)The definition of detection of … More virus using the patterns. The program (written in Standard ML) is defined based on the specification described by the first order predicate logic using Extended ML. The specification, the part (2) and the part (3) are frozen spot of the framework of behavioral pattern detection program. The part (2)is a hot spot of the framework that may be changed according to some behavioral patterns that we want to detect them. In 2004, we defined the specification of the program as some modules and examined the effectiveness of aspect oriented programming techniques to our framework. However, the big merit was not found compared with defining the program by only classes. In 2005, we studied and implemented a method of tracking data movement in order to detect computer virus entering via mail system. We conducted some experiments to detect the virus. Such malicious programs have some devices to make it difficult to analyze themselves. We also defined a way to make the device ineffective. We are planning to verify the validity of this framework. Less

Report

(4 results)
  • 2005 Annual Research Report   Final Research Report Summary
  • 2004 Annual Research Report
  • 2003 Annual Research Report
  • Research Products

    (12 results)

All 2006 2005 2004 Other

All Journal Article (10 results) Publications (2 results)

  • [Journal Article] データ移動アドレス追跡によるメール添付型ウイルスの振る舞い検出2006

    • Author(s)
      池田健太, 松浦佐江子
    • Journal Title

      第68回全国大会講演論文集 情報処理学会 1

    • Description
      「研究成果報告書概要(和文)」より
    • Related Report
      2005 Final Research Report Summary
  • [Journal Article] Behavior detection of mail attached type virus by data movement address pursuit.2006

    • Author(s)
      K.Ikeda, S.Matsuura
    • Journal Title

      The 68^<th> National Convention of IPSJ 1J-1

    • Description
      「研究成果報告書概要(欧文)」より
    • Related Report
      2005 Final Research Report Summary
  • [Journal Article] Detection of Computer Virus entering via Mail System.2006

    • Author(s)
      K.Ikeda, S.Matsuura
    • Journal Title

      The 67^<th> National Convention of IPSJ 3T-8

    • Description
      「研究成果報告書概要(欧文)」より
    • Related Report
      2005 Final Research Report Summary
  • [Journal Article] メール添付型ウイルスの振る舞い検出2005

    • Author(s)
      池田健太, 松浦佐江子
    • Journal Title

      第67回全国大会講演論文集 情報処理学会 3

    • Description
      「研究成果報告書概要(和文)」より
    • Related Report
      2005 Final Research Report Summary 2004 Annual Research Report
  • [Journal Article] A Unit Testing Framework for Aspects without Weaving2005

    • Author(s)
      Y.Yamazaki, K.Sakurai, S.Matsuura, H.Masuhara, H.Hashiura, S.Komiya
    • Journal Title

      the 4-th International Conference on Aspect-Oriented Software Development, Workshop WTAOP

    • Description
      「研究成果報告書概要(和文)」より
    • Related Report
      2005 Final Research Report Summary
  • [Journal Article] A Unit Testing Framework for Aspects without Weaving.2005

    • Author(s)
      Y.Yamazaki, K.Sakurai, S.Matsuura, H.Masuhara, H.Hashiura, S.Komiya
    • Journal Title

      The 4th International Conference on Aspect-Oriented Software Development (AOSD'05) WTAOP

    • Description
      「研究成果報告書概要(欧文)」より
    • Related Report
      2005 Final Research Report Summary
  • [Journal Article] データ移動アドレス追跡によるメール添付型ウイルスの振る舞い検出2005

    • Author(s)
      池田健太, 松浦佐江子
    • Journal Title

      第68回全国大会講演論文集 情報処理学会 1

    • Related Report
      2005 Annual Research Report
  • [Journal Article] A Unit Testing Framework for Aspects without Weaving2005

    • Author(s)
      Y.Yamazaki, K.Sakurai, S.Matsuura, H.Masuhara, H.Hashiura, S.Komiya
    • Journal Title

      Proceedings of the 4-th International Conference on Aspect-Oriented Software Development, Workshop WTAOP

    • Related Report
      2004 Annual Research Report
  • [Journal Article] Association Aspects2004

    • Author(s)
      K.Sakurai, H.Masuhara, Ubayashi, S.Matsuura, S.Komiya
    • Journal Title

      proc. of International Conference on Aspect-Oriented Software Development (ASOD'04)

      Pages: 16-25

    • NAID

      110002911465

    • Description
      「研究成果報告書概要(和文)」より
    • Related Report
      2005 Final Research Report Summary
  • [Journal Article] Association Aspects.2004

    • Author(s)
      K.Sakurai, H.Masuhara, N.Ubayashi, S.Matsuura, S.Komiya
    • Journal Title

      Proc.of the 3rd International Conference on Aspect-Oriented Software Development (AOSD'04)

      Pages: 16-25

    • NAID

      110002911465

    • Description
      「研究成果報告書概要(欧文)」より
    • Related Report
      2005 Final Research Report Summary
  • [Publications] K.Sakurai, H.Masuhara, N.Ubayashi, S.Matsuura, S.Komiya: "Association Aspects"Proceedings of the 3rd International Conference on Aspect-Oriented Software Development (AOSD'04). 16-25 (2004)

    • Related Report
      2003 Annual Research Report
  • [Publications] 櫻井, 増原, 鵜林, 松浦, 古宮: "連想アスペクト"情報処理学会研究報告. SE144-28. (2004)

    • Related Report
      2003 Annual Research Report

URL: 

Published: 2003-04-01   Modified: 2016-04-21  

Information User Guide FAQ News Terms of Use Attribution of KAKENHI

Powered by NII kakenhi