• Search Research Projects
  • Search Researchers
  • How to Use
  1. Back to previous page

An automatic unpacking method for computer virus effective in the virus filter based on Bayesian theorem

Research Project

Project/Area Number 23500074
Research Category

Grant-in-Aid for Scientific Research (C)

Allocation TypeMulti-year Fund
Section一般
Research Field Computer system/Network
Research InstitutionIwate University

Principal Investigator

KOI Yuji  岩手大学, 工学部, 非常勤講師 (20333750)

Co-Investigator(Kenkyū-buntansha) NAKAYA Naoshi  岩手大学, 工学部, 准教授 (20322969)
Project Period (FY) 2011 – 2013
Project Status Completed (Fiscal Year 2013)
Budget Amount *help
¥5,200,000 (Direct Cost: ¥4,000,000、Indirect Cost: ¥1,200,000)
Fiscal Year 2013: ¥390,000 (Direct Cost: ¥300,000、Indirect Cost: ¥90,000)
Fiscal Year 2012: ¥1,820,000 (Direct Cost: ¥1,400,000、Indirect Cost: ¥420,000)
Fiscal Year 2011: ¥2,990,000 (Direct Cost: ¥2,300,000、Indirect Cost: ¥690,000)
Keywordsベイジアンフィルタ / ベイズの定理 / 難読化 / 暗号化 / 実行可能圧縮 / 未知ウイルス / スパイウェア / ベイジアンウイルスフィルタ / ボット / サイバーテロ / コンピュータウイルス / ボット
Research Abstract

A rapid automatic virus detection algorithm using static code analysis is necessary.However,recent computer viruses are almost compressed into the executable compress format and are obfuscated.Thus,it is difficult to determine the characteristics of the binary code from the obfuscated computer viruses.
In this research,a method that unpacks compressed computer viruses automatically without restriction to compression type is proposed.The proposed method unpacks the common compression formats accurately 80% of the time,while unknown compression formats can also be unpacked.The proposed method is effective against unknown viruses by combining it with the existing known virus detection system like Bayesian Virus Filter.We could achieve to implement 95% detection rates and 0.02% false detection rates.

Report

(4 results)
  • 2013 Annual Research Report   Final Research Report ( PDF )
  • 2012 Research-status Report
  • 2011 Research-status Report
  • Research Products

    (2 results)

All 2012 Other

All Presentation (2 results)

  • [Presentation] ベイズ学習アルゴリズムによるWineを用いた未知ウイルスの検出2012

    • Author(s)
      加藤正喜,中谷直司,厚井裕司
    • Organizer
      平成24年度 情報処理学会東北支部研究会
    • Place of Presentation
      岩手大学(岩手県)
    • Related Report
      2012 Research-status Report
  • [Presentation] Wineを用いたAPIログによるコンピュータウイルスの検出

    • Author(s)
      村上智裕,中谷直司,厚井裕司
    • Organizer
      平成23年度第4回情報処理学会東北支部研究会
    • Place of Presentation
      岩手大学(岩手県)
    • Related Report
      2011 Research-status Report

URL: 

Published: 2011-08-05   Modified: 2019-07-29  

Information User Guide FAQ News Terms of Use Attribution of KAKENHI

Powered by NII kakenhi