• Search Research Projects
  • Search Researchers
  • How to Use
  1. Back to project page

2005 Fiscal Year Final Research Report Summary

A Study on a Framework of Detection of Malicious Behavior Patterns

Research Project

Project/Area Number 15500025
Research Category

Grant-in-Aid for Scientific Research (C)

Allocation TypeSingle-year Grants
Section一般
Research Field Software
Research InstitutionShibaura Institute of Technology

Principal Investigator

MATSUURA Saeko  Shibaura Institute of Technology, Faculty of System Engieering, Department of Electronic & Information Systems, Assistant Professor, システム工学部, 助教授 (10348906)

Project Period (FY) 2003 – 2005
KeywordsDetection of Computer Virus / Framework / Behavioral Pattern / Object Oriented Model / Aspect Oriented / Detection Model / Data Movement Tracking / APISPY
Research Abstract

We studied a framework of the program that detects malicious behavioral patterns from the program that performs some malicious behavior which was not intended by the user. This framework was built based on a method which judges whether a program was a computer virus including unknown viruses. Computer virus is a typical malicious behavioral program. Moreover, we developed a program that collects behavioral data of the target program. In 2003, the unknown virus detection program was redesigned the model from both viewpoints of object-oriented development and meta-modeling. First, the program structure was analyzed based on the graphical model of the specification of behavioral patterns and the detection program by UML which is a unified modeling language in object-oriented development. The detection program consists of the following three parts. (1)An abstract model of the program execution environment. (2)The definition of behavioral patterns of virus. (3)The definition of detection of … More virus using the patterns. The program (written in Standard ML) is defined based on the specification described by the first order predicate logic using Extended ML. The specification, the part (2) and the part (3) are frozen spot of the framework of behavioral pattern detection program. The part (2)is a hot spot of the framework that may be changed according to some behavioral patterns that we want to detect them. In 2004, we defined the specification of the program as some modules and examined the effectiveness of aspect oriented programming techniques to our framework. However, the big merit was not found compared with defining the program by only classes. In 2005, we studied and implemented a method of tracking data movement in order to detect computer virus entering via mail system. We conducted some experiments to detect the virus. Such malicious programs have some devices to make it difficult to analyze themselves. We also defined a way to make the device ineffective. We are planning to verify the validity of this framework. Less

  • Research Products

    (8 results)

All 2006 2005 2004

All Journal Article (8 results)

  • [Journal Article] データ移動アドレス追跡によるメール添付型ウイルスの振る舞い検出2006

    • Author(s)
      池田健太, 松浦佐江子
    • Journal Title

      第68回全国大会講演論文集 情報処理学会 1

      Pages: 1-63-1-64

    • Description
      「研究成果報告書概要(和文)」より
  • [Journal Article] Behavior detection of mail attached type virus by data movement address pursuit.2006

    • Author(s)
      K.Ikeda, S.Matsuura
    • Journal Title

      The 68^<th> National Convention of IPSJ 1J-1

    • Description
      「研究成果報告書概要(欧文)」より
  • [Journal Article] Detection of Computer Virus entering via Mail System.2006

    • Author(s)
      K.Ikeda, S.Matsuura
    • Journal Title

      The 67^<th> National Convention of IPSJ 3T-8

    • Description
      「研究成果報告書概要(欧文)」より
  • [Journal Article] メール添付型ウイルスの振る舞い検出2005

    • Author(s)
      池田健太, 松浦佐江子
    • Journal Title

      第67回全国大会講演論文集 情報処理学会 3

      Pages: 3-581-3-582

    • Description
      「研究成果報告書概要(和文)」より
  • [Journal Article] A Unit Testing Framework for Aspects without Weaving2005

    • Author(s)
      Y.Yamazaki, K.Sakurai, S.Matsuura, H.Masuhara, H.Hashiura, S.Komiya
    • Journal Title

      the 4-th International Conference on Aspect-Oriented Software Development, Workshop WTAOP

    • Description
      「研究成果報告書概要(和文)」より
  • [Journal Article] A Unit Testing Framework for Aspects without Weaving.2005

    • Author(s)
      Y.Yamazaki, K.Sakurai, S.Matsuura, H.Masuhara, H.Hashiura, S.Komiya
    • Journal Title

      The 4th International Conference on Aspect-Oriented Software Development (AOSD'05) WTAOP

    • Description
      「研究成果報告書概要(欧文)」より
  • [Journal Article] Association Aspects2004

    • Author(s)
      K.Sakurai, H.Masuhara, Ubayashi, S.Matsuura, S.Komiya
    • Journal Title

      proc. of International Conference on Aspect-Oriented Software Development (ASOD'04)

      Pages: 16-25

    • Description
      「研究成果報告書概要(和文)」より
  • [Journal Article] Association Aspects.2004

    • Author(s)
      K.Sakurai, H.Masuhara, N.Ubayashi, S.Matsuura, S.Komiya
    • Journal Title

      Proc.of the 3rd International Conference on Aspect-Oriented Software Development (AOSD'04)

      Pages: 16-25

    • Description
      「研究成果報告書概要(欧文)」より

URL: 

Published: 2007-12-13  

Information User Guide FAQ News Terms of Use Attribution of KAKENHI

Powered by NII kakenhi