• 研究課題をさがす
  • 研究者をさがす
  • KAKENの使い方
  1. 課題ページに戻る

2023 年度 実施状況報告書

Research on IoT Anti-malware Technology beyond CPU Architectures

研究課題

研究課題/領域番号 22K12038
研究機関国立研究開発法人情報通信研究機構

研究代表者

班 涛  国立研究開発法人情報通信研究機構, サイバーセキュリティ研究所, 主任研究員 (80462878)

研究期間 (年度) 2022-04-01 – 2025-03-31
キーワードIoT malware analysis / IoT security / static analysis / packer / explainable AI / machine learning
研究実績の概要

In FY 2023, we advanced research on compatible malware protection across CPU architectures and resilience against cyberattacks. Here are the expanded details:
(1) Our research on employing explainable AI to identify unique characteristics in malware families was successfully concluded. We proposed the Color-coded Attribute Graph for intuitive and accurate malware analysis, which garnered significant attention in the cybersecurity community.
(2) Our exploration into detecting IoT malware in packed samples has provided valuable insights. Through an analysis of trends in packed malware on VirusTotal and overcoming challenges with reverse engineering tools, we have developed a robust solution. This solution involves feature selection and automated malware classification, shedding light on accurately and efficiently detecting packed IoT malware. It is poised to significantly enhance the overall security of IoT devices.
(3) With a keen focus on efficiency in resource-constrained devices and cross-platform compatibility, we delved deeper into methods for analyzing IoT malware using printable strings extracted from binary files. Our extensive validation process confirmed the effectiveness of these methods, paving the way for more robust malware detection techniques in the future.

現在までの達成度 (区分)
現在までの達成度 (区分)

2: おおむね順調に進展している

理由

In this FY, our primary objective of analyzing IoT malware across CPU architectures has yielded expected results: 1 conference paper accepted, 2 in preparation. Side research on packed malware faced slight delays; 1 paper withdrawn due to data insufficiency, prompting further investigation.
(1) Research on XAI for IoT malware analysis is successfully concluded, resulting in 1 international conference paper.
(2) Work on printable string-based malware detection is ongoing, utilizing effective suffix tree-based string processing methods, with 2 papers be in preparation.
(3) New research started on reinterpreting opcodes as system calls for malware samples without symbolic tables, aiming for compatible CPU architecture analysis through a transition from opcode to system call-level analysis.

今後の研究の推進方策

In the concluding year of this research project, our goal is to craft a pragmatic and precise malware detection system tailored for widespread IoT devices by integrating accumulated findings. Specifically, we aim to:
(1) Enhance malware detection through printable strings, refining classification accuracy and lessening reliance on system resources.
(2) Conclude our investigation into text processing methods grounded in suffix trees, fine-tuning parameters for effective analysis of IoT-related malware.
(3) Finalize our exploration of reinterpreting opcodes as system calls, enhancing malware analysis and ensuring compatibility across platforms.
(4) Persist in monitoring the evolving trends of packed programs within IoT malware, ensuring proactive measures against forthcoming threats.

次年度使用額が生じた理由

Originally, we had planned to participate in the International Symposium on Computer and Communications (ISCC2023) in Tunisia. However, due to changes in the country's visa policy, visa applications for overseas participants had not yet opened by the time of the conference. As a result, the overseas business trip was canceled, and the corresponding travel expenses were deferred to the fiscal year 2024. With the trip canceled, the paper is still published with ISCC2023 and the presentation is done remotely online.

  • 研究成果

    (2件)

すべて 2023 その他

すべて 国際共同研究 (1件) 学会発表 (1件) (うち国際学会 1件)

  • [国際共同研究] Taiwan Information Security Center/National Taiwan Uni. of Sci. and Tech.(その他の国・地域)

    • 国名
      その他の国・地域
    • 外国機関名
      Taiwan Information Security Center/National Taiwan Uni. of Sci. and Tech.
  • [学会発表] Color-coded Attribute Graph: Visual Exploration of Distinctive Traits of IoT-Malware Families2023

    • 著者名/発表者名
      Jiaxing Zhou, Tao Ban, Tomohiro Morikawa, Takeshi Takahashi, Daisuke Inoue
    • 学会等名
      2023 IEEE Symposium on Computers and Communications (ISCC)
    • 国際学会

URL: 

公開日: 2024-12-25  

サービス概要 検索マニュアル よくある質問 お知らせ 利用規程 科研費による研究の帰属

Powered by NII kakenhi