東京大学 · 情報科学
リカマ・ミツハシ教授の研究室は、暗号化されたDNS通信(DoH)におけるマルウェアの隠れ家や不正通信を効果的に検出するための機械学習ベースのネットワーク監視技術を開発しています。特に、DGA(ドメイン生成アルゴリズム)を用いたマルウェアの通信を、階層的機械学習手法を用いて識別する仕組みを提案しており、リアルタイムでの知識更新と高い検出精度を実現しています。近年のDoHの普及に伴うセキュリティ課題に的を射た、実用的で実践的な研究が特徴です。
Figures are computed from collected data and may differ slightly.
DNS over HTTPS (Do) can mitigate the risk of privacy breaches but makes it difficult to control network security services due to the DNS traffic encryption. However, since malicious DNS tunnel tools for the DoH protocol pose network security threats, network administrators need to recognize malicious communications even after the DNS traffic encryption has become widespread. In this paper, we propose a malicious DNS tunnel tool recognition system using persistent DoH traffic analysis based on ma
Analyzing a large amount of malware is a major burden for security analysts. Since emerging malware is often a variant of existing malware, automatically classifying malware into known families greatly reduces a part of their burden. Image-based malware classification with deep learning is an attractive approach due to its simplicity, versatility, and affinity with the latest technologies. However, the impact of differences in deep learning models and the degree of transfer learning on the class
Encrypted domain name resolution can reduce the risk of privacy leakage for Internet users, but it may also prevent network administrators from detecting suspicious communications. Since operating systems supporting DNS over HTTPS (DoH) have increased in recent years, malware that uses Domain Generation Algorithm (DGA) can exploit it to hide the generated domain names. In this paper, we propose a system that detects DGA-based malware communications from DoH traffic. Based on the concept of hiera
Analyzing a huge amount of malware is a major burden for security analysts. Since emerging malware is often a variant of existing ones, automatically classifying malware into known families greatly reduces their burden. Image-based malware classification with deep learning is an attractive approach for its simplicity, versatility, and affinity with existing technologies. However, the impact of different deep learning models and the degree of transfer learning on the classification accuracy has n
Encrypted domain name resolution is increasingly being used to protect the privacy of Internet users, but it may prevent network administrators from detecting malicious communications. Unfortunately, DGA-based malware can exploit it to hide the domain names it generates, so network administrators need a monitoring framework to maintain network security. In this paper, we propose a novel malware detection system using hierarchical machine learning analysis, which incorporates machine learning mod
Open papers in the app to read, cite, and organize with AI.