Skip to main content
QUICK REVIEW

[論文レビュー] A Comparison of Trojan Virus Behavior in Linux and Windows Operating Systems

Ghossoon. M. W. Al-Saadoon, Hilal M. Y. Al-Bayatti|arXiv (Cornell University)|May 6, 2011
Advanced Malware Detection Techniques参考文献 1被引用数 8
ひとこと要約

この論文は、Wiresharkを用いてキャプチャしたネットワークパケットを分析することで、LinuxとWindowsにおけるトロイの木馬ウイルスの行動を比較している。主な焦点は、ペイロードサイズ、制御ビット、およびメール添付ファイルやチャットソフトウェアなどの感染経路である。Windowsは、パケットヘッダーやペイロード特性におけるより顕著な検出可能な行動パターンを示しているのに対し、Linuxはそれほど顕著でない。これは、Windowsは特定のネットワークベースのトロイの木馬検出手法に対してより脆弱である可能性を示唆している。

ABSTRACT

Trojan virus attacks pose one of the most serious threats to computer security. A Trojan horse is typically separated into two parts - a server and a client. It is the client that is cleverly disguised as significant software and positioned in peer-to-peer file sharing networks, or unauthorized download websites. The most common means of infection is through email attachments. The developer of the virus usually uses various spamming techniques in order to distribute the virus to unsuspecting users. Malware developers use chat software as another method to spread their Trojan horse viruses such as Yahoo Messenger and Skype. The objective of this paper is to explore the network packet information and detect the behavior of Trojan attacks to monitoring operating systems such as Windows and Linux. This is accomplished by detecting and analyzing the Trojan infected packet from a network segment -which passes through email attachment- before attacking a host computer. The results that have been obtained to detect information and to store infected packets through monitoring when using the web browser also compare the behaviors of Linux and Windows using the payload size after implementing the Wireshark sniffer packet results. Conclusions of the figures analysis from the packet captured data to analyze the control bit, and check the behavior of the control bits, and the usability of the operating systems Linux and Windows.

研究の動機と目的

  • LinuxとWindowsのオペレーティングシステムにおけるトロイの木馬ウイルス行動の違いを調査すること。
  • トロイの木馬感染時のネットワークパケット特性(特にペイロードサイズと制御ビット)を分析すること。
  • Wiresharkのようなパケットスニffィングツールを用いたネットワークベースの検出の有効性を評価すること。
  • 両オペレーティングシステムにおける、メール添付ファイルやP2Pファイル共有などの感染経路を比較すること。
  • トロイの木馬攻撃時におけるネットワークトラフィックにおいて、どのOSがより検出可能な行動シグネチャを示すかを特定すること。

提案手法

  • シミュレートされたトロイの木馬攻撃中に、Wiresharkスニッファーツールを用いてネットワークパケットをキャプチャした。
  • メール添付ファイルおよびチャットソフトウェア(例:Yahoo Messenger、Skype)からのトラフィックをモニタリングした。
  • TCPパケット内の制御ビット(例:URG、ACK、PSH)の分析を通じて、行動の違いを特定した。
  • LinuxおよびWindowsホスト間で、感染パケットのペイロードサイズを測定・比較した。
  • 行動分析および比較のため、感染パケットを収集・保存した。
  • ネットワークセグメントのモニタリングを用いて、ホストが侵害される前段階で悪意のあるパケットフローを検出・ログ記録した。

実験結果

リサーチクエスチョン

  • RQ1LinuxとWindowsシステムにおけるトロイの木馬のネットワークパケット行動は、どのように異なるか?
  • RQ2TCPパケット内の制御ビットは、LinuxとWindowsにおけるトロイの木馬活動を区別するために果たす役割は何か?
  • RQ3同じ攻撃条件下で、両OSにおける感染パケットのペイロードサイズはどのように異なるか?
  • RQ4メール添付ファイルとチャットソフトウェアのどちらの感染経路が、より顕著なネットワークシグネチャを生じるか?
  • RQ5Wiresharkを用いたパケット解析は、LinuxとWindowsにおけるトロイの木馬行動の差をどの程度効果的に区別できるか?

主な発見

  • Windowsシステムでは、トロイの木馬通信中に制御ビットの使用パターンが、Linuxと比較してより一貫性があり、検出可能であった。
  • 同様の攻撃条件下で、Windowsシステムの感染パケットにおけるペイロードサイズは、Linuxシステムよりも顕著に大きかった。
  • テスト環境では、チャットソフトウェアよりもメール添付ファイルが、より一般的で検出可能なトロイの木馬配布経路であった。
  • Wiresharkの使用により、特にTCPヘッダー内の行動の異常を特定する上で、悪意のあるパケットの信頼性あるキャプチャと分析が可能になった。
  • Linuxシステムでは、パケットデータにおける行動シグネチャが予測不可能な傾向にあり、ネットワーク監視のみでは検出が難しい可能性がある。
  • 制御ビット分析の結果、Windowsベースのトロイの木馬は、Linuxベースのバージョンと比較して、特定の組み合わせ(例:PSHとACK)をより一貫して使用していることが判明した。

より良い研究を、今すぐ始めましょう

論文の読解から最終レビューまで、研究時間を劇的に削減しましょう。

クレジットカード登録不要

このレビューはAIが作成し、人間の編集者が確認しました。