The University of Tokyo · 컴퓨터과학
리키마 미츠하시 교수의 연구실은 암호화된 DNS 트래픽 환경에서의 사이버 위협 탐지에 초점을 맞추고 있습니다. 특히 DNS over HTTPS (DoH)로 암호화된 트래픽 내에서 악성 도메인 생성 알고리즘(DGA)을 이용한 악성 소프트웨어나 DNS 터널링 공격을 인식하기 위한 기계학습 기반의 지능형 감시 시스템을 개발하고 있습니다. 연구는 고도화된 머신러닝 기법, 특히 계층적 기계학습 및 트리 기반 앙상블 모델(XGBoost, LightGBM 등)을 활용하여 실시간 보안 제어를 가능하게 합니다. 또한, 이미지 기반 딥러닝을 활용한 악성코드 유형 분류에 대한 체계적 연구도 병행하고 있습니다.
표시된 성과는 수집된 데이터 기준으로 산출되며, 일부 차이가 있을 수 있습니다.
DNS over HTTPS (Do) can mitigate the risk of privacy breaches but makes it difficult to control network security services due to the DNS traffic encryption. However, since malicious DNS tunnel tools for the DoH protocol pose network security threats, network administrators need to recognize malicious communications even after the DNS traffic encryption has become widespread. In this paper, we propose a malicious DNS tunnel tool recognition system using persistent DoH traffic analysis based on ma
Analyzing a large amount of malware is a major burden for security analysts. Since emerging malware is often a variant of existing malware, automatically classifying malware into known families greatly reduces a part of their burden. Image-based malware classification with deep learning is an attractive approach due to its simplicity, versatility, and affinity with the latest technologies. However, the impact of differences in deep learning models and the degree of transfer learning on the class
Encrypted domain name resolution can reduce the risk of privacy leakage for Internet users, but it may also prevent network administrators from detecting suspicious communications. Since operating systems supporting DNS over HTTPS (DoH) have increased in recent years, malware that uses Domain Generation Algorithm (DGA) can exploit it to hide the generated domain names. In this paper, we propose a system that detects DGA-based malware communications from DoH traffic. Based on the concept of hiera
Analyzing a huge amount of malware is a major burden for security analysts. Since emerging malware is often a variant of existing ones, automatically classifying malware into known families greatly reduces their burden. Image-based malware classification with deep learning is an attractive approach for its simplicity, versatility, and affinity with existing technologies. However, the impact of different deep learning models and the degree of transfer learning on the classification accuracy has n
Encrypted domain name resolution is increasingly being used to protect the privacy of Internet users, but it may prevent network administrators from detecting malicious communications. Unfortunately, DGA-based malware can exploit it to hide the domain names it generates, so network administrators need a monitoring framework to maintain network security. In this paper, we propose a novel malware detection system using hierarchical machine learning analysis, which incorporates machine learning mod