The University of Tokyo · Computer Science
Professor Rikima Mitsuhashi's research lab specializes in cybersecurity, with a primary focus on detecting advanced cyber threats in encrypted network traffic. The lab develops machine learning-based systems to identify malicious activities such as DNS tunneling and DGA (Domain Generation Algorithm)-based malware, particularly in the context of encrypted DNS protocols like DNS over HTTPS (DoH). Their work emphasizes hierarchical machine learning models and transfer learning techniques for malware classification and network anomaly detection, enabling real-time threat identification while maintaining privacy. The lab also investigates the impact of deep learning architectures on malware variant recognition, aiming to reduce the workload of security analysts through automated classification systems.
Figures are computed from collected data and may differ slightly.
DNS over HTTPS (Do) can mitigate the risk of privacy breaches but makes it difficult to control network security services due to the DNS traffic encryption. However, since malicious DNS tunnel tools for the DoH protocol pose network security threats, network administrators need to recognize malicious communications even after the DNS traffic encryption has become widespread. In this paper, we propose a malicious DNS tunnel tool recognition system using persistent DoH traffic analysis based on ma
Analyzing a large amount of malware is a major burden for security analysts. Since emerging malware is often a variant of existing malware, automatically classifying malware into known families greatly reduces a part of their burden. Image-based malware classification with deep learning is an attractive approach due to its simplicity, versatility, and affinity with the latest technologies. However, the impact of differences in deep learning models and the degree of transfer learning on the class
Encrypted domain name resolution can reduce the risk of privacy leakage for Internet users, but it may also prevent network administrators from detecting suspicious communications. Since operating systems supporting DNS over HTTPS (DoH) have increased in recent years, malware that uses Domain Generation Algorithm (DGA) can exploit it to hide the generated domain names. In this paper, we propose a system that detects DGA-based malware communications from DoH traffic. Based on the concept of hiera
Analyzing a huge amount of malware is a major burden for security analysts. Since emerging malware is often a variant of existing ones, automatically classifying malware into known families greatly reduces their burden. Image-based malware classification with deep learning is an attractive approach for its simplicity, versatility, and affinity with existing technologies. However, the impact of different deep learning models and the degree of transfer learning on the classification accuracy has n
Encrypted domain name resolution is increasingly being used to protect the privacy of Internet users, but it may prevent network administrators from detecting malicious communications. Unfortunately, DGA-based malware can exploit it to hide the domain names it generates, so network administrators need a monitoring framework to maintain network security. In this paper, we propose a novel malware detection system using hierarchical machine learning analysis, which incorporates machine learning mod
Open papers in the app to read, cite, and organize with AI.