MISC

2020年

IoT社会に向けた圧縮パケットに対するマルウェア検知手法の提案と評価

木更津工業高等専門学校紀要
  • 若葉 陽一

53
0
開始ページ
41
終了ページ
45
記述言語
日本語
掲載種別
DOI
10.19025/bnitk.53.0_41
出版者・発行元
独立行政法人 国立高等専門学校機構 木更津工業高等専門学校

This paper proposes a new malware detection method for a LZ compressed packet in NIDS. In this method, NIDS first inspects a compressed packet roughly, and selects a packet that is possibility of malware, that is like screening test. Subsequently, NIDS decompresses only the selected packet and inspects it exactly. Evaluation results show that this method is not practical for original LZ compression. Hence, this paper also denotes LZ based compression method which is suitable the proposed method. Re-evaluation results show that the proposed method archives 240% speed up proportion to the existing method by sacrificing compression size. It is expected that the proposed method contributes to compression as a new option.

リンク情報
DOI
https://doi.org/10.19025/bnitk.53.0_41
CiNii Articles
http://ci.nii.ac.jp/naid/130007826149
ID情報
  • DOI : 10.19025/bnitk.53.0_41
  • ISSN : 2188-9201
  • CiNii Articles ID : 130007826149

エクスポート
BibTeX RIS