FIT2014 第13回情報科学技術フォーラム 開催日:2014年9月3日(水)~5日(金) 会場:筑波大学筑波キャンパス 一般社団法人電子情報通信学会 情報・システムソサイエティ 一般社団法人電子情報通信学会 ヒューマンコミュニケーショングループ 一般社団法人情報処理学会 筑波大学
Malware visualization based on the behavior and its classification
浦辻和也(愛媛大)・松重雄大(神戸大)・甲斐 博(愛媛大)・森井昌克(神戸大)
We consider a malware visualization scheme based on malware behaviors. Our purpose is to understand intuitively malware’s characteristics from the visualization. The behaviors are obtained from the "Technical Details" of the Security Response in the Symantec's webpage. We classified them into 4 categories, such as manipulation activities, subversive activities, information collection activities, infection activities. We collect words, which describe malware behaviors, from the Technical Details, then associate them with the categories. Then, we constructed malware models using word frequency arise in the categories. In this paper, we propose malware visualization models and a method for their automated creation.