The Experts below are selected from a list of 126 Experts worldwide ranked by ideXlab platform
Mitsutaka Itoh - One of the best experts on this subject based on the ideXlab platform.
-
Intelligent High-Interaction Web Honeypots Based on URL Conversion Scheme
IEICE Transactions on Communications, 2011Co-Authors: Takeshi Yagi, Naoto Tanimoto, Takeo Hariu, Mitsutaka ItohAbstract:Vulnerabilities in web applications expose computer networks to security threats. For example, attackers use a large number of normal user websites as hopping sites, which are illegally operated using malware distributed by abusing vulnerabilities in web applications on these websites, for attacking other websites and user terminals. Thus, the security threats, resulting from vulnerabilities in web applications prevent service providers from constructing secure networking environments. To protect websites from attacks based on the vulnerabilities of web applications, security vendors and service providers collect attack information using web honeypots, which masquerade as vulnerable systems. To collect all accesses resulting from attacks that include further network attacks by malware, such as downloaders, vendors and providers use high-interaction web honeypots, which are composed of vulnerable systems with surveillance functions. However, conventional high-interaction web honeypots can collect only limited information and malware from attacks, whose paths in the destination URLs do not match the path structure of the web honeypot since these attacks are failures. To solve this problem, we propose a scheme in which the destination URLs of these attacks are corrected by determining the correct path from the path structure of the web honeypot. Our Internet Investigation revealed that 97% of attacks are failures. However, we confirmed that approximately 50% of these attacks will succeed with our proposed scheme. We can use much more information with this scheme to protect websites than with conventional high-interaction web honeypots because we can collect complete information and malware from these attacks.
-
ISCC - Enhanced attack collection scheme on high-interaction web honeypots
The IEEE symposium on Computers and Communications, 2010Co-Authors: Takeshi Yagi, Naoto Tanimoto, Takeo Hariu, Mitsutaka ItohAbstract:Vulnerabilities in web applications expose computer networks to security threats. In fact, a large number of websites are used by attackers as hopping sites for attacking other websites and user terminals. These incidents prevent service providers from constructing secure networking environments. To protect websites from attacks based on vulnerabilities of web applications, security vendors and service providers collect attack information using web honeypots, which masquerade as vulnerable systems. To gain full access and to launch further network attacks by executing malware, such as a downloader, vendors and providers use high-interaction web honeypots, which are composed of real vulnerable systems and surveillance functions. However, conventional high-interactive web honeypots can collect only limited information and malware from attacks, whose path to the destination URL does not match the path structure of the web honeypot, due to the fact that these attacks are failures. To solve this problem, we propose scheme in which the destination URLs of these attacks are corrected by determining the correct path from the path structure of the web honeypot. Our Internet Investigation reveals that 97 percent of attacks are failures. However, we confirmed that about 50 percent of these attacks will succeed with our proposed scheme. With our proposed scheme, we can use much more information to protect websites than with conventional high-interaction web honeypots because we can collect complete information and malware from these attacks.
-
Enhanced attack collection scheme on high-interaction web honeypots
Proceedings - IEEE Symposium on Computers and Communications, 2010Co-Authors: Takeshi Yagi, Naoto Tanimoto, Takeo Hariu, Mitsutaka ItohAbstract:Vulnerabilities in web applications expose computer networks to security threats. In fact, a large number of websites are used by attackers as hopping sites for attacking other websites and user terminals. These incidents prevent service providers from constructing secure networking environments. To protect websites from attacks based on vulnerabilities of web applications, security vendors and service providers collect attack information using web honeypots, which masquerade as vulnerable systems. To gain full access and to launch further network attacks by executing malware, such as a downloader, vendors and providers use high-interaction web honeypots, which are composed of real vulnerable systems and surveillance functions. However, conventional high-interactive web honeypots can collect only limited information and malware from attacks, whose path to the destination URL does not match the path structure of the web honeypot, due to the fact that these attacks are failures. To solve this problem, we propose scheme in which the destination URLs of these attacks are corrected by determining the correct path from the path structure of the web honeypot. Our Internet Investigation reveals that 97 percent of attacks are failures. However, we confirmed that about 50 percent of these attacks will succeed with our proposed scheme. With our proposed scheme, we can use much more information to protect websites than with conventional high-interaction web honeypots because we can collect complete information and malware from these attacks.
Takeshi Yagi - One of the best experts on this subject based on the ideXlab platform.
-
Intelligent High-Interaction Web Honeypots Based on URL Conversion Scheme
IEICE Transactions on Communications, 2011Co-Authors: Takeshi Yagi, Naoto Tanimoto, Takeo Hariu, Mitsutaka ItohAbstract:Vulnerabilities in web applications expose computer networks to security threats. For example, attackers use a large number of normal user websites as hopping sites, which are illegally operated using malware distributed by abusing vulnerabilities in web applications on these websites, for attacking other websites and user terminals. Thus, the security threats, resulting from vulnerabilities in web applications prevent service providers from constructing secure networking environments. To protect websites from attacks based on the vulnerabilities of web applications, security vendors and service providers collect attack information using web honeypots, which masquerade as vulnerable systems. To collect all accesses resulting from attacks that include further network attacks by malware, such as downloaders, vendors and providers use high-interaction web honeypots, which are composed of vulnerable systems with surveillance functions. However, conventional high-interaction web honeypots can collect only limited information and malware from attacks, whose paths in the destination URLs do not match the path structure of the web honeypot since these attacks are failures. To solve this problem, we propose a scheme in which the destination URLs of these attacks are corrected by determining the correct path from the path structure of the web honeypot. Our Internet Investigation revealed that 97% of attacks are failures. However, we confirmed that approximately 50% of these attacks will succeed with our proposed scheme. We can use much more information with this scheme to protect websites than with conventional high-interaction web honeypots because we can collect complete information and malware from these attacks.
-
ISCC - Enhanced attack collection scheme on high-interaction web honeypots
The IEEE symposium on Computers and Communications, 2010Co-Authors: Takeshi Yagi, Naoto Tanimoto, Takeo Hariu, Mitsutaka ItohAbstract:Vulnerabilities in web applications expose computer networks to security threats. In fact, a large number of websites are used by attackers as hopping sites for attacking other websites and user terminals. These incidents prevent service providers from constructing secure networking environments. To protect websites from attacks based on vulnerabilities of web applications, security vendors and service providers collect attack information using web honeypots, which masquerade as vulnerable systems. To gain full access and to launch further network attacks by executing malware, such as a downloader, vendors and providers use high-interaction web honeypots, which are composed of real vulnerable systems and surveillance functions. However, conventional high-interactive web honeypots can collect only limited information and malware from attacks, whose path to the destination URL does not match the path structure of the web honeypot, due to the fact that these attacks are failures. To solve this problem, we propose scheme in which the destination URLs of these attacks are corrected by determining the correct path from the path structure of the web honeypot. Our Internet Investigation reveals that 97 percent of attacks are failures. However, we confirmed that about 50 percent of these attacks will succeed with our proposed scheme. With our proposed scheme, we can use much more information to protect websites than with conventional high-interaction web honeypots because we can collect complete information and malware from these attacks.
-
Enhanced attack collection scheme on high-interaction web honeypots
Proceedings - IEEE Symposium on Computers and Communications, 2010Co-Authors: Takeshi Yagi, Naoto Tanimoto, Takeo Hariu, Mitsutaka ItohAbstract:Vulnerabilities in web applications expose computer networks to security threats. In fact, a large number of websites are used by attackers as hopping sites for attacking other websites and user terminals. These incidents prevent service providers from constructing secure networking environments. To protect websites from attacks based on vulnerabilities of web applications, security vendors and service providers collect attack information using web honeypots, which masquerade as vulnerable systems. To gain full access and to launch further network attacks by executing malware, such as a downloader, vendors and providers use high-interaction web honeypots, which are composed of real vulnerable systems and surveillance functions. However, conventional high-interactive web honeypots can collect only limited information and malware from attacks, whose path to the destination URL does not match the path structure of the web honeypot, due to the fact that these attacks are failures. To solve this problem, we propose scheme in which the destination URLs of these attacks are corrected by determining the correct path from the path structure of the web honeypot. Our Internet Investigation reveals that 97 percent of attacks are failures. However, we confirmed that about 50 percent of these attacks will succeed with our proposed scheme. With our proposed scheme, we can use much more information to protect websites than with conventional high-interaction web honeypots because we can collect complete information and malware from these attacks.
Naoto Tanimoto - One of the best experts on this subject based on the ideXlab platform.
-
Intelligent High-Interaction Web Honeypots Based on URL Conversion Scheme
IEICE Transactions on Communications, 2011Co-Authors: Takeshi Yagi, Naoto Tanimoto, Takeo Hariu, Mitsutaka ItohAbstract:Vulnerabilities in web applications expose computer networks to security threats. For example, attackers use a large number of normal user websites as hopping sites, which are illegally operated using malware distributed by abusing vulnerabilities in web applications on these websites, for attacking other websites and user terminals. Thus, the security threats, resulting from vulnerabilities in web applications prevent service providers from constructing secure networking environments. To protect websites from attacks based on the vulnerabilities of web applications, security vendors and service providers collect attack information using web honeypots, which masquerade as vulnerable systems. To collect all accesses resulting from attacks that include further network attacks by malware, such as downloaders, vendors and providers use high-interaction web honeypots, which are composed of vulnerable systems with surveillance functions. However, conventional high-interaction web honeypots can collect only limited information and malware from attacks, whose paths in the destination URLs do not match the path structure of the web honeypot since these attacks are failures. To solve this problem, we propose a scheme in which the destination URLs of these attacks are corrected by determining the correct path from the path structure of the web honeypot. Our Internet Investigation revealed that 97% of attacks are failures. However, we confirmed that approximately 50% of these attacks will succeed with our proposed scheme. We can use much more information with this scheme to protect websites than with conventional high-interaction web honeypots because we can collect complete information and malware from these attacks.
-
ISCC - Enhanced attack collection scheme on high-interaction web honeypots
The IEEE symposium on Computers and Communications, 2010Co-Authors: Takeshi Yagi, Naoto Tanimoto, Takeo Hariu, Mitsutaka ItohAbstract:Vulnerabilities in web applications expose computer networks to security threats. In fact, a large number of websites are used by attackers as hopping sites for attacking other websites and user terminals. These incidents prevent service providers from constructing secure networking environments. To protect websites from attacks based on vulnerabilities of web applications, security vendors and service providers collect attack information using web honeypots, which masquerade as vulnerable systems. To gain full access and to launch further network attacks by executing malware, such as a downloader, vendors and providers use high-interaction web honeypots, which are composed of real vulnerable systems and surveillance functions. However, conventional high-interactive web honeypots can collect only limited information and malware from attacks, whose path to the destination URL does not match the path structure of the web honeypot, due to the fact that these attacks are failures. To solve this problem, we propose scheme in which the destination URLs of these attacks are corrected by determining the correct path from the path structure of the web honeypot. Our Internet Investigation reveals that 97 percent of attacks are failures. However, we confirmed that about 50 percent of these attacks will succeed with our proposed scheme. With our proposed scheme, we can use much more information to protect websites than with conventional high-interaction web honeypots because we can collect complete information and malware from these attacks.
-
Enhanced attack collection scheme on high-interaction web honeypots
Proceedings - IEEE Symposium on Computers and Communications, 2010Co-Authors: Takeshi Yagi, Naoto Tanimoto, Takeo Hariu, Mitsutaka ItohAbstract:Vulnerabilities in web applications expose computer networks to security threats. In fact, a large number of websites are used by attackers as hopping sites for attacking other websites and user terminals. These incidents prevent service providers from constructing secure networking environments. To protect websites from attacks based on vulnerabilities of web applications, security vendors and service providers collect attack information using web honeypots, which masquerade as vulnerable systems. To gain full access and to launch further network attacks by executing malware, such as a downloader, vendors and providers use high-interaction web honeypots, which are composed of real vulnerable systems and surveillance functions. However, conventional high-interactive web honeypots can collect only limited information and malware from attacks, whose path to the destination URL does not match the path structure of the web honeypot, due to the fact that these attacks are failures. To solve this problem, we propose scheme in which the destination URLs of these attacks are corrected by determining the correct path from the path structure of the web honeypot. Our Internet Investigation reveals that 97 percent of attacks are failures. However, we confirmed that about 50 percent of these attacks will succeed with our proposed scheme. With our proposed scheme, we can use much more information to protect websites than with conventional high-interaction web honeypots because we can collect complete information and malware from these attacks.
Takeo Hariu - One of the best experts on this subject based on the ideXlab platform.
-
Intelligent High-Interaction Web Honeypots Based on URL Conversion Scheme
IEICE Transactions on Communications, 2011Co-Authors: Takeshi Yagi, Naoto Tanimoto, Takeo Hariu, Mitsutaka ItohAbstract:Vulnerabilities in web applications expose computer networks to security threats. For example, attackers use a large number of normal user websites as hopping sites, which are illegally operated using malware distributed by abusing vulnerabilities in web applications on these websites, for attacking other websites and user terminals. Thus, the security threats, resulting from vulnerabilities in web applications prevent service providers from constructing secure networking environments. To protect websites from attacks based on the vulnerabilities of web applications, security vendors and service providers collect attack information using web honeypots, which masquerade as vulnerable systems. To collect all accesses resulting from attacks that include further network attacks by malware, such as downloaders, vendors and providers use high-interaction web honeypots, which are composed of vulnerable systems with surveillance functions. However, conventional high-interaction web honeypots can collect only limited information and malware from attacks, whose paths in the destination URLs do not match the path structure of the web honeypot since these attacks are failures. To solve this problem, we propose a scheme in which the destination URLs of these attacks are corrected by determining the correct path from the path structure of the web honeypot. Our Internet Investigation revealed that 97% of attacks are failures. However, we confirmed that approximately 50% of these attacks will succeed with our proposed scheme. We can use much more information with this scheme to protect websites than with conventional high-interaction web honeypots because we can collect complete information and malware from these attacks.
-
ISCC - Enhanced attack collection scheme on high-interaction web honeypots
The IEEE symposium on Computers and Communications, 2010Co-Authors: Takeshi Yagi, Naoto Tanimoto, Takeo Hariu, Mitsutaka ItohAbstract:Vulnerabilities in web applications expose computer networks to security threats. In fact, a large number of websites are used by attackers as hopping sites for attacking other websites and user terminals. These incidents prevent service providers from constructing secure networking environments. To protect websites from attacks based on vulnerabilities of web applications, security vendors and service providers collect attack information using web honeypots, which masquerade as vulnerable systems. To gain full access and to launch further network attacks by executing malware, such as a downloader, vendors and providers use high-interaction web honeypots, which are composed of real vulnerable systems and surveillance functions. However, conventional high-interactive web honeypots can collect only limited information and malware from attacks, whose path to the destination URL does not match the path structure of the web honeypot, due to the fact that these attacks are failures. To solve this problem, we propose scheme in which the destination URLs of these attacks are corrected by determining the correct path from the path structure of the web honeypot. Our Internet Investigation reveals that 97 percent of attacks are failures. However, we confirmed that about 50 percent of these attacks will succeed with our proposed scheme. With our proposed scheme, we can use much more information to protect websites than with conventional high-interaction web honeypots because we can collect complete information and malware from these attacks.
-
Enhanced attack collection scheme on high-interaction web honeypots
Proceedings - IEEE Symposium on Computers and Communications, 2010Co-Authors: Takeshi Yagi, Naoto Tanimoto, Takeo Hariu, Mitsutaka ItohAbstract:Vulnerabilities in web applications expose computer networks to security threats. In fact, a large number of websites are used by attackers as hopping sites for attacking other websites and user terminals. These incidents prevent service providers from constructing secure networking environments. To protect websites from attacks based on vulnerabilities of web applications, security vendors and service providers collect attack information using web honeypots, which masquerade as vulnerable systems. To gain full access and to launch further network attacks by executing malware, such as a downloader, vendors and providers use high-interaction web honeypots, which are composed of real vulnerable systems and surveillance functions. However, conventional high-interactive web honeypots can collect only limited information and malware from attacks, whose path to the destination URL does not match the path structure of the web honeypot, due to the fact that these attacks are failures. To solve this problem, we propose scheme in which the destination URLs of these attacks are corrected by determining the correct path from the path structure of the web honeypot. Our Internet Investigation reveals that 97 percent of attacks are failures. However, we confirmed that about 50 percent of these attacks will succeed with our proposed scheme. With our proposed scheme, we can use much more information to protect websites than with conventional high-interaction web honeypots because we can collect complete information and malware from these attacks.
Azri Azmi - One of the best experts on this subject based on the ideXlab platform.
-
Analysing malware log files for Internet Investigation using Hadoop platform
International Journal of Digital Enterprise Technology, 2019Co-Authors: Mohd Sharudin Mat Deli, Saiful Adli Ismail, Othman Mohd Yusop, Mohd Nazri Kama, Azri AzmiAbstract:To protect the computer and Internet users from exposing themselves towards malware attacks, identifying the attacks through investigating malware log file is an essential step to curb this threat. The log file exposes crucial information in identifying the malware, such as algorithm and functional characteristic, the network interaction between the source and the destination, and type of malware. By nature, the log file size is humongous and requires the Investigation process to be executed on faster and stable platform such as big data environment. In this study, Hadoop technology used to process and extract the information from the malware log files that obtains from university's security equipment. The Python program was used for data transformation then analysis it in Hadoop simulation environment. The results of log processing have reduced 50% of the original log file size, while the total execution time would not increase linearly with the size of the data.
-
Malware log files for Internet Investigation using hadoop: A review
2017 IEEE Conference on Big Data and Analytics (ICBDA), 2017Co-Authors: Mohd Sharudin Mat Deli, Saiful Adli Ismail, Nazri Kama, Othman Mohd Yusop, Azri Azmi, Yazriwati YahyaAbstract:On the Internet, malware is one of the most serious threats to system security. Major complex issues and problems on some software systems are oftentimes made by malware. Malware can infect any computer software that causes connection to Internet infrastructure. There are many types of malware and some of the popular malware are Botnet, Trojans, Viruses, Spyware and Adware. Internet users with lesser knowledge of the malware threats are susceptible to this issue. To protect and prevent the computer and Internet users from exposing themselves towards malware attacks, identifying the attacks through investigating malware log file is an essential step to curb this threat. The log file exposes crucial information in identifying the malware, such as algorithm and functional characteristic, the network interaction between the source and the destination, and type of malware. By nature, the log file size is humongous and requires the Investigation process to be executed on faster and stable platforms such as the big data environment. In this study, the authors had adopted Hadoop, an open source software framework to process and extract the information from the malware log files. The information of data will be used for further prevention and protection from malware threats.