EP3200115B1

Specification device, specification method, and specification program

Abstract

This record has no abstract on file.

EP3200115B1, drawing sheet 1
Sheet 1 of 6

Term

9 yearsleft in the term

Expires 8 October 2035.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Expires

5 claims: 3 independent, 2 dependent

  1. 1
    An identifying device (10) comprising:a malware execution environment unit (10a) configured to execute malware (11) to be analyzed on a guest OS (12);a monitoring unit (13a) configured to monitor the malware (11) and acquire, as log data, the malware (11), download data downloaded from a communication destination, and a relation of data transfer performed with the malware (11) or the communication destination of the download data;a creating unit (15) configured to create, by using the log data acquired by the monitoring unit (13a), a dependency relation graph that is a digraph in which the malware (11), the download data, and the communication destination are set as nodes and a dependency relation of each node is set as an edge;and an identifying unit (16) configured to detect a malicious node by collating the respective nodes of the dependency relation graph created by the creating unit (15) with known maliciousness information, to trace an edge between nodes having a data dependency relation from a terminal point which is the detected malicious node to a start point, to identify the start point as malicious on the ground of maliciousness of the terminal node, and to identify a traced node between the start point and the terminal point as a new malicious node, wherein the monitoring unit (13a) performs monitoring by assigning a tag to a file of the malware (11), and in the case where the malware (11) calls an API to be monitored, the monitoring unit (13a) acquires the log data by assigning, to data related to the API, a tag that can uniquely identify a transmission source of the data and then tracking propagation of the data assigned with the tag, and wherein the monitoring unit (13a) further performs monitoring by acquiring a value of an instruction pointer register and determining if a memory region indicated by the instruction pointer register is assigned with a monitoring target tag, and the creating unit (15) is configured to track a dependency relation between the download data and execution of program code based on the determining if the memory region is assigned with a monitoring target tag.
  2. 4
    An identifying method executed in an identifying device (10), comprising processes of:executing malware (11) to be analyzed on a guest OS (12) ;monitoring the malware (11) and acquiring, as log data, the malware (11), download data downloaded from a communication destination, and a relation of data transfer performed with the malware (11) or the communication destination of the download data;creating, by using the log data acquired in the monitoring process, a dependency relation graph that is a digraph in which the malware (11), the download data, and the communication destination are set as nodes and a dependency relation of each node is set as an edge;and detecting a malicious node by collating the respective nodes of the dependency relation graph created in the creating process with known maliciousness information, and tracing an edge between nodes having a data dependency relation from a terminal point which is the detected malicious node to a start point, identifying the start point as malicious on the ground of maliciousness of the terminal node, and identifying a traced node between the start point and the terminal point as a new malicious node, wherein the monitoring is performed by assigning a tag to a file of the malware (11), and in the case where the malware (11) calls an API to be monitored, the monitoring unit (13a) acquires the log data by assigning, to data related to the API, a tag that can uniquely identify a transmission source of the data and then tracking propagation of the data assigned with the tag, and wherein the monitoring is further performed by acquiring a value of an instruction pointer register and determining if a memory region indicated by the instruction pointer register is assigned with a monitoring target tag, and the creating is performed by tracking a dependency relation between the download data and execution of program code based on the determining if the memory region is assigned with a monitoring target tag.
  3. 5
    An identifying program to cause a computer to execute steps of:executing malware (11) to be analyzed on a guest OS (12) ;monitoring the malware (11) and acquiring, as log data, the malware (11), download data downloaded from a communication destination, and a relation of data transfer performed with the malware (11) or the communication destination of the download data;creating, by using the log data acquired in the monitoring step, a dependency relation graph that is a digraph in which the malware (11), the download data, and the communication destination are set as nodes and a dependency relation of each node is set as an edge;and detecting a malicious node by collating the respective nodes of the dependency relation graph created in the creating step with known maliciousness information, and tracing an edge between nodes having a data dependency relation from a terminal point which is the detected malicious node to a start point, identifying the start point as malicious on the ground of maliciousness of the terminal node, and identifying a traced node between the start point and the terminal point as a new malicious node, wherein the monitoring is performed by assigning a tag to a file of the malware (11), and in the case where the malware (11) calls an API to be monitored, the monitoring unit (13a) acquires the log data by assigning, to data related to the API, a tag that can uniquely identify a transmission source of the data and then tracking propagation of the data assigned with the tag, and wherein the monitoring is further performed by acquiring a value of an instruction pointer register and determining if a memory region indicated by the instruction pointer register is assigned with a monitoring target tag, and the creating is performed by tracking a dependency relation between the download data and execution of program code based on the determining if the memory region is assigned with a monitoring target tag.