发明名称 IDENTIFICATION DEVICE, IDENTIFICATION METHOD, AND IDENTIFICATION PROGRAM
摘要 In the present invention, when malware (11a) is executed a command server identification device (10) assigns to data received by the malware (11a) a tag capable of uniquely identifying identification information of the data transmission source, and tracks the propagation of the tagged data. In addition, the command server identification device (10) acquires, among the tracked data, the tag of data referenced by a branch command executed by the malware (11a). Furthermore, the command server identification device (10) analyzes information pertaining to the commands of branch destinations not executed by the malware (11a) after the branch command. Then, on the basis of the analysis result, the command server identification device (10) identifies, from the identification information of the transmission source corresponding to the acquired tag, the identification information of the command server issuing commands to the malware (11a).
申请公布号 WO2016093182(A1) 申请公布日期 2016.06.16
申请号 WO2015JP84215 申请日期 2015.12.04
申请人 NIPPON TELEGRAPH AND TELEPHONE CORPORATION 发明人 IKUSE, TOMONORI;AOKI, KAZUFUMI;HARIU, TAKEO
分类号 G06F21/56;G06F21/53 主分类号 G06F21/56
代理机构 代理人
主权项
地址