发明名称 攻撃分析システム及び連携装置及び攻撃分析連携方法及びプログラム
摘要 In a log analysis cooperation system 1000 including a logger 901 that collects a log of a communication device 904 and stores the log in a storage device, a SIEM apparatus 902 that detects an attack, and a log analysis apparatus 903 that analyzes the log collected by the logger 901, a log analysis cooperation apparatus 1 stores an attack scenario 1104 in a storage device, receives from the SIEM apparatus 902 warning information 1201' including information on the detected attack, computes a predicted occurrence time of an attack predicted to occur subsequent to the detected attack based on the warning information 1201' and the attack scenario 1104, and transmits to the log analysis apparatus 903 a scheduled search 915 to search the log at predicted occurrence time computed. The log analysis apparatus 903 transmits a scheduled search 916 to the logger 901 to search the log at the predicted occurrence time.
申请公布号 JP5972401(B2) 申请公布日期 2016.08.17
申请号 JP20140557329 申请日期 2013.11.08
申请人 三菱電機株式会社 发明人 榊原 裕之;桜井 鐘治;河内 清人
分类号 G06F21/55 主分类号 G06F21/55
代理机构 代理人
主权项
地址