发明名称 MALICIOUS COMMUNICATION PATTERN EXTRACTION DEVICE, MALICIOUS COMMUNICATION PATTERN EXTRACTION METHOD, AND MALICIOUS COMMUNICATION PATTERN EXTRACTION PROGRAM
摘要 A malicious communication pattern extraction device (10) accepts input of one or more malware traffic groups, and extracts the communication pattern of the inputted traffic group. With respect to a traffic group in which there is variation in the value of a prescribed field, the value of the field in which there is variation is replaced with a wild card. The malicious communication pattern extraction device (10) classifies malwares in which the traffic group communication patterns resemble each other into the same cluster, and extracts, as a malicious communication pattern for each of the clusters, a communication pattern group in which the occurrence ratio of each of the malwares in the traffic group within the cluster is greater than or equal to a prescribed value. Thereafter, the malicious communication pattern extraction device (10) removes a malicious communication pattern, among the extracted malicious communication patterns, in which the ratio of conformity with a traffic group that is not infected by malware is greater than or equal to a prescribed value.
申请公布号 WO2016080232(A1) 申请公布日期 2016.05.26
申请号 WO2015JP81498 申请日期 2015.11.09
申请人 NIPPON TELEGRAPH AND TELEPHONE CORPORATION 发明人 KAMIYA, KAZUNORI;AOKI, KAZUFUMI
分类号 G06F21/56 主分类号 G06F21/56
代理机构 代理人
主权项
地址