发明名称 情報処理装置及び情報処理方法及びプログラム
摘要 When an attack on an information system is possibly carried out, a progress status of the attack is visualized to display a warning to a user, without using a correlation rule. A table storage unit 1001 stores a past case table indicating a phase string obtained by concatenating phase values indicating attack progress degrees according to an event occurrence pattern in a past case. A phase string generation unit 1002 obtains a phase string by concatenating phase values according to the occurrence pattern of events that have occurred in the information system. A similarity degree calculation unit 1003 calculates a similarity degree between the phase string obtained by the phase string generation unit 1002 and the phase string indicated in the past case table. An attack status visualization unit 1004 visualizes the progress status of the attack on the information system, based on the phase string obtained by the phase string generation unit 1002 and a result of calculation of the similarity degree by the similarity degree calculation unit 1003.
申请公布号 JP5868514(B2) 申请公布日期 2016.02.24
申请号 JP20140536717 申请日期 2013.08.29
申请人 三菱電機株式会社 发明人 桜井 鐘治;河内 清人
分类号 G06F21/55 主分类号 G06F21/55
代理机构 代理人
主权项
地址