发明名称 OPERATION DETECTION DEVICE AND COMPUTER PROGRAM
摘要 PROBLEM TO BE SOLVED: To detect an operation upon equipment without installing any application in the equipment.SOLUTION: An operation pattern extraction part 12 calculates a feature amount for each protocol from a packet of target equipment during a preparation period before extracting an operation and generates a feature vector including the feature amount as an element. Further, the feature vector is clustered, and a center vector of the clusters is generated and made correspondent to a corresponding operation name in an operation name database 16. When detecting the operation, in an operation detection part 13, a feature vector is generated from the packet of the target equipment, similarity to the center vector is calculated and if a maximum value of the similarity is equal to or greater than a threshold value, the operation name corresponding to the center vector is read out.
申请公布号 JP2015176553(A) 申请公布日期 2015.10.05
申请号 JP20140054745 申请日期 2014.03.18
申请人 NIPPON TELEGR & TELEPH CORP <NTT> 发明人 ASHIKAGA ERIKA;KONDO SHIGEKUNI;TOJIMA YUKA;TAMAKI MIKISUKE
分类号 G06F17/30;G06F11/30 主分类号 G06F17/30
代理机构 代理人
主权项
地址