发明名称 ATTACK ANALYSIS SYSTEM, COOPERATION APPARATUS, ATTACK ANALYSIS COOPERATION METHOD, AND PROGRAM
摘要 In a log analysis cooperation system including a logger that collects a log of a communication device and stores the log in a storage device, a SIEM apparatus that detects an attack, and a log analysis apparatus that analyzes the log collected by the logger, a log analysis cooperation apparatus stores an attack scenario in a storage device, receives from the SIEM apparatus warning information including information on the detected attack, computes a predicted occurrence time of an attack predicted to occur subsequent to the detected attack based on the warning information and the attack scenario, and transmits to the log analysis apparatus a scheduled search to search the log at predicted occurrence time computed. The log analysis apparatus transmits a scheduled search to the logger to search the log at the predicted occurrence time.
申请公布号 US2015256554(A1) 申请公布日期 2015.09.10
申请号 US201314433560 申请日期 2013.11.08
申请人 MITSUBISHI ELECTRIC CORPORATION 发明人 Sakakibara Hiroyuki;Sakurai Shoji;Kawauchi Kiyoto
分类号 H04L29/06 主分类号 H04L29/06
代理机构 代理人
主权项
地址 Tokyo JP