发明名称 INFORMATION PROCESSING DEVICE, ILLICIT ACTIVITY DETERMINATION METHOD, ILLICIT ACTIVITY DETERMINATION PROGRAM, INFORMATION PROCESSING DEVICE, ACTIVITY DETERMINATION METHOD, AND ACTIVITY DETERMINATION PROGRAM
摘要 A problem to be solved by the present invention is to reduce false positives and false negatives in malware detection. Provided is an information processing device (20), comprising: a comparison unit (251) which compares communications from terminals which are connected to a network with pre-retained patterns; a determination unit (254) which, according to the result of the comparison, determines evaluation values which signify the degree to which it is presumed that the terminals are acting illicitly and illicit activity phases; a retaining unit (255) which retains maximum evaluation values for each phase for each terminal; and an assessment unit (257) which assesses whether the terminals are carrying out the illicit activities on the basis of the maximum evaluation values for each phase.
申请公布号 WO2015107861(A1) 申请公布日期 2015.07.23
申请号 WO2014JP84690 申请日期 2014.12.26
申请人 PFU LIMITED 发明人 KOIDE, KAZUHIRO;MICHINE, KEIJI
分类号 G06F21/56;G06F13/00;G06F21/55;H04L12/26;H04L12/70 主分类号 G06F21/56
代理机构 代理人
主权项
地址