发明名称 MALWARE COMMUNICATION ANALYZER AND MALWARE COMMUNICATION ANALYSIS METHOD
摘要 PROBLEM TO BE SOLVED: To efficiently identify a communication content performed by malware without making the malware actually act. ! SOLUTION: A malware communication analyzer stores a signature describing a characteristic of communication performed by malware, key extraction information describing a method for extracting a cipher key from a communication packet, and decryption function information, which is information on a decryption function used by the malware, in association with each other; analyzes a communication packet to generate packet analysis data in which a result of the analysis is stored; compares the packet analysis data with a signature to determine whether or not both of them agree with each other; extracts a cipher key from the packet analysis data by using key extraction information associated with the signature when it is determined that both agree; and decrypts cipher text of the packet analysis data by using the cipher key and decryption function information corresponding to the si
申请公布号 JP2015106914(A) 申请公布日期 2015.06.08
申请号 JP20130249953 申请日期 2013.12.03
申请人 MITSUBISHI ELECTRIC CORP 发明人 OGOSHI FUYUHIKO ; KAWACHI KIYOTO
分类号 H04L9/08;G06F21/56 主分类号 H04L9/08
代理机构 代理人
主权项
地址