发明名称 LOG ANALYZING DEVICE, METHOD AND PROGRAM
摘要 PROBLEM TO BE SOLVED: To provide a log analyzing device that identifies communication devices suffering a brute force attack to attack intermittently changing attack sources to a plurality of attack destinations, and groups communication devices suffering such an attack by analyzing a short-period log of a security device in order to take measures against the attack.SOLUTION: A log analyzing device classifies a plurality of attacked communication devices suffering an attack from attacking communication devices on the basis of a log collected from a network device. The log analyzing device includes a correlation coefficient calculation unit that calculates a correlation coefficient between detection time of the attack detected by the network device and the number of attacks in a period when the attacks have been done including the detection time on the basis of the log regarding a combination of a plurality of attacked communication devices; and an extraction unit that extracts, as a high correlation communication device group, a combination of a plurality of attacked communication devices whose correlation coefficient is equal to and more than a prescribed threshold value and whose attacking communication device is the same in the period.
申请公布号 JP2015076863(A) 申请公布日期 2015.04.20
申请号 JP20130214198 申请日期 2013.10.11
申请人 FUJITSU LTD 发明人 HONDA TOSHIMI;FUJISHIMA YUKI;TAKENAKA MASAHIKO;TORII SATORU
分类号 H04L12/70;G06F21/55 主分类号 H04L12/70
代理机构 代理人
主权项
地址