发明名称 MALWARE DETECTION METHOD AND MALWARE DETECTION DEVICE
摘要 <P>PROBLEM TO BE SOLVED: To detect presence of a malware infected terminal in a network. <P>SOLUTION: Normal internal communication defined between an internal terminal and another internal terminal in an internal network and normal external communication defined between an internal terminal and an external terminal connecting to an external network are pre-stored in a storage device. A malware detection device obtains communication information about an internal terminal from a network connection device, refers to the normal internal communication and the normal external communication, and obtains from the communication information and stores abnormal internal communication not defined between an internal terminal and another internal terminal and abnormal external communication not defined between an internal terminal and an external terminal to the storage device. An internal terminal is detected as a suspicious terminal based on the number of times of the stored abnormal external communication performed within a predetermined period. Presence of an internal terminal infected with malware in the internal network is detected based on the number of times of occurrence of the stored abnormal internal communication between a suspicious terminal and another suspicious terminal. <P>COPYRIGHT: (C)2012,JPO&INPIT
申请公布号 JP2012084994(A) 申请公布日期 2012.04.26
申请号 JP20100227653 申请日期 2010.10.07
申请人 HITACHI LTD 发明人 KAWAGUCHI NOBUTAKA;OKOCHI KAZUYA;KAJI TADASHI;KAWAGUCHI RYUNOSHIN
分类号 H04L12/66;G06F13/00;G06F21/20;G06F21/22 主分类号 H04L12/66
代理机构 代理人
主权项
地址