发明名称 INFECTION INSPECTION SYSTEM, INFECTION INSPECTION METHOD, STORAGE MEDIUM, AND PROGRAM
摘要 When detecting a traffic abnormality, an abnormality detection apparatus 131 notifies a malware infected terminal that has caused the traffic abnormality to a terminal whitelist generation apparatus 133, the terminal whitelist generation unit 133 generates a whitelist indicating software allowed to be installed to the malware infected terminal and setting of a reference terminal device 134 managed not to be infected with the malware, and loads a inspection object extraction program into the malware infected terminal, the inspection object extraction program detects software and setting in the malware infected terminal, and inspects whether or not the detected software and setting coincide with the software and the setting in the whitelist, it is highly likely that software or a setting not coinciding with the whitelist is associated with the malware, by analyzing the software or the setting, the malware may be promptly identified.
申请公布号 US2012005755(A1) 申请公布日期 2012.01.05
申请号 US201113074685 申请日期 2011.03.29
申请人 KITAZAWA SHIGEKI;FUJII SEIJI;SAIGA YOSHIHARU;YAHAGI KOICHI;NAKANO TAKAAKI;KATO TAKAYA;MITSUBISHI ELECTRIC CORPORATION;THE BANK OF TOKYO-MITSUBISHI UFJ, LTD.;MITSUBISHI ELECTRIC INFORMATION NETWORK CORP. 发明人 KITAZAWA SHIGEKI;FUJII SEIJI;SAIGA YOSHIHARU;YAHAGI KOICHI;NAKANO TAKAAKI;KATO TAKAYA
分类号 G06F11/00 主分类号 G06F11/00
代理机构 代理人
主权项
地址