发明名称 SYSTEM, METHOD, AND APPARATUS FOR CAUSE SPECIFICATION COOPERATING WITH DETECTION OF CHANGE IN TRAFFIC AMOUNT, AND PROGRAM
摘要 <p><P>PROBLEM TO BE SOLVED: To solve the following problem: analysis cannot be performed because the difference in abnormal traffic amount between a normal time and an abnormal time is buried in the change of the total traffic amount when the ratio of the abnormal traffic to the total traffic amount is small, in an abnormal traffic analysis technique which analyses an attack by use of the difference in traffic amount between the normal time and the abnormal time. <P>SOLUTION: A system 300 for cause specification of change in traffic amount, in corporation with an abnormality detection external function part 200, uses the attack type (protocol) and the traffic information (an IP address, an AS number, etc.) of a detected abnormal traffic as filters to extract a flow to be analyzed, retains information which can be used or can be targets as a compound attack on the basis of each attack type and each traffic information, and uses the information to extract the flow to be analyzed. Accordingly, when the difference in abnormal traffic amount between the normal time and the abnormal time is buried in the change in the total traffic amount, the difference can be extracted and the compound attack can simultaneously be detected and analyzed. <P>COPYRIGHT: (C)2011,JPO&INPIT</p>
申请公布号 JP2011176434(A) 申请公布日期 2011.09.08
申请号 JP20100037395 申请日期 2010.02.23
申请人 NIPPON TELEGR & TELEPH CORP 发明人 MARUYOSHI MASAHIRO;KUWABARA TAKESHI;MINAMI MASAKI;MURAYAMA JUNICHI
分类号 H04L12/70 主分类号 H04L12/70
代理机构 代理人
主权项
地址