发明名称 SOURCE DETECTION DEVICE FOR DETECTING A SOURCE OF SENDING A VIRUS AND/OR A DNS ATTACK LINKED TO AN APPLICATION, METHOD THEREOF, AND PROGRAM THEREOF
摘要 An original attacker which has set a computer as a springboard is detected by detecting a source of a virus or a DNS attack linked to an application, which attacks other computers. A source detection device for detecting a source of a virus or a DNS attack captures packets from a network under setting conditions, and extracts required information. The source detection device stores data such as information concerning behaviors and/or features of viruses and/or DNS attacks, and/or logs of respective servers, which are required for an application traceback. Linkage of a virus or a DNS attack is determined from an application traceback processing result stored in a database and from various data, and new conditions are set accordingly. Under the new conditions, source detection is carried out for a virus or a DNS attack. Data is updated and accumulated accordingly, and linkage and a relationship between a behavior of an attack and a virus or a DNS attack is determined, thereby to detect a source of the attack.
申请公布号 US2009319659(A1) 申请公布日期 2009.12.24
申请号 US20070521026 申请日期 2007.12.28
申请人 TERASAKI HIROSHI;TAMAI MASAYOSHI;KAWATSU SONOMI 发明人 TERASAKI HIROSHI;TAMAI MASAYOSHI;KAWATSU SONOMI
分类号 G06F15/173 主分类号 G06F15/173
代理机构 代理人
主权项
地址