Extraction criterion determination method, communication monitoring system, extraction criterion determination apparatus and extraction criterion determination program
First Claim
1. An extraction criterion determination method performed by an extraction criterion determination apparatus that is connected to a wide area network, the method comprising:
- collecting a log information entries of a communication performed in a predetermined period of time, the log information entry being determined to be a malignant communication, the log information entries being obtained from a communication monitoring device configured to collect the log information entries in a network that connects to the wide area network, wherein the wide area network is accessible by at least one of an attacker terminal, a malware distribution server, and a malicious server;
analyzing respective communication source addresses in the collected log information entries;
generating analysis information including a plurality of statistical values, for each respective communication source address, which include at least a number of communications, a statistic related to a communication interval, and a statistic related to an amount of traffic of communications;
extracting a communication satisfying a criterion from the analysis information with reference to a memory storing an extraction criterion, the criterion being used to extract the malignant communication from the log information entries, the criterion being defined in the extraction criterion, the criterion being one of a plurality of criteria that is based on the plurality of statistical values;
determining to adopt the extraction criterion when a ratio of a number of malignant communications to the extracted communications is larger than or equal to a threshold; and
performing a control to output the adopted extraction criterion which is applied for identifying future communications as malignant.
1 Assignment
0 Petitions
Accused Products
Abstract
An extraction criterion determination method performed by an extraction criterion determination apparatus includes collecting a log information entry that is in a predetermined period of time and determined to be a specific communication, extracting a communication satisfying a criterion used to extract the specific communication from log information entries from the collected log information entries with reference to a storage unit storing an extraction criterion in which the criterion is defined, determining to adopt the extraction criterion when the ratio of the specific communications to the extracted communications is larger than or equal to a threshold, and performing a control to output the adopted extraction criterion.
17 Citations
8 Claims
-
1. An extraction criterion determination method performed by an extraction criterion determination apparatus that is connected to a wide area network, the method comprising:
-
collecting a log information entries of a communication performed in a predetermined period of time, the log information entry being determined to be a malignant communication, the log information entries being obtained from a communication monitoring device configured to collect the log information entries in a network that connects to the wide area network, wherein the wide area network is accessible by at least one of an attacker terminal, a malware distribution server, and a malicious server; analyzing respective communication source addresses in the collected log information entries; generating analysis information including a plurality of statistical values, for each respective communication source address, which include at least a number of communications, a statistic related to a communication interval, and a statistic related to an amount of traffic of communications; extracting a communication satisfying a criterion from the analysis information with reference to a memory storing an extraction criterion, the criterion being used to extract the malignant communication from the log information entries, the criterion being defined in the extraction criterion, the criterion being one of a plurality of criteria that is based on the plurality of statistical values; determining to adopt the extraction criterion when a ratio of a number of malignant communications to the extracted communications is larger than or equal to a threshold; and performing a control to output the adopted extraction criterion which is applied for identifying future communications as malignant. - View Dependent Claims (2, 3, 4)
-
-
5. A communication monitoring system comprising:
-
a communication monitoring device that monitors communications in a network that connects to a wide area network that is accessible by at least one of an attacker terminal, a malware distribution server, and a malicious server; and an extraction criterion determination apparatus that is connected to the wide area network, the extraction criterion determination apparatus including; a memory that stores an extraction criterion in which a criterion used to extract a malignant communication from log information entries of the communications is defined; and processing circuitry configured to collect a log information entry from the communication monitoring device, the log information entry being log information of a communication in a predetermined period of time, the log information entry being determined to be the malignant communication; analyze respective communication source addresses in the collected log information entries; generate analysis information including a plurality of statistical values, for each respective communication source address, which include at least a number of communications, a statistic related to a communication interval, and a statistic related to an amount of traffic of communications; extract a communication satisfying the criterion from the collected log information entries with reference to the memory, the criterion being one of a plurality of criteria that is based on the plurality of statistical values; determine to adopt the extraction criterion when a ratio of a number of malignant communications to the extracted communications is larger than or equal to a threshold; and perform a control to output the adopted extraction criterion which is applied for identifying future communications as malignant. - View Dependent Claims (6)
-
-
7. An extraction criterion determination apparatus that is configured to connect to a wide area network comprising:
-
a memory that stores an extraction criterion in which a criterion used to extract a malignant communication from log information entries of communications is defined; and processing circuitry configured to collect a log information entry, the log information entry being log information of a communication in a predetermined period of time, the log information entry being determined to be the malignant communication, the log information entry being obtained from a communication monitoring device configured to collect the log information entry in a network that connects to the wide area network, wherein the wide area network is accessible by at least one of an attacker terminal, a malware distribution server, and a malicious server; analyze respective communication source addresses in the collected log information entries; generate analysis information including a plurality of statistical values, for each respective communication source address, which include at least a number of communications, a statistic related to a communication interval, and a statistic related to an amount of traffic of communications; extract a communication satisfying the criterion from the collected log information entries with reference to the memory, the criterion being one of a plurality of criteria that is based on the plurality of statistical values; determine to adopt the extraction criterion when a ratio of a number of malignant communications to the extracted communications is larger than or equal to a threshold; and perform a control to output the adopted extraction criterion which is applied for identifying future communications as malignant.
-
-
8. A non-transitory computer-readable recording medium having stored an extraction criterion determination program for causing an extraction criterion determination apparatus that is connected to a wide area network to execute a process comprising:
-
collecting a log information entry of a communication performed in a predetermined period of time, the log information entry being determined to be a malignant communication, the log information entry being obtained from a communication monitoring device configured to collect the log information entry in a network that connects to the wide area network, wherein the wide area network is accessible by at least one of an attacker terminal, a malware distribution server, and a malicious server; analyzing respective communication source addresses in the collected log information entries; generating analysis information including a plurality of statistical values, for each respective communication source address, which include at least a number of communications, a statistic related to a communication interval, and a statistic related to an amount of traffic of communications; extracting a communication satisfying a criterion from the analysis information with reference to a memory storing an extraction criterion, the criterion being used to extract the malignant communication from the log information entries, the criterion being defined in the extraction criterion, the criterion being one of a plurality of criteria that is based on the plurality of statistical values; determining to adopt the extraction criterion when a ratio of a number of malignant communications to the extracted communications is larger than or equal to a threshold; and performing a control to output the adopted extraction criterion which is applied for identifying future communications as malignant.
-
Specification