×

Extraction criterion determination method, communication monitoring system, extraction criterion determination apparatus and extraction criterion determination program

  • US 10,257,213 B2
  • Filed: 03/16/2015
  • Issued: 04/09/2019
  • Est. Priority Date: 03/19/2014
  • Status: Active Grant
First Claim
Patent Images

1. An extraction criterion determination method performed by an extraction criterion determination apparatus that is connected to a wide area network, the method comprising:

  • collecting a log information entries of a communication performed in a predetermined period of time, the log information entry being determined to be a malignant communication, the log information entries being obtained from a communication monitoring device configured to collect the log information entries in a network that connects to the wide area network, wherein the wide area network is accessible by at least one of an attacker terminal, a malware distribution server, and a malicious server;

    analyzing respective communication source addresses in the collected log information entries;

    generating analysis information including a plurality of statistical values, for each respective communication source address, which include at least a number of communications, a statistic related to a communication interval, and a statistic related to an amount of traffic of communications;

    extracting a communication satisfying a criterion from the analysis information with reference to a memory storing an extraction criterion, the criterion being used to extract the malignant communication from the log information entries, the criterion being defined in the extraction criterion, the criterion being one of a plurality of criteria that is based on the plurality of statistical values;

    determining to adopt the extraction criterion when a ratio of a number of malignant communications to the extracted communications is larger than or equal to a threshold; and

    performing a control to output the adopted extraction criterion which is applied for identifying future communications as malignant.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×