×

ATTACK DETECTION DEVICE, ATTACK DETECTION METHOD, AND NON-TRANSITORY COMPUTER READABLE RECORDING MEDIUM RECORDED WITH ATTACK DETECTION PROGRAM

  • US 20160378980A1
  • Filed: 02/26/2014
  • Published: 12/29/2016
  • Est. Priority Date: 02/26/2014
  • Status: Active Grant
First Claim
Patent Images

1. An attack detection device comprising:

  • an event stage information storage unit which stores, for a plurality of events, event stage information describing an event, a pre-event stage, and a post-event stage, the event being observed by an information system when an attack against the information system is underway, the pre-event stage being a stage of a progress of an attack which is made before the event is observed, the post-event stage being a stage of a progress of an attack which is made after the event is observed;

    an observed event notice information reception unit which receives observed event notice information notifying an observed event observed by the information system; and

    an event sequence creation unit which searches for event stage information describing the observed event notified by the observed event notice information, from the event stage information storage unit, searches for event stage information describing a post-event stage coinciding with a pre-event stage of the event stage information searched for or a pre-event stage coinciding with a post-event stage of the event stage information searched for, from the event stage information storage unit, and if an event of the event stage information searched for is an observation non-available event that cannot be observed, creates an event sequence by treating the observation non-available event as having been observed and connecting the observed event and the observation non-available event to each other with a dependency.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×