IDENTIFICATION APPARATUS, CONTROL METHOD THEREFOR, AND STORAGE MEDIUM
First Claim
1. An identification apparatus for identifying a spread range of malware, comprising:
- a storage unit configured to store an operation history as a history of an operation executed in at least one information processing apparatus;
an acquisition unit configured to acquire malware spread information including information indicating malware; and
an identification unit configured toidentify, based on the operation history, an intrusion route of the malware indicated by the malware spread information acquired by the acquisition unit,generate at least one piece of malware spread information corresponding to at least one operation included in the intrusion route in the operation history, andidentify, in the operation history, for each of the at least one piece of malware spread information, at least one operation of spreading the malware by setting, as a direct or indirect start point, the malware indicated by the malware spread information.
1 Assignment
0 Petitions
Accused Products
Abstract
There is provided an identification apparatus. A storage unit stores an operation history as a history of an operation executed in at least one information processing apparatus. An acquisition unit acquires malware spread information including information indicating malware. An identification unit identifies, based on the operation history, an intrusion route of the malware indicated by the malware spread information acquired by the acquisition unit, generates at least one piece of malware spread information corresponding to at least one operation included in the intrusion route in the operation history, and identifies, in the operation history, for each of the at least one piece of malware spread information, at least one operation of spreading the malware by setting, as a direct or indirect start point, the malware indicated by the malware spread information.
8 Citations
14 Claims
-
1. An identification apparatus for identifying a spread range of malware, comprising:
-
a storage unit configured to store an operation history as a history of an operation executed in at least one information processing apparatus; an acquisition unit configured to acquire malware spread information including information indicating malware; and an identification unit configured to identify, based on the operation history, an intrusion route of the malware indicated by the malware spread information acquired by the acquisition unit, generate at least one piece of malware spread information corresponding to at least one operation included in the intrusion route in the operation history, and identify, in the operation history, for each of the at least one piece of malware spread information, at least one operation of spreading the malware by setting, as a direct or indirect start point, the malware indicated by the malware spread information. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12)
-
-
13. A control method for an identification apparatus for identifying a spread range of malware, comprising:
-
storing an operation history as a history of an operation executed in at least one information processing apparatus; acquiring malware spread information including information indicating malware; and identifying, based on the operation history, an intrusion route of the malware indicated by the malware spread information acquired in the acquiring, generating at least one piece of malware spread information corresponding to at least one operation included in the intrusion route in the operation history, and identifying, in the operation history, for each of the at least one piece of malware spread information, at least one operation of spreading the malware by setting, as a direct or indirect start point, the malware indicated by the malware spread information. - View Dependent Claims (14)
-
Specification