×

Attack analysis system, cooperation apparatus, attack analysis cooperation method, and program

  • US 9,853,994 B2
  • Filed: 11/08/2013
  • Issued: 12/26/2017
  • Est. Priority Date: 01/21/2013
  • Status: Active Grant
First Claim
Patent Images

1. An attack analysis system including a log collection apparatus that includes log collection circuitry and that collects a log of at least one device connected to a network being monitored and stores the log in a storage device as log information, a detection apparatus that includes detection circuitry and that detects an attack on the network being monitored, and an analysis apparatus that includes analysis circuitry and that analyzes the log information collected by the log collection apparatus, the attack analysis system comprising:

  • a cooperation apparatus that includes cooperation circuitry and that is connected to the detection apparatus and connected to the analysis apparatus, whereinupon detection of the attack on the network being monitored, the detection apparatus transmits to the cooperation apparatus warning information including an attack identifier for identifying the detected attack and an attack occurrence time at which the detected attack has occurred,the cooperation apparatus includesan attack scenario information storage unit, implemented by the cooperation circuitry, that stores attack scenario information in a storage device in advance, the attack scenario information including a plurality of attack identifiers for identifying a respective plurality of attacks predicted to occur on the network being monitored,a scheduled analysis request unit, implemented by the cooperation circuitry, that when the warning information is received from the detection apparatus, computes a predicted occurrence time of a subsequent attack that has not yet occurred and is predicted to occur at a time after the attack occurrence time at which the detected attack has occurred, based on the warning information received and the attack scenario information stored by the attack scenario information storage unit, and transmits to the analysis apparatus a scheduled analysis request that is a request for analyzing the log information at the predicted occurrence time computed, the subsequent attack being one of the plurality of attacks included in the attack scenario information and being predicted to occur at the time after the attack occurrence time, andthe analysis apparatus analyzes the log information at the predicted occurrence time, based on the scheduled analysis request transmitted from the scheduled analysis request unit of the cooperation apparatus.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×