首页> 外国专利> MALICIOUS COMMUNICATION PATTERN EXTRACTION DEVICE, MALICIOUS COMMUNICATION PATTERN EXTRACTION SYSTEM, MALICIOUS COMMUNICATION PATTERN EXTRACTION METHOD AND MALICIOUS COMMUNICATION PATTERN EXTRACTION PROGRAM

MALICIOUS COMMUNICATION PATTERN EXTRACTION DEVICE, MALICIOUS COMMUNICATION PATTERN EXTRACTION SYSTEM, MALICIOUS COMMUNICATION PATTERN EXTRACTION METHOD AND MALICIOUS COMMUNICATION PATTERN EXTRACTION PROGRAM

机译:恶意通信模式提取设备,恶意通信模式提取系统,恶意通信模式提取方法和恶意通信模式提取程序

摘要

A malicious communication pattern extraction device (10) includes a statistical value calculation unit (132) that calculates a statistical value for an appearance frequency of each of a plurality of communication patterns that is a combination of a field and a value, from a traffic log (31) obtained from the traffic caused by malware, and a traffic log (21) obtained from traffic in a predetermined communication environment; a malicious list candidate extraction unit (134) that compares between the appearance frequency of the traffic log (21) and the appearance frequency of the traffic log (31) for each of the communication patterns, based on the statistical value calculated by the statistical value calculation unit (132), and extracts the communication pattern as the malicious communication pattern when a difference between both of the appearance frequencies is equal to or more than a predetermined threshold; and a threshold setting unit (135) that sets a threshold so that an erroneous detection rate being probability of erroneously detecting the traffic caused by malware is equal to or less than a certain value as well as a detection rate that is probability of detecting the traffic caused by malware is equal to or more than a certain value.
机译:恶意通信模式提取装置(10)包括统计值计算单元(132),该统计值计算单元从交通日志中计算作为字段和值的组合的多个通信模式中的每一个的出现频率的统计值。 (31)从恶意软件引起的流量中获取,以及从预定通信环境中的流量中获取的流量日志(21);恶意列表候选提取单元(134),基于由统计值计算出的统计值,针对每个通信模式,比较通信日志(21)的出现频率和通信日志(31)的出现频率。计算单元(132),并且当两个出现频率之间的差等于或大于预定阈值时,提取该通信模式作为恶意通信模式;阈值设定部(135),其设定阈值,以使作为错误检测出恶意软件的流量的概率的错误检测率和检测流量的概率的检测率等于或小于特定值。由恶意软件引起的等于或大于某个值。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号