首页> 外国专利> DEVICE FOR DETECTING TERMINAL INFECTED BY MALWARE, SYSTEM FOR DETECTING TERMINAL INFECTED BY MALWARE, METHOD FOR DETECTING TERMINAL INFECTED BY MALWARE, AND PROGRAM FOR DETECTING TERMINAL INFECTED BY MALWARE

DEVICE FOR DETECTING TERMINAL INFECTED BY MALWARE, SYSTEM FOR DETECTING TERMINAL INFECTED BY MALWARE, METHOD FOR DETECTING TERMINAL INFECTED BY MALWARE, AND PROGRAM FOR DETECTING TERMINAL INFECTED BY MALWARE

机译:检测被恶意软件感染的终端的设备,检测被恶意软件感染的终端的系统,检测被恶意软件感染的终端的方法以及检测被恶意软件感染的终端的程序

摘要

A detection device (100) generates an event sequence from events that are acquired for each of identifiers that distinguish among terminals in a monitoring target network or pieces of malware, by taking into account an order of occurrence of the events. The detection device (100) retrieves events that commonly occur in event sequences belonging to a same cluster among clusters including event sequences with similarities at a predetermined level or higher, and extracts, as a detection event sequence, a representative event sequence based on a relationship between events that have high occurrence rates in similar common event sequences. The detection device (100) detects a malware infected terminal in the monitoring target network based on whether the event sequence generated based on a communication in the monitoring target network and the extracted detection event sequence match each other.
机译:检测设备(100)通过考虑事件的发生顺序,从针对在监视目标网络中的终端或恶意软件中进行区分的每个标识符获取的事件中生成事件序列。检测装置(100)在包含具有预定水平以上的相似度的事件序列的聚类中的属于相同聚类的事件序列中通常发生的事件,并基于关系提取代表事件序列作为检测事件序列。在相似的常见事件序列中具有较高发生率的事件之间。检测设备(100)基于基于监视目标网络中的通信而生成的事件序列与所提取的检测事件序列是否彼此匹配,来检测监视目标网络中的被恶意软件感染的终端。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号