首页>
外国专利>
Attack detection device, attack detection method, and non-transitory computer readable recording medium recorded with attack detection program
Attack detection device, attack detection method, and non-transitory computer readable recording medium recorded with attack detection program
展开▼
机译:攻击检测装置,攻击检测方法以及记录有攻击检测程序的非暂时性计算机可读记录介质
展开▼
页面导航
摘要
著录项
相似文献
摘要
For a plurality of events, event stage information is stored which describes an event observed by an information system when an attack against the information system is underway, a pre-event stage, and a post-event stage. Observed event notice information is received which notifies an observed event observed by the information system. Event stage information is searched for which describes the observed event notified by the observed event notice information. Event stage information is searched for which describes a post-event stage coinciding with a pre-event stage of the event stage information searched for, or a pre-event stage coinciding with a post-event stage of the event stage information searched for. If an event of the event stage information searched for is an observation non-available event that cannot be observed, an event sequence is created by treating the observation non-available event as having been observed and connecting the observed event and the observation non-available event to each other with a dependency.
展开▼