首页> 外国专利> DEVICE FOR DETECTING MALWARE INFECTED TERMINAL, SYSTEM FOR DETECTING MALWARE INFECTED TERMINAL, METHOD FOR DETECTING MALWARE INFECTED TERMINAL, AND PROGRAM FOR DETECTING MALWARE INFECTED TERMINAL

DEVICE FOR DETECTING MALWARE INFECTED TERMINAL, SYSTEM FOR DETECTING MALWARE INFECTED TERMINAL, METHOD FOR DETECTING MALWARE INFECTED TERMINAL, AND PROGRAM FOR DETECTING MALWARE INFECTED TERMINAL

机译:用于检测恶意软件感染的终端的设备,用于检测恶意软件感染的终端的系统,用于检测恶意软件感染的终端的方法以及用于检测恶意软件感染的终端的程序

摘要

A detection device generates an event sequence from events that are acquired for each of identifiers that distinguish among terminals in a monitoring target network or pieces of malware, by taking into account an order of occurrence of the events. The detection device retrieves events that commonly occur in event sequences belonging to a same cluster among clusters including event sequences with similarities at a predetermined level or higher, and extracts, as a detection event sequence, a representative event sequence based on a relationship between events that have high occurrence rates in similar common event sequences. The detection device detects a malware infected terminal in the monitoring target network based on whether the event sequence generated based on a communication in the monitoring target network and the extracted detection event sequence match each other.
机译:检测设备通过考虑事件的发生顺序,根据针对在监视目标网络中的终端或恶意软件中进行区分的每个标识符所获取的事件来生成事件序列。检测装置在包括具有预定水平以上的相似度的事件序列的聚类中的属于相同聚类的事件序列中通常发生的事件,并基于事件之间的关系提取代表事件序列作为检测事件序列。在类似的常见事件序列中发生率很高。检测设备基于基于监视目标网络中的通信而生成的事件序列与提取的检测事件序列是否彼此匹配,来检测监视目标网络中的被恶意软件感染的终端。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号