Invention Grant
- Patent Title: Threat information extraction apparatus and threat information extraction system
-
Application No.: US16968974Application Date: 2019-02-08
-
Publication No.: US11546356B2Publication Date: 2023-01-03
- Inventor: Yuichi Nakatani
- Applicant: Nippon Telegraph and Telephone Corporation
- Applicant Address: JP Tokyo
- Assignee: Nippon Telegraph and Telephone Corporation
- Current Assignee: Nippon Telegraph and Telephone Corporation
- Current Assignee Address: JP Tokyo
- Agency: Fish & Richardson P.C.
- Priority: JPJP2018-025426 20180215
- International Application: PCT/JP2019/004586 WO 20190208
- International Announcement: WO2019/159833 WO 20190822
- Main IPC: H04L9/40
- IPC: H04L9/40

Abstract:
The present invention discloses a technique for extending threat information and/or generating new threat information by analyzing packet headers flowing through a network using threat information obtained by analyzing malware behavior or the like. An aspect of the present invention relates to a threat information extraction device provided with a network information DB that stores flow information and a threat information extraction unit that extracts new threat information from acquired threat information using the flow information, in which the threat information extraction unit extracts a first IP address from the acquired threat information, creates totalization information on the first IP address from the flow information, estimates a feature value of communication associated with the first IP address from the totalization information, extracts zero or one or more other IP addresses similar to the first IP address at which communication is in progress based on the estimated feature value and generates threat information.
Public/Granted literature
- US20210058411A1 THREAT INFORMATION EXTRACTION DEVICE AND THREAT INFORMATION EXTRACTION SYSTEM Public/Granted day:2021-02-25
Information query