Extraction device, extraction method, recording medium, and detection device

US11526605B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-11526605-B2
Application numberUS-201817042622-A
CountryUS
Kind codeB2
Filing dateApr 27, 2018
Priority dateApr 27, 2018
Publication dateDec 13, 2022
Grant dateDec 13, 2022

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

An extraction device includes: at least one memory configured to store instructions; and at least one processor configured to execute the instructions to: sort each set of frames that have the same identifier associated with a node, into frames maintaining a cycle and frames out of the cycle; and extract, as an event rule, a feature of a bit change in a data field related to an event occurrence, from the frames that have the same identifier and are out of the cycle.

First claim

Opening claim text (preview).

What is claimed is: 1. A monitoring apparatus comprising: an extraction device comprising: at least one first memory configured to store instructions; and at least one first processor configured to execute the instructions to: sort each set of frames that have the same identifier associated with a node, into frames maintaining a cycle and frames out of the cycle; extract, as an event rule, a feature of a bit change in a data field related to an event occurrence, from the frames that have the same identifier and are out of the cycle; and exclude the frames that have the same identifier and maintain the cycle from the set of frames having the same identifier, and select the frames that are out of the cycle, and a detection device that is communicably connected to the extraction device comprising: at least one second memory configured to store instructions; and at least one second processor configured to execute the instructions to: determine a detection target frame out of the cycle to be an illegal frame when the data field of the detection target frame does not match the feature extracted by the extraction device and determine the detection target frame out of the cycle to be a normal frame when the data field of the detection target frame matches the feature extracted by the extraction device; and update, after a frame out of the cycle is determined to be a normal frame, a base point of the cycle to a frame that is output at a time of an event occurrence, wherein the feature of the bit change in the data field is that a bit at a specific position in the data field takes the same value before and after the event occurrence. 2. The extraction device according to claim 1 , wherein the feature of the bit change in the data field is inversion of a bit at a specific position in the data field. 3. The extraction device according to claim 1 , wherein the feature of the bit change in the data field is a combination of bits designated as 0 and 1 in the data field. 4. An extraction method comprising: sorting frames that have the same identifier associated with a node, into frames maintaining a cycle and frames out of the cycle; extracting, as an event rule, a feature of a bit change in a data field related to an event occurrence, from the frames that have the same identifier and are out of the cycle; excluding the frames that have the same identifier and maintain the cycle from the set of frames having the same identifier, and select the frames that are out of the cycle; determining a detection target frame out of the cycle to be an illegal frame when the data field of the detection target frame does not match the extracted feature and determine the detection target frame out of the cycle to be a normal frame when the data field of the detection target frame matches the extracted feature; and updating, after a frame out of the cycle is determined to be a normal frame, a base point of the cycle to a frame that is output at a time of an event occurrence, wherein the feature of the bit change in the data field is that a bit at a specific position in the data field takes the same value before and after the event occurrence. 5. A non-transitory computer-readable recording medium storing a program for causing a computer to: sort each set of frames that have the same identifier associated with a node, into frames maintaining a cycle and frames out of the cycle; extract, as an event rule, a feature of a bit change in a data field related to an event occurrence, from the frames that have the same identifier and are out of the cycle; exclude the frames that have the same identifier and maintain the cycle from the set of frames having the same identifier, and select the frames that are out of the cycle; determine a detection target frame out of the cycle to be an illegal frame when the data field of the detection target frame does not match the extracted feature and determine the detection target frame out of the cycle to be a normal frame when the data field of the detection target frame matches the extracted feature; and update, after a frame out of the cycle is determined to be a normal frame, a base point of the cycle to a frame that is output at a time of an event occurrence, wherein the feature of the bit change in the data field is that a bit at a specific position in the data field takes the same value before and after the event occurrence. 6. The extraction device according to claim 2 , wherein the feature of the bit change in the data field is inversion of a bit at a specific position in the data field. 7. The extraction device according to claim 2 , wherein the feature of the bit change in the data field is a combination of bits designated as 0 and 1 in the data field. 8. The extraction device according to claim 2 , wherein the feature of the bit change in the data field is that a bit at a specific position in the data field takes the same value before and after the event occurrence.

Assignees

Inventors

Classifications

  • G06F21/552Primary

    involving long-term monitoring or reporting · CPC title

  • Countermeasures against malicious traffic (countermeasures against attacks on cryptographic mechanisms H04L9/002) · CPC title

  • Multiple levels of security · CPC title

  • G06F21/554Primary

    involving event detection and direct action · CPC title

  • with means for detecting characters not meant for transmission · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US11526605B2 cover?
An extraction device includes: at least one memory configured to store instructions; and at least one processor configured to execute the instructions to: sort each set of frames that have the same identifier associated with a node, into frames maintaining a cycle and frames out of the cycle; and extract, as an event rule, a feature of a bit change in a data field related to an event occurrence…
Who is the assignee on this patent?
Nec Corp
What technology area does this patent fall under?
Primary CPC classification G06F21/552. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Dec 13 2022 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 6 related publications on this page (citations in our corpus or others sharing the same primary CPC).