Attack detection device, attack detection method, and non-transitory computer readable recording medium recorded with attack detection program

US2016378980A1 · US · A1

Patent metadata
FieldValue
Publication numberUS-2016378980-A1
Application numberUS-201415121716-A
CountryUS
Kind codeA1
Filing dateFeb 26, 2014
Priority dateFeb 26, 2014
Publication dateDec 29, 2016
Grant date

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

For a plurality of events, event stage information is stored which describes an event observed by an information system when an attack against the information system is underway, a pre-event stage, and a post-event stage. Observed event notice information is received which notifies an observed event observed by the information system. Event stage information is searched for which describes the observed event notified by the observed event notice information. Event stage information is searched for which describes a post-event stage coinciding with a pre-event stage of the event stage information searched for, or a pre-event stage coinciding with a post-event stage of the event stage information searched for. If an event of the event stage information searched for is an observation non-available event that cannot be observed, an event sequence is created by treating the observation non-available event as having been observed and connecting the observed event and the observation non-available event to each other with a dependency.

First claim

Opening claim text (preview).

1 . An attack detection device comprising: an event stage information storage unit which stores, for a plurality of events, event stage information describing an event, a pre-event stage, and a post-event stage, the event being observed by an information system when an attack against the information system is underway, the pre-event stage being a stage of a progress of an attack which is made before the event is observed, the post-event stage being a stage of a progress of an attack which is made after the event is observed; an observed event notice information reception unit which receives observed event notice information notifying an observed event observed by the information system; and an event sequence creation unit which searches for event stage information describing the observed event notified by the observed event notice information, from the event stage information storage unit, searches for event stage information describing a post-event stage coinciding with a pre-event stage of the event stage information searched for or a pre-event stage coinciding with a post-event stage of the event stage information searched for, from the event stage information storage unit, and if an event of the event stage information searched for is an observation non-available event that cannot be observed, creates an event sequence by treating the observation non-available event as having been observed and connecting the observed event and the observation non-available event to each other with a dependency. 2 . The attack detection device according to claim 1 , wherein the event sequence creation unit searches for event stage information describing a post-event stage coinciding with a pre-event stage of the observation non-available event or a pre-event stage coinciding with a post-event stage of the observation non-available event, from the event stage information storage unit, and if an event of the event stage information searched for is observed, creates an event sequence by treating the observation non-available event as having been observed and connecting the observed event and the observation non-available event to each other with a dependency. 3 . The attack detection device according to claim 1 , further comprising a chain probability storage unit which stores a chain probability of the plurality of events, wherein the event sequence creation unit calculates an occurrence probability of the event sequence based on the chain probability stored in the chain probability storage unit, and if the occurrence probability is equal to or larger than a threshold value, creates an event sequence by treating the observation non-available event as having been observed and connecting the observed event and the observation non-available event to each other with a dependency. 4 . The attack detection device according to claim 1 , further comprising a detection pass-through rate storage unit which stores a detection pass-through rate of an event, wherein when the detection pass-through rate stored in the detection pass-through rate storage unit exceeds a threshold value, the event sequence creation unit creates an event sequence by treating the observation non-available event as having been observed and connecting the observed event and the observation non-available event to each other with a dependency. 5 . The attack detection device according to claim 1 , wherein the event stage information stored in the event stage information storage unit describes a plurality of pre-event stages or a plurality of post-event stages, and wherein the event sequence creation unit creates an event sequence based on a determination result on observation availability of the plurality of pre-event stages or post-event stages described in the event stage information. 6 . The attack detection device according to claim 1 , further comprising an observation-expecting event storage unit which stores event stage information describing a pre-event stage with which a post-event stage of the observed event coincides, wherein the event sequence creation unit creates an event sequence by searching for event stage information in which the pre-event stage describing an observed event, from the observation-expecting event storage unit. 7 . An attack detection method of an attack detection device which detects an attack against an information system, comprising: an event stage information storage storing step, by an event stage information storage unit, of storing, for a plurality of events, event stage information describing an event, a pre-event stage, and a post-event stage, the event being observed by the information system when an attack against the information system is underway, the pre-event stage being a stage of a progress of an attack which is made before the event is observed, the post-event stage being a stage of a progress of an attack which is made after the event is observed; a step, by an observed event notice information reception unit, of receiving observed event notice information notifying an observed event observed by the information system; and an event sequence creation step, by an event sequence creation unit, of searching for event stage information describing the observed event notified by the observed event notice information, from the event stage information storage unit, searching for event stage information describing a post-event stage coinciding with a pre-event stage of the event stage information searched for or a pre-event stage coinciding with a post-event stage of the event stage information searched for, from the event stage information storage unit, and if an event of the event stage information searched for is an observation non-available event that cannot be observed, creating an event sequence by treating the observation non-available event as having been observed and connecting the observed event and the observation non-available event to each other with a dependency. 8 . A non-transitory computer readable recording medium which records an attack detection program that causes a computer which stores, for a plurality of events, event stage information describing an event, a pre-event stage, and a post-event stage, the event being observed by an information system when an attack against the information system is underway, the pre-event stage being a stage of a progress of an attack which is made before the event is observed, the post-event stage being a stage of a progress of an attack which is made after the event is observed, to perform: an observed event notice information reception process of receiving observed event notice information notifying an observed event observed by the information system; and an event sequence creation process of searching for event stage information describing the observed event notified by the observed event notice information, searching for event stage information describing a post-event stage coinciding with a pre-event stage of the event stage information searched for or a pre-event stage coinciding with a post-event stage of the event stage information searched for, and if an event of the event stage information searched for is an observation non-available event that cannot be observed, creating an event sequence by treating the observation non-available event as having been observed and connecting the observed event and the observation non-available event to each other with a dependency.

Assignees

Inventors

Classifications

  • G06F21/554Primary

    involving event detection and direct action · CPC title

  • G06F21/55Primary

    Detecting local intrusion or implementing counter-measures · CPC title

  • Event detection, e.g. attack signature detection · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US2016378980A1 cover?
For a plurality of events, event stage information is stored which describes an event observed by an information system when an attack against the information system is underway, a pre-event stage, and a post-event stage. Observed event notice information is received which notifies an observed event observed by the information system. Event stage information is searched for which describes the …
Who is the assignee on this patent?
Mitsubishi Electric Corp
What technology area does this patent fall under?
Primary CPC classification G06F21/554. Mapped technology areas include Physics.
When was this patent published?
Publication date Thu Dec 29 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (A1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 2 related publications on this page (citations in our corpus or others sharing the same primary CPC).