Systems and methods for intelligent phishing threat detection and phishing threat remediation in a cyber security threat detection and mitigation platform
US-2024414198-A1 · Dec 12, 2024 · US
US2021390178A1 · US · A1
| Field | Value |
|---|---|
| Publication number | US-2021390178-A1 |
| Application number | US-201917283552-A |
| Country | US |
| Kind code | A1 |
| Filing date | May 20, 2019 |
| Priority date | Oct 10, 2018 |
| Publication date | Dec 16, 2021 |
| Grant date | — |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
An information processing device includes an element extraction unit that extracts elements relating to actions of an attacker from each input log, a generation unit that generates a parser based on definition information defining the actions of the attacker in a formal grammar, the parser detecting, from a log, a log string having a feature corresponding to an action defined by the definition information, a parsing unit that detects, from a log consisting of the elements extracted by the element extraction unit, log strings having features corresponding to the actions defined by the definition information by using the parser, and a reconstruction unit that reconstructs the log strings detected by the parsing unit, adds a label indicating an action defined by the definition information to each of the reconstructed log strings, and outputs the labeled log strings as a log corresponding to a series of actions of the attacker.
Opening claim text (preview).
1 . An information processing device comprising: a memory; and a processor coupled to the memory and programmed to execute a process comprising: extracting elements relating to actions of an attacker from each input log; generating a parser based on definition information that defines the actions of the attacker in a formal grammar, the parser being configured to detect, from a log, a log string having a feature corresponding to an action defined by the definition information; detecting, from a log consisting of the elements extracted by the extracting, log strings having features corresponding to the actions defined by the definition information by using the parser; and reconstructing the log strings detected by the detecting, add a label indicating an action defined by the definition information to each of the reconstructed log strings, and output the labeled log strings as a log corresponding to a series of actions of the attacker. 2 . The information processing device of claim 1 , wherein the definition information is described in a formal grammar dealing with an element as a terminal symbol. 3 . The information processing device of claim 1 , wherein the definition information includes information indicating an order of the actions of the attacker, and the reconstructing disposes the labeled log strings in the order indicated by the definition information and outputs the log as a log corresponding to a series of actions of the attacker. 4 . A computer-readable recording medium having stored therein an analysis program for causing a computer to execute a process comprising: a step of extracting elements relating to actions of an attacker from each input log; a step of generating a parser based on definition information that defines the actions of the attacker in a formal grammar, the parser being configured to detect, from a log, a log string having a feature corresponding to an action defined by the definition information; a step of detecting, from a log consisting of the elements extracted at the step of extracting the elements, log strings having features corresponding to the actions defined by the definition information by using the parser; and a step of reconstructing the log strings detected at the step of detecting the log strings, adding a label indicating an action defined by the definition information to each of the reconstructed log strings, and outputting the labeled log strings as a log corresponding to a series of actions of the attacker.
involving long-term monitoring or reporting · CPC title
Test or assess a computer or a system · CPC title
Parsing · CPC title
Detecting local intrusion or implementing counter-measures · CPC title
Traffic logging, e.g. anomaly detection · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.