SAMPLE DATA GENERATION APPARATUS, SAMPLE DATA GENERATION METHOD, AND COMPUTER READABLE MEDIUM

    公开(公告)号:US20210157909A1

    公开(公告)日:2021-05-27

    申请号:US16641603

    申请日:2017-10-11

    摘要: An acquisition unit (10) acquires normal sample data and non-normal sample data. A model generation unit (120) generates a normal model representing the normal sample data. A change unit (141) generates a non-normal feature vector of the non-normal sample data, and generates a non-normal changed vector obtained by changing an element of the non-normal feature vector. When the non-normal changed vector and the normal model are similar to each other, a verification unit (142) executes a process using sample data represented by the non-normal changed vector. The verification unit (142) verifies whether an anomalous event is detected by a detection device. Upon verification that an anomalous event is not detected, the verification unit (142) determines whether an anomalous event is present, independently of the detection device. Upon determination that an anomalous event is present, the verification unit (142) stores the sample data represented by the non-normal changed vector as missed-detection sample data (154) in a storage unit (150).

    KEY GENERATION SOURCE IDENTIFICATION DEVICE, KEY GENERATION SOURCE IDENTIFICATION METHOD, AND COMPUTER READABLE MEDIUM

    公开(公告)号:US20190121968A1

    公开(公告)日:2019-04-25

    申请号:US16094450

    申请日:2016-06-16

    IPC分类号: G06F21/55 G06F21/56 H04L9/08

    摘要: A key generation source identification device (10) is provided with a key identification unit (11) to cause malware to execute an encryption process, acquire an execution trace representing an execution status of the encryption process, and identify an encryption key used in the encryption process as an analysis key based on the execution trace, and an extraction unit (31) to extract, from the execution trace, a list of instructions on which the analysis key depends, as an instruction list. The key generation source identification device (10) is also provided with an acquisition unit (32) to determine whether a function called by a call instruction included in the instruction list is a dynamic acquisition function that acquires dynamic information dynamically changing and, when the function is the dynamic acquisition function, acquire the instruction list as a candidate of a key generation source which is at least a part of a program that generated the analysis key in the encryption process.

    DATA PROCESSING APPARATUS, DATA PROCESSING METHOD, AND PROGRAM
    4.
    发明申请
    DATA PROCESSING APPARATUS, DATA PROCESSING METHOD, AND PROGRAM 审中-公开
    数据处理设备,数据处理方法和程序

    公开(公告)号:US20160210474A1

    公开(公告)日:2016-07-21

    申请号:US14915161

    申请日:2013-08-27

    IPC分类号: G06F21/62 G06F21/60

    摘要: An information leakage prevention apparatus 100 receives, from a LAN 109, communication data transmitted by a PC 112 to Internet 111, and when the received data has been encrypted, analyzes a log describing content of data processing performed in the PC 112 and extracts a key used to encrypt the communication data in the PC 112. Further, the information leakage prevention apparatus 100 decrypts the communication data using the extracted key and determines whether or not a keyword is included in a decryption result. If the keyword is not included in the decryption result, the information leakage prevention apparatus 100 transmits the communication data to the Internet 111 through a WAN 110.

    摘要翻译: 信息泄露防止装置100从LAN109接收由PC 112向因特网111发送的通信数据,并且当接收到的数据被加密时,分析描述在PC 112中执行的数据处理的内容的日志,并提取密钥 用于对PC 112中的通信数据进行加密。此外,信息泄露防止装置100使用提取的密钥对通信数据进行解密,并且确定关键字是否包括在解密结果中。 如果关键字不包括在解密结果中,则信息泄漏防止装置100通过WAN110将通信数据发送到因特网111。

    SECURITY MONITORING DEVICE, COMMUNICATION SYSTEM, SECURITY MONITORING METHOD, AND COMPUTER READABLE MEDIUM

    公开(公告)号:US20190149569A1

    公开(公告)日:2019-05-16

    申请号:US16302963

    申请日:2016-06-15

    IPC分类号: H04L29/06 G06F21/62

    摘要: An electronic file copy notification reception unit acquires identification information on a terminal device connected to a first network switch to which a file server is connected, as first identification information, when the terminal device acquires a copy of an electronic file from the file server. A determination instruction unit acquires identification information on a device, as second identification information, when the device is newly connected to a second network switch different from the first network switch. The determination instruction unit matches the first identification information with the second identification information and instructs the second network switch to restrict communication to and from the terminal device via the second network switch in case where the first identification information coincides with the second identification information.

    FALSE SUBMISSION FILTER DEVICE, FALSE SUBMISSION FILTER SYSTEM, FALSE SUBMISSION FILTER METHOD, AND COMPUTER READABLE MEDIUM

    公开(公告)号:US20210365431A1

    公开(公告)日:2021-11-25

    申请号:US16603138

    申请日:2017-05-25

    IPC分类号: G06F16/23 G06F16/9537

    摘要: In an SNS server (103) corresponding to a false submission filter device, an event specifying unit (604) analyzes contents of a submission informing of an occurrence of an event and specifies a location (721) of occurrence of the event. A query destination specifying unit (605) searches a query destination database (613) and specifies a query destination corresponding to the location (721) specified by the event specifying unit (604). A query unit (606) transmits a request for checking the presence or absence of occurrence of the event from the observation result of one or more machines to the query destination specified by the query destination specifying unit (605). The query unit (606) receives a response to the request. A result reflecting unit (607) determines whether the contents of the submission are true or false from a check result indicated by the response received by the query unit (606). The result reflecting unit (607) performs a process in accordance with a determination result on the submission.

    VERIFICATION DEVICE, COMPUTER READABLE MEDIUM, AND VERIFICATION METHOD

    公开(公告)号:US20200382291A1

    公开(公告)日:2020-12-03

    申请号:US16636554

    申请日:2017-09-15

    IPC分类号: H04L9/08 H04L9/32

    摘要: An acquisition unit acquires reception data. A first extraction unit extracts a domain name being a download domain name from the reception data. A second extraction unit extracts owner information indicating an owner of a public key certificate included in the reception data. A search unit searches a domain information search service using the owner information as a search key, and acquires a management domain name managed by the owner indicated by the owner information. A determination unit collates the management domain name with the domain name to determine whether a program included in the reception data is illegitimate.