IP Library Granted Patent US 10,243,982
Granted Patent B2
US 10,243,982 · App. 15/315,756 · Granted Mar 26, 2019

Log analyzing device, attack detecting device, attack detection method, and program

Inventors: Yang Zhong (Musashino, JP); Hiroshi Asakura (Musashino, JP); Shingo Orihara (Musashino, JP); Kazufumi Aoki (Musashino, JP)
Assignee: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
H04L63/1425G06F13/00G06F21/552G06F21/554H04L63/0245H04L63/1408G06N99/005
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,243,982
App. No.
15/315,756
Granted
Mar 26, 2019
Kind
B2
Abstract

A device including: a parameter extracting unit that extracts each parameter from an access request, a character-string class converting unit that, with regard to each parameter, compares each part of a parameter value with a previously defined character string class, replaces the part with a longest matching character string class, and conducting conversion for a class sequence that is sequentially arranged in order of replacement, a profile storing unit that stores, as a profile in a storage unit, a class sequence with the appearance frequency of equal to or more than a predetermined value in the above-described group of class sequences with regard to the access request of the normal data as learning data, and a failure detecting unit that determines the presence or absence of an attack in accordance with the degree of similarity between the above-described class sequence and the profile with regard to the access request.

Claims (38)

1. A log analyzing device that analyzes an access log collected from an information processing apparatus connected to a network, the log analyzing device comprising:

a memory that stores a profile that is a criteria for determining whether analysis-target data indicates an attack on the information processing apparatus; and

processing circuitry configured to

perform an extraction of each parameter from a request, received from a client device via the network, in the access log;

with regard to each parameter extracted perform a class conversion to compare each part of a parameter value, from a first character, with a previously defined character string class, replace the part with a longest character string class that matches the character string class, and conduct conversion for a class sequence in which replaced character string classes are sequentially arranged;

store, as the profile in the memory, a class sequence with an appearance frequency of equal to or more than a predetermined value in a group of the class sequences that are obtained by the parameter extraction and the class conversion with regard to the access log of normal data as learning data; and

calculate a degree of similarity between the profile and the class sequence that is obtained by the parameter extraction and the class conversion with regard to the access log in the analysis-target data and determine whether an attack on the information processing apparatus occurs in accordance with the degree of similarity.

2. An attack detecting device that detects an attack on an information processing apparatus connected to a network, the attack detecting device comprising:

a memory that stores a profile that is a criteria for determining whether an access request for the information processing apparatus attacks the information processing apparatus; and

processing circuitry configured to

perform an extraction of each parameter from the access request;

with regard to each parameter extracted, compare each part of a parameter value, from a first character, with a previously defined character string class, replace the part with a longest character string class that matches the character string class, and conduct conversion for a class sequence in which replaced character string classes are sequentially arranged;

store, as the profile in the memory, a class sequence with an appearance frequency of equal to or more than a predetermined value in a group of the class sequences that are obtained by the parameter extraction and the class conversion with regard to the access request of normal data as learning data; and

calculate a degree of similarity between the profile and the class sequence that is obtained by the parameter extraction and the class conversion with regard to the access request, which is an analysis target, and determine whether an attack on the information processing apparatus occurs in accordance with the degree of similarity.

3. The attack detecting device according to claim 2 , wherein the processing circuitry stores, as the profile in the memory, a single class sequence with the appearance frequency of maximum in the group of the class sequences.

4. The attack detecting device according to claim 2 , wherein the processing circuitry stores, as the profile in the memory, multiple class sequences with the appearance frequency of equal to or more than a predetermined value in the group of the class sequences.

5. The attack detecting device according to claim 2 , wherein

in a case where the group of the class sequences satisfies a predetermined condition, the processing circuitry stores, as the profile in the memory, a unique group of all the character string classes, included in the group of the class sequences, and

the processing circuitry

in a case where the group of the class sequences satisfies a predetermined condition, determines whether an attack occurs depending on whether the profile includes the entire unique group of the character string classes in the class sequence of the analysis-target data during determination by using the degree of similarity, and

in a case where the group of class sequences does not satisfy the predetermined condition, calculates the degree of similarity between the profile and the class sequence of the analysis-target data.

6. The attack detecting device according to claim 4 , wherein

the processing circuitry

in a case where the multiple class sequences satisfy a predetermined condition, stores, as the profile in the memory, a unique group of all the character string classes included in the multiple class sequences,

in a case where the group of the multiple class sequences satisfies a predetermined condition, determines whether an attack occurs depending on whether the profile includes the entire unique group of the character string classes in the class sequence of the analysis-target data during determination by using the degree of similarity, and

in a case where the group of the multiple class sequences does not satisfy the predetermined condition, makes a determination by using a degree of similarity of a maximal value among the degrees of similarity between the class sequence of the analysis-target data and each of the multiple class sequences included in the profile.

7. An attack detection method by an attack detecting device that detects an attack on an information processing apparatus connected to a network,

extracting each parameter from an access request in normal data, received from a client device via the network, as learning data for the information processing apparatus, comparing each part of a parameter value, from a first character, with a previously defined character string class with regard to each parameter, replacing the part with a longest character string class that matches the character string class, conducting conversion for a class sequence in which replaced character string classes are sequentially arranged, and storing, in a storage unit as a profile that is a criteria for determining whether analysis-target data indicates an attack on the information processing apparatus, a class sequence with an appearance frequency of equal to or more than a predetermined value in a group of the class sequences;

extracting a parameter from the access request in the analysis-target data;

converting a value of the extracted parameter into the class sequence in accordance with the character string class;

calculating a degree of similarity between the class sequence and the profile; and

determining whether an attack on the information processing apparatus occurs in accordance with the degree of similarity.

8. A non-transitory computer-readable recording medium having stored a program causing a computer, which detects an attack on an information processing apparatus connected to a network, to execute a process comprising:

a step of extracting each parameter from an access request in normal data, received from a client device via the network, as learning data for the information processing apparatus, comparing each part of a parameter value, from a first character, with a previously defined character string class with regard to each parameter, replacing the part with a longest character string class that matches the character string class, conducting conversion for a class sequence in which replaced character string classes are sequentially arranged, and storing, in a storage unit as a profile that is a criteria for determining whether analysis-target data indicates an attack on the information processing apparatus, a class sequence with an appearance frequency of equal to or more than a predetermined value in a group of the class sequences;

a step of extracting a parameter from the access request in the analysis-target data;

a step of converting a value of the extracted parameter into the class sequence in accordance with the character string class;

a step of calculating a degree of similarity between the class sequence and the profile; and

a step of determining whether an attack on the information processing apparatus occurs in accordance with the degree of similarity.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 2, 2016
From: ZHONG, YANG; ASAKURA, HIROSHI; ORIHARA, SHINGO; AOKI, KAZUFUMI
To: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
Reel/Frame 040492/0871 →
Priority Claims (1)
JP 2014-117756 · Jun 6, 2014 · national
Continuity (1)
Related Publication 20170126724A1 · May 4, 2017