IP Library › Granted Patent US 11,985,151
Granted Patent B2
US 11,985,151 · App. 17/254,875 · Granted May 14, 2024

Generation device, generation method, and generation program

Inventors: Takeshi Nakatsuru (Musashino, JP); Tomoyasu Sato (Musashino, JP); Takuya Minami (Musashino, JP); Naoto Fujiki (Musashino, JP); Masami Izumi (Musashino, JP)
Assignee: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
H04L63/1425G06F21/554H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,985,151
App. No.
17/254,875
Granted
May 14, 2024
Kind
B2
Abstract

A generation device includes a memory, and processing circuitry coupled to the memory and configured to sense anomaly of a network based on information having a plurality of items related to communication in the network, identify a cause of anomaly corresponding to each piece of the information when anomaly is sensed, and generate, based on values of the items in the information and the cause of anomaly identified, a cause-of-anomaly pattern for each predetermined set of pieces of the information.

Claims (28)

1. A generation device comprising:

a memory; and

processing circuitry coupled to the memory and configured to:

sense anomaly of a network based on information having a plurality of items related to communication in the network,

identify an intrusion detection and prevention signature as a cause of anomaly corresponding to each piece of the information when anomaly is sensed, the identification of the intrusion detection and prevention signature being based on a comparison of each piece of the information to a table associating row information including at least source addresses, destination addresses, source ports, destination ports, duration, and protocol to intrusion detection and prevention signatures, and

generate, based on values of the items in the information, source address classification and destination address classification, and the cause of anomaly identified, a cause-of-anomaly pattern for each predetermined set of pieces of the information.

2. The generation device according to claim 1 , wherein the processing circuitry is further configured to generate, based on meta information generated from the values of the items in the information, a pattern indicating combination of causes of anomaly per flow corresponding to the information, the pattern expressing that a plurality of flows correspond to each cause of anomaly.

3. The generation device according to claim 1 , wherein the processing circuitry is further configured to refer to a storage that stores the pattern generated and determine, when a first pattern is generated, whether the first pattern is identical to the pattern stored in the storage.

4. The generation device according to claim 1 , wherein the processing circuitry is further configured to:

generate, based on information related to communication through the network in normal operation, a sensing model to sense anomaly of a network,

generate, based on the information related to communication through the network, an identification model to identify a cause of anomaly of the network,

sense anomaly of the network using the sensing model based on sensing target information,

identify a cause of anomaly corresponding to each piece of the sensing target information using the identification model when anomaly is sensed, and

generate a cause-of-anomaly pattern for a set of pieces of the sensing target information per flow.

5. The generation device according to claim 1 , wherein the plurality of items include duration of the communication through the nets pork and a size of the communication through the network.

6. The generation device according to claim 5 , wherein the size of the communication through the network includes at least one of a number of bytes uploaded or a number of bytes downloaded.

7. The generation device according to claim 1 wherein the classification of source and destination addresses indicates at least an in-network address, a general web address, or a server address.

8. The generation device according to claim 1 , wherein the anomaly includes a malware attack.

9. The generation device according to claim 8 , wherein the malware attack is a denial of service attack.

10. The generation device according to claim 9 , wherein the anomaly is identified as a denial of service attack based on analysis of the communication in the network.

11. A generation method comprising:

sensing anomaly of a network based on information having a plurality of items related to communication in the network;

identifying an intrusion detection and prevention signature as a cause of anomaly corresponding to each piece of the information when anomaly is sensed, the identification of the intrusion detection and prevention signature being based on a comparison of each piece of the information to a table associating row information including at least source addresses, destination addresses, source ports, destination ports, duration, and protocol to intrusion detection and prevention signatures; and

generating, based on values of the items in the information, source address classification and destination address classification, and the cause of anomaly identified, a cause-of-anomaly pattern for each predetermined set of pieces of the information, by processing circuitry.

12. A non-transitory computer-readable recording medium storing therein a generation program that causes a computer to execute a process comprising:

sensing anomaly of a network based on information having a plurality of items related to communication in the network;

identifying an intrusion detection and prevention signature as a cause of anomaly corresponding to each piece of the information when anomaly is sensed, the identification of the intrusion detection and prevention signature being based on a comparison of each piece of the information to a table associating row information including at least source addresses destination addresses source ports, destination ports duration and protocol to intrusion detection and prevention signatures; and

generating, based on values of the items in the information, source address classification and destination address classification, and the cause of anomaly identified, a cause-of-anomaly pattern for each predetermined set of pieces of the information.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 22, 2020
From: NAKATSURU, TAKESHI; SATO, TOMOYASU; MINAMI, TAKUYA; FUJIKI, NAOTO; IZUMI, MASAMI
To: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
Reel/Frame 054718/0693 →
Priority Claims (1)
JP 2018-126189 · Jul 2, 2018 · national
Continuity (1)
Related Publication 20210273963A1 · Sep 2, 2021