EXTRACTION METHOD, EXTRACTION DEVICE, AND EXTRACTION PROGRAM
A feature information extraction unit acquires a history of actions taken by an analyst with respect to investigation of an IOC included in information on cyber security. A feature information extraction unit creates IOC feature information on the basis of information obtained from the acquired history of actions.
1 . An extraction method which is executed by an extraction device, comprising:
acquiring a history of actions taken by an analyst with respect to investigation of an indicator of compromise (IOC) included in information on cyber security; and
creating IOC feature information on the basis of information obtained from the history of actions acquired by the acquiring.
2 . The extraction method according to claim 1 , wherein the creating creates the feature information on the basis of information on the number of actions and an interval of time between the actions.
3 . The extraction method according to claim 1 , wherein the creating creates the feature information on the basis of information on an elapsed time from a point in time when the action was performed within a predetermined time window.
4 . The extraction method according to claim 1 , wherein the creating creates the feature information on the basis of information on a date and time when the action was performed and the analyst's work pattern.
5 . The extraction method according to claim 1 , wherein the creating creates the feature information on the basis of information obtained from the history of actions and a statistic calculated from the information.
6 . An extraction device comprising: a memory; and a processor coupled to the memory and programmed to execute a process comprising:
acquiring a history of actions taken by an analyst with respect to investigation of an indicator of compromise (IOC) included in information on cyber security; and
creating IOC feature information on the basis of information obtained from the history of actions acquired by the acquiring.
7 . A non-transitory computer-readable recording medium storing therein a processing program that causes a computer to execute a process comprising:
acquiring a history of actions taken by an analyst with respect to investigation of an indicator of compromise (IOC) included in information on cyber security; and
creating IOC feature information on the basis of information obtained from the history of actions acquired by the acquiring.