EXTRACTION METHOD, EXTRACTION DEVICE, AND EXTRACTION PROGRAM
An extraction method executed by an extraction device includes acquiring an observation result by a predetermined organization with respect to an indicator of compromise (IOC) included in information on cyber security, and creating feature information of the IOC based on information obtained from the observation result acquired.
1 . An extraction method executed by an extraction device, the extraction method comprising:
acquiring an observation result by a predetermined organization with respect to an indicator of compromise (IOC) included in information on cyber security; and
creating feature information of the IOC based on information obtained from the observation result acquired.
2 . The extraction method according to claim 1 , wherein a detection status of an IOC-related matter by a threat intelligence service is acquired, and
the feature information is created based on the detection status.
3 . The extraction method according to claim 1 , wherein a domain name system (DNS) record corresponding to a domain name associated with the IOC is acquired as the observation result, and
the feature information is created based on a number of changes in the information of the DNS record.
4 . The extraction method according to claim 1 , wherein a domain name system (DNS) record corresponding to a domain name associated with the IOC is acquired as the observation result, and
the feature information is created based on a number of times of use and a period of use of the DNS record.
5 . The extraction method according to claim 1 , wherein the feature information is created based on information obtained from the observation result and a statistic calculated from the information.
6 . An extraction device comprising:
processing circuitry configured to:
acquire an observation result by a predetermined organization with respect to an indicator of compromise (IOC) included in information on cyber security; and
create feature information of the IOC based on information obtained from the observation result acquired.
7 . A non-transitory computer-readable recording medium storing therein an extraction program that causes a computer to execute a process comprising:
acquiring an observation result by a predetermined organization with respect to an indicator of compromise (IOC) included in information on cyber security; and
creating feature information of the IOC based on information obtained from the observation result acquired.