IP Library › Granted Patent US 12,609,943
Granted Patent B2
US 12,609,943 · App. 18/554,769 · Granted Apr 21, 2026

Application attack determination device, application attack determination method, and application attack determination program

Inventor: Yo Kanemoto (Tokyo, JP)
Assignee: NTT, Inc.
H04L63/1416H04L63/1425H04L63/1466
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,609,943
App. No.
18/554,769
Granted
Apr 21, 2026
Kind
B2
Abstract

A determination device includes processing circuitry configured to detect a communication log of an attack causing different damage in accordance with a function of a web application of a request destination using a URL of the request destination in a communication log in which an attack is to be detected, determine whether or not the attack has succeeded using whether or not there is a login form in the URL of the request destination, a response size to a request, or a status code, or any combination thereof, for the communication log in which the attack has been detected, and output a result of the determination.

Claims (36)

1 . A determination device comprising:

processing circuitry configured to:

detect, based on a Universal Resource Locator (“URL”) of a request destination of a request in a communication log that has captured a network communication of a web application, the communication log that indicates an attack on the web application, wherein the attack has caused a distinct damage in accordance with a function of the web application of the request destination;

determine, by using the detected communication log, a result of the attack, wherein the result of the attack is based on:

whether the URL of the request destination of the request in the detected communication log indicating a login form and at least either one of a response size in a response to the request or a status code in the response, and

determining whether or not the attack has succeeded as the result of the attack by collating:

whether or not there is the login form in the URL of the request destination in the request against profile information of the function of the web application indicating whether or not the function of the web application has a login form, and

the response size in the response to the request in which the attack has been detected against a range of a response size when the response is returned to an external device; and

output a result of the determination.

2 . The determination device according to claim 1 ,

wherein the processing circuitry is further configured to detect

the communication log of the attack causing different damage in accordance with the function of the web application of the request destination using a regular expression “OR.*=.* #”, a regular expression “OR (1|‘t’) (#|--)”, or a regular expression “.+[′″] (#|--)”, or any combination thereof as an attack detection signature.

3 . The determination device according to claim 1 , wherein the processing circuitry is further configured to

create profile information of the function of the web application based on normal communication performed between the external device and the function of the web application.

4 . The determination device according to claim 1 ,

wherein the processing circuitry is further configured to determine

in a case where it is determined for the communication log in which the attack has been detected that there is a login form in the URL of the request destination and the status code is one of 300 to 309, that an attack aiming at authentication bypass has succeeded.

5 . The determination device according to claim 1 ,

wherein the processing circuitry is further configured to determine

in a case where it is determined for the communication log in which the attack has been detected that there is no login form in the URL of the request destination and a response size to the request exceeds a range of a response size indicated in profile information of the function of the web application by equal to or greater than a predetermined value, that an attack aiming at information leakage has succeeded.

6 . A determination method executed by a determination device, the determination method comprising:

detecting, based on a Universal Resource Locator (“URL”) of a request destination of a request in a communication log that has captured a network communication of a web application, the communication log that indicates an attack on the web application, wherein the attack has caused a distinct damage in accordance with a function of the web application of the request destination;

determining, by using the detected communication log, a result of the attack, wherein the result of the attack is based on:

whether the URL of the request destination of the request in the detected communication log indicating a login form and at least either one of a response size in a response to the request or a status code in the response, and

determining whether or not the attack has succeeded as the result of the attack by collating:

whether or not there is the login form in the URL of the request destination in the request against profile information of the function of the web application indicating whether or not the function of the web application has a login form, and

the response size in the response to the request in which the attack has been detected against a range of a response size when the response is returned to an external device; and

outputting a result of the determination.

7 . A non-transitory computer-readable recording medium storing therein a determination program that causes a computer to execute a process comprising:

detecting, based on a Universal Resource Locator (“URL”) of a request destination of a request in a communication log that has captured a network communication of a web application, the communication log that indicates an attack on the web application, wherein the attack has caused a distinct damage in accordance with a function of the web application of the request destination;

determining, by using the detected communication log, a result of the attack, wherein the result of the attack is based on:

whether the URL of the request destination of the request in the detected communication log indicating a login form and at least either one of a response size in a response to the request or a status code in the response, and

determining whether or not the attack has succeeded as the result of the attack by collating:

whether or not there is the login form in the URL of the request destination in the request against profile information of the function of the web application indicating whether or not the function of the web application has a login form, and

the response size in the response to the request in which the attack has been detected against a range of a response size when the response is returned to an external device; and

outputting a result of the determination.

Assignments (2)
CHANGE OF NAME Recorded Oct 3, 2025
From: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
To: NTT, INC.
Reel/Frame 073007/0308 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 10, 2023
From: KANEMOTO, YO
To: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
Reel/Frame 065173/0933 →
Continuity (1)
Related Publication 20240187429A1 · Jun 6, 2024
References Cited (14)
US 10628764B1 · Kaplan · 2020 [cited by examiner]
US 20090049547A1 · Fan · 2009 [cited by examiner]
US 20120284237A1 · Li · 2012 [cited by examiner]
US 20170063793A1 · Galbreath · 2017 [cited by examiner]
US 20170126627A1 · Yang · 2017 [cited by examiner]
US 20170308688A1 · Orihara · 2017 [cited by examiner]
US 20190370476A1 · Zhong · 2019 [cited by examiner]
US 20190394233A1 · Li · 2019 [cited by examiner]
US 20200201987A1 · Kanemoto · 2020 [cited by applicant]
US 20210226967A1 · Shin · 2021 [cited by examiner]
JP 2019533841A · 2019 [cited by applicant]
JP 6708794B2 · 2020 [cited by applicant]
Uehara, Takayuki (1999) “Operation management and log monitoring are indispensable for Internet safety measures that go one step further” Nikkei Communications, Mar. 15, 1999, No. 290, pp. 216-221, ISSN 0910-7215, in pa… [cited by applicant]
Gu, Haifeng et al. (2019) “DIAVA: A Traffic-Based Framework for Detection of SQL Injection Attacks and Vulnerability Analysis of Leaked Data” IEEE Transactions on Reliability., Jul. 24, 2019, vol. 69, No. 1, pp. 188-202… [cited by applicant]