IP Library Granted Patent US 12,542,806
Granted Patent B2
US 12,542,806 · App. 18/563,346 · Granted Feb 3, 2026

Analysis device, analysis method, and analysis system

Inventors: Kotomi Kuroki (Tokyo, JP); Yo Kanemoto (Tokyo, JP)
Assignee: NTT, Inc.
H04L63/1458
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,542,806
App. No.
18/563,346
Granted
Feb 3, 2026
Kind
B2
Abstract

When an attack by command injection is detected, an analysis device ( 10 ) extracts an attack command string inserted for the attack from an attack request transmitted in the attack, and acquires information obtained by executing the extracted attack command string. Also, the analysis device ( 10 ) determines an intention of the attack by the command injection using the acquired information, and outputs information indicating the determined intention of the attack.

Claims (64)

1 . An analysis device comprising:

at least one processor; and

memory storing instructions that, when executed by the at least one processor, causes the device to perform a set of operations, the set of operations comprising:

extracting, when an attack by command injection is detected, an attack command string inserted for the attack from an attack request transmitted in the attack, wherein the extracting further comprises extracting the attack command string using a predetermined list of commands;

acquiring information obtained by executing the attack command string;

determining an intention of the attack by the command injection using the acquired information; and

outputting information indicating the intention of the attack,

wherein the acquiring further comprises acquiring a system call log by executing the attack command string, and

the determining further comprises determining that the intention of the attack is falsification when the system call log includes an open system call with authority to write to a file.

2 . The analysis device according to claim 1 , wherein the extracting further comprises extracting the attack command string using a preset command list.

3 . The analysis device according to claim 1 ,

wherein the acquiring further comprises acquiring an execution time of the attack command string, and

the determining further comprises determining that the intention of the attack is a Denial-of-Service attack when the execution time of the attack command string is longer than a first time.

4 . The analysis device according to claim 3 , wherein the determining further comprises determining that the intention of the attack is vulnerability reconnaissance when:

the execution time of the attack command string is equal to or shorter than the first time,

the execution time of the attack command string is longer than a second time, and

the second time is shorter than the first time.

5 . The analysis device according to claim 1 ,

wherein the acquiring further comprises acquiring a system call log by executing the attack command string, and

the determining further comprises determining that the intention of the attack is information leakage when the system call log includes a write system call and when the system call log further includes a predetermined instruction to acquire data before performing the write system call.

6 . The analysis device according to claim 1 , wherein the acquiring further comprises acquiring, as the acquired information, a result of executing the attack command string as emulation, and the result includes an output of executing the attack command string, a time duration of executing the attack command string, and a trace log of executing the attack command string.

7 . An analysis method, the analysis method comprising:

extracting, when an attack by command injection is detected, an attack command string inserted for the attack from an attack request transmitted in the attack;

acquiring information obtained by executing the extracted attack command string;

determining an intention of the attack by the acquired command injection using the acquired information; and

outputting information indicating the intention of the attack,

wherein the acquiring further comprises acquiring a system call log by executing the attack command string, and

the determining further comprises determining that the intention of the attack is falsification when the system call log includes an open system call with authority to write to a file.

8 . The analysis method according to claim 7 , wherein the extracting further comprises extracting the attack command string using a predetermined list of commands.

9 . The analysis method according to claim 7 ,

wherein the acquiring further comprises acquiring an execution time of the attack command string, and

the determining further comprises determining that the intention of the attack is a Denial-of-Service attack when the execution time of the attack command string is longer than a first time.

10 . The analysis method according to claim 9 , wherein the determining further comprises determining that the intention of the attack is vulnerability reconnaissance when:

the execution time of the attack command string is equal to or shorter than the first time,

the execution time of the attack command string is longer than a second time, and

the second time is shorter than the first time.

11 . The analysis method according to claim 7 ,

wherein the acquiring further comprises acquiring a system call log by executing the attack command string, and

the determining further comprises determining that the intention of the attack is information leakage when the system call log includes a write system call and when the system call log further includes a predetermined instruction to acquire data before performing the write system call.

12 . The analysis method according to claim 7 , wherein the acquiring further comprises acquiring, as the acquired information, a result of executing the attack command string as emulation, and the result includes an output of executing the attack command string, a time duration of executing the attack command string, and a trace log of executing the attack command string.

13 . An analysis system comprising:

a first processor for analyzing data a second processor for emulating an attack command string,

wherein the first processor is configured to execute operations comprising:

when an attack by command injection is detected, extracting the attack command string inserted for the attack from an attack request transmitted in the attack, wherein the extracting further comprises extracting the attack command string using a predetermined list of commands,

acquiring information obtained by the second processor executing the attack command string,

determining an intention of the attack by the command injection using the acquired information, and

presenting information indicating the determined intension of the attack, and

the second processor is configured to execute operations comprising:

executing the attack command string as emulation,

wherein the acquiring further comprises acquiring a system call log by executing the attack command string, and

the determining further comprises determining that the intention of the attack is falsification when the system call log includes an open system call with authority to write to a file.

14 . The analysis system according to claim 13 , wherein the extracting further comprises extracting the attack command string using a predetermined list of commands.

15 . The analysis system according to claim 13 ,

wherein the acquiring further comprises acquiring an execution time of the attack command string,

the determining further comprises determining that the intention of the attack is a Denial-of-Service attack when the execution time of the attack command string is longer than a first time, and

wherein the determining further comprises determining that the intention of the attack is vulnerability reconnaissance when:

the execution time of the attack command string is equal to or shorter than the first time,

the execution time of the attack command string is longer than a second time, and

the second time is shorter than the first time.

16 . The analysis system according to claim 13 ,

wherein the acquiring further comprises acquiring a system call log by executing the attack command string, and

the determining further comprises determining that the intention of the attack is information leakage when the system call log includes a write system call and when the system call log further includes a predetermined instruction to acquire data before performing the write system call.

17 . The analysis system according to claim 13 ,

wherein the acquiring further comprises acquiring, as the acquired information, a result of executing the attack command string as emulation, and the result includes an output of executing the attack command string, an execution time of the attack command string, and a trace log of executing the attack command string.

Assignments (2)
CHANGE OF NAME Recorded Jan 1, 2026
From: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
To: NTT, INC.
Reel/Frame 074164/0725 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 21, 2023
From: KUROKI, KOTOMI; KANEMOTO, YO
To: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
Reel/Frame 065641/0081 →
Continuity (1)
Related Publication 20240214417A1 · Jun 27, 2024
References Cited (28)
US 11438361B2 · Rakesh · 2022 [cited by examiner]
US 20200304534A1 · Rakesh · 2020 [cited by examiner]
US 20210150022A1 · Karas · 2021 [cited by examiner]
US 20230015273A1 · Kura · 2023 [cited by examiner]
US 20230084768A1 · Inui · 2023 [cited by examiner]
US 20230132559A1 · Ishihara · 2023 [cited by examiner]
US 20230370482A1 · Zhang · 2023 [cited by examiner]
US 20230376607A1 · Kamimura · 2023 [cited by examiner]
US 20230388344A1 · Vissamsetty · 2023 [cited by examiner]
US 20230394138A1 · Noeth · 2023 [cited by examiner]
US 20240015182A1 · Kim · 2024 [cited by examiner]
US 20240054213A1 · Takahashi · 2024 [cited by examiner]
US 20240146757A1 · Isoyama · 2024 [cited by examiner]
US 20240152603A1 · Usui · 2024 [cited by examiner]
US 20240152615A1 · Usui · 2024 [cited by examiner]
US 20240154976A1 · Kanemoto · 2024 [cited by examiner]
US 20240160746A1 · Kamimura · 2024 [cited by examiner]
US 20240187429A1 · Kanemoto · 2024 [cited by examiner]
US 20240356971A1 · Vissamsetty · 2024 [cited by examiner]
US 20240386109A1 · Kurtz · 2024 [cited by examiner]
US 20250077648A1 · Karas · 2025 [cited by examiner]
EP 3637292A1 · 2020 [cited by examiner]
Stasinopoulos et al. (2018) “Commix: automating evaluation and exploitation of command injection vulnerabilities in Web applications” International Journal of Information Security, Feb. 1, 2018. [cited by applicant]
Pietraszek et al. (2005) “Defending against Injection Attacks through Context-Sensitive String Evaluation” Proceedings of Recent Advances in Intrusion Detection (RAID2005), Sep. 7, 2005. [cited by applicant]
Lin et al. (2007) “The Automatic Defense Mechanism for Malicious Injection Attack” 7th IEEE International Conference on Computer and Information Technology (CIT 2007), Oct. 16, 2007. [cited by applicant]
Kuroki et al. (2020) “Attack Intention Estimation Based on Syntax Analysis and Dynamic Analysis for SQL Injection” 2020 IEEE 44th Annual Computers, Software, and Applications Conference (COMPSAC), Jul. 13, 2020, pp. 151… [cited by applicant]
Kuroki et al. (2020) “A Damage Identification Method Based on Syntax Analysis and Semantic Analysis for SQL Injection” Proceedings of the 2020 Symposium on Cryptography and Information Security, Jan. 21, 2020, pp. 1-8. [cited by applicant]
Zhong et al. (2015) “A Log Correlation Method to Identify the Target and the Effect of Web Attacks” Computer Security Symposium 2015 Proceedings, vol. 2015, No. 3, pp. 132-139. [cited by applicant]