IP Library › Granted Patent US 10,104,124
Granted Patent B2
US 10,104,124 · App. 15/119,162 · Granted Oct 16, 2018

Analysis rule adjustment device, analysis rule adjustment system, analysis rule adjustment method, and analysis rule adjustment program

Inventors: Kensuke Nakata (Musashino, JP); Kazunori Kamiya (Musashino, JP); Takeshi Yagi (Musashino, JP); Tohru Sato (Musashino, JP); Daiki Chiba (Musashino, JP)
Assignee: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
H04L63/20G06F21/552H04L12/6418H04L43/04G06F2221/2151H04L63/1425H04L2463/144
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,104,124
App. No.
15/119,162
Granted
Oct 16, 2018
Kind
B2
Abstract

There is provided an analysis rule adjustment device that adjusts an analysis rule used in a communication log analysis performed to detect malicious communication through a network. The analysis rule adjustment device includes a log acquisition unit, a log analysis unit, and a first analysis unit. The log acquisition unit acquires a communication log through a network to be defended and a communication log generated by malware. The log analysis unit analyzes the communication log acquired by the log acquisition unit on the basis of predetermined analysis rule and tuning condition. The first analysis unit analyzes an analysis result by the log analysis unit and calculates a recommended tuning value used in an adjustment of the predetermined analysis rule and satisfying the tuning condition.

Claims (46)

1. An analysis rule adjustment device that adjusts an analysis rule used in analyzing a communication log to detect malicious communication through a network, the device comprising:

circuitry configured to implement:

a log acquisition unit that acquires a communication log through a network to be defended and a communication log generated by malware;

a log analysis unit that analyzes each of the communication logs acquired by the log acquisition unit on the basis of each analysis rule included in a predetermined set of analysis rules and a tuning condition, the predetermined set of analysis rules and the tuning condition being used to analyze the same communication log; and

a first analysis unit that analyzes an analysis result on the basis of each analysis rule included in the predetermined set of analysis rules of the log analysis unit and calculates a recommended tuning value corresponding to each analysis rule included in the predetermined set of analysis rules and used in an adjustment of the predetermined set of analysis rules and satisfying the tuning condition, the predetermined set of analysis rules that has been adjusted by the recommended tuning value preventing intrusion of malicious communication into the network.

2. The analysis rule adjustment device according to claim 1 , wherein:

the first analysis unit simultaneously analyzes the analysis result.

3. The analysis rule adjustment device according to claim 1 , wherein the first analysis unit outputs the recommended tuning value as well as sample identification information uniquely identifying a sample detected when the recommended tuning value is applied.

4. The analysis rule adjustment device according to claim 3 , further comprising:

a second analysis unit, implemented as circuitry, that analyzes the recommended tuning value and the sample identification information output by the first analysis unit,

wherein:

the first analysis unit outputs the recommended tuning value and sample identification information for each analysis rule included in the predetermined set of analysis rules, and

the second analysis unit outputs a recommended rule set obtained by reducing the number of analysis rules included in the predetermined set of analysis rules on the basis of the sample identification information.

5. The analysis rule adjustment device according to claim 3 , further comprising:

a memory that stores the analysis result of the log analysis unit,

wherein the first analysis unit performs an analysis on a different set of analysis rules on the basis of the analysis result stored in the memory.

6. The analysis rule adjustment device according to claim 1 , wherein the log analysis unit receives designation of a predetermined range of parameters as the tuning condition and analyzes each of the communication logs with respect to the predetermined range being designated.

7. The analysis rule adjustment device according to claim 1 , further comprising:

a feedback unit, implemented as circuitry, that updates the predetermined set of analysis rules on the basis of the recommended tuning value calculated by the first analysis unit.

8. An analysis rule adjustment system that adjusts an analysis rule used in analyzing a communication log to detect malicious communication through a network, the system comprising:

log storage circuitry that acquires, normalizes and stores a communication log through a network to be defended and a communication log generated by malware; and

analysis rule adjustment circuitry that adjusts the analysis rule by analyzing each of the communication logs stored in the log storage circuitry,

wherein:

the analysis rule adjustment circuitry includes:

log acquisition circuitry that acquires each of the communication logs from the log storage circuitry;

log analysis circuitry that analyzes each of the communication logs acquired by the log acquisition circuitry on the basis of each analysis rule included in a predetermined set of analysis rules and a tuning condition, the predetermined set of analysis rules and the tuning condition being used to analyze the same communication log; and

first analysis circuitry that analyzes an analysis result on the basis of each analysis rule included in the predetermined set of analysis rules of the log analysis circuitry and calculates a recommended tuning value corresponding to each analysis rule included in the predetermined set of analysis rules and used in an adjustment of the predetermined set of analysis rules and satisfying the tuning condition, the predetermined set of analysis rules that has been adjusted by the recommended tuning value preventing intrusion of malicious communication into the network.

9. An analysis rule adjustment method that adjusts an analysis rule used in analyzing a communication log to detect malicious communication through a network, the method comprising:

acquiring, using circuitry, a communication log through a network to be defended and a communication log generated by malware and storing each of the communication logs in log storage circuitry;

acquiring, using circuitry, each of the communication logs stored in the log storage circuitry;

analyzing, using circuitry, each of the acquired communication logs on the basis of each analysis rule included in a predetermined set of analysis rules and a tuning condition, the predetermined set of analysis rules and the tuning condition being used to analyze the same communication log; and

analyzing, using circuitry, an analysis result of analyzing each of the acquired communication logs, on the basis of each analysis rule included in the predetermined set of analysis rules and calculating a recommended tuning value corresponding to each analysis rule included in the predetermined set of analysis rules and used in an adjustment of the predetermined set of analysis rules and satisfies the tuning condition, the predetermined set of analysis rules that has been adjusted by the recommended tuning value preventing intrusion of malicious communication into the network.

10. A non-transitory computer readable recording medium having stored therein a program which causes a computer to adjust an analysis rule used in analyzing a communication log to detect malicious communication through a network and prevent intrusion, the program comprising:

acquiring a communication log through a network to be defended and a communication log generated by malware;

analyzing each of the acquired communication logs on the basis of each analysis rule included in a predetermined set of analysis rules and a tuning condition, the predetermined set of analysis rules and the tuning condition being used to analyze the same communication log; and

analyzing an analysis result of analyzing each of the acquired communication logs, on the basis of each analysis rule included in the predetermined set of analysis rules and calculating a recommended tuning value corresponding to each analysis rule included in the predetermined set of analysis rules and used in an adjustment of the predetermined set of analysis rules and satisfies the tuning condition, the predetermined set of analysis rules that has been adjusted by the recommended tuning value preventing intrusion of malicious communication into the network.

11. The analysis rule adjustment device according to claim 1 , further comprising:

intrusion prevention circuitry to prevent malicious communication into the network using the predetermined analysis rule that has been adjusted by the recommended tuning value.

12. The analysis rule adjustment device according to claim 4 , further comprising:

intrusion prevention circuitry prevents the malicious communication into the network using the predetermined analysis rule that has been adjusted by the recommended tuning value and the recommended rule set.

13. The system according to claim 8 , further comprising:

intrusion prevention circuitry to prevent malicious communication into the network using the analysis rule that has been adjusted.

14. The method according to claim 9 , further comprising:

preventing malicious communication into the network using the predetermined analysis rule that has been adjusted by the recommended tuning value.

15. The non-transitory computer readable recording medium, according to claim 10 , wherein the program further comprises:

preventing malicious communication into the network using the predetermined analysis rule that has been adjusted by the recommended tuning value.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 16, 2016
From: NAKATA, KENSUKE; KAMIYA, KAZUNORI; YAGI, TAKESHI; SATO, TOHRU; CHIBA, DAIKI
To: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
Reel/Frame 039452/0001 →
Priority Claims (1)
JP 2014-056660 · Mar 19, 2014 · national
Continuity (1)
Related Publication 20170013018A1 · Jan 12, 2017