IP Library › Granted Patent US 10,382,477
Granted Patent B2
US 10,382,477 · App. 15/281,798 · Granted Aug 13, 2019

Identification apparatus, control method therefor, and storage medium

Inventor: Kazuki Takano (Iruma-gun, JP)
Assignee: Canon Denshi Kabushiki Kaisha
H04L63/145G06F21/552G06F21/56H04L63/1408H04L2463/146
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,382,477
App. No.
15/281,798
Granted
Aug 13, 2019
Kind
B2
Abstract

There is provided an identification apparatus. A storage unit stores an operation history as a history of an operation executed in at least one information processing apparatus. An acquisition unit acquires malware spread information including information indicating malware. An identification unit identifies, based on the operation history, an intrusion route of the malware indicated by the malware spread information acquired by the acquisition unit, generates at least one piece of malware spread information corresponding to at least one operation included in the intrusion route in the operation history, and identifies, in the operation history, for each of the at least one piece of malware spread information, at least one operation of spreading the malware by setting, as a direct or indirect start point, the malware indicated by the malware spread information.

Claims (45)

1. An identification apparatus for identifying a spread range of malware, the spread range being a set of media to which the malware has been spread, comprising:

at least one memory that stores instructions and stores an operation history as a history of an operation executed in at least one information processing apparatus; and

at least one processor that, upon executing the instructions, functions as

an acquisition unit configured to acquire malware spread information including information indicating malware; and

an identification unit configured to

identify, based on the operation history, an intrusion route of the malware indicated by the malware spread information acquired by the acquisition unit,

generate at least one piece of malware spread information corresponding to at least one operation included in the intrusion route in the operation history, and

identify the spread range of the malware by, for each of the at least one piece of malware spread information, identifying at least one operation of spreading the malware in the operation history by setting, as a direct or indirect start point, the malware indicated by the malware spread information.

2. The identification apparatus according to claim 1 , wherein

the malware spread information further includes cause information indicating a cause of one of spread and intrusion of the malware, and

the identification unit identifies the at least one operation by processing based on the cause information.

3. The identification apparatus according to claim 2 , wherein

if the cause information indicates that the malware has been spread due to a file, the identification unit identifies, in the operation history, an operation for at least one of file creation, file change, registry creation, registry change, and access to a shared memory by a process generated by executing the malware indicated by the malware spread information.

4. The identification apparatus according to claim 2 , wherein

if the cause information indicates that the malware has been spread due to the file, the identification unit identifies, in the operation history, an operation for at least one of file creation, file change, registry creation, registry change, and access to a shared memory by one of a process activated by the process generated by executing the malware indicated by the malware spread information and a process which has loaded the malware indicated by the malware spread information.

5. The identification apparatus according to claim 2 , wherein

if the cause information indicates that the malware has been spread due to the file, the identification unit identifies, in the operation history, an operation for at least one of a copy, movement, and rename of the malware indicated by the malware spread information.

6. The identification apparatus according to claim 2 , wherein

if the cause information indicates that the malware has entered due to Web access, the identification unit identifies, in the operation history, an operation for at least one of file creation and file overwrite, which has been performed by a process that has accessed a URL of an intrusion source indicated by the malware spread information between access to the URL of the intrusion source and access to another URL.

7. The identification apparatus according to claim 2 , wherein

if the cause information indicates that the malware has entered due to mail reception, the identification unit identifies, in the operation history, an operation for at least one of file creation and file overwrite by a process which has received mail from a mail address of an intrusion source indicated by the malware spread information.

8. The identification apparatus according to claim 2 , wherein

if the cause information indicates that the malware has been spread due to a removable device, the identification unit identifies, in the operation history, an operation for at least one of a copy, movement, and rename of a file from the removable device of an intrusion source indicated by the malware spread information.

9. The identification apparatus according to claim 2 , wherein

if the cause information indicates that the malware has been spread due to a shared folder, the identification unit identifies, in the operation history, an operation for at least one of a copy, movement, and rename of a file from the shared folder of an intrusion source indicated by the malware spread information.

10. The identification apparatus according to claim 1 , wherein

the identification unit generates at least one piece of malware spread information corresponding to at least one operation identified based on the malware spread information acquired by the acquisition unit.

11. The identification apparatus according to claim 1 , wherein, upon executing the instructions, the at least one processor further functions as:

a detection unit configured to detect malware,

wherein the acquisition unit acquires malware spread information corresponding to the malware detected by the detection unit.

12. The identification apparatus according to claim 1 , wherein

the acquisition unit acquires malware spread information input by a user.

13. A control method for an identification apparatus for identifying a spread range of malware, the spread range being a set of media to which the malware has been spread, comprising:

storing an operation history as a history of an operation executed in at least one information processing apparatus;

acquiring malware spread information including information indicating malware; and

identifying, based on the operation history, an intrusion route of the malware indicated by the malware spread information acquired in the acquiring,

generating at least one piece of malware spread information corresponding to at least one operation included in the intrusion route in the operation history, and

identifying the spread range of the malware by, for each of the at least one piece of malware spread information, identifying at least one operation of spreading the malware in the operation history by setting, as a direct or indirect start point, the malware indicated by the malware spread information.

14. A non-transitory computer-readable storage medium which stores a program for causing a computer to execute a control method for identifying a spread range of malware, the spread range being a set of media to which the malware has been spread, the method comprising:

storing an operation history as a history of an operation executed in at least one information processing apparatus;

acquiring malware spread information including information indicating malware; and

identifying, based on the operation history, an intrusion route of the malware indicated by the malware spread information acquired in the acquiring,

generating at least one piece of malware spread information corresponding to at least one operation included in the intrusion route in the operation history, and

identifying the spread range of the malware by, for each of the at least one piece of malware spread information, identifying at least one operation of spreading the malware in the operation history by setting, as a direct or indirect start point, the malware indicated by the malware spread information.

15. The identification apparatus according to claim 1 , wherein the set of media includes information about one or more types of media including computers, files, registries, shared memories, and removable storage devices.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 3, 2016
From: TAKANO, KAZUKI
To: CANON DENSHI KABUSHIKI KAISHA
Reel/Frame 039922/0940 →
Priority Claims (1)
JP 2014-225422 · Nov 5, 2014 · national
Continuity (2)
Continuation PCTJP2015080171 · Oct 27, 2015
Related Publication 20170019415A1 · Jan 19, 2017