IP Library › Granted Patent US 11,550,920
Granted Patent B2
US 11,550,920 · App. 16/479,924 · Granted Jan 10, 2023

Determination apparatus, determination method, and determination program

Inventors: Yang Zhong (Musashino, JP); Tohru Sato (Musashino, JP)
Assignee: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
G06F21/577G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,550,920
App. No.
16/479,924
Granted
Jan 10, 2023
Kind
B2
Abstract

A determination apparatus includes a keyword extraction unit that extracts keywords characterizing a vulnerability from known vulnerability information, and a 0-day attack determination unit that compares the keywords characterizing the vulnerability and keywords included in a request used for an attack, and when a value of a score indicating a degree of inclusion of same keywords as the keywords characterizing the vulnerability in the request is smaller than a predetermined threshold, determines that the request is a 0-day attack that is neither a known attack nor an attack similar to the known attack.

Claims (18)

1. A determination apparatus comprising:

a memory; and

a processor coupled to the memory and programmed to execute a process comprising:

extracting keywords characterizing a vulnerability from known vulnerability information; and

comparing the keywords characterizing the vulnerability and keywords included in a request used for an attack, and when a value of a score indicating a level of degree of inclusion of same keywords as the keywords characterizing the vulnerability in the request is smaller than a predetermined threshold, determining that the request is a 0-day attack that is neither a known attack nor an attack similar to the known attack and which is an attack for which a countermeasure is not established, so as to determine whether the attack is the 0-day attack or not with accuracy, so that efficiency of responding against the attack after detecting the attack is improved, wherein

the determining includes performing matching between keywords that are extracted from a URL path of the request that has been determined as the attack and keywords of a URL path of a request in a Data Base without performing matching with keywords in other portions.

2. The determination apparatus according to claim 1 , wherein the value of the score is a ratio of the number of keywords that are the same as the keywords characterizing the vulnerability and that are included in the request to the number of the keywords characterizing the vulnerability.

3. The determination apparatus according to claim 1 , wherein when extracting the keywords characterizing the vulnerability from the known vulnerability information, the process further includes extracting, from the known vulnerability information, the keywords in at least one of fields of a URL path, a URL parameter, a header, and a cookie that are included in the request used for an attack against a Web site.

4. The determination apparatus according to claim 3 , wherein when comparing the keywords, the process further includes comparing keywords in a same field of an extraction source between the keywords characterizing the vulnerability and the keywords included in the request used for the attack.

5. The determination apparatus according to claim 1 , wherein when extracting the keywords characterizing the vulnerability from the known vulnerability information, the process further includes eliminating a keyword that is commonly used for attacks against a plurality of vulnerabilities or eliminating a predetermined keyword that is prepared in advance.

6. A determination method comprising:

extracting keywords characterizing a vulnerability from known vulnerability information; and

comparing the keywords characterizing the vulnerability and keywords included in a request used for an attack, and when a score indicating a degree of inclusion of same keywords as the keywords characterizing the vulnerability in the request is smaller than a predetermined threshold, determining that the request is a 0-day attack that is neither a known attack nor an attack similar to the known attack and which is an attack for which a countermeasure is not established, so as to determine whether the attack is the 0-day attack or not with accuracy, so that efficiency of responding against the attack after detecting the attack is improved, wherein

the determining includes performing matching between keywords that are extracted from a URL path of the request that has been determined as the attack and keywords of a URL path of a request in a Data Base without performing matching with keywords in other portions.

7. A non-transitory computer-readable recording medium having stored a determination program causing a computer to execute a process comprising:

extracting keywords characterizing a vulnerability from known vulnerability information; and

comparing the keywords characterizing the vulnerability and keywords included in a request used for an attack, and when a score indicating a degree of inclusion of same keywords as the keywords characterizing the vulnerability in the request is smaller than a predetermined threshold, determining that the request is a 0-day attack that is neither a known attack nor an attack similar to the known attack and which is an attack for which a countermeasure is not established, so as to determine whether the attack is the 0-day attack or not with accuracy, so that efficiency of responding against the attack after detecting the attack is improved, wherein

the determining includes performing matching between keywords that are extracted from a URL path of the request that has been determined as the attack and keywords of a URL path of a request in a Data Base without performing matching with keywords in other portions.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 23, 2019
From: ZHONG, YANG; SATO, TOHRU
To: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
Reel/Frame 049825/0966 →
Priority Claims (1)
JP JP2017-015951 · Jan 31, 2017 · national
Continuity (1)
Related Publication 20190370476A1 · Dec 5, 2019