IP Library › Granted Patent US 12,355,635
Granted Patent B2
US 12,355,635 · App. 18/566,076 · Granted Jul 8, 2025

Analysis device, analysis method, and analysis program

Inventors: Shosuke Oba (Tokyo, JP); Kazunori Kamiya (Tokyo, JP); Bo Hu (Tokyo, JP)
Assignee: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
H04L41/22H04L41/0816H04L41/14
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,355,635
App. No.
18/566,076
Filed
Nov 30, 2023
Granted
Jul 8, 2025
Kind
B2
Art Unit
2441
USPC
709/221
Abstract

An analysis device includes processing circuitry configured to generate a graph in which each IP host indicated in communication information is set as a node and communication between the each IP host is set as an edge on a basis of the communication information of a network, calculate a degree of relevance between a predetermined IP host and each IP host on the graph using the generated graph, correct the graph by adding or deleting an edge connecting each IP host on the graph on a basis of a degree of relevance between a predetermined IP host and each IP host on the graph, calculate a degree of relevance between the predetermined IP host and each IP host using the corrected graph, and output a degree of relevance between the predetermined IP host and each IP host.

Claims (27)

1. An analysis device comprising:

processing circuitry configured to:

generate, based on data traffic information of a plurality of Internet Protocol (IP) hosts in a network, a graph, wherein the graph comprises a plurality of IP hosts as respective nodes and communication between a first IP host of the plurality of IP hosts and a second IP host of the plurality of IP hosts as an edge;

identify, based on similarity of neighborhoods between a predetermined IP host of the plurality of IP hosts and the first IP host of the plurality of IP hosts on the graph, a first degree of relevance between the predetermined IP host of the plurality of IP hosts and the first IP host of the plurality of IP hosts on the generated graph, wherein the predetermined IP host represents a malicious IP host that cause one or more IP hosts of the plurality of IP hosts to perform relevant malicious operations;

update, based on a first predetermined threshold degree of relevance and the first degree of relevance between the predetermined IP host and the first IP host, the generated graph by modifying an edge connecting the predetermined IP host and the first IP host;

identify, based on the updated graph according to the modified edge, a second degree of relevance between the predetermined IP host and the first IP host; and

identify and extract, based on a second predetermined threshold degree of relevance and the identified second degree of relevance between the predetermined IP host and the first IP host, the first IP host from the network as relevant to the malicious IP host.

2. The analysis device according to claim 1 , wherein the processing circuitry is further configured to update the graph by adding an edge from the predetermined IP host to an IP host having the first degree of relevance equal to or greater than the first predetermined threshold degree of relevance in a case where there is no edge from the predetermined IP host to the IP host having the first degree of relevance equal to or greater than the first predetermined threshold degree of relevance in the graph.

3. The analysis device according to claim 1 , wherein the processing circuitry is further configured to update the graph by deleting the edge in a case where the edge from the predetermined IP host to the first IP host has the first degree of relevance less than the first predetermined threshold degree of relevance in the graph.

4. The analysis device according to claim 1 , wherein the processing circuitry is further configured to calculate the second degree of relevance by a predetermined calculation algorithm.

5. The analysis device according to claim 1 , wherein the processing circuitry is further configured to:

calculate the first degree of relevance between the predetermined IP host and the first IP host using the graph by Deep Walk, and

calculate the second degree of relevance between the predetermined IP host and the first IP host using the updated graph by Personalized PageRank.

6. The analysis device according to claim 1 , wherein

the predetermined IP host represents the malicious IP host designated in advance, the predetermined IP host corresponds to a predetermined node of the graph, and the predetermined host communicates with the first IP host of the plurality of IP hosts over the network.

7. An analysis method performed by an analysis device, the analysis method comprising:

generating, based on data traffic information of a plurality of Internet Protocol (IP) hosts in a network, a graph, wherein the graph comprises a plurality of IP hosts as respective nodes and communication between a first IP host of the plurality of IP hosts and a second IP host of the plurality of IP hosts as an edge;

identifying, based on similarity of neighborhoods between a predetermined IP host of the plurality of IP hosts and the first IP host of the plurality of IP hosts in the graph, a first degree of relevance between the predetermined IP host of the plurality of IP hosts and the first IP host of the plurality of IP hosts on the generated graph, wherein the predetermined IP host represents a malicious IP host that cause one or more IP hosts of the plurality of IP hosts to perform relevant malicious operations;

updating, based on a first predetermined threshold degree of relevance and the first degree of relevance between the predetermined IP host and the first IP host, the generated graph by modifying an edge connecting the predetermined IP host and the first IP host;

identifying, based on the updated graph according to the modified edge, calculating a second degree of relevance between the predetermined IP host and the first IP host; and

identifying and extracting, based on a second predetermined threshold degree of relevance and the identified second degree of relevance between the predetermined IP host and the identified first IP host, the first IP host from the network as relevant to the malicious IP host.

8. A non-transitory computer-readable recording medium storing therein an analysis program that causes a computer to execute a process comprising:

generating, based on data traffic information of a plurality of Internet Protocol (IP) hosts in a network, a graph, wherein the graph comprises a plurality of IP hosts as respective nodes and communication between a first IP host of the plurality of IP hosts and a second IP host of the plurality of IP hosts as an edge;

identifying, based on similarity of neighborhoods between a predetermined IP host of the plurality of IP hosts and the first IP host of the plurality of IP hosts on the graph, a first degree of relevance between the predetermined IP host of the plurality of IP hosts and the first IP host of the plurality of IP hosts on the generated graph, wherein the predetermined IP host represents a malicious IP host that cause one or more IP hosts of the plurality of IP hosts to perform relevant malicious operations;

updating, based on a first predetermined threshold degree of relevance and the first degree of relevance between the predetermined IP host and the first IP host, the generated graph by modifying an edge connecting the predetermined IP host and the first IP host;

identifying, based on the updated graph according to the modified edge, calculating a second degree of relevance between the predetermined IP host and the first IP host; and

identifying and extracting, based on a second predetermined threshold degree of relevance and the identified second a degree of relevance between the predetermined IP host and the identified first IP host, the first IP host from the network as relevant to the malicious IP host.

Assignments (2)
CHANGE OF NAME Recorded Oct 3, 2025
From: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
To: NTT, INC.
Reel/Frame 073007/0308 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 30, 2023
From: OBA, SHOSUKE; KAMIYA, KAZUNORI; HU, BO
To: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
Reel/Frame 065725/0601 →
Continuity (1)
Related Publication 20240380677A1 · Nov 14, 2024
References Cited (6)
US 12174963B1 · Alamuri · 2024 [cited by examiner]
US 20210042359A1 · Nagayama et al. · 2021 [cited by applicant]
WO 2019168072A1 · 2019 [cited by applicant]
Jeh et al. (2003) “Scaling Personalized Web Search” WWW '03: Proceedings of the 12th International Conference on World Wide Web, May 2003, pp. 271-279, https://doi.org/10.1145/775152.775191. [cited by applicant]
Perozzi et al. (2014) “DeepWalk: Online Learning of Social Representations” KDD '14: Proceedings of the 20th ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, Aug. 2014, pp. 701-710, https://do… [cited by applicant]
Uno et al. (2014) “Clustering by Clique Enumeration and Data Cleaning like Method” IPSJ Technical Report, vol. 2014-AL-146, No. 2, pp. 1-8, sections 1, 4. [cited by applicant]