IP Library › Granted Patent US 12,407,698
Granted Patent B2
US 12,407,698 · App. 18/297,035 · Granted Sep 2, 2025

Information processing device, information processing method, and computer readable medium

Inventors: Takumi Yamamoto (Tokyo, JP); Kiyoto Kawauchi (Tokyo, JP)
Assignee: MITSUBISHI ELECTRIC CORPORATION
H04L63/1416H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,407,698
App. No.
18/297,035
Granted
Sep 2, 2025
Kind
B2
Abstract

A normal classification unit ( 101 ) extracts a true positive access that is known to be an access aimed to attack and that has been determined by a detection unit ( 102 ) to be an access aimed to attack. A modification unit ( 107 ) modifies a feature of the true positive access by using a feature of a true negative access that is known to be a normal access and that has been determined by the detection unit ( 102 ) to be a normal access.

Claims (62)

1. An information processing device comprising:

processing circuitry to:

extract, from a database of true positive accesses, a true positive access,

wherein each of the true positive accesses is an access that is

known prior to being processed by an access detection system to be an access aimed to attack, and

detected by the attack detection system to be an access aimed to attack;

extract, from a database of true negative accesses, a true negative access,

wherein each of the true negative accesses is an access that is

known prior to being processed by the access detection system to be a normal access, and

determined by the attack detection system to be a normal access; and

modify a feature of the extracted true positive access by using a feature of the extracted true negative access to increase the likelihood that the access detection system will determine the modified true positive access to be a normal access,

wherein the processing circuitry modifies the feature of the true positive access by using the feature of the true negative access and data of a corresponding feature of a false positive access,

wherein the false positive access is an access that is

known prior to being processed by an access detection system to be a normal access, and

detected by the attack detection system to be an access aimed to attack.

2. The information processing device according to claim 1 , wherein

the processing circuitry modifies the feature of the true positive access so that a modified true positive access which is the true positive access whose feature has been modified is determined by the attack detection system to be a normal access.

3. The information processing device according to claim 1 , wherein

when the extracted true positive access which is the true positive access whose feature has been modified is determined by the attack detection system to be an access aimed to attack, the processing circuitry further modifies the feature of the modified true positive access by using the feature of the extracted true negative access.

4. The information processing device according to claim 1 , wherein

the processing circuitry extracts from the database of true negative accesses, an access including a feature similar to the particular feature of the true positive access, as the true negative access, and

modifies the data of the particular feature of the true positive access by using the data of the similar corresponding feature of the extracted true negative access.

5. The information processing device according to claim 1 , wherein

the processing circuitry selects as the feature to modify from the plurality of features of the true positive access, a feature that matches with a selection condition, and

modifies the selected feature by using the feature of the true negative access.

6. The information processing device according to claim 5 , wherein

the processing circuitry calculates for each of the plurality of features, an importance degree of a feature which is a degree of distinguishing between the true positive access and the true negative access, and

selects from the plurality of features, a feature whose importance degree matches with the selection condition.

7. The information processing device according to claim 6 , wherein

the processing circuitry calculates an importance degree of each of the plurality of features so that higher importance degree is set to a feature which has higher degree of distinguishing between the true positive access and the true negative access.

8. The information processing device according to claim 1 , wherein

when a modified true positive access which is the true positive access whose particular feature has been modified is determined by the attack detection system to be an access aimed to attack, the processing circuitry further modifies the feature of the modified true positive access by using the feature of the false positive access and the feature of the true negative access.

9. The information processing device according to claim 1 , wherein

the processing circuitry selects the feature of the true positive access to be modified by eliminating as a possible selection a feature corresponding to a feature of the true negative access that overlaps with a corresponding feature of the false positive access.

10. An information processing method comprising:

extracting, from a database of true positive accesses, a true positive access,

wherein each of the true positive accesses is an access that is

known prior to being processed an access detection system to be an access aimed to attack, and

detected by the attack detection system to be an access aimed to attack;

extracting, from a database of true negative accesses, a true negative access,

wherein each of the true negative accesses is an access that is

known prior to being processed by the access detection system to be a normal access, and

determined by the attack detection system to be a normal access; and

modifying a feature of the extracted true positive access by using a feature of the extracted true negative access to increase the likelihood that the attack detection system will determine the modified true positive access to be a normal access,

wherein the modifying step modifies the feature of the true positive access by using the feature of the true negative access and data of a corresponding feature of a false positive access,

wherein the false positive access is an access that is

known prior to being processed by an access detection system to be a normal access, and

detected by the attack detection system to be an access aimed to attack.

11. A non-transitory computer readable medium storing an information processing program for causing a computer to execute:

an extraction process to extract, from a database of true positive accesses, a true positive access,

wherein each of the true positive accesses is an access that is

known prior to being processed by an access detection system to be an access aimed to attack, and

detected by the attack detection system to be an access aimed to attack;

a second extraction process to extract, from a database of true negative accesses, a true negative access,

wherein each of the true negative accesses is an access that is

known before being processed by the access detection system to be a normal access, and

determined by the attack detection system to be a normal access; and

a modification process to modify a feature of the extracted true positive access by using a feature of the extracted true negative access to increase the likelihood that the attack detection system will determine the modified true positive access to be a normal access,

wherein the modification process modifies the feature of the true positive access by using the feature of the true negative access and data of a corresponding feature of a false positive access,

wherein the false positive access is an access that is

known prior to being processed by an access detection system to be a normal access, and

detected by the attack detection system to be an access aimed to attack.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 7, 2023
From: YAMAMOTO, TAKUMI; KAWAUCHI, KIYOTO
To: MITSUBISHI ELECTRIC CORPORATION
Reel/Frame 063255/0248 →
Continuity (2)
Continuation PCTJP2020045452 · Dec 7, 2020
Related Publication 20230262075A1 · Aug 17, 2023
References Cited (22)
US 20170061322A1 · Chari et al. · 2017 [cited by applicant]
US 20170345294A1 · Hirotsu · 2017 [cited by examiner]
US 20180115568A1 · Du · 2018 [cited by applicant]
US 20190034836A1 · Chari · 2019 [cited by examiner]
US 20190080089A1 · Chen · 2019 [cited by examiner]
US 20190294803A1 · Yamamoto · 2019 [cited by examiner]
US 20190384910A1 · Orihara et al. · 2019 [cited by applicant]
US 20210157909A1 · Yamamoto et al. · 2021 [cited by applicant]
US 20230247035A1 · Matsubayashi · 2023 [cited by examiner]
JP 2015114833A · 2015 [cited by applicant]
JP 201867304A · 2018 [cited by applicant]
JP 6548837B2 · 2019 [cited by applicant]
JP 2019185183A · 2019 [cited by applicant]
JP 6698956B2 · 2020 [cited by applicant]
WO WO2018159361A1 · 2018 [cited by applicant]
WO WO2019073557A1 · 2019 [cited by applicant]
Maryam Nezhadkamali, Android malware detection based on overlapping of static features, Oct. 26-27, 2017. [cited by examiner]
International Search Report (PCT/ISA/210) issued in PCT/JP2020/045452, dated on Mar. 2, 2021,. [cited by applicant]
Steve T.K. Jan et al., “Throwing Darts in the Dark? Detecting Bots with Limited Data using Neural Data Augmentation”, Security & Privacy 2020, (https://people.cs.vt.edu/vbimal/publications/syntheticdatasp20.pdf), 17 pag… [cited by applicant]
German Office Action for German Application No. 11 2020 007 653.9, dated Mar. 5, 2024, with partial translation. [cited by applicant]
Pham et al., “Generating Artificial Attack Data for Intrusion Detection Using Machine Learning”, Proceedings of the 5th Symposium on Information and Communication Technology, 2014, pp. 286-291. [cited by applicant]
Chinese Office Action and Search Report for Chinese Application No. 202080107438.3, dated Apr. 30, 2025, with English translation. [cited by applicant]