IP Library Granted Patent US 12,732,520
Granted Patent B2
US 12,732,520 · App. 18/839,744 · Granted Sep 8, 2026

Generation device, generation method, and generation program

Inventor: Nariyoshi Chida (Musashino, JP)
Assignee: NTT, Inc.
H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,732,520
App. No.
18/839,744
Granted
Sep 8, 2026
Kind
B2
Abstract

A generation device includes processing circuitry configured to extract log information in which a trace of intrusion remains from the log information construct graph structure data indicating an attack behavior order using time-series information included in the log information and generate a signature indicating a trace of an attack based on graph structure data constructed.

Claims (29)

1 . A generation device comprising:

processing circuitry configured to:

extract event data in which a trace of intrusion remains from log information;

construct, using time-series information included in the event data, graph structure data indicating an attack behavior order that is an order of events of an attack included in the event data; and

generate a signature indicating a trace of the attack based on the constructed graph structure data indicating the attack behavior order.

2 . The generation device according to claim 1 , wherein the processing circuitry is further configured to:

search for a character string corresponding to the trace of the intrusion in the event data, and

extract the event data including the character string corresponding to the trace of the intrusion.

3 . The generation device according to claim 1 , wherein the processing circuitry is further configured to construct a nondeterministic finite automaton (NFA) as the graph structure data.

4 . The generation device according to claim 3 , wherein the processing circuitry is further configured to generate the signature by converting the constructed NFA by an algorithm for converting the NFA into a regular expression.

5 . A generation method executed by a generation device, the generation method comprising:

extracting event data in which a trace of intrusion remains from log information;

constructing, using time-series information included in the event data, graph structure data indicating an attack behavior order that is an order of events of an attack included in the event data; and

generating a signature indicating a trace of the attack based on the constructed graph structure data indicating the attack behavior order.

6 . A non-transitory computer-readable recording medium storing therein a generation program for causing a computer to execute:

extracting event data in which a trace of intrusion remains from log information;

constructing, using time-series information included in the event data, graph structure data indicating an attack behavior order that is an order of events of an attack included in the event data; and

generating a signature indicating a trace of the attack based on the constructed graph structure data indicating the attack behavior order.

7 . The generation device according to claim 1 , wherein the processing circuitry is configured to add a vertex corresponding to the trace of intrusion to the graph structure data.

8 . The generation device according to claim 7 , wherein the processing circuitry is configured to add the vertex corresponding to the trace of intrusion to the graph structure data if there is no vertex corresponding to the trace in the graph structure data.

9 . The generation device according to claim 1 , wherein the processing circuitry is configured to add an epsilon transition to a vertex corresponding to the trace of intrusion.

10 . The generation device according to claim 9 , wherein the processing circuitry is configured to add the epsilon transition to the vertex corresponding to the trace if the vertex corresponding to the trace of intrusion already exists in the graph structure data.

11 . The generation device according to claim 1 , wherein the processing circuitry is configured to generate the signature by replacing a label of the constructed graph structure data with a terminal symbol.

12 . The generation device according to claim 11 , wherein the processing circuitry is configured to add a predetermined arrow symbol before the terminal symbol of the signature.

13 . The generation device according to claim 1 , wherein the signature is described in an Event Log Language (ELL).

14 . The generation device according to claim 1 , wherein the processing circuitry is configured to collate the log information and an Indicator of Compromise (IoC).

15 . The generation device according to claim 4 , wherein the processing circuitry is configured to apply a state elimination method to convert the NFA into the regular expression.

16 . The generation device according to claim 1 , wherein the event data extracted from the log information includes a process name and a file name.

17 . The generation device according to claim 1 , wherein the constructed graph structure data represents an appearance positional relationship of the trace of intrusion.

Assignments (2)
CHANGE OF NAME Recorded Aug 20, 2025
From: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
To: NTT, INC.
Reel/Frame 072556/0180 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 20, 2024
From: CHIDA, NARIYOSHI
To: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
Reel/Frame 068341/0549 →
Continuity (1)
Related Publication 20250175481A1 · May 29, 2025
References Cited (20)
US 9398028B1 · Karandikar · 2016 [cited by examiner]
US 10243982B2 · Zhong · 2019 [cited by examiner]
US 10721244B2 · Chiba · 2020 [cited by examiner]
US 11677760B2 · Shahbaz · 2023 [cited by examiner]
US 20070112512A1 · McConnell · 2007 [cited by examiner]
US 20080034427A1 · Cadambi · 2008 [cited by examiner]
US 20120331554A1 · Goyal · 2012 [cited by examiner]
US 20170054742A1 · Matsumoto · 2017 [cited by examiner]
US 20180091528A1 · Shahbaz · 2018 [cited by examiner]
US 20200342095A1 · Ijiro · 2020 [cited by examiner]
US 20210021614A1 · Shahbaz · 2021 [cited by examiner]
US 20250227117A1 · Shahbaz · 2025 [cited by examiner]
Christian Kreibich, “Honeycomb—Creating Intrusion Detection Signatures Using Honeypots” ACM SIGCOMM Computer Communications Review, Jan. 2004. [cited by examiner]
Md Nahid Hossain, “Sleuth: Real-time Attack Scenario Reconstruction from COTS Audit Data” 2017. [cited by examiner]
Xueyuan Han, “Provenance-based Intrusion Detection: Opportunities and Challenges” 2018. [cited by examiner]
Kurogome et al., “Eiger: Automated IOC Generation for Accurate and Interpretable Endpoint Malware Detection”, ACSAC 2019, Dec. 9-13, 2019, pp. 687-701. [cited by applicant]
Liao et al., “Acing the IOC Game: Toward Automatic Discovery and Analysis of Open-Source Cyber Threat Intelligence”, CCS 2016, Oct. 24-28, 2016, pp. 755-766. [cited by applicant]
Husari et al., “TTPDrill: Automatic and Accurate Extraction of Threat Actions from Unstructured Text of CTI Sources”, ACSAC 2017, pp. 103-115. [cited by applicant]
Satvat et al., “Extractor: Extracting Attack Behavior from Threat Reports”, arXiv:2104.08618v1 [cs.CR], Apr. 17, 2021, 18 pages. [cited by applicant]
Gao et al., “Enabling Efficient Cyber Threat Hunting With Cyber Threat Intelligence”, arXiv:2010.13637v2 [cs.CR], Feb. 25, 2021, 12 pages. [cited by applicant]