SIGNATURE GENERATING DEVICE, SIGNATURE GENERATING METHOD, AND NON-TRANSITORY COMPUTER-READABLE MEDIUM STORING PROGRAM

    公开(公告)号:US20200380128A1

    公开(公告)日:2020-12-03

    申请号:US16497124

    申请日:2017-12-20

    Inventor: Tatsuya ITO

    Abstract: A signature generating device (2) includes a collecting unit (11) configured to collect threat information, an extracting unit (21) configured to extract attack data from the threat information collected by the collecting unit (11), and a generating unit (31) configured to generate a signature on the basis of the attack data extracted by the extracting unit (21). When plural pieces of attack data having a common character string are extracted by the extracting unit (21), the generating unit (31) tentatively generates a signature including the common character string, evaluates whether a tentatively generated signature includes a character string used in non-attack data, and when the tentatively generated signature includes the character string used in the non-attack data, removes the character string from the tentatively generated signature to generate a signature.

    SIGNATURE GENERATION DEVICE, SIGNATURE GENERATION METHOD, RECORDING MEDIUM STORING SIGNATURE GENERATION PROGRAM, AND SOFTWARE DETERMINATION SYSTEM

    公开(公告)号:US20190163906A1

    公开(公告)日:2019-05-30

    申请号:US16320677

    申请日:2017-07-21

    Inventor: Tatsuya ITO

    Abstract: Provided is a signature generation device, etc., generating signature information with high accuracy. The signature generation device calculates hash values for at least a partial area in individual files; calculates a similarity degree between the calculated hash values and classifies the plurality of files into groups based on the calculated degree; specifies common strings among, at least, some of the files in strings included in files of a group, the strings being symbol strings or bit strings; and generates signature information being a criterion for determining whether or not at least a part of the common string in the specified common strings is included.

Patent Agency Ranking