-
公开(公告)号:US20230141747A1
公开(公告)日:2023-05-11
申请号:US18093631
申请日:2023-01-05
Inventor: Tatsumi OBA , Hiroyuki OKADA
CPC classification number: H04L63/1425 , H04L63/166 , H04L41/16
Abstract: This method includes: extracting, from communication in a network, a first communication triplet that is a 3-tuple including information indicating a source device, information indicating a destination device, and information indicating the type of communication performed between devices; determining whether the first communication triplet extracted corresponds to any of a plurality of second communication triplets stored in storage in advance as a whitelist and each being a 3-tuple including information indicating a source device, information indicating a destination device, and information indicating the type of communication; and estimating, as a score, a possibility that the first communication triplet emerges as the communication, by using a model that has been trained, when the first communication triplet does not correspond to any of the plurality of second communication triplets.
-
公开(公告)号:US20240430283A1
公开(公告)日:2024-12-26
申请号:US18596369
申请日:2024-03-05
Inventor: Hiroyuki OKADA , Tatsumi OBA
IPC: H04L9/40
Abstract: A communication analysis system includes: an information receiver that receives information indicating analysis target communication performed by a monitoring target; an information obtainer that obtains past communication information indicating communication by the monitoring target; a WL determiner that determines, using the obtained analysis target communication and the whitelist, that non-WL communication has been established in the analysis target communication; a similar terminal extractor that extracts one or more terminals similar to destination and source terminals included in a non-WL communication link determined; a primary similar communication link extractor that extracts a past communication link similar to the non-WL communication link as a primary similar communication link from the obtained past communication information using the extracted similar terminals; and a NW graph creator that creates a NW graph for analysis as graph information for analyzing the non-whitelist communication using the extracted primary similar communication link and the obtained past communication information.
-
公开(公告)号:US20240214809A1
公开(公告)日:2024-06-27
申请号:US18598799
申请日:2024-03-07
Inventor: Hiroyuki OKADA , Tatsumi OBA
Abstract: A communication analysis system includes: an information obtainer that obtains past communication information indicating communication performed by a monitoring target; a prediction target link extractor that extracts, based on the past communication information obtained, an unestablished communication link of communication that has not been established in the past communication information, the unestablished communication link being at least one communication link that is a prediction target; a link confidence level calculator that calculates a confidence level indicating the likelihood that the unestablished communication link extracted will be established as a normal communication link in the future; and a NW graph creator that creates a NW graph, in which the unestablished communication link and information regarding the unestablished communication link are mapped, as graph information for determining whether to add the communication link to a whitelist, using the unestablished communication link extracted, the confidence level calculated, and the past communication information obtained.
-
-