The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Dec. 24, 2019

Filed:

Jul. 25, 2016
Applicant:

Nippon Telegraph and Telephone Corporation, Chiyoda-ku, JP;

Inventors:

Yang Zhong, Musashino, JP;

Hiroshi Asakura, Musashino, JP;

Masaki Tanikawa, Musashino, JP;

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
G06F 12/14 (2006.01); H04L 29/06 (2006.01); G06F 21/55 (2013.01); H04L 12/26 (2006.01);
U.S. Cl.
CPC ...
H04L 63/1425 (2013.01); G06F 21/55 (2013.01); H04L 43/04 (2013.01); H04L 63/1416 (2013.01); H04L 63/1441 (2013.01);
Abstract

In order to detect an attack to a web application accurately by accurately correlating different types of events having occurred in the same server, an event acquiring unit acquires a log of events containing a HTTP request to a server, an event correlator creates a set of the request and events relevant to the request as an event block by using process IDs of processes having processed events contained in the log, and an attack detector contrasts the event block that is created from the log of events in which an attack is to be detected with an event block that is created from normal events to calculate a degree of similarity and, when the degree of similarity is equal to or lower than a threshold, detects the event block as an event block containing an event that is abnormal due to an attack.


Find Patent Forward Citations

Loading…