To provide a means of analyzing abnormal traffic with a small amount of preknowledge.
A traffic acquiring means 21 acquires traffic. A traffic pattern and communication device correspondence list generation section 25 classify the acquired traffic according to the communication device having sent the traffic and the traffic pattern. A temporary abnormal communication device judgement section 26 extracts a communication device having sent traffic corresponding to a predetermined specific traffic pattern. A traffic pattern score calculating means 27 calculates the score of the traffic pattern based upon the rate of communication devices having sent the traffic pattern among communication devices that the temporary abnormal communication device judgement section 26 extracts and the rate of communication devices having sent the traffic pattern among unextracted communication devices. A communication device score calculating means 28 calculates the score of the communication device based upon the score of the traffic pattern of the traffic that the communication device has sent.
COPYRIGHT: (C)2007,JPO&INPIT
Go Toyono
Hirotaka Matsuoka
Masafumi Higuchi
JP2006054652A | ||||
JP2003273929A |
Keiichi Chino