Analysis device, analysis method, and analysis program

The analysis device identifies and extracts C2 servers by analyzing communication flow information to detect bots involved in DDoS attacks, enhancing the accuracy of attack detection.

JP7796921B1Active Publication Date: 2026-01-09NTT DOCOMO BUSINESS INC
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
JP2025037542
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2025-03-10
Publication Date
2026-01-09
Estimated Expiration
2045-03-10

AI Technical Summary

Technical Problem

Conventional techniques fail to accurately identify C2 servers that have participated in attacks.

Method used

An analysis device that identifies bots performing DDoS attacks and extracts servers with which a predetermined percentage of these bots have communicated within a specific communication volume range, using communication flow information.

Benefits of technology

Enables detection of C2 servers that have actually participated in DDoS attacks, facilitating effective countermeasures against such attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007796921000001_ABST
    Figure 0007796921000001_ABST
Patent Text Reader

Abstract

Detect the C2 server that actually participated in the attack. In the analysis device, an identification unit identifies bots that perform a distributed denial-of-service attack from communication flow information. An extraction unit extracts servers with which a predetermined percentage or more of the identified bots have performed communication within a predetermined range of communication volume, based on past communications of the distributed denial-of-service attack.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an analysis device, an analysis method, and an analysis program. [Background technology]

[0002] In recent years, the existence of Command and Control (C2) servers has become known (see Non-Patent Document 1). A C2 server is a remote server used by malware and botnets to communicate with external attackers. Attackers can control malware via the C2 server and carry out various attack activities, such as stealing information, collecting data, and distributing additional malware. Therefore, detecting C2 servers is an urgent task in attack countermeasures. [Prior art documents] [Non-patent literature]

[0003] [Non-Patent Document 1] “[Threat Analysis Report] Sliver C2 - An attack framework exploited by many threat actors,” [online], April 2023, Cyber ​​Season, [Retrieved February 20, 2025], Internet<URL:https: / / www.cybereason.co.jp / blog / threat-analysis-report / 10261 / > Summary of the Invention [Problem to be solved by the invention]

[0004] However, conventional techniques have the problem that it is unclear whether a detected C2 server actually participated in an attack.

[0005] The present invention has been made in view of the above, and aims to detect C2 servers that have actually participated in attacks. [Means for solving the problem]

[0006] In order to solve the above-mentioned problems and achieve the objectives, the analysis device of the present invention is characterized by having an identification unit that identifies bots that carry out distributed denial of service attacks from communication flow information, and an extraction unit that extracts servers with which a predetermined percentage or more of the identified bots have communicated within a predetermined range of communication volume from past communications of the distributed denial of service attacks. [Effects of the Invention]

[0007] According to the present invention, it is possible to detect the C2 server that actually participated in the attack. [Brief explanation of the drawings]

[0008] [Figure 1] FIG. 1 is a schematic diagram illustrating the general configuration of an analysis device. [Figure 2] FIG. 2 is a diagram for explaining the processing of the analysis device. [Figure 3] FIG. 3 is a diagram for explaining the processing of the analysis device. [Figure 4] FIG. 4 is a flowchart illustrating an example of the analysis processing procedure. [Figure 5] FIG. 5 is a diagram illustrating a computer that executes an analysis program. DETAILED DESCRIPTION OF THE INVENTION

[0009] Hereinafter, an embodiment of the present invention will be described in detail with reference to the drawings. Note that the present invention is not limited to this embodiment. In addition, in the description of the drawings, the same parts are designated by the same reference numerals.

[0010] [Analysis equipment configuration] Fig. 1 is a schematic diagram illustrating the general configuration of an analysis device. Fig. 2 and Fig. 3 are diagrams for explaining the processing of the analysis device. First, as illustrated in Fig. 1, an analysis device 10 is realized by a general-purpose computer such as a personal computer, and includes an input unit 11, an output unit 12, a communication control unit 13, a storage unit 14, and a control unit 15.

[0011] The input unit 11 is realized using input devices such as a keyboard and a mouse, and inputs various instruction information such as starting processing to the control unit 15 in response to input operations by an operator. The output unit 12 is realized by a display device such as a liquid crystal display, a printing device such as a printer, etc.

[0012] The communication control unit 13 is realized by a NIC (Network Interface Card) or the like, and controls communication between an external device via a network and the control unit 15. For example, the communication control unit 13 controls communication between the control unit 15 and a management device or the like that manages communication flow information to be processed in the analysis process described later.

[0013] The storage unit 14 is realized by a semiconductor memory element such as a RAM (Random Access Memory) or a flash memory, or a storage device such as a hard disk or an optical disk. The storage unit 14 stores in advance the processing programs that operate the analysis device 10 and data used during the execution of the processing programs, or temporarily stores them each time processing is performed. The storage unit 14 may be configured to communicate with the control unit 15 via the communication control unit 13.

[0014] In this embodiment, the storage unit 14 stores, for example, communication flow information used in the analysis process described below, analysis process results, and the like.

[0015] The control unit 15 is realized using a CPU (Central Processing Unit) or the like, and executes a processing program stored in a memory. As a result, the control unit 15 functions as an acquisition unit 15a, an identification unit 15b, an extraction unit 15c, and an estimation unit 15d, as exemplified in FIG. 1. Note that each or some of these functional units may be implemented in different hardware. For example, the acquisition unit 15a may be implemented in a device separate from the other functional units. The control unit 15 may also include other functional units.

[0016] The acquiring unit 15a acquires communication flow information. For example, the acquiring unit 15a acquires current and past communication flow information to be subjected to analysis processing (described later) via the input unit 11 or via the communication control unit 13 from a management device or the like that collects and manages communication flow information.

[0017] The identification unit 15b identifies bots that perform a distributed denial of service attack (DDoS, hereinafter referred to as a DDoS attack) from the communication flow information. For example, as illustrated in FIG. 2, the identification unit 15b observes current communication flow information and identifies multiple bots that have participated in the DDoS attack.

[0018] The extraction unit 15c extracts servers with which a predetermined percentage or more of the identified bots performed communication within a predetermined range of communication volume from past communications of the DDoS attack. Specifically, as illustrated in Fig. 3, the extraction unit 15c extracts servers that meet the above conditions from communications within a predetermined time immediately before the DDoS attack. First, the extraction unit 15c observes communications performed by the identified bots, targeting communications within, for example, three hours immediately before the occurrence of the DDoS attack.

[0019] Then, the extraction unit 15c identifies a server with which a predetermined percentage or more of the bots being observed, such as more than half of the bots, are communicating. This is because it is expected that the C2 server will instruct the bots "where and what type of attack" immediately before a DDoS attack.

[0020] Furthermore, the extraction unit 15c extracts servers that perform communication with a predetermined amount of traffic from among the servers. Specifically, the extraction unit 15c extracts servers that perform communication with a predetermined amount of traffic, that is, 100 bytes or more but less than 1000 bytes per packet. This means that communication between the C2 server and a bot is small in volume, while the scan response is very small in volume, for example, 40 bytes or less. Therefore, communication of 100 bytes or more is estimated to be communication between the C2 server and a bot.

[0021] On the other hand, the volume of communication between the game server, advertisement server, etc. is larger than the volume of communication between the C2 server and the bot. Therefore, the predetermined range of communication volume between the C2 server and the bot is set to, for example, less than 1000 bytes.

[0022] Furthermore, the extraction unit 15c may add a condition that the port number is not a port number used for communication with a game server, etc. For example, the extraction unit 15c may add a condition that the port number is not 25565 / TCP in Minecraft, 2593 / TCP in Ultima Online, or the like, to the above conditions.

[0023] The extraction unit 15c may extract a server that satisfies the above conditions from communications going back a predetermined number of times at a predetermined time interval before the DDoS attack. This is because it is expected that the C2 server will periodically communicate with the bot, for example, 100 times every 60 seconds, to issue a command for the DDoS attack.

[0024] The estimation unit 15d estimates the extracted server as a malicious server, i.e., a C2 server, thereby making it possible to identify a server that is estimated to be a C2 server that actually participated in a DDoS attack.

[0025] The estimation unit 15d may store the estimated C2 server in the storage unit 14. At that time, the estimation unit 15d may assign a label associated with the characteristics of the DDoS attack. This makes it possible to create a database that is effective in countering DDoS attacks.

[0026] Furthermore, if it is certain that the infected computer is a C2 server, the estimation unit 15d can identify the infected computer. Furthermore, the estimation unit 15d may instruct the network devices connected to the C2 server or the infected computer to shut them down. Alternatively, the estimation unit 15d may notify the owner of the bot. This makes it possible to prevent future incidents.

[0027] [Analysis processing procedure] Next, an example of analysis processing by the analysis device 10 according to this embodiment will be described with reference to Fig. 4. Fig. 4 is a flowchart illustrating an example of the analysis processing procedure. The flowchart in Fig. 4 starts, for example, when an input is made to instruct the start of the analysis processing.

[0028] First, the identifying unit 15b identifies bots that perform a DDoS attack from the communication flow information (step S1). For example, the identifying unit 15b observes the current communication flow information and identifies multiple bots that have participated in the DDoS attack.

[0029] Next, the extraction unit 15c extracts servers with which a predetermined percentage or more of the identified bots have performed communication within a predetermined range of communication volume from past communications of the DDoS attack (step S2). Specifically, the extraction unit 15c extracts servers with which communication with a predetermined range of communication volume has performed communication with 100 bytes or more and less than 1000 bytes per packet.

[0030] The extraction unit 15c extracts servers that meet the above conditions from communications within a predetermined time period immediately before the DDoS attack, or from communications going back a predetermined number of times at predetermined time intervals before the DDoS attack.

[0031] Then, the estimation unit 15d estimates that the extracted server is a malicious C2 server (step S3), thereby completing the series of analysis processes.

[0032] [effect] As described above, in the analysis device 10 of the above embodiment, the identification unit 15b identifies bots that carry out DDoS attacks from communication flow information. The extraction unit 15c extracts servers with which a predetermined percentage or more of the identified bots have communicated within a predetermined range of communication volume, based on past communications of the DDoS attacks.

[0033] Specifically, the extraction unit 15c extracts servers that have performed communication with a predetermined communication volume of 100 bytes or more and less than 1000 bytes per packet, which enables the analysis device 10 to detect C2 servers that are presumed to have actually participated in a DDoS attack.

[0034] The extraction unit 15c may also extract the above-mentioned servers from past communications within a predetermined time period immediately prior to the DDoS attack. Alternatively, the extraction unit 15c may extract the above-mentioned servers from past communications going back a predetermined number of times at a predetermined interval before the DDoS attack. This allows the analysis device 10 to more accurately estimate the C2 servers that actually participated in the DDoS attack.

[0035] [System configuration, etc.] The components of each device shown in the figure are conceptual functional units and do not necessarily have to be physically configured as shown. In other words, the specific form of distribution and integration of each device is not limited to that shown, and all or part of each device can be functionally or physically distributed and integrated in any unit depending on various loads and usage conditions. Furthermore, all or any part of the processing functions performed by each device can be realized by a CPU or GPU (Graphics Processing Unit) and a program analyzed and executed by the CPU or GPU, or can be realized as hardware using wired logic.

[0036] Furthermore, among the processes described in this embodiment, all or part of the processes described as being performed automatically can be performed manually, or all or part of the processes described as being performed manually can be performed automatically using a known method.In addition, the information including the processing procedures, control procedures, specific names, various data and parameters shown in the above documents and drawings can be changed as desired unless otherwise specified.

[0037] [program] It is also possible to create a program in which the processing performed by the analysis device described in the above embodiment is written in a language executable by a computer. For example, it is also possible to create a program in which the processing performed by the analysis device 10 according to the embodiment is written in a language executable by a computer. In this case, the same effects as those of the above embodiment can be obtained by having a computer execute the program. Furthermore, such a program may be recorded on a computer-readable recording medium, and the program recorded on the recording medium may be read and executed by a computer to realize processing similar to that of the above embodiment.

[0038] 5 is a diagram showing an example of a computer that executes an analysis program. The computer 1000 includes, for example, a memory 1010, a CPU 1020, a hard disk drive interface 1030, a disk drive interface 1040, a serial port interface 1050, a video adapter 1060, and a network interface 1070. These components are connected by a bus 1080.

[0039] The memory 1010 includes a ROM (Read Only Memory) 1011 and a RAM 1012. The ROM 1011 stores, for example, a boot program such as a BIOS (Basic Input Output System). The hard disk drive interface 1030 is connected to a hard disk drive 1031. The disk drive interface 1040 is connected to a disk drive 1041. A removable storage medium such as a magnetic disk or optical disk is inserted into the disk drive 1041. The serial port interface 1050 is connected to, for example, a mouse 1051 and a keyboard 1052. The video adapter 1060 is connected to, for example, a display 1061.

[0040] Here, the hard disk drive 1031 stores, for example, an OS (Operating System) 1091, application programs 1092, program modules 1093, and program data 1094. The various pieces of information described in the above embodiments are stored in the hard disk drive 1031 or memory 1010, for example.

[0041] The analysis program is stored in the hard disk drive 1031 as, for example, a program module 1093 in which instructions to be executed by the computer 1000 are written. Specifically, the program module 1093 in which each process executed by the analysis device 10 described in the above embodiment is written is stored in the hard disk drive 1031.

[0042] Furthermore, data used for information processing by the analysis program is stored as program data 1094, for example, in the hard disk drive 1031. Then, the CPU 1020 reads the program module 1093 and the program data 1094 stored in the hard disk drive 1031 into the RAM 1012 as necessary, and executes each of the above-described procedures.

[0043] The program module 1093 and program data 1094 related to the analysis program are not limited to being stored in the hard disk drive 1031, but may be stored in a removable storage medium and read by the CPU 1020 via the disk drive 1041, etc. Alternatively, the program module 1093 and program data 1094 related to the analysis program may be stored in another computer connected via a network such as a LAN (Local Area Network) or a WAN (Wide Area Network), and read by the CPU 1020 via the network interface 1070.

[0044] Although the present invention has been described above as an embodiment, the present invention is not limited to the description and drawings that form part of the disclosure of the present invention. In other words, other embodiments, examples, and operational techniques that can be made by those skilled in the art based on the present invention are all included in the scope of the present invention. [Explanation of symbols]

[0045] 10 Analysis device 11 Input section 12 Output section 13 Communication control section 14 Storage section 15 Control Unit 15a Acquisition part 15b Specific part 15c Extraction part 15d Estimation part

Claims

1. an identification unit that identifies a bot that performs a distributed denial of service attack from communication flow information; an extraction unit that extracts servers that have communicated with a predetermined percentage or more of the identified bots within a predetermined range of communication volume from among servers that have communicated within a predetermined time period immediately before the distributed denial of service attack; An analysis device comprising:

2. 2. The analysis device according to claim 1, wherein the extraction unit extracts servers that have performed communication with a volume of communication per packet of 100 bytes or more but less than 1000 bytes as the predetermined range of communication volume.

3. The analysis device according to claim 1 , wherein the extraction unit extracts the server from communications within the immediately preceding predetermined time period going back a predetermined number of times at a predetermined interval before the distributed denial of service attack.

4. An analysis method executed by an analysis device, an identifying step of identifying a bot that performs a distributed denial of service attack from the communication flow information; an extraction step of extracting servers that have communicated with a predetermined percentage or more of the identified bots within a predetermined range of communication volume from among the servers that have communicated within a predetermined time period immediately before the distributed denial of service attack; An analysis method comprising:

5. an identifying step of identifying a bot that performs a distributed denial of service attack from communication flow information; an extraction step of extracting servers that have communicated with a predetermined percentage or more of the identified bots within a predetermined range of communication volume from among the servers that have communicated within a predetermined time period immediately before the distributed denial of service attack; An analysis program for running the above on a computer.

Citation Information

Patent Citations

  • Flow analysis device, traffic analysis system and flow analysis method

    JP2018037961A

  • Detection apparatus, detection method, and detection program

    JP2018169897A

  • Threat information extraction device and threat information extraction system

    JP2019145879A

  • Detection device, detection method, and detection program

    JP7215571B2

  • Network threat validation and monitoring

    US11038906B1