Detection device and detection method

The detection device effectively identifies command tower servers by analyzing network data and communication patterns, addressing the limitations of existing methods in detecting DDoS attack instructors and enabling effective countermeasures.

JP2025089673APending Publication Date: 2025-06-16NIPPON TELEGRAPH & TELEPHONE CORP
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2023204441
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-12-04
Publication Date
2025-06-16

AI Technical Summary

Technical Problem

Existing methods fail to effectively detect the command tower server that instructs DDoS attacks due to difficulties in obtaining malware specimens and extracting relevant information from large datasets.

Method used

A detection device comprising a DDoS attack detection unit, a bot detection unit, and a command tower server detection unit, which analyzes network data to identify bots participating in DDoS attacks and subsequently detects the command tower server by analyzing communication patterns between bots and potential command servers.

Benefits of technology

Enables accurate detection of the command tower server that instructs DDoS attacks, allowing for targeted countermeasures such as blocking communication with the command tower server, thereby mitigating DDoS attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025089673000001_ABST
    Figure 2025089673000001_ABST
Patent Text Reader

Abstract

To appropriately detect a command and control server which delivers a DDoS attack, from information about the DDoS attack.SOLUTION: A detection device 100 comprises a DDoS attack detection unit 121, a bot detection unit 122 and a command and control server detection unit 123. The DDoS attack detection unit 121 detects a DDoS attack, based on network data. The bot detection unit 122 detects a bot which is participating with the DDoS attack, from information about the plurality of DDoS attacks detected by the DDoS attack detection unit 121. The command and control server detection unit 123 detects the command and control server which delivers the DDoS attack, from the information about the bot detected by the bot detection unit 122.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a detection device and a detection method.

Background Art

[0002] In recent years, in the Internet, DDoS (Distributed Denial of Service) attacks that interfere with Internet services due to a large amount of traffic transmission have become a problem. A DDoS attack is an attack in which an attacker gives an attack instruction to a large number of bots controlled by hijacking or the like on the Internet, and the attack is transmitted all at once from the bots, thus driving the Internet service into interference.

[0003] DDoS attacks occur frequently, and if individual attacks are detected and defended against, they do not scale to a large number of attacks. Also, when the attack becomes large-scale, it is assumed that it becomes difficult to maintain as a network service. Frequent DDoS attacks can also be considered as a DDoS attack group, and there is a possibility that they are being instructed from the same command tower server. Therefore, there is a possibility that the DDoS attack group can be prevented by identifying the command tower server and blocking the communication of the command tower server or taking down the command tower server.

[0004] Here, as a method for detecting the command tower server, there are known techniques for detecting the command tower server related to bots that perform network scans (see, for example, Patent Document 1), techniques for detecting the command tower server using machine learning from network traffic data (see, for example, Non-Patent Document 1), and methods for statically analyzing and dynamically analyzing malware.

Prior Art Documents

Patent Documents

[0005]

Patent Document 1

Non-Patent Documents

[0006] [Non-Patent Document 1] B. Hu, K. Kamiya, K. Takahashi and A. Nakao, "Piper: A Unified Machine Learning Pipeline for Internet-scale Traffic Analysis," GLOBECOM 2020 ― 2020 IEEE Global Communications Conference, Taipei, Taiwan, 2020, pp. 1-6, doi: 10.1109 / GLOBECOM42002.2020.9322531. [Summary of the Invention] [Problems to be Solved by the Invention]

[0007] However, in the above prior art, it is not possible to appropriately detect the command tower server that instructs the DDoS attack from the information related to the DDoS attack. For example, in the prior art, since it is difficult to obtain malware specimens related to a DDoS attack group, there are cases where sufficient analysis cannot be performed and the command tower server cannot be appropriately detected. Also, it is not easy to extract only the command tower server that actually instructs the DDoS attack from the analysis results of a large number of malware. [Means for Solving the Problems]

[0008] In order to solve the above-described problems and achieve the object, the detection device of the present invention includes a DDoS attack detection unit that detects a DDoS attack based on network data, a bot detection unit that detects bots participating in the DDoS attack from information related to a plurality of DDoS attacks detected by the DDoS attack detection unit, and a command tower server detection unit that detects a command tower server that instructs the DDoS attack from information related to the bots detected by the bot detection unit. [Effects of the Invention]

[0009] According to the present invention, there is an effect that a command tower server instructing a DDoS attack can be appropriately detected from information related to the DDoS attack.

Brief Description of the Drawings

[0010]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Embodiments for Carrying Out the Invention

[0011] Hereinafter, embodiments of the detection device and detection method according to the present application will be described in detail with reference to the drawings. Note that the detection device and detection method according to the present application are not limited by this embodiment.

[0012] 〔1. Overall Configuration〕 First, the overall configuration of the system including the detection device 100 according to this embodiment will be described. FIG. 1 is a diagram showing a system including the detection device according to the embodiment. The system shown in FIG. 1 includes a detection device 100, a device "Upper-C2" possessed by an attacker of a DDoS attack, two command tower servers "C2", a number of bots "bot", and two devices "Victim" possessed by victims of DDoS attacks, which are communicably connected via a network (not shown) such as the Internet.

[0013] Each device shown in FIG. 1 is an information processing terminal capable of transmitting and receiving information to and from each other via a network, and is realized by, for example, a computer. The command tower server "C2" is operated by the device "Upper-C2" possessed by the attacker, and a plurality of bots "bot" that have received an attack command from the command tower server transmit a large amount of data to the device "Victim" possessed by the victim, thereby performing a DDoS attack.

[0014] The detection device 100 detects a DDoS attack based on network data, and detects bots participating in the DDoS attack from information on the detected plurality of DDoS attacks. Then, the detection device 100 detects the command tower server that has instructed the DDoS attack from the information on the detected bots.

[0015] First, the detection device 100 collects network data such as the traffic volume of data transmitted to the device "Victim" possessed by the victim at regular intervals, and the IP address of the transmission source. When the traffic volume calculated for each IP address of the transmission source exceeds a threshold value, the detection device 100 determines that a DDoS attack is being performed, thereby detecting the DDoS attack.

[0016] Next, the detection device 100 extracts, for example, DDoS attacks with high importance from the detection results of a plurality of DDoS attacks based on information such as the attack type and the traffic volume of the attacks, and for each source IP address in the extracted DDoS attacks, extracts statistical values of the number of attack IDs and traffic volume described later. Then, the detection device 100 detects, for example, a device having a source IP address whose statistical value of the number of attack IDs or traffic volume exceeds a threshold as a bot.

[0017] Subsequently, the detection device 100 generates, for example, a graph structure described later based on network data starting from the information about the detected bot, and detects a device that is a one-hop communication destination of the bot and has a high communication ratio with the bot and a low communication ratio with other devices as a command tower server.

[0018] Thereby, the detection device 100 can detect the bot that has carried out the DDoS attack and the command tower server that has issued an attack instruction to the bot from the network data when the DDoS attack is actually carried out, so that the command tower server that has instructed the DDoS attack can be appropriately detected from the information related to the DDoS attack.

[0019] 〔2. Configuration of Detection Device 100〕 Next, with reference to FIG. 2, the configuration of the detection device 100 shown in FIG. 1 will be described. FIG. 2 is a block diagram showing a configuration example of the detection device according to the embodiment. The detection device 100 includes a communication unit 110, a control unit 120, and a storage unit 130, and is communicably connected to devices related to DDoS attacks via the network N.

[0020] The communication unit 110 is realized by, for example, a NIC (Network Interface Card) or the like. The communication unit 110 is connected to the network N and mediates the acquisition of network data such as the transmission and reception history of data related to DDoS attacks and the source IP address.

[0021] The storage unit 130 is realized by a storage device such as a RAM (Random Access Memory) or a hard disk, for example. The storage unit 130 stores data and programs necessary for various processes by the control unit 120. The storage unit 130 has, for example, a network data storage unit 131, a DDoS attack-related data storage unit 132, and a bot-related data storage unit 133.

[0022] The network data storage unit 131 stores network data which is information extracted from packet information collected from the network at a certain time. Here, referring to FIG. 3, the data stored in the network data storage unit 131 will be described. FIG. 3 is a diagram showing an example of data stored in the detection device according to the embodiment. The network data storage unit 131 shown in the example of FIG. 3 is composed of items such as "time", "source IP address", "protocol", "source port number", "destination port number", "number of bytes", and "number of packets".

[0023] Note that the network data storage unit 131 minimally includes information related to the items shown in FIG. 3, and may store information other than the said items. Also, in a large-scale network such as an ISP, only some network data may be collected by sampling and the payload may not be acquired.

[0024] The DDoS attack-related data storage unit 132 stores data of the detection results of DDoS attacks detected by the DDoS attack detection unit 121 described later. Here, referring to FIG. 4, the data stored in the DDoS attack-related data storage unit 132 will be described. FIG. 4 is a diagram showing an example of data stored in the detection device according to the embodiment. The DDoS attack-related data storage unit 132 shown in the example of FIG. 4 is composed of items such as "attack ID", "detection time", "DDoS source IP address group", "attack start time", "attack end time", "attack type", "maximum traffic volume (bytes)", and "maximum traffic volume (packets)".

[0025] The "Attack ID" stores the number assigned to each detected DDoS attack. The "Victim IP Address" stores, for example, the single IP address (IPv4, IPv6, etc.) of the victim targeted by the DDoS attack, or in the case of a carpet bombing type attack, the network range. The "DDoS Source IP Address Group" stores all the source IP addresses from which attack communications to the victim IP address were observed. For example, if attacks were observed from 1000 sources, it stores 1000 IP addresses. The "Attack Type" stores the types of DDoS attack types such as TCP SYN, HTTP, ICMP, etc.

[0026] Note that in the example of FIG. 4, the DDoS attack-related data storage unit 132 stores only the maximum value of the traffic volume of the corresponding DDoS attack as the "maximum traffic volume", but it is not limited to this. For example, it can also store the traffic volume for each time. Further, the DDoS attack-related data storage unit 132 minimally includes information regarding the items shown in FIG. 4, and may store information other than these items.

[0027] The bot-related data storage unit 133 stores data regarding bots detected by the bot detection unit 122 described later. Here, referring to FIG. 5, the data stored in the bot-related data storage unit 133 will be described. FIG. 5 is a diagram showing an example of data stored in the detection device according to the embodiment. The bot-related data storage unit 133 shown in the example of FIG. 5 is composed of items such as "bot IP address", "related DDoS attack ID", "First_Seen", "Last_Seen", "maximum traffic volume (bytes)", and "maximum traffic volume (packets)".

[0028] The "related DDoS attack ID" stores the attack ID of the DDoS attack corresponding to the bot IP address. "First_Seen" and "Last_Seen" store the date and time when the DDoS attack by the corresponding bot was first observed and the date and time when it was last observed.

[0029] Note that in the example of FIG. 5, the bot-related data storage unit 133 stores only the maximum value of the traffic volume transmitted by the corresponding bot as the "maximum traffic volume", but it is not limited to this. For example, statistical information on the traffic volume over a certain period can also be stored as appropriate. Further, the bot-related data storage unit 133 minimally includes information related to the items shown in FIG. 5, and may store information other than these items.

[0030] Returning to the description of FIG. 2. The control unit 120 is realized by various programs stored in the internal storage device of the apparatus being executed with the RAM as the working area by a CPU (Central Processing Unit), an MPU (Micro Processing Unit), or the like. Further, the control unit 120 is realized by an integrated circuit such as an ASIC (Application Specific Integrated Circuit) or an FPGA (Field Programmable Gate Array). The control unit 120 includes a DDoS attack detection unit 121, a bot detection unit 122, and a command tower server detection unit 123, and optionally includes a command tower server determination unit 124.

[0031] The DDoS attack detection unit 121 detects a DDoS attack based on network data. For example, the DDoS attack detection unit 121 refers to the information stored in the network data storage unit 131, calculates the traffic volume for each destination address and each destination network for each attack type of the DDoS attack for the network data over a certain period (Window), and detects it as a DDoS attack when the calculated traffic volume exceeds a preset threshold.

[0032] Then, the DDoS attack detection unit 121 determines whether the detected DDoS attack is a newly started one, a continuation from the previous Window, or has ended. For the ended DDoS attack, it extracts the traffic volume for each time series, the source addresses participating in the DDoS attack, the traffic volume for each source address, etc., and stores them in the DDoS attack-related data storage unit 132.

[0033] Note that the DDoS attack detection unit 121 can determine the attack type of the DDoS attack from the content of the packets of the network data to be detected by referring to, for example, the correspondence relationship between the attack type of the DDoS attack stored in advance and the content of the packets.

[0034] The bot detection unit 122 detects bots participating in the DDoS attack from the information regarding a plurality of DDoS attacks detected by the DDoS attack detection unit 121. For example, the bot detection unit 122 extracts, as bot candidates, the source addresses whose participation ratio in the DDoS attack is higher than a predetermined threshold from the information regarding a plurality of DDoS attacks, and detects the bots participating in the DDoS attack based on the communication history of the bot candidates.

[0035] First, the bot detection unit 122, for example, refers to the information stored in the DDoS attack-related data storage unit 132, and determines, as highly important DDoS attacks, the DDoS attacks that exceed a preset specific attack type or traffic volume threshold among the detected plurality of DDoS attacks.

[0036] Subsequently, the bot detection unit 122, for example, extracts the attack ID and the statistical value of the traffic volume for each source address for the highly important DDoS attacks, and extracts the source addresses whose attack ID count and traffic volume statistical value exceed the preset threshold as bot candidates with a high participation ratio in the DDoS attack.

[0037] Then, the bot detection unit 122 refers to, for example, the information stored in the network data storage unit 131, and detects, as bots, those that are likely to be bots from the activity content other than DDoS attacks obtained from the network data of bot candidates, and stores them in the bot-related data storage unit 133 together with information such as the ID of the related DDoS attack and the maximum traffic volume.

[0038] Here, activities that are likely to be bots are characteristic activities found in the communication history of bots, such as a high proportion of network scans being performed or a low proportion of communication with normal hosts. The bot detection unit 122 can detect bots by determining whether the content of the communication history of bot candidates corresponds to the aforementioned activities.

[0039] Also, the command tower server detection unit 123 detects the command tower server that instructs the DDoS attack from the information about the bots detected by the bot detection unit 122. For example, the command tower server detection unit 123 extracts the host that multiple bots communicate with in common as a command tower server candidate, and from the command tower server candidate, determines whether there is two-way communication between the bot and the command tower server candidate, whether the command tower server candidate is not the target of the DDoS attack, and whether the communication between the command tower server candidate and hosts other than the bot is less than the communication between the command tower server and the bot. It makes one or more of these determinations and detects the command tower server according to the determination result.

[0040] The command tower server detection unit 123 refers to, for example, the information stored in the network data storage unit 131 and the information stored in the bot-related data storage unit 133, and generates a graph structure starting from the bots from the communication history of the bots. Here, with reference to FIG. 6, the graph structure generated by the command tower server detection unit 123 will be described. FIG. 6 is a diagram showing a specific example of the graph structure generated by the command tower server detection unit according to the embodiment.

[0041] The graph structure shown in FIG. 6 is generated by extracting, starting from the bot, devices related to the detection of the command tower server described later from among the devices of the 1Hop communication destination and the 2Hop communication destination from the bot.

[0042] Specifically, first, the command tower server detection unit 123 extracts the IP address or IP address and port of the 1Hop communication destination from the bot and the IP address of the 2Hop communication destination from the bot based on the network data. Next, the command tower server detection unit 123 extracts the IP address, etc. of the communication destination where two-way communication has been confirmed, such as when an ACK (ACKnowledgement) is observed from the communication destination or when two-way traffic is confirmed, among the extracted communication destinations.

[0043] Subsequently, the command tower server detection unit 123 excludes communication destinations with abnormal traffic volume, etc. among the 1Hop communication destinations from the bot that are the targets of DDoS attacks or brute force attacks.

[0044] Through the series of processes described above, the command tower server detection unit 123 represents, starting from the bot, communication destinations where two-way communication with the bot has been confirmed and that are not the targets of attacks such as DDoS attacks among the 1Hop communication destinations from the bot as command tower server (C2) candidates, and can generate a graph structure in which there is two-way communication with the command tower server candidates other than the bot and the 2Hop communication destinations from the bot are represented as non-malicious terminals.

[0045] Then, the command tower server detection unit 123 detects, for example, as the command tower server those command tower server candidates in the generated graph structure that have a high communication ratio with the bot and a low communication ratio with other non-malicious terminals. In the example of FIG. 6, the command tower server candidate shown by the diagonal lines that only communicates with the bot is detected as the command tower server, and command tower server candidates with a communication ratio with other non-malicious terminals below a preset threshold (for example, 80%) are not detected as the command tower server.

[0046] Return to the description of FIG. 2. The command tower server determination unit 124 determines whether a specific server is related to a DDoS attack based on information about the bot. For example, when the device extracted from the source information included in the communication of a specific server input from the outside is the same as the bot detected by the bot detection unit 122, the command tower server determination unit 124 determines that the specific server is related to a DDoS attack.

[0047] For example, for a specific server regarded as a command tower server input from the outside, the command tower server determination unit 124 matches the source IP address included in the communication history of the server extracted from the network data with the bot IP address stored in the bot-related data storage unit 133. When there is a registration in the bot IP address, it is determined that the server is related to a DDoS attack.

[0048] [[3. An Example of the Processing of the Detection Device 100]] Here, with reference to FIG. 7, the overall flow of the processing performed by the detection device 100 will be described. FIG. 7 is a flowchart showing an example of the overall flow of the processing of the detection device according to the embodiment. First, the DDoS attack detection unit 121 of the detection device 100 detects a DDoS attack based on network data (S11). Next, the bot detection unit 122 of the detection device 100 detects bots participating in the detected DDoS attacks from the information about the detected multiple DDoS attacks (S12). Subsequently, the command tower server detection unit 123 of the detection device 100 detects a command tower server that has instructed the DDoS attack from the information about the detected bots (S13), and the detection device 100 ends the process.

[0049] Subsequently, with reference to FIGS. 8 to 10, the flow of each process performed by the detection device 100 will be individually described. FIG. 8 is a flowchart showing an example of the flow of the processing of the DDoS attack detection unit according to the embodiment. FIG. 9 is a flowchart showing an example of the flow of the processing of the bot detection unit according to the embodiment. FIG. 10 is a flowchart showing an example of the flow of the processing of the command tower server detection unit according to the embodiment.

[0050] First, referring to FIG. 8, the processing of the DDoS attack detection unit 121 (corresponding to S11 in FIG. 7) will be described. Note that the series of processes shown in FIG. 8 are repeatedly performed each time network data for a certain period (Window) is collected, and a plurality of DDoS attacks are detected as a result of the repeatedly performed processes.

[0051] The DDoS attack detection unit 121 extracts network data every certain period (Window) (S111). Next, the DDoS attack detection unit 121 calculates the traffic volume for each DstIP (destination IP address) and DstNet (destination network address) for each DDoS attack pattern (S112). Then, the DDoS attack detection unit 121 determines whether the calculated traffic volume exceeds a threshold value (S113).

[0052] When the calculated traffic volume exceeds the threshold value (S113; Yes), the DDoS attack detection unit 121 detects the attack as a DDoS attack (S114). On the other hand, when the calculated traffic volume does not exceed the threshold value (S113; No), the DDoS attack detection unit 121 ends the process for the network data.

[0053] After the process of S114, the DDoS attack detection unit 121 extracts the statistical information of the detected DDoS attack, the SrcIP (source IP address), and the traffic volume for each SrcIP (S115). Then, the DDoS attack detection unit 121 determines the start, end, and continuation of the DDoS attack (S116), and ends the process for the network data.

[0054] Next, referring to FIG. 9, the processing of the bot detection unit 122 (corresponding to S12 in FIG. 7) will be described. The bot detection unit 122 extracts DDoS attack-related data every certain period (Window) (S121). Next, the bot detection unit 122 extracts highly important DDoS attacks from among the plurality of DDoS attacks based on the attack type and traffic volume (S122).

[0055] Then, for DDoS attacks with high importance, the bot detection unit 122 extracts statistical values of attack IDs and traffic volumes for each SrcIP (S123). After that, the bot detection unit 122 detects SrcIPs with the number of attack IDs and traffic volume greater than the threshold as bots (S124), and ends the process.

[0056] Subsequently, referring to FIG. 10, the process of the command tower server detection unit 123 (corresponding to S13 in FIG. 7) will be described. The command tower server detection unit 123 extracts network data, DDoS attack-related data, and bot-related data for each fixed period (Window) (S131). Next, the command tower server detection unit 123 generates a graph structure based on the network graphic data starting from the bot (S132).

[0057] Then, the command tower server detection unit 123 extracts the communication destinations of 1Hop and 2Hop from the generated graph structure (S133). After that, the command tower server detection unit 123 extracts those with confirmed two-way communication from the extracted communication destinations (S134). Subsequently, the command tower server detection unit 123 excludes the communication destinations estimated to be the attack destinations of cyberattacks from the 1Hop communication destinations (S135). After that, the command tower server detection unit 123 detects, as the command tower server, those with a high communication ratio with bots and a low communication ratio with 2Hop communication destinations that are not bots from the 1Hop communication destinations (S136), and ends the process.

[0058] 〔4. Effects of the Embodiment〕 As described above, the detection device 100 according to the present embodiment includes a DDoS attack detection unit 121, a bot detection unit 122, and a command tower server detection unit 123. The DDoS attack detection unit 121 detects DDoS attacks based on network data. The bot detection unit 122 detects bots participating in DDoS attacks from information on a plurality of DDoS attacks detected by the DDoS attack detection unit 121. The command tower server detection unit 123 detects a command tower server instructing DDoS attacks from information on the bots detected by the bot detection unit 122.

[0059] As a result, after detecting a DDoS attack from network data such as packet information, destination information, and source information collected by the detection device 100 from the network, the detection device 100 can detect the bots participating in the DDoS attack and the command tower server that instructs the bots to perform the DDoS attack. Therefore, the command tower server that instructs the DDoS attack can be appropriately detected from the information related to the DDoS attack.

[0060] Then, when the command tower server is identified by the detection device 100, the communication from the bots to the command tower server can be blocked. Therefore, the DDoS attack instruction can be blocked and DDoS attack countermeasures can be implemented.

[0061] In addition, the bot detection unit 122 of the detection device 100 extracts, as bot candidates, the sources with a participation ratio in a plurality of DDoS attacks higher than a predetermined threshold from the information related to the DDoS attacks, and detects the bots participating in the DDoS attacks based on the communication history of the bot candidates.

[0062] As a result, the detection device 100 detects, as bots, the devices with a high participation ratio in the detected plurality of DDoS attacks and performing activities characteristic of bots, so that the bots participating in the DDoS attacks can be appropriately detected.

[0063] Furthermore, the command tower server detection unit 123 of the detection device 100 extracts, as command tower server candidates, the hosts that a plurality of bots commonly communicate with, and determines any one or more of the following: whether there is two-way communication between the bots and the command tower server candidates, whether the command tower server candidates are not the attack destinations of the DDoS attack, and whether the communication between the command tower server candidates and hosts other than the bots is less compared to the communication between the command tower server and the bots. The command tower server is detected according to the determination result.

[0064] As a result, the detection device 100 can appropriately detect a command tower server that is instructing a DDoS attack by extracting candidate command tower servers from the communication histories of the detected multiple bots and detecting, as the command tower server, a device having a characteristic communication history for the command tower server.

[0065] In addition, the detection device 100 includes a command tower server determination unit 124. The command tower server determination unit 124 determines whether a specific server is related to a DDoS attack based on information about the bots.

[0066] As a result, the detection device 100 can use, as a block list, a device determined to be related to a DDoS attack by determining whether a device regarded as a command tower server grasped by malware analysis or the like is related to a DDoS attack based on the relevance to the detected bots.

[0067] In addition, the command tower server determination unit 124 of the detection device 100 determines that a specific server is related to a DDoS attack when a device extracted from source information included in the communication of the specific server is the same as a bot detected by the bot detection unit 122.

[0068] As a result, the detection device 100 can determine whether a device extracted from the communication history of a device regarded as a command tower server input from the outside matches the detected bots, so that a device having a communication history with the bots can be appropriately determined as a device related to a DDoS attack.

[0069] 〔5. System configuration, etc.〕 Among the processes described in the above embodiments, part of the processes described as being automatically performed can also be performed manually. Alternatively, all or part of the processes described as being performed manually can also be automatically performed by known methods. In addition, regarding the process procedures, specific names, and information including various data and parameters shown in the above documents and drawings, they can be arbitrarily changed unless otherwise specified. For example, the various information shown in each figure is not limited to the illustrated information.

[0070] Also, each component of each device shown in the drawings is conceptually functional and does not necessarily have to be physically configured as shown in the drawings. That is, the specific form of the distribution and integration of each device is not limited to that shown, and all or part of it can be functionally or physically distributed and integrated in any unit according to various loads, usage situations, etc. Furthermore, each processing function performed by each device can be realized in whole or in any part by a CPU and a program analyzed and executed by the CPU, or can be realized as hardware by wired logic.

[0071] For example, part or all of the storage unit 130 shown in FIG. 2 may be held not by the detection device 100 but by a storage server or the like. In this case, the detection device 100 acquires various information by accessing the storage server.

[0072] 〔6. Hardware Configuration〕 FIG. 11 is a diagram showing an example of a hardware configuration. The detection device 100 according to the above-described embodiment is realized by a computer 1000 having a configuration as shown in FIG. 11, for example.

[0073] FIG. 11 is a diagram showing an example of a computer that executes an analysis program. The computer 1000 has, for example, a memory 1010 and a CPU 1020. The computer 1000 also has a hard disk drive interface 1030, a disk drive interface 1040, a serial port interface 1050, a video adapter 1060, and a network interface 1070. These components are connected by a bus 1080.

[0074] The memory 1010 includes a ROM (Read Only Memory) 1011 and a RAM 1012. The ROM 1011 stores a boot program such as a BIOS (Basic Input Output System), for example. The hard disk drive interface 1030 is connected to a hard disk drive 1090. The disk drive interface 1040 is connected to a disk drive 1041. A removable storage medium such as a magnetic disk or an optical disk is inserted into the disk drive 1041, for example. The serial port interface 1050 is connected to, for example, a mouse 1110 and a keyboard 1120. The video adapter 1060 is connected to, for example, a display 1130.

[0075] The hard disk drive 1090 stores, for example, an OS (Operating System) 1091, an application program 1092, a program module 1093, and program data 1094. That is, the program that defines each process of the detection device 100 is implemented as a program module 1093 in which executable code by the computer 1000 is described. The program module 1093 is stored in the hard disk drive 1090, for example. For example, a program module 1093 for executing the same process as the functional configuration in the detection device 100 is stored in the hard disk drive 1090. Note that the hard disk drive 1090 may be replaced by an SSD (Solid State Drive).

[0076] In addition, the setting data used in the processing of the above-described embodiment is stored, for example, in the memory 1010 or the hard disk drive 1090 as program data 1094. Then, the CPU 1020 reads out and executes the program modules 1093 and program data 1094 stored in the memory 1010 or the hard disk drive 1090 into the RAM 1012 as needed.

[0077] Note that the program modules 1093 and program data 1094 are not limited to being stored in the hard disk drive 1090, and may be stored, for example, in a removable storage medium and read by the CPU 1020 via a disk drive 1041 or the like. Alternatively, the program modules 1093 and program data 1094 may be stored in another computer connected via a network (LAN, WAN, etc.). Then, the program modules 1093 and program data 1094 may be read by the CPU 1020 from another computer via the network interface 1070.

Explanation of Reference Numerals

[0078] 100 Detection device 110 Communication unit 120 Control unit 121 DDoS attack detection unit 122 Bot detection unit 123 Command tower server detection unit 124 Command tower server determination unit 130 Storage unit 131 Network data storage unit 132 DDoS attack-related data storage unit 133 Bot-related data storage unit

Claims

1. A DDoS attack detection unit that detects a DDoS (Distributed Denial of Service) attack based on network data, A bot detection unit that detects bots participating in the DDoS attack from information on a plurality of DDoS attacks detected by the DDoS attack detection unit, A command tower server detection unit that detects a command tower server instructing the DDoS attack from information on the bots detected by the bot detection unit, A detection device, characterized by comprising the above.

2. The bot detection unit extracts, from information on a plurality of the DDoS attacks, a transmission source whose participation rate in the DDoS attack is higher than a predetermined threshold as a bot candidate, and detects a bot participating in the DDoS attack based on the communication history of the bot candidate The detection device according to claim 1, characterized by the above.

3. The command tower server detection unit extracts a host that a plurality of the bots commonly communicate with as a command tower server candidate, and from the command tower server candidate, determines whether there is two-way communication between the bot and the command tower server candidate, determines whether the command tower server candidate is not the target of the DDoS attack, and determines whether the communication between the command tower server candidate and a host other than the bot is less than the communication between the command tower server and the bot. One or more of the above determinations are made, and the command tower server is detected according to the determination result The detection device according to claim 1, characterized by the above.

4. Further comprising a command tower server determination unit that determines whether a specific server is related to the DDoS attack based on information on the bot The detection device according to claim 1, characterized by the above.

5. When the device extracted from the source information included in the communication of the specific server is the same as the bot detected by the bot detection unit, the command tower server determination unit determines that the specific server is related to a DDoS attack. The detection device according to claim 4, characterized in that.

6. A detection method executed by a detection device, A DDoS attack detection step of detecting a DDoS attack based on network data, A bot detection step of detecting a bot participating in the DDoS attack from information on a plurality of DDoS attacks detected by the DDoS attack detection step, A command tower server detection step of detecting a command tower server instructing the DDoS attack from information on the bot detected by the bot detection step, The detection method characterized by including the above.

Citation Information

Patent Citations

  • Sensing device, sensing method, and sensing program

    WO2020245930A1