Identification apparatus and identification method

By converting IPv4 and IPv6 feature information to generate common features, the identification device addresses the scarcity of IPv6 teacher data, enabling accurate communication identification and reducing false detections, particularly in IPv6-based systems.

JP2025097860APending Publication Date: 2025-07-01NIPPON TELEGRAPH & TELEPHONE CORP
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2023214321
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-12-19
Publication Date
2025-07-01

AI Technical Summary

Technical Problem

Existing communication identification technologies face challenges in performing accurate identification processing due to the scarcity of teacher data for IPv6 traffic, especially when migrating from IPv4 to IPv6, and the need to account for protocol differences between IPv4 and IPv6, leading to inefficiencies and high false detection rates in unsupervised learning.

Method used

The identification device converts IPv4 and IPv6 feature information to generate common feature information, using a learned identifier to perform identification processing on IPv6-based communication, leveraging existing IPv4 traffic data when IPv6 data is scarce.

Benefits of technology

Enables effective communication identification processing even when teacher data is limited, reducing false detections and improving accuracy by generating common feature information across protocols, allowing for efficient learning and identification of malicious communications.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025097860000001_ABST
    Figure 2025097860000001_ABST
Patent Text Reader

Abstract

To enable an execution of an identification processing of an appropriate communication even in the case where a preparation of a teaching data to be used for learning is hard.SOLUTION: An identification apparatus 100 converts at least any one of feature information of an IPv4 and feature information of IPv6 so that the feature information extracted from a traffic data of a communication based on the IPv4 and the feature information extracted from the traffic data of the communication based on the IPv6 become common, and generates the common feature information. The identification apparatus 100 learns an identifier for performing an identification processing for the communication based on the IPv6 by using the common feature information to be generated. The identification apparatus 100 performs the identification processing for the communication based on the IPv6 on the basis of a result to be obtained by inputting the common feature information to be generated by using the traffic data of the communication based on the IPv6 of an identification object into the identifier to be learned.SELECTED DRAWING: Figure 3
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an identification device and an identification method.

Background Art

[0002] In the Internet, communication based on IPv4 (Internet Protocol version 4) is used. Therefore, many attack bases such as botnets that abuse the Internet are established by attackers based on IPv4.

[0003] In order to detect the entire picture of the attack base, a method of detecting a suspicious communication destination by performing traffic analysis using network traffic data (hereinafter, may be simply referred to as "traffic data") including information such as the communication destination, source, and communication capacity by a network operator is known. For example, as a conventional technique, a machine learning model is learned using traffic data based on IPv4 that exists in large quantities (hereinafter, may be simply referred to as "IPv4 traffic data") as teacher data, and a suspicious communication based on IPv4 is detected based on the learned machine learning model (see, for example, Non-Patent Document 1 and Patent Document 1). Further, as a conventional technique, a technique of detecting a suspicious communication of an attacker by extracting features from packet data, which is a type of traffic data, and flow data recording statistical information of the packet data, and learning and classifying the communication characteristics of the attacker using machine learning technology is known (see, for example, Non-Patent Document 2).

Prior Art Documents

Patent Documents

[0004]

Patent Document 1

Non-Patent Documents

[0005]

Non-Patent Document 1

[0006] However, in the above-described conventional technology, there is a problem that appropriate communication identification processing cannot be executed when it is difficult to prepare teacher data used for learning. For example, in recent years, due to the exhaustion of IPv4 addresses, which are IP (Internet Protocol) addresses based on IPv4, IPv6 addresses, which are IP addresses based on IPv6 (Internet Protocol version 6), have been increasingly used. However, since there is not enough suspicious communication traffic data using IPv6 addresses for use as teacher data, there is little data that can be used as teacher data, and it is difficult to efficiently train a machine learning model to have practical accuracy. Also, even when training a model using the conventional technology, it is necessary to design features considering the differences between the IPv6 protocol and the IPv4 protocol. In addition, although the conventional technology that performs training based on unsupervised learning does not require teacher data, there are problems such as many false detections occurring.

Means for Solving the Problems

[0007] Therefore, in order to solve the above-described problems and achieve the object, the identification device of the present invention converts at least one of the IPv4 feature information and the IPv6 feature information so that the feature information extracted from the traffic data of IPv4-based communication and the feature information extracted from the traffic data of IPv6-based communication are common, and generates common feature information; an identifier learning unit that learns an identifier for performing identification processing on IPv6-based communication using the common feature information generated by the feature generation unit; and an identification unit that performs identification processing on the IPv6-based communication based on the result obtained by inputting the common feature information generated using the traffic data of the IPv6-based communication to be identified to the learned identifier.

Effects of the Invention

[0008] According to the present invention, even when it is difficult to prepare teacher data used for learning, an effect of enabling execution of appropriate communication identification processing is achieved.

Brief Description of the Drawings

[0009]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Figure 12

Figure 13

Modes for Carrying Out the Invention

[0010] Hereinafter, embodiments for implementing the present invention (hereinafter referred to as "embodiments") will be described with reference to the drawings. Note that each embodiment is not limited to the content described below.

[0011] <Explanation of the overall image of the processing by the identification device 100> FIG. 1 is a diagram for explaining the overall image of the processing by the identification device 100 according to the present embodiment. The identification device 100 shown in FIG. 1 uses the received traffic data to generate common feature information (hereinafter simply referred to as "common feature information") in which the types of features extracted for each traffic data with different protocols are common and the items for identifying the types of features are common, and learns an identifier for performing identification processing, and executes predetermined identification processing such as malicious communication and application identification related to communication (hereinafter sometimes referred to as "identification processing"). It is an example of a computer that provides a technique.

[0012] An attack infrastructure for executing malicious communication or the like (hereinafter sometimes referred to as "malicious communication") that abuses the Internet is often constructed based on IPv4, which is the current communication protocol. Therefore, in order to detect the entire picture of the attack infrastructure constructed by an attacker, traffic analysis may be performed using IPv4 traffic data. For example, as an example of traffic analysis, a reference technique for detecting malicious communication based on IPv4 is known in which a machine learning model is trained using IPv4 traffic data related to a large amount of malicious communication as teacher data.

[0013] However, since the related art uses a machine learning model trained with a large amount of teacher data to perform predetermined identification processing such as detection of malicious communication and attack infrastructure, it may be difficult to perform appropriate identification processing when there is no or little teacher data used for learning. As a specific example, with the recent shift to IPv6 addresses due to the depletion of IPv4 addresses, there have been cases where attackers have established attack infrastructure based on IPv6. When migrating from IPv4 to IPv6, since the attack infrastructure is established based on IPv6, it is necessary to train a machine learning model using traffic data of communication based on IPv6 (hereinafter sometimes simply referred to as "IPv6 traffic data") to identify malicious communication based on IPv6.

[0014] However, the use of IPv6 by attackers is still limited in part, and since it is difficult to prepare a large amount of teacher data related to IPv6 used for training the machine learning model, the related art cannot perform effective learning and identification processing. Also, due to reasons such as the need to design feature information in consideration of the fact that the IPv6 protocol is different from the IPv4 protocol, the related art cannot perform effective learning and identification processing.

[0015] Therefore, there is a known related art that performs unsupervised learning using IPv4 traffic data and IPv6 traffic data to detect anomalies. However, although there is also a known related art that performs unsupervised learning that does not require teacher data, since such unsupervised learning may have a high possibility of false detection, it is difficult to perform identification processing with high accuracy.

[0016] Therefore, in order to solve the above-described problems, the identification device 100 according to the present embodiment learns an identifier for identifying target communication using common feature information generated using IPv4 traffic data that exists in large quantities due to being the current communication protocol, IPv6 traffic data related to malicious communication implemented based on IPv6, etc., and executes an identification process for identifying the target communication.

[0017] From here, a series of processes of the identification device 100 will be described with reference to FIG. 1. For example, as shown in (1) of FIG. 1, the identification device 100 converts at least one of the feature information extracted from IPv4 traffic data and the feature information extracted from IPv6 traffic data so that the feature information common to the feature information extracted from the learning traffic data is the same, and generates common feature information.

[0018] For example, in order to make the most of the large amount of IPv4 traffic data that exists, the identification device 100 converts the items of the feature information generated using the IPv4 traffic data (hereinafter sometimes referred to as "IPv4 feature information") so that they have the same meaning as the items for identifying the types of features of the feature information generated using the IPv6 traffic data (hereinafter sometimes referred to as "IPv6 feature information"), and generates the IPv4 feature information as common feature information. Further, when there is IPv6 traffic data related to malicious communication, the identification device 100 converts the items of the IPv6 feature information generated using the IPv6 traffic data so that they have the same meaning as the items for identifying the types of features of the IPv4 feature information, and generates the IPv6 feature information as common feature information.

[0019] As shown in (2) of FIG. 1, the identification device 100 learns an identifier for performing identification processing on IPv6-based communication using the generated common feature information. For example, the identification device 100 includes IPv4 feature information (hereinafter, may be referred to as "IPv4 feature information with label") that includes a label (hereinafter, may be simply referred to as "label") for identifying whether the communication based on the target IPv6 is malicious communication, which is generated as common feature information, IPv6 feature information without a label (hereinafter, may be referred to as "IPv6 feature information without label"), and IPv6 feature information with a label (hereinafter, may be referred to as "IPv6 feature information with label"), and combines them according to the situation during the execution of the identification process, the model to be used, etc., to learn a machine learning model such as an identification model included in the identifier that executes the identification process (hereinafter, may be simply referred to as "model").

[0020] An example of the learning process using the above-mentioned "IPv4 feature information with label", "IPv6 feature information without label", and "IPv6 feature information with label" will be described in the description items of FIGS. 6 to 10 below.

[0021] The identification device 100 performs identification processing on IPv6-based communication based on the result obtained by inputting the common feature information generated using the IPv6 traffic data (traffic data to be identified) related to the IPv6-based communication to be identified into the learned identifier. For example, the identification device 100 inputs the common feature information (FIG. 1 (3-1)) generated from the IPv6 traffic data related to the communication based on the target IPv6 into the learned identifier (FIG. 1 (3-2)) and executes identification processing such as "the communication based on the IPv6 is malicious communication" (FIG. 1 (3-3)).

[0022] As described above, even when using traffic data with different protocols such as IPv4 and IPv6, the identification device 100 according to this embodiment generates common feature information so that the generated feature information has the same meaning for IPv4 and IPv6. Then, the identification device 100 performs identification processing on the common feature information of the communication based on IPv6 to be identified using a learned identifier learned using the generated common feature information for learning.

[0023] Thereby, the identification device 100 enables execution of identification processing such as whether the communication based on IPv6 related to the common feature information of the identification target is malicious communication. That is, due to being the current communication protocol, the identification device 100 creates feature information common to IPv4 and IPv6 using a large amount of IPv4 traffic data existing as teacher data, so that even when it is difficult to prepare teacher data for learning because there is no available IPv6 traffic data as teacher data, it has the effect of enabling execution of appropriate communication identification processing. Also, when there is available IPv6 traffic data related to malicious communication as teacher data, the identification device 100 creates feature information common to IPv4 and IPv6 using both the IPv6 traffic data and the above-described IPv4 traffic data, and by learning the model, it has the effect of enabling efficient execution of appropriate communication identification processing.

[0024] <Description of Identification Device 100> Next, as an example of the identification processing by the identification device 100 according to this embodiment, the flow of the learning processing and the detection processing will be described in detail. FIG. 2 is a diagram for explaining an example of the processing by the identification device 100 according to this embodiment.

[0025] In this embodiment, the traffic data includes "IPv4 traffic data" and "IPv6 traffic data". The feature information includes "IPv4 feature information" and "IPv6 feature information". The IPv4 feature information includes "labeled IPv4 feature information" as learning data. The IPv6 feature information includes "unlabeled IPv6 feature information" and "labeled IPv6 feature information" as learning data, and "identification IPv6 feature information" as identification data.

[0026] First, the identification device 100 receives traffic data (Fig. 2(1-1)). Then, the identification device 100 stores the received traffic data in the traffic data DB 121 (Fig. 2(1-2)).

[0027] The identification device 100 generates common feature information using the stored traffic data. For example, the IPv4 feature generation unit 1321 generates "labeled IPv4 feature information 122a" as common feature information in which the items for identifying the IPv6 feature information and the type of feature are common, using a large amount of existing IPv4 traffic data (Fig. 2(2-1)).

[0028] Also, for example, the IPv6 feature generation unit 1322 generates "unlabeled IPv6 feature information 122b" as common feature information in which the items for identifying the IPv4 feature information and the type of feature are common, using the IPv6 traffic data (Fig. 2(2-2)). When there is IPv6 traffic data related to malicious communication, the IPv6 feature generation unit 1322 generates "labeled IPv6 feature information 122c" that can be used as teacher data as common feature information in which the items for identifying the IPv4 feature information and the type of feature are common (Fig. 2(2-3)).

[0029] The identifier learning unit 133 learns an identifier using the generated common feature information (see (3-1) in FIG. 2). Specifically, the identifier learning unit 133 learns an identifier used to execute identification processing by combining one or more of the labeled IPv4 feature information, unlabeled IPv6 feature information, and labeled IPv6 feature information.

[0030] For example, when there is no IPv6 traffic data related to malicious communication, the identifier learning unit 133 learns an identifier using the common feature information generated from a large amount of existing IPv4 traffic data. On the other hand, when there is IPv6 traffic data related to malicious communication, the identifier learning unit 133 learns an identifier using both the common feature information generated from the IPv6 traffic data related to the malicious communication and the common feature information generated from a large amount of existing IPv4 traffic data.

[0031] Then, the identifier learning unit 133 stores the model related to the learned identifier in the model DB 123 (see (3-2) in FIG. 2).

[0032] The identification unit 134 executes a predetermined identification process using the learned identifier. For example, the identification unit 134 inputs the identification IPv6 feature information 122d (see (4-1) in FIG. 2), which is common feature information generated using traffic data related to communication based on the IPv6 to be identified, into the learned identifier (see (4-2) in FIG. 2), and identifies whether the communication related to the identification IPv6 feature information is malicious communication. Then, the identification unit 134 stores the result of the identification process in the identification result DB 124 (see (4-3) in FIG. 2).

[0033] In this way, the identification device 100 can effectively learn an identifier even when there is no IPv6 traffic data that can be prepared as teacher data by generating common feature information using a large amount of existing IPv4 traffic data. As a result, the identification device 100 can execute effective identification processing even when there is no teacher data, or when the amount of teacher data is small.

[0034] Furthermore, when there is IPv6 traffic data that can be used as training data, the identification device 100 uses both the IPv6 traffic data and the IPv4 traffic data to realize more effective learning of the identifier than before, enabling highly accurate identification of malicious communications.

[0035] <Description of the identification device 100> Next, the device configuration of the identification device 100 will be described. FIG. 3 is a diagram showing an example of the configuration of the identification device 100 according to the present embodiment. As shown in FIG. 3, the identification device 100 includes a communication unit 110, a storage unit 120, and a control unit 130. Although not shown in FIG. 3, the identification device 100 can include an input unit such as a keyboard and a mouse for receiving inputs such as operations by a user or the like. Further, the identification device 100 can include a display unit such as a display for displaying information such as the execution result of the identification process to the user or the like.

[0036] (Communication unit 110) The communication unit 110 performs data communication related to inputs such as traffic data and training data, and outputs of execution results of identification processes such as identification results by the identification unit 134 described later. The communication unit 110 is realized by a NIC (Network Interface Card) or the like, and controls communication via a telecommunications line such as a LAN (Local Area Network) or the Internet. Then, the communication unit 110 is connected to the network by wire or wirelessly as necessary, and can transmit and receive information bidirectionally.

[0037] (Storage unit 120) The storage unit 120 stores data and programs used for various processes by the control unit 130, and various data obtained by the operation of the control unit 130. The storage unit 120 is realized by a semiconductor memory element such as a RAM (Random Access Memory) or a flash memory, or a storage device such as a hard disk or an optical disk. As shown in FIG. 4, the storage unit 120 includes a traffic data DB 121, a feature information DB 122, a model DB 123, and an identification result DB 124.

[0038] (Traffic Data DB 121) The traffic data DB 121 is a database that stores IPv4 traffic data and IPv6 traffic data as the received traffic data. Specifically, the traffic data DB 121 stores, as traffic data, No, time, source IP address, destination IP address, protocol, source port number, destination port number, TCP (Transmission Control Protocol) flag, number of bytes, number of packets, etc. in association with each other.

[0039] The No described above is identification information for identifying the stored traffic data. The source IP address and the destination IP address are identification numbers assigned to communication devices connected to the network, and include, for example, an IPv4 address or an IPv6 address. The protocol is information that defines the communication procedure and the interaction. The source port number and the destination port number are sub (auxiliary) addresses provided under the IP address for connecting to a plurality of partners simultaneously in Internet communication. The TCP flag is information included in a 6-bit field in the TCP header indicating the packet content. The number of bytes is the amount of data collected at a certain time. The number of packets is the number of packets collected at a certain time.

[0040] Here, an example of the traffic data stored in the traffic data DB 121 will be described. FIG. 4 is a table diagram showing an example of the traffic data according to the present embodiment. For example, as shown in FIG. 4, the traffic data DB 121 can store the time "t1", the source IP address "SIP1", the destination IP address "DIP1", the protocol "PR1", the source port number "SP1", the destination port number "DP1", the TCP flag "FLG1", the number of bytes "BYT1", the number of packets "PKT1", etc. in association with the identifier information No "1".

[0041] Note that when the received communication is related to IPv4 communication, the source IP address "SIP1" and the destination IP address "DIP1" will contain IPv4 addresses. Also, when the received communication is related to IPv6 communication, the source IP address "SIP1" and the destination IP address "DIP1" will contain IPv6 addresses.

[0042] (Feature information DB 122) Here, returning to FIG. 3, the description will be continued. The feature information DB 122 is a database that stores the common feature information generated using the traffic data stored in the traffic data DB 121. Specifically, the feature information DB 122 stores the labeled IPv4 feature information 122a, the unlabeled IPv6 feature information 122b, the labeled IPv6 feature information 122c, and the identification IPv6 feature information 122d generated by the feature generation unit 132 described later. Note that the details and generation methods of each feature information will be described in the items related to the feature generation unit 132 described later.

[0043] (Model DB 123) The model DB 123 is a database that stores a model (identification model) used for the identifier learned by the identifier learning unit 133 described later. For example, the model DB 123 can store an identification model using a known technique such as DANN (Domain Adversarial Neural Networks) as a model for identifying whether the communication to be identified is malicious communication.

[0044] As described above, DANN is a type of neural network that connects a neural network with a feature extractor and classifiers (label classification and domain classification). In DANN, a layer that reverses the gradient is sandwiched between the domain classifier and the feature extractor, and the gradient is backpropagated so that the feature extractor learns in a direction where it cannot identify the domain. By using DANN, the discrimination device 100 in the present embodiment can be trained to eliminate the differences between IPv4 feature information generated using IPv4 traffic data and IPv6 feature information generated using IPv6 traffic data.

[0045] (Discrimination result DB124) The discrimination result DB124 is a database that stores the results of discrimination processing executed by the discrimination unit 134 described later. For example, when the discrimination unit 134 described later discriminates that "the feature information is feature information related to malicious communication" based on the feature information of traffic data related to IPv6 input, the discrimination result DB124 can store the information for discriminating the communication in association with flag information such as "malicious communication".

[0046] (Control unit 130) The control unit 130 has an internal memory for temporarily storing programs and processing data that define various processing procedures and the like of the discrimination device 100, and is realized by an electronic circuit such as a CPU (Central Processing Unit) or an MPU (Micro Processing Unit), or an integrated circuit such as an ASIC (Application Specific Integrated Circuit) or an FPGA (Field Programmable Gate Array). As shown in FIG. 3, the control unit 130 includes a reception unit 131, a feature generation unit 132, a discriminator learning unit 133, a discrimination unit 134, and an output unit 135.

[0047] (Reception unit 131) The reception unit 131 receives traffic data such as IPv4 traffic data and IPv6 traffic data from an external communication device or the like via the communication unit 110 described above.

[0048] (Feature generation unit 132) The feature generation unit 132 extracts features for each traffic data using various information included in the traffic data, and generates feature information. For example, the feature generation unit 132 generates IPv4 feature information from IPv4 traffic data and generates IPv6 feature information from IPv6 traffic data.

[0049] Here, an example of the feature information generated by the feature generation unit 132 will be described. FIG. 5 is a diagram showing an example of the feature information according to the present embodiment. FIG. 5 shows an example of the feature information generated from IPv4 traffic data and IPv6 traffic data.

[0050] There may be a difference in the items for identifying the types of the respective features between the feature information related to IPv4 and the feature information related to IPv6. For example, as shown in (1) of FIG. 5, for the item of "# of unique / 24 prefixes", in IPv4, since " / 24" is the minimum unit of network division commonly used on the Internet, it is set to "24". On the other hand, in IPv6, the minimum unit of network division commonly used is "48". Therefore, even if a feature corresponding to "# of unique / 24 prefixes" of the IPv4 feature information is extracted as the feature information related to IPv6, it may be recognized as a different feature.

[0051] Also, as another example (not shown in FIG. 5), for the "ICMP (Internet Control Message Protocol) usage rate (usage ratio of the ICMP protocol)", in IPv4, it is calculated based on the number of flows with the protocol number "= 1 (ICMP)". On the other hand, in IPv6, it is calculated based on the protocol number "= 58 (ICMPv6)". Therefore, since features are generated based on different protocol numbers for IPv4 and IPv6, even if the content of the features is the same or similar, they may be recognized as different features respectively.

[0052] As described above, although the IPv4 feature information and the IPv6 feature information have similar feature content, they are different feature information. Therefore, even if they are directly used for learning, appropriate learning cannot be performed. Thus, the feature generation unit 132 generates feature information such that the feature information classified the same between the IPv4 traffic data and the IPv6 traffic data is classified the same. That is, the feature generation unit 132 identifies items for identifying the types of features so that the types of features expressed by the IPv4 feature information and the types of features expressed by the IPv6 feature information are recognized as the same type of features using the traffic data, and converts them to generate common feature information. Note that the feature generation unit 132 includes an IPv4 feature generation unit 1321 and an IPv6 feature generation unit 1322, and in each functional unit, the above-described generation of common feature information is performed.

[0053] Specifically, the IPv4 feature generation unit 1321 uses the IPv4 traffic data to convert the items for identifying the types of features extracted from the IPv4 traffic data so as to be common with the items for identifying the types of features extracted from the IPv6 traffic data, and generates common feature information (IPv4 feature information). For example, the IPv4 feature generation unit 1321 uses the labeled IPv4 traffic data to generate the labeled IPv4 feature information as common feature information common to the IPv6 feature information.

[0054] In addition, the IPv6 feature generation unit 1322 uses the IPv6 traffic data to convert the items for identifying the types of features extracted from the IPv4 traffic data so as to be common, and generates common feature information (IPv6 feature information). For example, the IPv6 feature generation unit 1322 uses the labeled IPv6 traffic data to generate labeled IPv6 feature information as common feature information common to the IPv4 feature information. Also, for example, the IPv6 feature generation unit 1322 uses the unlabeled IPv6 traffic data to generate unlabeled IPv6 feature information as common feature information common to the IPv4 feature information. Further, the IPv6 feature generation unit 1322 uses the IPv6 traffic data related to the communication for identification processing to generate identification-use IPv6 feature information as common feature information common to the IPv4 feature information.

[0055] (Classifier learning unit 133) Here, returning to FIG. 3, the explanation will be continued. The classifier learning unit 133 learns a classifier for executing a predetermined identification process using the common feature information generated by the feature generation unit 132. For example, the classifier learning unit 133 uses, as the common feature information, one or a combination of the labeled IPv4 feature information, the labeled IPv6 feature information, and the unlabeled IPv6 feature information to learn a classifier for identifying malicious communication as an identification process related to IPv6. Note that an example of the implementation of the learning process combining the above-described feature information will be described in detail in the description items of FIGS. 6 to 10 to be described later, and thus the description is omitted here.

[0056] (Identification unit 134) The identification unit 134 performs identification processing on the communication in question based on the result obtained by inputting the feature information related to the communication to be identified into the trained identifier. For example, the identification unit 134 inputs the IPv6 feature information related to the communication based on IPv6 to be identified into the trained identifier, and based on the result obtained, identifies whether the communication based on the IPv6 is malicious communication. Then, the identification unit 134 stores the result of the identification processing in the identification result DB 124.

[0057] (Output unit 135) The output unit 135 outputs the result of the identification processing stored in the identification result DB 124. For example, the output unit 135 can output the result of the identification processing to an external information processing device or the like via the communication unit 110 described above. Also, for example, the output unit 135 can output (display, print out, etc.) the result of the identification processing to the user via a display unit or the like provided in the identification device 100.

[0058] (An example of identification processing) Hereinafter, an example of the identification processing realized by the identification device 100 according to the present embodiment will be described with reference to FIGS. 6 to 10. FIGS. 6 to 10 are diagrams showing an example of the learning processing and the detection processing according to the present embodiment.

[0059] Note that FIG. 6 is an example of identification processing using a large amount of existing IPv4 traffic data, which is the main function realized by the identification device 100 according to the present embodiment. FIGS. 7 to 10 are examples of identification processing using both IPv4 traffic data and IPv6 traffic data when there is label-free IPv6 traffic data or labeled IPv6 traffic data.

[0060] Note that the "IPv4 feature information with label", "IPv6 feature information without label", "IPv6 feature information with label", and "IPv6 feature information for identification" shown in FIGS. 6 to 10 are all feature information generated as common feature information. Also, the "model" shown in FIGS. 6 to 10 means a machine learning model such as an identification model used to realize the functions of the above-mentioned "identifier".

[0061] (First Embodiment) First, as a first embodiment, an example of learning processing using IPv4 feature information with label and detection processing using IPv6 feature information for identification will be described with reference to FIG. 6.

[0062] The first embodiment is an example where a large amount of IPv4 traffic data with label exists and IPv6 traffic data with label does not exist.

[0063] That is, the first embodiment is an example of the basic processing of the identification device 100 according to the present embodiment, which enables effective identification of malicious communication by making the most of a large amount of existing IPv4 traffic data even when there is no IPv6 traffic data with label related to malicious communication that can be used as teacher data.

[0064] As shown in FIG. 6, the identification device 100 receives traffic data (FIG. 6(1)). Next, the identification device 100 uses the received traffic data to generate IPv4 feature information with label as learning data (FIGS. 6(2-1) and (2-2)).

[0065] The identification device 100 uses the generated IPv4 feature information with label as learning data to learn the "model (IPv4)" shown in FIG. 6(3-2) (FIG. 6(3-1)).

[0066] The identification device 100 generates identification IPv6 feature information using the traffic data related to the received communication to be identified ((4) in FIG. 6). Next, the identification device 100 executes an identification process based on the result obtained by inputting the generated identification IPv6 feature information into a learned model ((5) in FIG. 6). Then, the identification device 100 stores the result of the identification process related to the obtained IPv6 ((6) in FIG. 6).

[0067] As described above, even when there is no desired teacher data (IPv6 traffic data with labels), the identification device 100 can learn a model using the common feature information generated from a large amount of IPv4 traffic data with labels. Then, the identification device 100 can perform an identification process based on the result obtained by inputting the common feature information generated from the IPv6 traffic data related to the communication to be identified into a learned model.

[0068] That is, by using the model learned using the common feature information, the identification device 100 can accurately execute the identification process related to IPv6 by using a large amount of IPv4 traffic data even when there is no IPv6 traffic data with labels related to malicious communication that can be used as teacher data.

[0069] (Second Embodiment) Next, as a second embodiment, an example of a learning process using labeled IPv4 feature information and unlabeled IPv6 feature information and a detection process using identification IPv6 feature information will be described with reference to FIG. 7.

[0070] The second embodiment is an example in a case where there is a large amount of labeled IPv4 traffic data and a large amount of unlabeled IPv6 traffic data. Also, the labeled IPv4 traffic data and the unlabeled IPv6 traffic data will be described as an example of existing as integrated data that is not separated but mixed.

[0071] That is, the second embodiment is an example of a process that enables effective identification of malicious communication by maximizing the use of a large amount of IPv4 traffic data and unlabeled IPv6 traffic data even when there is no labeled IPv6 traffic data related to malicious communication that can be used as teacher data.

[0072] As shown in FIG. 7, the identification device 100 receives traffic data ((1) in FIG. 7). Next, the identification device 100 uses the received traffic data to generate labeled IPv4 feature information and unlabeled IPv6 feature information as learning data ((2-1) and (2-2) in FIG. 7).

[0073] The identification device 100 uses the generated labeled IPv4 feature information and unlabeled IPv6 feature information as learning data to learn the "Model (IPv4&IPv6)" shown in (3-2) of FIG. 7 and the "Model (Domain)" shown in (3-3) of FIG. 7 ((3-1) in FIG. 7). Note that the model used in the second embodiment may be a model such as DANN suitable for learning using learning data without labels and with domain information.

[0074] The identification device 100 uses the traffic data related to the communication to be identified that has been received to generate identification IPv6 feature information ((4) in FIG. 7). Next, the identification device 100 executes an identification process based on the result obtained by inputting the generated identification IPv6 feature information into the model ((5) in FIG. 7). Then, the identification device 100 stores the result of the identification process related to the obtained IPv6 ((6) in FIG. 7).

[0075] As described above, even when there is no desired teacher data (IPv6 traffic data with labels), the identification device 100 can train a model using common feature information generated from a large amount of IPv4 traffic data with labels and IPv6 traffic data without labels. Then, the identification device 100 can perform identification processing based on the result obtained by inputting the common feature information generated from the IPv6 traffic data related to the communication to be identified into the trained model.

[0076] That is, by using the model trained with the common feature information, the identification device 100 can accurately perform identification processing related to IPv6 by using a large amount of IPv4 traffic data and IPv6 traffic data without labels even when there is no IPv6 traffic data with labels as teacher data. Further, in the second embodiment, the identification device 100 can efficiently train the identifier even with mixed data in which a large amount of IPv4 traffic data and IPv6 traffic data without labels are not separated.

[0077] (Third Embodiment) Next, as a third embodiment, an example of the training process using IPv4 feature information with labels and IPv6 feature information with labels and the detection process using IPv6 feature information for identification will be described with reference to FIG. 8.

[0078] The third embodiment is an example in which there is a large amount of IPv4 traffic data with labels and a small amount of IPv6 traffic data with labels. Further, it will be described as an example in which the IPv4 traffic data with labels and the IPv6 traffic data with labels exist as integrated data that is not separated but mixed.

[0079] That is, in the case where there is labeled IPv6 traffic data related to malicious communication that can be used as teacher data, the third embodiment is an example of a process that enables effective identification of malicious communication by using both a large amount of existing IPv4 traffic data and the labeled IPv6 traffic data.

[0080] As shown in FIG. 8, the identification device 100 receives traffic data ((1) in FIG. 8). Next, the identification device 100 uses the received traffic data to generate labeled IPv4 feature information and labeled IPv6 feature information as learning data ((2-1) and (2-2) in FIG. 8).

[0081] The identification device 100 uses the generated labeled IPv4 feature information and labeled IPv6 feature information as learning data to learn the "model (IPv4&IPv6)" shown in (3-2) of FIG. 8 ((3-1) in FIG. 8).

[0082] The identification device 100 uses the traffic data related to the communication to be identified that it has received to generate identification-use IPv6 feature information ((4) in FIG. 8). Next, the identification device 100 executes an identification process based on the result obtained by inputting the generated identification-use IPv6 feature information into the model ((5) in FIG. 8). Then, the identification device 100 stores the result of the identification process related to the obtained IPv6 ((6) in FIG. 8).

[0083] As described above, even when the desired teacher data (labeled IPv6 traffic data) exists but is mixed with other data, the identification device 100 can learn the model using the common feature information generated from the traffic data in which the data is mixed. Then, the identification device 100 can perform an identification process based on the result obtained by inputting the common feature information generated from the IPv6 traffic data related to the communication to be identified into the learned model.

[0084] That is, by using the model learned with the common feature information, when there is even a small amount of labeled IPv6 feature information which is the teacher data, the identification device 100 can effectively learn the model by using both the IPv4 traffic data existing in a large amount and the labeled IPv6 traffic data. As a result, the identification device 100 can accurately execute the identification process related to IPv6 by using the learned model. In the third embodiment, since the IPv6 feature information has a label, the model to be used can be the model shown in the first embodiment instead of a model such as DANN.

[0085] (Fourth Embodiment) Next, as a fourth embodiment, an example of the learning process using the individually existing labeled IPv4 feature information and labeled IPv6 feature information and the detection process using the identification-use IPv6 feature information will be described with reference to FIG. 9.

[0086] The fourth embodiment is an example in the case where there is a large amount of labeled IPv4 traffic data and a small amount of labeled IPv6 traffic data. Also, it will be described as an example in which the labeled IPv4 traffic data and the labeled IPv6 traffic data are separated and exist as independent data groups.

[0087] That is, the fourth embodiment is an example of a process that enables effective identification of malicious communication by using both the IPv4 traffic data existing in a large amount and the labeled IPv6 traffic data even when there is no labeled IPv6 traffic data related to malicious communication that can be used as teacher data. The difference between the fourth embodiment and the second embodiment is whether the labeled IPv4 traffic data and the unlabeled IPv6 traffic data included in the learning data are separated.

[0088] As shown in FIG. 9, the identification device 100 receives traffic data (FIG. 9(1)). Next, the identification device 100 uses the received traffic data to generate labeled IPv4 feature information and labeled IPv6 feature information as learning data (from FIG. 9(2-1) to (2-3)). In the fourth embodiment, the identification device 100 generates the labeled IPv4 feature information and the labeled IPv6 feature information as independent data groups, respectively.

[0089] The identification device 100 uses only the generated labeled IPv4 feature information as learning data to train the "Model (IPv4)" shown in FIG. 9(3-2) (FIG. 9(3-1)). Next, the identification device 100 performs additional training (fine-tuning) on the model (IPv4) that has been trained in the process of FIG. 9(3-1) using the generated labeled IPv6 feature information as learning data (FIG. 9(4-1), (4-2)). In addition to the additional training, the identification device 100 may generate a "Model (IPv4&IPv6)" by combining a small-scale model trained using the generated labeled IPv6 feature information as learning data with the model (IPv4).

[0090] The identification device 100 generates identification IPv6 feature information using the received traffic data related to the communication to be identified (FIG. 9(5)). Next, the identification device 100 executes an identification process based on the result obtained by inputting the generated identification IPv6 feature information into the model (IPv4&IPv6) (FIG. 9(6)). Then, the identification device 100 stores the result of the identification process related to the obtained IPv6 (FIG. 9(7)).

[0091] As described above, when the labeled IPv4 traffic data and the labeled IPv6 traffic data, which are teacher data, exist independently, the identification device 100 can learn a model using the common feature information generated from each traffic data. Then, the identification device 100 can perform identification processing based on the result obtained by inputting the common feature information generated from the IPv6 traffic data related to the communication to be identified into the model.

[0092] That is, by using the model learned using the common feature information, when there is even a small amount of data related to labeled IPv6 as teacher data that is independent of the data related to IPv4, the identification device 100 can effectively learn the model by using both the large amount of IPv4 traffic data and the labeled IPv6 traffic data. As a result, the identification device 100 can accurately perform the identification processing related to IPv6 using the learned model.

[0093] (The Fifth Embodiment) Next, as a fifth embodiment, an example of the learning process using the labeled IPv4 feature information, the unlabeled IPv6 feature information, and the labeled IPv6 feature information, and the detection process using the identification IPv6 feature information will be described with reference to FIG. 10.

[0094] The fifth embodiment is an example in which there is a large amount of labeled IPv4 traffic data, a large amount of unlabeled IPv6 traffic data, and a small amount of labeled IPv6 traffic data. Also, the labeled IPv4 traffic data, the unlabeled IPv6 traffic data, and the labeled IPv6 traffic data will be described as an example of existing as integrated data that is not separated but mixed.

[0095] That is, in the fifth embodiment, when there is labeled IPv6 traffic data related to malicious communication and unlabeled IPv6 traffic data that can be used as teacher data, by using all of the large amount of existing IPv4 traffic data, labeled IPv6 traffic data, and unlabeled IPv6 traffic data, it is an example of a process that enables effective identification of malicious communication.

[0096] As shown in FIG. 10, the identification device 100 receives traffic data ((1) in FIG. 10). Next, the identification device 100 uses the received traffic data to generate labeled IPv4 feature information, unlabeled IPv6 feature information, and labeled IPv6 feature information as learning data ((2-1) and (2-2) in FIG. 10).

[0097] The identification device 100 uses the generated labeled IPv4 feature information, unlabeled IPv6 feature information, and labeled IPv6 feature information as learning data to learn the "model (IPv4&IPv6)" shown in (3-2) of FIG. 10 and the "model (Domain)" shown in (3-3) of FIG. 10 ((3-1) in FIG. 10).

[0098] The identification device 100 generates identification IPv6 feature information using the traffic data related to the communication to be identified that has been received ((4) in FIG. 10). Next, the identification device 100 executes an identification process based on the result obtained by inputting the generated identification IPv6 feature information into the model ((5) in FIG. 10). Then, the identification device 100 stores the result of the identification process related to the obtained IPv6 ((6) in FIG. 10).

[0099] As described above, even when the IPv6 feature information that is the teacher data is mixed with the labeled IPv4 feature information and the unlabeled IPv6 feature information, the identification device 100 can train a model using the common feature information generated from the traffic data in which the data is mixed. Then, the identification device 100 can perform identification processing based on the result obtained by inputting the common feature information generated from the IPv6 traffic data related to the communication to be identified into the trained model.

[0100] That is, by using the model trained using the common feature information, when there is even a small amount of labeled IPv6 feature information that is the teacher data, the identification device 100 can effectively train the model by using all of the large amount of IPv4 traffic data, the labeled IPv6 traffic data, and the unlabeled IPv6 traffic data. As a result, the identification device 100 can accurately perform the identification processing related to IPv6 by using the trained model. Note that in the third embodiment, since the IPv6 feature information has a label, the model to be used can be the model shown in the first embodiment instead of a model such as DANN.

[0101] (Procedure of Processing by Identification Device 100) Hereinafter, the procedure of the processing realized by the identification device 100 according to the present embodiment will be described separately for "training processing" and "identification processing". First, "training processing" will be described with reference to FIG. 11. FIG. 11 is a flowchart showing an example of the training processing procedure according to the present embodiment.

[0102] The reception unit 131 receives training traffic data such as IPv4 traffic data and IPv6 traffic data (S101).

[0103] Here, when the traffic data for learning is IPv6 traffic data (Yes in S102), the feature generation unit 132 generates common feature information (IPv6 feature information) using the IPv6 traffic data (S103). On the other hand, when the traffic data for learning is not IPv6 traffic data but IPv4 traffic data (No in S102), the feature generation unit 132 generates common feature information (IPv4 feature information) using the IPv4 traffic data (S104).

[0104] The discriminator learning unit 133 learns the discriminator using the common feature information generated by the feature generation unit 132 (S105).

[0105] Here, when the predetermined learning end condition is not satisfied (No in S106), the identification device 100 returns to the previous step and continues the process. In this embodiment, an example of returning to the previous step before S101 is shown in FIG. 11. However, for example, when additional feature information is not generated, the process may return to before S105. Also, the learning end condition mentioned here may be an arbitrarily determined condition, for example, conditions such as whether the number of learning times or an index indicating the accuracy of the model exceeds a preset threshold value, etc.

[0106] On the other hand, when the predetermined learning end condition is satisfied (Yes in S106), the identification device 100 ends the process.

[0107] Next, the "identification process" will be described with reference to FIG. 12. FIG. 12 is a flowchart showing an example of the identification process procedure according to this embodiment.

[0108] The reception unit 131 receives traffic data to be identified, such as IPv4 traffic data or IPv6 traffic data (S201).

[0109] Here, when the traffic data for identification is IPv6 traffic data (Yes in S202), the feature generation unit 132 generates common feature information (identification IPv6 feature information) using the IPv6 traffic data (S203). On the other hand, when the traffic data for identification is not IPv6 traffic data but IPv4 traffic data (No in S202), the feature generation unit 132 can generate common feature information (identification IPv4 feature information) using the IPv4 traffic data (S204).

[0110] The identification unit 134 performs an identification process using the learned identifier learned by the identifier learning unit 133 (S205). Next, the output unit 135 outputs the result of the identification process (S206). Then, the identification device 100 ends the process.

[0111] (Effect) Hereinafter, the effects exhibited by the identification device 100 according to the present embodiment will be described. As described above, although there is a large amount of IPv4 traffic data based on the current communication protocol IPv4, since the implementation of malicious communication based on IPv6 is still small, it may be difficult to use labeled IPv6 traffic data related to malicious communication as teacher data.

[0112] Therefore, the feature generation unit 132 of the identification device 100 according to the present embodiment converts at least one of the IPv4 feature information and the IPv6 feature information so that the feature information extracted from the IPv4 traffic data and the feature information extracted from the IPv6 traffic data are common, and generates common feature information. Then, the identification unit 134 of the identification device 100 performs an identification process for communication related to IPv6 based on the result obtained by inputting the common feature information generated using the IPv6 traffic data related to the communication to be identified to the learned identifier. Therefore, according to the identification device 100 of the present embodiment, even when it is difficult to prepare teacher data for learning, an appropriate communication identification process can be executed.

[0113] That is, the identification device 100 can equivalently generate common feature information using either IPv4 traffic data or IPv6 traffic data as learning data. Therefore, the identification device 100 has the effect of generating common feature information according to the situation, purpose, etc. of performing learning processing and identification processing, enabling appropriate learning of an identifier and execution of identification processing using the identifier.

[0114] For example, when there is a large amount of labeled IPv4 traffic data and there is not enough labeled IPv6 traffic data, the items can be converted so that the IPv6 feature information has the same meaning as the IPv4 feature information, and common feature information can be generated to perform model learning. Therefore, the identification device 100 can minimize the conversion processing of feature information for learning. As a result, the identification device 100 can achieve efficiency improvement, speed increase, reduction of calculation amount, etc.

[0115] Note that the processing realized by the above-described identification device 100 can also be applied when the abundance amounts of IPv4 traffic data and IPv6 traffic data are reversed. For example, even when the migration from the current communication protocol IPv4 to IPv6 progresses and IPv4 traffic data becomes scarce in the future such that IPv6 is used as the mainstream communication protocol, the identification device 100 can perform learning of an identifier using a large amount of existing IPv6 traffic data to realize abnormal detection related to IPv4.

[0116] In addition, the identifier learning unit 133 learns an identifier for performing identification of malicious communication as an identification process related to IPv6 using, as common feature information, one or a combination of multiple of labeled IPv4 feature information, labeled IPv6 feature information, and unlabeled IPv6 feature information.

[0117] In this way, when there is not enough teacher data or when there are multiple pieces of teacher data but they are mixed, the identification device 100 can perform appropriate learning of the identifier according to various situations. Therefore, the identification device 100 has the effect of generating common feature information according to the situation, purpose, etc. of performing the learning process and the identification process, enabling the learning of an appropriate identifier and the execution of the identification process using the identifier.

[0118] Also, the identifier learning unit 133 identifies whether the communication based on IPv6 is malicious communication based on the result obtained by inputting the common feature information generated using the IPv6 traffic data to be identified into the learned identifier.

[0119] In this way, the identification device 100 also generates, as common feature information common to IPv4 and IPv6, the feature information generated from the traffic data related to the communication to be identified, enabling the identification of whether the communication to be received is malicious communication regardless of whether it is IPv4 or IPv6.

[0120] In addition, the identification device 100 is not limited to detecting malicious communication based on IPv6, but can also execute identification processing in a case where there is not enough teacher data related to IPv6, such as application identification using the traffic data of communication based on IPv6, but there is enough teacher data based on IPv4.

[0121] As described above, even when it is difficult to prepare a large amount of teacher data such as IPv6 traffic data, the identification device 100 according to the present embodiment enables detection of malicious communication based on the attacker's IPv6. That is, when there is no labeled IPv6 traffic data, the identification device 100 learns an identifier using a large amount of existing IPv4 traffic data, enabling identification processing of malicious communication. Further, when there is even a small amount of labeled IPv6 traffic data, the identification device 100 uses both the IPv6 traffic data and the IPv4 traffic data to realize more effective learning of the identifier and identification processing of malicious communication using the identifier.

[0122] Furthermore, the identification device 100 according to the present embodiment appropriately uses the common feature information generated using traffic data according to the situation during the learning process and the identification process, enabling appropriate learning processing and identification processing according to the priority and importance of the processing, the load status of the computer, etc. Therefore, the identification device 100 can reduce the load on the computer for learning processing and identification processing.

[0123] <Modification example> A modification example realized by the identification device 100 according to the present embodiment will be described below.

[0124] (Data, etc.) The names of models such as traffic data, feature information, common feature information, identifier, and identification model, the names of the functional units of the identification device 100, steps, processes, and the names of steps or processes used in the description of the above embodiment are merely examples and can be arbitrarily changed.

[0125] For example, the traffic data DB 121 stores, as traffic data, items such as No, time, source IP address, destination IP address, protocol, source port number, destination port number, TCP flag, number of bytes, and number of packets. However, the content shown in FIG. 4 is merely an example and is not limited thereto. Further, since the above-described traffic data is information extracted from packet information collected from the network at an arbitrary time, the above-described items may be merely the minimum information included. Also, in a large-scale network such as an ISP (Internet Service Provider), only a part of the packets may be collected by sampling, and the payload may not be acquired.

[0126] For example, the feature information DB 122 stores, as feature information generated using the traffic data generated by the feature generation unit 132, information related to the items shown in FIG. 5. However, the content shown in FIG. 5 is merely an example, and the feature information DB 122 is not limited thereto and can store items included in the range of feature information. For example, the model DB 123 stores a predetermined identification model, but is not limited to the above-described DANN or the like, and can store any learning model capable of executing identification processing.

[0127] (Flowchart, etc.) Each step in a flowchart or the like may be implemented by being swapped within a non-contradictory range, or there may be steps that are not implemented. Also, conjunctions such as "next", "subsequently", "furthermore", "at this time", and "at this moment" in the description of the flowchart do not limit the order or timing of the implementation of the processing in the flowchart.

[0128] (System) Regarding the processing procedures, control procedures, specific names, and information including various data and parameters shown in the above documents and drawings, they can be arbitrarily changed unless otherwise specified.

[0129] Moreover, each component of each illustrated device is a functional concept and does not necessarily have to be physically configured as shown in the figure. That is, the specific forms of distribution and integration of each device are not limited to those shown in the figure. In other words, all or part of it can be functionally or physically distributed and integrated in any unit according to various loads, usage situations, etc.

[0130] <Hardware Configuration> Each component of each illustrated device is a functional concept and does not necessarily have to be physically configured as shown. That is, the specific forms of distribution and integration of each device are not limited to those shown, and all or part of it can be functionally or physically distributed and integrated in any unit according to various loads, usage situations, etc. Furthermore, each processing function performed by each device can be realized in whole or in any part by a CPU and a program analyzed and executed by the CPU, or can be realized as hardware by wired logic.

[0131] Also, among the various processes described in this embodiment, all or part of the processes described as being automatically performed can be manually performed by known methods. In addition, the processing procedures, control procedures, specific names, and information including various data and parameters shown in the drawings can be arbitrarily changed unless otherwise specified.

[0132] <Program> As one embodiment, various devices constituting the identification device 100 can be implemented by installing an identification program on a desired computer as package software or online software. For example, by causing the information processing device to execute the above-described identification program, it can function as various devices constituting the identification device 100. The information processing device mentioned here includes desktop or notebook personal computers. In addition, other information processing devices include mobile communication terminals such as smartphones and mobile phones, and further slate terminals such as PDAs (Personal Digital Assistants) are included in this category.

[0133] FIG. 13 is a diagram showing an example of a computer that realizes the identification device according to the present embodiment. The computer 1000 has, for example, a memory 1010 and a CPU 1020. The computer 1000 also has a hard disk drive interface 1030, a disk drive interface 1040, a serial port interface 1050, a video adapter 1060, and a network interface 1070. These components are connected by a bus 1080.

[0134] The memory 1010 includes a ROM (Read Only Memory) 1011 and a RAM 1012. The ROM 1011 stores a boot program such as a BIOS (Basic Input Output System), for example. The hard disk drive interface 1030 is connected to the hard disk drive 1090. The disk drive interface 1040 is connected to the disk drive 1100. A removable storage medium such as a magnetic disk or an optical disk is inserted into the disk drive 1100, for example. The serial port interface 1050 is connected to, for example, a mouse 1110 and a keyboard 1120. The video adapter 1060 is connected to, for example, a display 1130.

[0135] The hard disk drive 1090 stores, for example, an OS (Operating System) 1091, application programs 1092, program modules 1093, and program data 1094. That is, the programs that define the respective processes of the various devices constituting the identification device 100 are implemented as program modules 1093 in which computer-executable code is described. The program modules 1093 are stored, for example, in the hard disk drive 1090. For example, program modules 1093 for executing processes similar to the functional configurations of the various devices constituting the identification device 100 are stored in the hard disk drive 1090. Note that the hard disk drive 1090 may be replaced by an SSD (Solid State Drive).

[0136] Also, the setting data used in the processes of the above-described embodiments is stored as program data 1094, for example, in the memory 1010 or the hard disk drive 1090. Then, the CPU 1020 reads out the program modules 1093 and program data 1094 stored in the memory 1010 or the hard disk drive 1090 into the RAM 1012 as necessary, and executes the processes of the above-described embodiments.

[0137] Note that the program modules 1093 and program data 1094 are not limited to being stored in the hard disk drive 1090, and may be stored, for example, in a removable storage medium and read by the CPU 1020 via a disk drive 1100 or the like. Alternatively, the program modules 1093 and program data 1094 may be stored in another computer connected via a network (LAN, WAN (Wide Area Network), etc.). Then, the program modules 1093 and program data 1094 may be read by the CPU 1020 from the other computer via the network interface 1070.

[0138] <Others> As described above, although this embodiment has been explained, this embodiment is not limited by the description and drawings that form part of the disclosure. That is, all other embodiments, examples, operation techniques, etc. made by those skilled in the art based on this embodiment are included in the scope of this embodiment.

Explanation of Signs

[0139] 100 Identification device 110 Communication unit 120 Storage unit 121 Traffic data DB 122 Feature information DB 122a Labeled IPv4 feature information 122b Unlabeled IPv6 feature information 122c Labeled IPv6 feature information 122d Identification-use IPv6 feature information 123 Model DB 124 Identification result DB 130 Control unit 131 Reception unit 132 Feature generation unit 1321 IPv4 feature generation unit 1322 IPv6 feature generation unit 133 Identifier learning unit 134 Identification unit 135 Output unit

Claims

1. A feature generation unit that converts at least one of the feature information of the IPv4 and the feature information of the IPv6 so that the feature information extracted from the traffic data of the communication based on IPv4 and the feature information extracted from the traffic data of the communication based on IPv6 are common, and generates common feature information; An identifier learning unit that learns an identifier for performing an identification process on communication based on IPv6 using the common feature information generated by the feature generation unit; An identification unit that performs an identification process on the communication based on IPv6 based on a result obtained by inputting the common feature information generated using the traffic data of the communication based on IPv6 to be identified to the learned identifier; An identification device, characterized by comprising the above.

2. The identifier learning unit: As the common feature information, one or a combination of a plurality of the feature information of the traffic data of the communication based on IPv4 with a label, the feature information of the traffic data of the communication based on IPv6 with a label, and the feature information of the traffic data of the communication based on IPv6 without a label are used to learn the identifier for performing the identification of malicious communication, which is the identification process on the communication based on IPv6. The identification device according to claim 1, characterized by the above.

3. The identification unit: Based on a result obtained by inputting the common feature information generated using the traffic data of the communication based on IPv6 to be identified to the learned identifier, it identifies whether the communication based on IPv6 is malicious communication. The identification device according to claim 1 or 2, characterized by the above.

4. An identification method executed by an identification device, comprising: A feature generation step of converting at least one of the feature information of the IPv4 and the feature information of the IPv6 so that the feature information extracted from the traffic data of the communication based on IPv4 and the feature information extracted from the traffic data of the communication based on IPv6 are common, and generating common feature information; An identifier learning step of learning an identifier for performing an identification process on communication based on IPv6 using the common feature information generated by the feature generation step; An identification step of performing identification processing on the IPv6-based communication based on the result obtained by inputting the common feature information generated using the traffic data of the IPv6-based communication to be identified into the learned identifier; An identification method characterized by including the above.

Citation Information

Patent Citations

  • Detection device, detection method, and detection program

    JP6749873B2