Detection device, detection method, and detection program
Abstract:
A detection device includes processing circuitry configured to identify candidate bots using flow data, use the flow data to count a number of the candidate bots communicating with servers, for each of the servers, and determine servers communicating with a predetermined number or more of the candidate bots among the servers to be malicious servers, and detect candidate bots communicating with the malicious servers that are determined among the candidate bots to be malicious bots.
Public/Granted literature
Information query
Patent Agency Ranking
0/0