| CPC H04L 63/1416 (2013.01) [H04L 63/1441 (2013.01)] | 11 Claims |

|
1. An information processing device comprising:
processing circuitry to:
extract, from a database of true positive accesses, a true positive access,
wherein each of the true positive accesses is an access that is
known prior to being processed by an access detection system to be an access aimed to attack, and
detected by the attack detection system to be an access aimed to attack;
extract, from a database of true negative accesses, a true negative access,
wherein each of the true negative accesses is an access that is
known prior to being processed by the access detection system to be a normal access, and
determined by the attack detection system to be a normal access; and
modify a feature of the extracted true positive access by using a feature of the extracted true negative access to increase the likelihood that the access detection system will determine the modified true positive access to be a normal access,
wherein the processing circuitry modifies the feature of the true positive access by using the feature of the true negative access and data of a corresponding feature of a false positive access,
wherein the false positive access is an access that is
known prior to being processed by an access detection system to be a normal access, and
detected by the attack detection system to be an access aimed to attack.
|