| CPC G06F 21/56 (2013.01) [G06F 18/10 (2023.01); G06F 18/241 (2023.01); G06F 18/2431 (2023.01); G06N 20/00 (2019.01)] | 7 Claims |

|
1. A data classification device, comprising:
a memory; and
a processor coupled to the memory and programmed to execute a process comprising:
receiving an input of known data, the known data being data already classified into a class and a subclass subordinate to the class;
extracting features from the known data, wherein the features which are extracted are features shared between the subclasses in the class;
determining whether classification of the known data belonging to the class into a subclass existing within the subclasses using a feature of the features which are extracted is a success or failure;
outputting the feature if it is determined that the feature causes the classification to fail; and
classifying classification target data into a class indicating malicious or not using the output feature for detecting an attack and notifying a terminal which sent the classification target data of a result of the classifying.
|