Scan-to-Attack Correlation Intelligence
Previous day 00:00-24:00 JST
Correlated Sessions
Honey attack sessions with correlation docs
Attack Source IPs
--
Unique source IPs
NICT Scan Matched
--
--
Attack-Port Scan Seen
--
--
Median Scan→Attack Lag
--
attack destination port scan
Top Scan Pattern
--
Seq / Mirai Signal
--
--
Strong Precursors
--
--
1. Scan Pattern → Attack Port → Attack Method
Sankey / relationship flow
2. Scan→Attack Time Lag
Histogram
3. Pre-Attack Scan Dest Port → Attack Dest Port
NICT scan observed before honeypot attack
This matrix shows the relationship between NICT darknet scan destination ports
observed before the attack and honeypot destination ports that were actually
attacked later. Darker cells indicate stronger scan-to-attack correlation.
4. Correlation Signal Trend
Hourly trend
5. Top Scan-to-Attack Relations
Explainable evidence
6. Analyst Drilldown Sessions
Click row to inspect details
セッション行をクリックすると、scan pattern / attack method / observed commands / correlation tags が表示されます。