WO2017061469A1 - 特定システム、特定装置および特定方法 - Google Patents
特定システム、特定装置および特定方法 Download PDFInfo
- Publication number
- WO2017061469A1 WO2017061469A1 PCT/JP2016/079620 JP2016079620W WO2017061469A1 WO 2017061469 A1 WO2017061469 A1 WO 2017061469A1 JP 2016079620 W JP2016079620 W JP 2016079620W WO 2017061469 A1 WO2017061469 A1 WO 2017061469A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- terminal
- infection
- infected
- state
- information
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1408—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
- H04L63/1416—Event detection, e.g. attack signature detection
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1408—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
- H04L63/1425—Traffic logging, e.g. anomaly detection
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F17/00—Digital computing or data processing equipment or methods, specially adapted for specific functions
- G06F17/10—Complex mathematical operations
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/55—Detecting local intrusion or implementing counter-measures
- G06F21/56—Computer malware detection or handling, e.g. anti-virus arrangements
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L41/00—Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
- H04L41/08—Configuration management of networks or network elements
- H04L41/0803—Configuration setting
- H04L41/0813—Configuration setting characterised by the conditions triggering a change of settings
- H04L41/082—Configuration setting characterised by the conditions triggering a change of settings the condition being updates or upgrades of network functionality
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L41/00—Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
- H04L41/28—Restricting access to network management systems or functions, e.g. using authorisation function to access network configuration
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1441—Countermeasures against malicious traffic
- H04L63/145—Countermeasures against malicious traffic the attack involving the propagation of malware through the network, e.g. viruses, trojans or worms
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L2463/00—Additional details relating to network architectures or network communication protocols for network security covered by H04L63/00
- H04L2463/146—Tracing the source of attacks
Definitions
- the present invention relates to a specific system, a specific device, and a specific method.
- malware malicious software
- malicious software such as malicious software and program code created with the intention of performing illegal and harmful operations such as computer viruses, spyware, and bots, known as malware
- Attack Graph is a technology that evaluates network threats by collecting network system configuration, terminal OS / application information, and statically calculating intrusion route candidates of external attackers.
- the conventional technology has a problem in that it is impossible to appropriately identify a terminal that is suspected of being infected or an infected terminal that may be infected in the future.
- targeted attacks and APT attacks have the feature of expanding intrusion or infection to multiple terminals in the same network system via unauthorized intrusion or malware-infected terminals, which are detected by security devices Even if a countermeasure such as blocking is performed on the infected terminal, if there is another undetected infected terminal, the attack is continued through the terminal.
- a countermeasure such as blocking
- a specification system of the present invention includes a configuration information storage device that stores information about a terminal in a network, and a specification device that specifies a state of the terminal.
- the configuration information storage device stores connection information indicating a connection relationship between terminals in the network, and the specific device detects security related to unauthorized intrusion into the network or terminal infection.
- the detection information is received from the device, the state specifying unit for specifying the state of the terminal from the information of the terminal included in the detection information and the activity content of the terminal, and the state of the terminal is infected with malware by the state specifying unit If it is identified as a state, the detection information is included in the detection information based on the connection information stored by the configuration information storage device.
- the infected terminal may infect a terminal located on a route that may be used for unauthorized intrusion or terminal infection in the future. It has the infection specific part to identify with the candidate of an infected terminal, It is characterized by the above-mentioned.
- the specific device of the present invention receives detection information related to detection from a security device that detects activity related to unauthorized intrusion into a network including a plurality of terminals or infection of the terminals, and information on the terminals included in the detection information and
- the state specifying unit that specifies the state of the terminal from the activity content of the terminal and the state specifying unit specifies that the state of the terminal is infected with malware
- connection between terminals in the network Based on the connection information indicating the relationship, a terminal that is suspected of being infected before reaching the terminal activity content included in the detection information is identified, and the infected terminal may be used for unauthorized intrusion or terminal infection in the future. It is characterized by having an infection specifying unit for specifying a candidate for an infected terminal that may infect a terminal located on the route.
- the identification method of the present invention is a identification method executed by the identification device, and receives detection information related to detection from a security device that detects activities related to unauthorized intrusion into a network including a plurality of terminals or terminal infection. Then, a state specifying step for specifying the state of the terminal from the information on the terminal included in the detection information and the activity content of the terminal, and the state specifying step is specified as a state in which the terminal is infected with malware. In such a case, based on the connection information indicating the connection relationship between the terminals in the network, the terminal that is suspected of being infected before reaching the activity content of the terminal included in the detection information is identified. Infection identification that identifies a candidate for an infected terminal that may infect a terminal located on a route that may be used for unauthorized intrusion or terminal infection Characterized in that it contains a degree.
- FIG. 1 is a diagram illustrating an example of a configuration of a specific system according to the first embodiment.
- FIG. 2 is a diagram illustrating an example of terminal connection information stored in the configuration information storage device according to the first embodiment.
- FIG. 3 is a diagram illustrating an example of terminal state information stored in the configuration information storage device according to the first embodiment.
- FIG. 4 is a diagram for explaining the process of specifying the state of the terminal in the specifying apparatus according to the first embodiment.
- FIG. 5 is a diagram for explaining a process for identifying a terminal suspected of being infected and a candidate for an infected terminal in the identifying apparatus according to the first embodiment.
- FIG. 6 is a diagram for explaining how to deal with a terminal whose infection is confirmed in the attack countermeasure apparatus according to the first embodiment.
- FIG. 1 is a diagram illustrating an example of a configuration of a specific system according to the first embodiment.
- FIG. 2 is a diagram illustrating an example of terminal connection information stored in the configuration information storage device according to
- FIG. 7 is a diagram for explaining a process for identifying a terminal suspected of being infected and a candidate for an infected terminal in the identifying apparatus according to the first embodiment.
- FIG. 8 is a diagram for explaining how to deal with a terminal having a high possibility of infection in the attack countermeasure apparatus according to the first embodiment.
- FIG. 9 is a flowchart showing the flow of processing of the specific apparatus according to the first embodiment.
- FIG. 10 is a sequence diagram showing a flow of processing of the specific system according to the first embodiment.
- FIG. 11 is a diagram illustrating a computer that executes a specific program.
- FIG. 1 is a diagram illustrating an example of a configuration of a specific system according to the first embodiment.
- the identification system 1 includes a identification device 10 that identifies a terminal that is suspected of being infected or a terminal that may be infected in the future, a security device 20 that monitors communication, and a terminal 50A in the network.
- Configuration information storage device 30 for storing information about 50E, attack countermeasure device 40 for monitoring and restricting communication, a plurality of terminals 50A to 50E, NW (Network) equipment 60 such as a firewall, router, switch, network It has the mail server 70 which provides a service.
- NW Network equipment
- the NW device 60 and the mail server 70 are connected to the Internet 80. Further, it is assumed that a network including a plurality of terminals 50A to 50E permits only communication necessary for business execution using a firewall ACL (Access Control List) or the like.
- ACL Access Control List
- FIG. 1 communication permitted by the firewall and logical communication of service connectivity (email, HTTP proxy, authentication system, etc.) are shown as device connection arrows.
- the number of each apparatus and function shown in FIG. 1 is an example to the last, and is not restricted to this.
- a plurality of terminals 50A to 50E are described without distinction, they are appropriately described as terminals 50.
- the security device 20 monitors the communication of each of the terminals 50A to 50E and the NW device 60 in the network, and transmits detection information to the specific device 10 when detecting unauthorized communication or the like.
- the detection information includes information on the terminal 50 that performed unauthorized communication, activity contents of the terminal 50, and the like.
- the configuration information storage device 30 stores connection information indicating a connection relationship between terminals in the network.
- the configuration information storage device 30 includes a “terminal name” indicating the name of the terminal, an “IP address” indicating the IP address of the terminal, and a “MAC address” indicating the MAC address of the terminal.
- the “connection information” indicating the connection relationship between the terminals is stored in association with each other.
- the configuration information storage device 30 includes a terminal name “terminal 1”, an IP address “10.1.1.1”, and a MAC address “70: 58: 12: 27: B7: 17”. And the connection information “mail server ⁇ terminal 1, terminal 1 ⁇ terminal 3” are stored in association with each other. This is because the IP address of the terminal 1 is “10.1.1.1”, the MAC address is “70: 58: 12: 27: B7: 17”, and the mail server 70 and the terminal 3 are connected. It means that there is.
- the configuration information storage device 30 includes terminal status information indicating the status of the terminal 50 specified by the status specifying unit 11 described later, a terminal suspected of being infected specified by the infection specifying unit 12 described later, and the infected terminal. Memorize the candidates. For example, as illustrated in FIG. 3, the configuration information storage device 30 includes a “terminal name” indicating the name of the terminal, a “terminal status” indicating the terminal status, and a “suspicion of infection score” indicating the degree of suspected infection. And an “infection risk score” indicating the degree of risk of infection in association with each other.
- the terminal status includes “suspected infection”, “infection”, “non-infection”, “infection spread candidate”, and “attacked”.
- “Suspected infection” is a state in which there is a suspicion of infection.
- “Infection” is a state in which infection is confirmed.
- “Non-infectious” is an uninfected state.
- the “infection extension candidate” is a state in which there is a possibility of infection in the future.
- “Attacked” is a state of being attacked by an infected terminal or the like. It is assumed that the higher the value of the suspected infection score, the stronger the suspicion of infection, and the higher the value of the infection risk score, the higher the possibility of infection.
- the configuration information storage device 30 sets the terminal name “terminal 1”, the terminal state “suspected infection”, the suspected infection score “0.33”, and the infection risk score “0.1”. Store in association with each other. This means that the current state of the terminal 1 is a suspected infection state, the suspected infection score is “0.33”, and the infection risk score is “0.1”.
- terminal name “terminal 1” corresponds to the terminal 50A in FIG. 1
- terminal name “terminal 2” corresponds to the terminal 50B in FIG. 1
- terminal name “terminal 3” 1 corresponds to the terminal 50C in FIG. 1
- terminal name “terminal 4” corresponds to the terminal 50D in FIG. 1
- terminal name “terminal 5” corresponds to the terminal 50E in FIG.
- attack countermeasure device 40 applies to an infected terminal specified by the state specifying unit 11 described later and a terminal having a high suspicion of infection among terminals suspected of being infected specified by the infection specifying unit 12 described later. , Block communication, monitor communication or restrict communication.
- the identifying device 10 identifies the state of the terminal, and identifies a terminal that is suspected of being infected and a terminal that is likely to be infected in the future. As illustrated in FIG. 1, the specifying device 10 includes a state specifying unit 11 and an infection specifying unit 12.
- the state specifying unit 11 receives detection information from the security device 20 that detects an activity related to unauthorized intrusion into the network or infection of the terminal 50, and based on the information on the terminal 50 and the activity content of the terminal included in the detection information.
- the state of the terminal 50 is specified. For example, when the detection information is information related to communication, the state specifying unit 11 specifies the state of the terminal 50 corresponding to the transmission source address and the transmission destination address of the communication, and the detection information is information related to the terminal 50. In the case, the state of the terminal 50 is specified.
- the state specifying unit 11 detects that the detection information “terminal 4” communicates with “terminal 5” and “terminal 4” attacks “terminal 5”.
- the state of “terminal 4” corresponding to the transmission source address and “terminal 5” corresponding to the transmission destination address is specified as information related to communication.
- the state specifying unit 11 specifies the state of “terminal 3” as information regarding the terminal 50. .
- FIG. 4 is a diagram for explaining the process of specifying the state of the terminal in the specifying apparatus according to the first embodiment.
- the numbers next to the terminals 50A to 50E are numerical examples of infection suspect scores and infection risk scores of the terminals.
- the suspected infection numerical value is “0” in all the terminals 50.
- the infection risk is set according to a certain rule in the terminal 50 having connectivity with the Internet 80.
- “0.1” is added as a numerical value to a terminal that is directly connected to the Internet 80 and the infected terminal, but is not limited to this, and the numerical value is determined.
- the method can be set arbitrarily.
- the terminal 50C having the terminal name “terminal 3” is infected with malware, and C & C communication, which is communication performed with a server of an external network to control the infected terminal from the outside, is installed in the network.
- C & C communication which is communication performed with a server of an external network to control the infected terminal from the outside.
- the processing when the security device 20 detects will be described.
- the state specifying unit 11 of the specifying device 10 determines the terminal 50 ⁇ / b> C based on the information that the terminal 3 included in the detection information received from the security device 20 has performed C & C communication with the outside. The state of is identified.
- the state specifying unit 11 detects C & C communication of the terminal 3, it can be determined that the terminal 3 is infected with malware, so the state of the terminal 3 is specified as an infected state.
- the infection suspicion score is set to “1.0”.
- the infection specifying unit 12 is included in the detection information based on the connection information stored by the configuration information storage device 30.
- the terminal 50 that is suspected of being infected before reaching the content of the activity of the terminal 50 to be identified is identified, and the infected terminal 50 can infect the terminal 50 that is located on a route that may be used for unauthorized intrusion or terminal infection in the future. To identify potential infected terminals.
- the infection identification unit 12 identifies the terminal 50 included in the communication path that can be the infection path of the infected terminal identified by the state identification unit 11 as the terminal 50 that is suspected of being infected, and the number of communication paths that can be the infection path. And a numerical value indicating the degree of suspicion of infection for each terminal 50 suspected of infection based on the past terminal state.
- the infection identification unit 12 may infect the terminal 50 that can be infected from the infected terminal using the connection information starting from the infected terminal identified by the state identification unit 11. Identified as a candidate.
- FIG. 5 is a diagram for explaining a process for identifying a terminal suspected of being infected and a candidate for an infected terminal in the identifying apparatus according to the first embodiment.
- the state identification unit 11 identifies the state of “terminal 3” as an infection state and the infection suspicion score is “1.0”.
- the infection identification unit 12 of the identification device 10 first identifies the infection route of the terminal 3 using the connection information of the configuration information storage device 30 when the state of the “terminal 3” included in the detection information is identified. .
- infection route candidates to the terminal 3 there are a total of three routes: an attack directly performed from the Internet 80 via the NW device 60, an attack via the terminal 1, or an attack via the terminal 2. Conceivable.
- the infection suspect score to be added from the number “3” of communication routes that can be infection routes is set to “0.33 (1/3)” and added to the past infection suspect scores of the terminal 1 and the terminal 2 to
- the infection suspicion score which is a numerical value indicating the degree of suspicion, is calculated.
- the allocation of infection suspicion scores when there are multiple infection routes we explained the case of evenly allocating in units of routes, but weighted allocation using statistical information is also possible, and the numerical value determination method Is not limited to this.
- the infection identification unit 12 identifies a candidate for the next infection spread destination terminal from the infected terminal and the terminal 50 suspected of being infected.
- the terminal 5 that is connected to the terminal 3 can be infected starting from the terminal 3 that is the infected terminal, and the terminal 5 is identified as a candidate for the infection spread destination terminal and the infection risk score is “0. Add 1 ”.
- the infection suspect score of the terminal 1 and the terminal 2 is “0.33”
- the terminal 4 that can spread the infection from the terminal 2 is multiplied by “0.1” to “0.33”
- the third decimal point The score “0.03” rounded down is added to the infection risk score.
- the infection risk score of the terminal 4 is “0.13”.
- FIG. 6 is a diagram for explaining how to deal with a terminal whose infection is confirmed in the attack countermeasure apparatus according to the first embodiment.
- the attack countermeasure device 40 determines a countermeasure for the terminal 3 when the infection suspect score of the terminal 3 exceeds a first threshold (for example, “0.9”). As illustrated in FIG. 6, since the suspected infection score of the terminal 3 is “1.0” and exceeds the first threshold value, it is determined to deal with the terminal 3. In the example of FIG. 6, since the terminal 3 is a terminal for which infection has been confirmed, as the content of the countermeasure, the terminal 3 is isolated and communication related to the terminal 3 is blocked.
- a first threshold for example, “0.9”.
- FIG. 7 is a diagram for explaining a process for identifying a terminal suspected of being infected and a candidate for an infected terminal in the identifying apparatus according to the first embodiment.
- FIG. 8 is a diagram for explaining how to deal with a terminal having a high possibility of infection in the attack countermeasure apparatus according to the first embodiment.
- the state specifying unit 11 of the specifying device 10 specifies the states of the terminal 4 and the terminal 5 based on the detection information received from the security device 20 (attack from the terminal 4 to the terminal 5). To do.
- the state of the terminal 4 is identified as an infectious state, and a suspected infection score “1.0” is added to the terminal 4, and the infection suspect score “1.0” of the terminal 4 is set.
- the infection suspicion score to be added from the number “2” of communication paths that can be infection routes is set to “0.5 (1/2)”, and the infection suspicion score of the terminal 2 located on the infection route candidate is “0. 5 ”is added. As a result, the infection suspicion score of the terminal 2 is “0.83”.
- the state of the terminal 5 is identified as the attacked state, and here, "0.5” is added to the infection suspect score, and the infection risk Add “1.0” to the score.
- the infection suspicion score of the terminal 5 is “0.5”
- the infection risk score is “1.1”.
- the attack countermeasure device 40 performs communication monitoring and communication as a countermeasure for the terminal 2. Determine limits. As illustrated in FIG. 8, since the suspected infection score of the terminal 2 is “0.83” and exceeds the second threshold value, it is determined to deal with the terminal 2. In the example of FIG. 8, since the terminal 2 is a terminal that has a high possibility of being infected, the contents of countermeasures include communication monitoring and countermeasures for communication restriction. In this way, by performing communication monitoring and communication restriction on a terminal that is highly likely to be infected, the spread of infection to a new terminal 50 when the terminal 2 is infected, and from the terminal 2 External C & C communication connection and the like can be prevented.
- the second threshold for example, “0.7”
- the specific device 10 every time the security device 20 detects an attack, as described above, the specific device 10 performs a process of specifying a terminal that is suspected of being infected or a terminal that is likely to be infected in the future.
- the candidate of the suspected infection terminal is identified, and the infected terminal other than the detected terminal is identified and calculated by, for example, accumulating the number of times the candidate terminal has become a candidate and the information quantifying the suspected infection.
- infection it is possible to expand the invasion and reduce the occurrence of damage.
- FIG. 9 is a flowchart showing the flow of processing of the specific apparatus according to the first embodiment.
- the state specifying unit 11 of the specifying device 10 receives the detection information from the security device 20 (Yes in Step S101), the state specifying unit 11 determines the information from the information on the terminal 50 and the activity content of the terminal included in the detection information. The state of the terminal 50 is specified (step S102).
- the infection specifying unit 12 of the specifying device 10 refers to the connection information stored in the configuration information storage device 30 when the state specifying unit 11 specifies that the state of the terminal 50 is infected with malware. Then, it is determined whether there is a terminal connected to the infected terminal (step S103).
- the infection identification unit 12 of the identification device 10 determines that there is no terminal connected to the infected terminal (No at Step S103)
- the infection identification unit 12 updates the state information of the terminal in the configuration information storage device 30. (Step S105), the process ends.
- each terminal 50 connected to the infected terminal reaches the infected terminal.
- the terminal 50 on the route is identified as the suspected infection terminal, and the terminal located ahead of the infected terminal is identified as the infection candidate terminal (step S104).
- the state information of the terminal of the configuration information storage device 30 is updated (step S105), and the process ends.
- FIG. 10 is a sequence diagram showing a flow of processing of the specific system according to the first embodiment.
- the security device 20 when the security device 20 detects unauthorized communication or the like (step S201), the security device 20 transmits detection information to the specific device 10 (step S202).
- the specifying device 10 specifies the state of the terminal 50 using the detection information (step S203). Specifically, the specifying device 10 specifies the state of the terminal 50 from the information of the terminal 50 included in the detection information and the activity content of the terminal.
- the specific apparatus 10 requests
- the identifying device 10 refers to the requested connection information (step S205), and for each terminal 50 connected to the infected terminal, identifies the terminal 50 on the path leading to the infected terminal as a suspected terminal, A terminal located ahead of the infected terminal is identified as an infection candidate terminal (step S206). Thereafter, the identification device 10 updates the state information of the terminal in the configuration information storage device 30 (step S207) and ends the process.
- the specific device 10 receives the detection information from the security device 20 that detects the activity related to the unauthorized intrusion into the network or the infection of the terminal 50, and the terminal included in the detection information
- the state of the terminal 50 is specified from the information of 50 and the activity content of the terminal 50.
- the specifying device 10 uses the connection information stored in the configuration information storage device 30 as detection information.
- the terminal 50 that is suspected of being infected before reaching the activity content of the included terminal 50 is identified, and the infected terminal 50 infects the terminal 50 that is located on a route that may be used for unauthorized intrusion or terminal infection in the future. Identify potential infected terminal candidates. For this reason, it is possible not only to detect an infected terminal, but also to identify a terminal that is suspected of being infected or an infected terminal that may be infected in the future.
- the specific device 10 when the specific device 10 detects an event related to a target-type attack or an APT attack, the specific device 10 is not only a detected terminal, but also a candidate for a terminal that is a route to the detected terminal or an intrusion / infection destination terminal It is possible to identify such terminals, and it is possible to take measures such as strengthening monitoring of these terminals, restricting communication, and blocking communication.
- each component of each illustrated apparatus is functionally conceptual, and does not necessarily need to be physically configured as illustrated.
- the specific form of distribution / integration of each device is not limited to that shown in the figure, and all or a part thereof may be functionally or physically distributed or arbitrarily distributed in arbitrary units according to various loads or usage conditions. Can be integrated and configured.
- the functions of the state specifying unit 11 and the infection specifying unit 12 of the specifying device 10 different devices may have the respective functions.
- the specific device 10 may store information in the configuration information storage device 30 or may have the function of the attack countermeasure device 40.
- all or any part of each processing function performed in each device may be realized by a CPU and a program analyzed and executed by the CPU, or may be realized as hardware by wired logic.
- the specifying device 10 can be implemented by installing a specific program for executing the above specific processing as package software or online software on a desired computer.
- the information processing apparatus can be caused to function as the specific apparatus 10 by causing the information processing apparatus to execute the above specific program.
- the information processing apparatus referred to here includes, for example, a desktop or notebook personal computer.
- a terminal device used by a user can be used as a client, and the client can be implemented as a server device that provides services related to the specific processing to the client.
- the identification device 10 is implemented as a server device that not only detects an infected terminal, but also provides a processing service that identifies a terminal that is suspected of being infected or a candidate for an infected terminal that may be infected in the future.
- the specific device 10 may be implemented as a Web server, or may be implemented as a cloud that provides a service related to the above specific processing by outsourcing.
- FIG. 11 is a diagram illustrating a computer that executes a specific program.
- the computer 1000 includes, for example, a memory 1010 and a CPU (Central Processing Unit) 1020.
- the computer 1000 also includes a hard disk drive interface 1030, a disk drive interface 1040, a serial port interface 1050, a video adapter 1060, and a network interface 1070. These units are connected by a bus 1080.
- the memory 1010 includes a ROM (Read Only Memory) 1011 and a RAM (Random Access Memory) 1012.
- the ROM 1011 stores a boot program such as BIOS (Basic Input Output System).
- BIOS Basic Input Output System
- the hard disk drive interface 1030 is connected to the hard disk drive 1031.
- the disk drive interface 1040 is connected to the disk drive 1041.
- a removable storage medium such as a magnetic disk or an optical disk is inserted into the disk drive 1041.
- the serial port interface 1050 is connected to a mouse 1051 and a keyboard 1052, for example.
- the video adapter 1060 is connected to the display 1061, for example.
- the hard disk drive 1031 stores, for example, an OS 1091, an application program 1092, a program module 1093, and program data 1094. That is, a program that defines each process of the specific device 10 is implemented as a program module 1093 in which a code executable by a computer is described.
- the program module 1093 is stored in the hard disk drive 1031, for example.
- a program module 1093 for executing processing similar to the functional configuration in the specific device 10 is stored in the hard disk drive 1031.
- the hard disk drive 1031 may be replaced by an SSD (Solid State Drive).
- the setting data used in the processing of the above-described embodiment is stored as program data 1094 in, for example, the memory 1010 or the hard disk drive 1031. Then, the CPU 1020 reads the program module 1093 and the program data 1094 stored in the memory 1010 and the hard disk drive 1031 to the RAM 1012 as necessary, and executes them.
- the program module 1093 and the program data 1094 are not limited to being stored in the hard disk drive 1031, but may be stored in, for example, a removable storage medium and read out by the CPU 1020 via the disk drive 1041 or the like. Alternatively, the program module 1093 and the program data 1094 may be stored in another computer connected via a network (LAN (Local Area Network), WAN (Wide Area Network), etc.). Then, the program module 1093 and the program data 1094 may be read by the CPU 1020 from another computer via the network interface 1070.
- LAN Local Area Network
- WAN Wide Area Network
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- General Engineering & Computer Science (AREA)
- Computer Hardware Design (AREA)
- Signal Processing (AREA)
- Computer Networks & Wireless Communication (AREA)
- Theoretical Computer Science (AREA)
- Physics & Mathematics (AREA)
- Software Systems (AREA)
- Computing Systems (AREA)
- General Physics & Mathematics (AREA)
- Virology (AREA)
- Health & Medical Sciences (AREA)
- General Health & Medical Sciences (AREA)
- Mathematical Physics (AREA)
- Data Mining & Analysis (AREA)
- Databases & Information Systems (AREA)
- Pure & Applied Mathematics (AREA)
- Mathematical Optimization (AREA)
- Mathematical Analysis (AREA)
- Computational Mathematics (AREA)
- Algebra (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
- Computer And Data Communications (AREA)
Abstract
Description
以下の実施の形態では、第一の実施の形態に係る特定システムの構成、特定装置および特定システムの処理の流れを順に説明し、最後に第一の実施の形態による効果を説明する。
図1は、第一の実施の形態に係る特定システムの構成の一例を示す図である。第一の実施の形態に係る特定システム1は、感染の疑いがある端末や今後感染する可能性のある端末の候補を特定する特定装置10、通信を監視するセキュリティ装置20、ネットワーク内の端末50A~50Eに関する情報を記憶する構成情報記憶装置30、通信の監視や通信の制限を行う攻撃対処装置40、複数の端末50A~50E、ファイヤーウォール、ルーター、スイッチ等のNW(Network)機器60、ネットワークサービスを提供するメールサーバ70を有する。
次に、図9を用いて、第一の実施の形態に係る特定装置10の処理の流れを説明する。図9は、第一の実施の形態に係る特定装置の処理の流れを示すフローチャートである。
次に、図10を用いて、第一の実施の形態に係る特定システム1の処理の流れを説明する。図10は、第一の実施の形態に係る特定システムの処理の流れを示すシーケンス図である。
このように、第一の実施の形態に係る特定装置10は、ネットワーク内への不正侵入または端末50の感染に関する活動を検知するセキュリティ装置20から検知情報を受信し、該検知情報に含まれる端末50の情報および該端末50の活動内容から当該端末50の状態を特定する。そして、特定装置10は、状態特定部11によって端末50の状態がマルウェアに感染した状態であると特定された場合には、構成情報記憶装置30によって記憶された接続情報に基づいて、検知情報に含まれる端末50の活動内容に至るまでに感染した疑いがある端末50を特定し、感染した端末50が今後不正侵入または端末の感染に用いる可能性がある経路上に位置する端末50を感染する可能性がある感染端末の候補と特定する。このため、感染端末を検知するだけでなく、感染の疑いがある端末や今後感染する可能性がある感染端末の候補を特定することが可能となる。
また、図示した各装置の各構成要素は機能概念的なものであり、必ずしも物理的に図示の如く構成されていることを要しない。すなわち、各装置の分散・統合の具体的形態は図示のものに限られず、その全部または一部を、各種の負荷や使用状況などに応じて、任意の単位で機能的または物理的に分散・統合して構成することができる。例えば、特定装置10の状態特定部11と感染特定部12の機能について、それぞれの機能を別々の装置が有するようにしてもよい。また、例えば、特定装置10が、構成情報記憶装置30の情報を記憶するようにしてもよいし、攻撃対処装置40の機能を有するようにしてもよい。さらに、各装置にて行なわれる各処理機能は、その全部または任意の一部が、CPUおよび当該CPUにて解析実行されるプログラムにて実現され、あるいは、ワイヤードロジックによるハードウェアとして実現され得る。
また、一実施形態として、特定装置10は、パッケージソフトウェアやオンラインソフトウェアとして上記の特定処理を実行する特定プログラムを所望のコンピュータにインストールさせることによって実装できる。例えば、上記の特定プログラムを情報処理装置に実行させることにより、情報処理装置を特定装置10として機能させることができる。ここで言う情報処理装置には、例えば、デスクトップ型またはノート型のパーソナルコンピュータが含まれる。また、ユーザが使用する端末装置をクライアントとし、当該クライアントに上記の特定処理に関するサービスを提供するサーバ装置として実装することもできる。例えば、特定装置10は、感染端末を検知するだけでなく、感染の疑いがある端末や今後感染する可能性がある感染端末の候補を特定する処理サービスを提供するサーバ装置として実装される。この場合、特定装置10は、Webサーバとして実装することとしてもよいし、アウトソーシングによって上記の特定処理に関するサービスを提供するクラウドとして実装することとしてもかまわない。
10 特定装置
11 状態特定部
12 感染特定部
20 セキュリティ装置
30 構成情報記憶装置
40 攻撃対処装置
50、50A~50E 端末
60 NW機器
70 メールサーバ
80 インターネット
Claims (9)
- ネットワーク内の端末に関する情報を記憶する構成情報記憶装置と、前記端末の状態を特定する特定装置とを有する特定システムであって、
前記構成情報記憶装置は、前記ネットワーク内における端末同士の接続関係を示す接続情報を記憶し、
前記特定装置は、
前記ネットワーク内への不正侵入または端末の感染に関する活動を検知するセキュリティ装置から検知情報を受信し、該検知情報に含まれる端末の情報および該端末の活動内容から当該端末の状態を特定する状態特定部と、
前記状態特定部によって前記端末の状態がマルウェアに感染した状態であると特定された場合には、前記構成情報記憶装置によって記憶された接続情報に基づいて、前記検知情報に含まれる端末の活動内容に至るまでに感染した疑いがある端末を特定し、感染した端末が今後不正侵入または端末の感染に用いる可能性がある経路上に位置する端末を感染する可能性がある感染端末の候補と特定する感染特定部と
を有することを特徴とする特定システム。 - 前記状態特定部は、前記検知情報が通信に関する情報である場合には、該通信の送信元アドレスおよび送信先アドレスに対応する端末の状態を特定し、前記検知情報が端末に関する情報である場合には、該端末の状態を特定することを特徴とする請求項1に記載の特定システム。
- 前記構成情報記憶装置は、前記ネットワーク内の端末のアドレス情報、前記状態特定部によって特定された端末の状態を示す端末状態情報、前記感染特定部によって特定された感染の疑いがある端末および感染端末の候補を記憶することを特徴とする請求項1または2に記載の特定システム。
- 前記感染特定部は、前記状態特定部によって特定された感染端末の感染経路となりうる通信経路に含まれる端末を感染の疑いがある端末と特定し、前記感染経路となりうる通信経路の数と、過去の端末の状態とに基づいて、感染の疑いがある各端末について、感染の疑いの度合いを示す数値を算出することを特徴とする請求項1または2に記載の特定システム。
- 前記感染特定部は、前記状態特定部によって特定された感染端末を起点に、前記接続情報を用いて、前記感染端末からの感染が可能である端末を感染する可能性がある感染端末の候補と特定することを特徴とする請求項1または2に記載の特定システム。
- 前記特定システムは、さらに攻撃対処装置を有し、
前記攻撃対処装置は、前記状態特定部によって特定された感染端末と、前記感染特定部によって特定された感染の疑いがある端末のうち感染の疑いが高い端末とに対して、通信の遮断、通信の監視または通信の制限を行うことを特徴とする請求項1または2に記載の特定システム。 - 前記攻撃対処装置は、前記端末の感染の疑いの度合いを示す感染疑いスコアが第1の閾値を超えた場合は、当該端末の通信を遮断し、第2の閾値を超えた場合は、当該端末の通信監視および通信制限を行うことを特徴とする請求項6に記載の特定システム。
- 複数の端末を含むネットワーク内への不正侵入または端末の感染に関する活動を検知するセキュリティ装置から検知に関する検知情報を受信し、該検知情報に含まれる端末の情報および該端末の活動内容から当該端末の状態を特定する状態特定部と、
前記状態特定部によって前記端末の状態がマルウェアに感染した状態であると特定された場合には、ネットワーク内の端末同士の接続関係を示す接続情報に基づいて、前記検知情報に含まれる端末の活動内容に至るまでに感染した疑いがある端末を特定し、感染した端末が今後不正侵入または端末の感染に用いる可能性がある経路上に位置する端末を感染する可能性がある感染端末の候補と特定する感染特定部と
を有することを特徴とする特定装置。 - 特定装置によって実行される特定方法であって、
複数の端末を含むネットワーク内への不正侵入または端末の感染に関する活動を検知するセキュリティ装置から検知に関する検知情報を受信し、該検知情報に含まれる端末の情報および該端末の活動内容から当該端末の状態を特定する状態特定工程と、
前記状態特定工程によって前記端末の状態がマルウェアに感染した状態であると特定された場合には、ネットワーク内の端末同士の接続関係を示す接続情報に基づいて、前記検知情報に含まれる端末の活動内容に至るまでに感染した疑いがある端末を特定し、感染した端末が今後不正侵入または端末の感染に用いる可能性がある経路上に位置する端末を感染する可能性がある感染端末の候補と特定する感染特定工程と
を含んだことを特徴とする特定方法。
Priority Applications (5)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| EP16853623.3A EP3337106B1 (en) | 2015-10-06 | 2016-10-05 | Identification system, identification device and identification method |
| AU2016335722A AU2016335722B2 (en) | 2015-10-06 | 2016-10-05 | Identification system, identification device and identification method |
| JP2017544527A JP6405055B2 (ja) | 2015-10-06 | 2016-10-05 | 特定システム、特定装置および特定方法 |
| CN201680057393.7A CN108141408B (zh) | 2015-10-06 | 2016-10-05 | 确定系统、确定装置及确定方法 |
| US15/765,527 US10972490B2 (en) | 2015-10-06 | 2016-10-05 | Specifying system, specifying device, and specifying method |
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| JP2015-198753 | 2015-10-06 | ||
| JP2015198753 | 2015-10-06 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2017061469A1 true WO2017061469A1 (ja) | 2017-04-13 |
Family
ID=58487708
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/JP2016/079620 Ceased WO2017061469A1 (ja) | 2015-10-06 | 2016-10-05 | 特定システム、特定装置および特定方法 |
Country Status (6)
| Country | Link |
|---|---|
| US (1) | US10972490B2 (ja) |
| EP (1) | EP3337106B1 (ja) |
| JP (1) | JP6405055B2 (ja) |
| CN (1) | CN108141408B (ja) |
| AU (1) | AU2016335722B2 (ja) |
| WO (1) | WO2017061469A1 (ja) |
Cited By (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2018157343A (ja) * | 2017-03-16 | 2018-10-04 | 日本電信電話株式会社 | 対処指示装置、対処指示方法、対処指示プログラム |
| JP2020014061A (ja) * | 2018-07-13 | 2020-01-23 | 株式会社Pfu | 情報処理装置、通信検査方法及びプログラム |
| WO2020090497A1 (ja) * | 2018-10-31 | 2020-05-07 | 日本電信電話株式会社 | 感染確率算出装置、感染確率算出方法、および、感染確率算出プログラム |
| JP2021044791A (ja) * | 2019-09-11 | 2021-03-18 | 財団法人 資訊工業策進会Institute For Information Industry | 攻撃経路の検出方法、攻撃経路の検出システム及び非一時的なコンピュータ読み取り可能な記録媒体 |
Families Citing this family (7)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP6577442B2 (ja) * | 2016-11-01 | 2019-09-18 | 日本電信電話株式会社 | 不正侵入防止装置、不正侵入防止方法および不正侵入防止プログラム |
| JP6723955B2 (ja) * | 2017-05-12 | 2020-07-15 | 日立オートモティブシステムズ株式会社 | 情報処理装置及び異常対処方法 |
| US12287883B2 (en) * | 2019-11-15 | 2025-04-29 | Nec Corporation | Analysis system, method, and program |
| US11693961B2 (en) | 2019-12-03 | 2023-07-04 | Sonicwall Inc. | Analysis of historical network traffic to identify network vulnerabilities |
| US20210194915A1 (en) * | 2019-12-03 | 2021-06-24 | Sonicwall Inc. | Identification of potential network vulnerability and security responses in light of real-time network risk assessment |
| US11388176B2 (en) | 2019-12-03 | 2022-07-12 | Sonicwall Inc. | Visualization tool for real-time network risk assessment |
| US12621331B2 (en) * | 2020-11-13 | 2026-05-05 | Cyberark Software Ltd. | Detection of security risks based on secretless connection data |
Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2008141398A (ja) * | 2006-11-30 | 2008-06-19 | Mitsubishi Electric Corp | 中継装置および中継装置の制御方法 |
| JP2009117929A (ja) * | 2007-11-02 | 2009-05-28 | Nippon Telegr & Teleph Corp <Ntt> | 不正アクセス監視装置およびその方法 |
| JP2011101172A (ja) * | 2009-11-05 | 2011-05-19 | Nec Corp | ワーム感染源特定システム、特定方法および特定プログラム、エージェント並びにマネージャコンピュータ |
| JP2015095159A (ja) * | 2013-11-13 | 2015-05-18 | 日本電信電話株式会社 | 評価方法及び評価装置 |
Family Cites Families (12)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US7194769B2 (en) * | 2003-12-11 | 2007-03-20 | Massachusetts Institute Of Technology | Network security planning architecture |
| US8117659B2 (en) | 2005-12-28 | 2012-02-14 | Microsoft Corporation | Malicious code infection cause-and-effect analysis |
| US8381289B1 (en) * | 2009-03-31 | 2013-02-19 | Symantec Corporation | Communication-based host reputation system |
| US8341745B1 (en) * | 2010-02-22 | 2012-12-25 | Symantec Corporation | Inferring file and website reputations by belief propagation leveraging machine reputation |
| US8938800B2 (en) * | 2010-07-28 | 2015-01-20 | Mcafee, Inc. | System and method for network level protection against malicious software |
| US9071636B2 (en) * | 2011-12-21 | 2015-06-30 | Verizon Patent And Licensing Inc. | Predictive scoring management system for application behavior |
| CN103248613B (zh) * | 2012-02-09 | 2014-07-23 | 腾讯科技(深圳)有限公司 | 控制应用程序访问网络的方法及装置 |
| US8813236B1 (en) * | 2013-01-07 | 2014-08-19 | Narus, Inc. | Detecting malicious endpoints using network connectivity and flow information |
| US9148441B1 (en) | 2013-12-23 | 2015-09-29 | Symantec Corporation | Systems and methods for adjusting suspiciousness scores in event-correlation graphs |
| US9191403B2 (en) * | 2014-01-07 | 2015-11-17 | Fair Isaac Corporation | Cyber security adaptive analytics threat monitoring system and method |
| US10164995B1 (en) * | 2014-08-14 | 2018-12-25 | Pivotal Software, Inc. | Determining malware infection risk |
| US11128641B2 (en) * | 2015-08-28 | 2021-09-21 | Hewlett Packard Enterprise Development Lp | Propagating belief information about malicious and benign nodes |
-
2016
- 2016-10-05 WO PCT/JP2016/079620 patent/WO2017061469A1/ja not_active Ceased
- 2016-10-05 EP EP16853623.3A patent/EP3337106B1/en active Active
- 2016-10-05 AU AU2016335722A patent/AU2016335722B2/en active Active
- 2016-10-05 CN CN201680057393.7A patent/CN108141408B/zh active Active
- 2016-10-05 JP JP2017544527A patent/JP6405055B2/ja active Active
- 2016-10-05 US US15/765,527 patent/US10972490B2/en active Active
Patent Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2008141398A (ja) * | 2006-11-30 | 2008-06-19 | Mitsubishi Electric Corp | 中継装置および中継装置の制御方法 |
| JP2009117929A (ja) * | 2007-11-02 | 2009-05-28 | Nippon Telegr & Teleph Corp <Ntt> | 不正アクセス監視装置およびその方法 |
| JP2011101172A (ja) * | 2009-11-05 | 2011-05-19 | Nec Corp | ワーム感染源特定システム、特定方法および特定プログラム、エージェント並びにマネージャコンピュータ |
| JP2015095159A (ja) * | 2013-11-13 | 2015-05-18 | 日本電信電話株式会社 | 評価方法及び評価装置 |
Cited By (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2018157343A (ja) * | 2017-03-16 | 2018-10-04 | 日本電信電話株式会社 | 対処指示装置、対処指示方法、対処指示プログラム |
| JP2020014061A (ja) * | 2018-07-13 | 2020-01-23 | 株式会社Pfu | 情報処理装置、通信検査方法及びプログラム |
| JP7045949B2 (ja) | 2018-07-13 | 2022-04-01 | 株式会社Pfu | 情報処理装置、通信検査方法及びプログラム |
| WO2020090497A1 (ja) * | 2018-10-31 | 2020-05-07 | 日本電信電話株式会社 | 感染確率算出装置、感染確率算出方法、および、感染確率算出プログラム |
| JP2021044791A (ja) * | 2019-09-11 | 2021-03-18 | 財団法人 資訊工業策進会Institute For Information Industry | 攻撃経路の検出方法、攻撃経路の検出システム及び非一時的なコンピュータ読み取り可能な記録媒体 |
| US11689558B2 (en) | 2019-09-11 | 2023-06-27 | Institute For Information Industry | Attack path detection method, attack path detection system and non-transitory computer-readable medium |
Also Published As
| Publication number | Publication date |
|---|---|
| CN108141408A (zh) | 2018-06-08 |
| EP3337106B1 (en) | 2020-02-19 |
| JPWO2017061469A1 (ja) | 2018-02-15 |
| CN108141408B (zh) | 2021-01-15 |
| US10972490B2 (en) | 2021-04-06 |
| AU2016335722A1 (en) | 2018-04-12 |
| EP3337106A4 (en) | 2019-04-03 |
| EP3337106A1 (en) | 2018-06-20 |
| US20190081970A1 (en) | 2019-03-14 |
| AU2016335722B2 (en) | 2020-01-30 |
| JP6405055B2 (ja) | 2018-10-17 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| JP6405055B2 (ja) | 特定システム、特定装置および特定方法 | |
| US10237351B2 (en) | Sub-networks based security method, apparatus and product | |
| US10311235B2 (en) | Systems and methods for malware evasion management | |
| US11171985B1 (en) | System and method to detect lateral movement of ransomware by deploying a security appliance over a shared network to implement a default gateway with point-to-point links between endpoints | |
| CN102694820B (zh) | 签名规则的处理方法、服务器及入侵防御系统 | |
| US9548990B2 (en) | Detecting a heap spray attack | |
| US10044740B2 (en) | Method and apparatus for detecting security anomalies in a public cloud environment using network activity monitoring, application profiling and self-building host mapping | |
| US9336386B1 (en) | Exploit detection based on heap spray detection | |
| US12261877B2 (en) | Detecting malware infection path in a cloud computing environment utilizing a security graph | |
| JP2015095159A (ja) | 評価方法及び評価装置 | |
| US12321461B2 (en) | Attack graph processing device, method, and program | |
| EP3252648B1 (en) | Security measure invalidation prevention device, security measure invalidation prevention method, and security measure invalidation prevention program | |
| JP6592196B2 (ja) | 悪性イベント検出装置、悪性イベント検出方法および悪性イベント検出プログラム | |
| US12563054B2 (en) | Detecting malware infection path in a cloud computing environment utilizing a security graph | |
| JP7166969B2 (ja) | ルータ攻撃検出装置、ルータ攻撃検出プログラム及びルータ攻撃検出方法 | |
| US12634341B1 (en) | System and method to detect lateral movement of ransomware by deploying a security appliance over a shared network to implement a default gateway with point-to-point links between endpoints | |
| AU2023435882B2 (en) | Information processing system, information processing method, and information processing program |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 16853623 Country of ref document: EP Kind code of ref document: A1 |
|
| ENP | Entry into the national phase |
Ref document number: 2017544527 Country of ref document: JP Kind code of ref document: A |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 2016853623 Country of ref document: EP |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| ENP | Entry into the national phase |
Ref document number: 2016335722 Country of ref document: AU Date of ref document: 20161005 Kind code of ref document: A |