Arrangement location selection device, arrangement location selection method, and arrangement location selection program

By analyzing access logs and behavior patterns in the file system, configuring bait files, and avoiding the access area of legitimate users, the problem of obstructing legitimate users' business in the spoofing system is solved, and more accurate bait file configuration is achieved, reducing the risk of interference for legitimate users.

CN120303661APending Publication Date: 2025-07-11MITSUBISHI ELECTRIC CORP
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202280102197.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2022-12-06
Publication Date
2025-07-11

Smart Images

  • Figure CN120303661A_ABST
    Figure CN120303661A_ABST
Patent Text Reader

Abstract

A placement location selection device (100) is provided with a bait placement unit (140) that places a bait file in a region that is a region corresponding to a part of a file tree and that is a region other than a region outside a first object and a region outside a second object in an object system. The first out-of-object region is a region that is estimated to be used by the high-risk user in the normal traffic of the high-risk user. The second out-of-object region is estimated to be configured as a region that is used by each user other than the high-risk user in the normal traffic of each user.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to a placement site selection device, a placement site selection method, and a placement site selection program. Background Art

[0002] As a countermeasure against security attacks, there is a deception system using decoy data. Patent Document 1 discloses the following technique: intercepting data reading from a process determined to be illegal and returning false data to the process.

[0003] Prior Art Documents

[0004] Patent Documents

[0005] Patent Document 1: U.S. Patent No. 9,773,109 Specification Summary of the Invention

[0006] Problems to be Solved by the Invention

[0007] In the technique disclosed in Patent Document 1, the accuracy of illegal evaluation is not necessarily perfect. Therefore, false data may be returned to a legitimate process. Here, when false data is returned to a legitimate process, the operations of a legitimate user without malicious intent are hindered. Therefore, according to this technique, there is a problem that there is a risk of hindering the operations of a legitimate user without malicious intent.

[0008] An object of the present disclosure is to reduce the risk of hindering the operations of a legitimate user without malicious intent in a deception system using decoy data.

[0009] Means for Solving the Problems

[0010] The configuration location selection device of the present disclosure includes a bait configuration unit that configures one or more bait files in a configuration target area, which is an area other than the first object outside area and the second object outside area, and is an area corresponding to a part of the file tree managed by the object system. The first object outside area is an area corresponding to a part of the file tree, which includes one or more files among the files included in the object file group that are estimated to be used by high-risk users, who are users of the object system, in their normal business. The object file group is composed of a plurality of files shown in the access logs in the object system that have been accessed by the high-risk users. The second object outside area is composed of an area corresponding to a part of the file tree, which includes one or more files that are estimated to be accessed by each user included in the object normal user group in their normal business. The object normal user group is composed of one or more users of the object system, and the one or more users are users other than the high-risk users who have accessed at least one file among the files included in the object file group that is outside the first object outside area.

[0011] Effects of the Invention

[0012] According to the present disclosure, bait files are configured in an area other than the first object outside area and the second object outside area. Here, the first object outside area is an area that includes one or more files estimated to be used by high-risk users in their normal business, and the second object outside area is an area that includes one or more files estimated to be accessed by each user other than high-risk users in their normal business. Therefore, according to the present disclosure, in a deception system using bait data, the risk of hindering the business of legitimate users without malice can be reduced. Brief Description of the Drawings

[0013] Figure 1 It is a diagram showing a structural example of the configuration location selection device 100 according to Embodiment 1.

[0014] Figure 2 It is a diagram for explaining the processing of the normal business analysis unit 130 and the bait configuration unit 140 according to Embodiment 1.

[0015] Figure 3 It is a diagram showing an example of the configuration location selection system 90 according to Embodiment 1.

[0016] Figure 4 It is a diagram showing a hardware structural example of the configuration location selection device 100 according to Embodiment 1.

[0017] Figure 5 It is a flowchart showing the operation of the configuration location selection device 100 according to Embodiment 1.

[0018] Figure 6 This is a diagram showing a hardware structure example of the configuration location selection device 100 according to a modification of Embodiment 1.

[0019] Figure 7 This is a diagram showing a structural example of the configuration location selection device 100 according to Embodiment 2.

[0020] Figure 8 This is a diagram for explaining the configuration of the decoy file 191 according to Embodiment 2.

[0021] Figure 9 This is a diagram for explaining the access mode 281 and the configuration rule 291 according to Embodiment 2.

[0022] Figure 10 This is a diagram for explaining the access mode 281 and the configuration rule 291 according to Embodiment 2.

[0023] Figure 11 This is a flowchart showing the operation of the configuration location selection device 100 according to Embodiment 2. Detailed Embodiment

[0024] In the description and drawings of the embodiments, the same reference numerals are assigned to the same elements and corresponding elements. The description of the elements with the same reference numerals is appropriately omitted or simplified. The arrows in the drawings mainly show the data flow or the process flow. In addition, "section" may be appropriately rewritten as "circuit", "step", "process", "processing", or "line".

[0025] Embodiment 1.

[0026] Hereinafter, this embodiment will be described in detail with reference to the drawings.

[0027] ***Description of the Structure***

[0028] Figure 1 This shows a structural example of the configuration location selection device 100 according to this embodiment. As shown in this figure, the configuration location selection device 100 includes a log collection unit 110, a risk value calculation unit 120, a normal operation analysis unit 130, a decoy configuration unit 140, and a decoy monitoring unit 150. In addition, the configuration location selection device 100 stores an access log DB (Database) 180 and a decoy file DB 190.

[0029] The log collection unit 110 collects the access log 21 and the access log for the decoy file 191, and records the collected logs in the access log DB 180. The access log 21 is a log of file access in the target system 20.

[0030] The object system 20 is a computer system used by multiple users in business and is a system for storing multiple files. As a specific example, the object system 20 is a system operated based on zero trust and is composed of at least any one of a local system and a cloud system. The object system 20 manages each of the multiple files as part of a file tree. A file tree is a file system that manages multiple files in a hierarchical manner. In the object system 20, each file is stored in an arbitrary folder, and each user uses a file access tool to access each file managed by the object system 20. A folder is also called a directory. A file access tool is a tool for each user to access each file. As a specific example, it is an explorer or a browser.

[0031] The risk value calculation unit 120 calculates a risk value corresponding to each user based on logs such as file access in the object system 20. Typically, when the decoy file 191 is not configured, the risk value calculation unit 120 calculates a risk value corresponding to each user based on the access pattern of each user in the object system 20. Even when the decoy file 191 is configured, the risk value calculation unit 120 can calculate a risk value corresponding to each user based on the access pattern of each user in the object system 20. When the decoy file 191 is configured in the object system 20, the risk value calculation unit 120 can also use the access log for the decoy file 191 when calculating the risk value corresponding to each user. The risk value calculation unit 120 can also increase the risk value corresponding to the target user when the target user accesses at least one of more than one decoy file 191. Each user is a user of the object system 20. Each user can be a person or a computer.

[0032] The risk value corresponding to each user is a value calculated based on the behavior of each user in the target system 20, and is a value corresponding to the likelihood that each user is actually an internal illegal actor. The behavior of each user in the target system 20 is the action of each user in the target system 20. As a specific example, the constituent elements of each user's behavior are the files accessed by each user, the order of file access by each user, the time period during which each user performed file access, and the number of file accesses per unit time by each user. An internal illegal actor is a subject that operates within an organization for the purpose of stealing data from the organization. As a specific example, an internal illegal actor is an internal criminal in the target system 20, or malware that has stolen a legitimate credential, and the malware is malware that infects a PC (Personal Computer) used in the organization that manages the target system 20. An internal criminal is a user with legitimate access rights who participates in a security attack within the organization. An internal criminal is also a malicious user. As a specific example, malware is software that operates autonomously as a single entity, or software that operates according to instructions from an attacker outside the organization via a Command&Control server on the Internet.

[0033] The risk value calculation unit 120 can also pre-model the normal behavior patterns in the target system 20 for each user according to logs such as file access, and calculate the degree to which the actual behavior of each user in the target system 20 deviates from the modeled normal behavior patterns, as the risk value corresponding to each user. When modeling the normal behavior patterns, the risk value calculation unit 120 can use technologies such as machine learning, or can also use technologies that detect behavioral anomalies for each user according to access logs such as User and Entity Behavior Analytics (UEBA).

[0034] In addition, the risk value calculation unit 120 generates high-risk user information 121 and outputs the generated high-risk user information 121. The high-risk user information 121 is information that shows each high-risk user and the characteristics of each high-risk user. As a specific example, the high-risk user information 121 includes each high-risk user, the risk value corresponding to each high-risk user, and data such as one or more files accessed by each high-risk user. A high-risk user is a user of the target system 20, and is a user of the target system 20 whose corresponding risk value is above a risk benchmark value that is a predetermined threshold, and is a user with a relatively high likelihood of being an internal illegal actor. In addition, when at least any one of the access log 21 and the decoy file access information 151 is updated, the high-risk user information 121 may sometimes be updated based on the updated information.

[0035] Generally, the normal business analysis unit 130 estimates the first out-of-scope area and the second out-of-scope area based on the access log 21. The first out-of-scope area is an area corresponding to a part of the file tree managed by the target system 20, and this area includes one or more files among the files included in the target file group that are estimated to be used by high-risk users in their normal business. The normal business can be defined in any way. The target file group consists of multiple files shown in the access log 21 that have been accessed by high-risk users. The second out-of-scope area consists of an area corresponding to a part of the file tree, and this area includes one or more files that are estimated to be accessed by each user included in the target normal user group in their normal business. When there are multiple users in the target normal user group, the second out-of-scope area is the union of the normal access areas corresponding to each user. The target normal user group consists of one or more users of the target system 20, and these one or more users are users other than high-risk users who have accessed at least one file outside the first out-of-scope area among the files included in the target file group. In addition, the normal business analysis unit 130 generates out-of-scope area information 131 and outputs the generated out-of-scope area information 131. The out-of-scope area information 131 is information indicating the area where the decoy file 191 is not configured.

[0036] As a specific example, the normal business analysis unit 130 determines the normal access area corresponding to each high-risk user based on the file access logs of each high-risk user shown in the high-risk user information 121, and adds the determined normal access area to the configured out-of-scope area. The normal access area corresponding to each user is the range of the file tree that each user usually accesses in their business, and is an area that each user accesses with a relatively high frequency. As a specific example, it consists of one or more files and one or more directories that each user usually accesses. At this time, as a specific example, the normal business analysis unit 130 sets the files and directories that each user has accessed a certain number of times or more within a given period as the files and directories that each user usually accesses. The configured out-of-scope area is an area corresponding to a part of the file tree and is an area where the decoy file 191 is not configured.

[0037] In addition, the General Business Analysis Department 130 typically determines, based on logs indicating accesses and the like to each file accessed by each high-risk user shown in the high-risk user information 121, one or more files and one or more directories accessed by other users who normally access each file at the same or a relatively close timing as each high-risk user, and adds the range including the determined one or more files and one or more directories to the out-of-configuration object area. At this time, as a specific example, the General Business Analysis Department 130 sets, as files and directories accessed by other users at the same or a relatively close timing as each high-risk user, files and directories having accesses a predetermined number of times or more within a predetermined period from the timing when each file accessed by each high-risk user was accessed.

[0038] The Bait Configuration Department 140 configures one or more bait files 191 in the configuration object area. Configuring the bait file 191 includes instructing the plug-in and the like to configure the bait file 191. The configuration object area is an area other than the first out-of-object area and the second out-of-object area, and is an area corresponding to a part of the file tree managed by the object system 20. The configuration object area may also include an area predicted to be accessed by high-risk users.

[0039] Specifically, the Bait Configuration Department 140 selects one or more bait files 191 from the bait file DB 190, executes an instruction to configure the selected bait files 191 in the following area in the file tree for the object system 20, generates bait file information 141 corresponding to the executed instruction, and outputs the generated bait file information 141, where the area is an area near the files accessed by each high-risk user shown in the high-risk user information 121 and is an area other than the out-of-configuration object area. The bait file information 141 corresponding to the bait file 191 is information indicating the file name and the configuration location of the bait file 191. At this time, the Bait Configuration Department 140 may randomly select the bait file 191 from the bait file DB 190, or may select the bait file 191 from the bait file DB 190 according to the characteristics of the high-risk users. The Bait Configuration Department 140 may also configure the bait file 191 in the object system 20 instead of executing the instruction to configure the bait file 191 for the object system 20.

[0040] In addition, the Bait Configuration Department 140 may also extract topics from the content and file names of the files accessed by high-risk users, further screen the areas where files or directories related to the extracted topics exist, and configure the bait file 191 in the screened areas. At this time, the Bait Configuration Department 140 may also use a topic model such as Top2Vec to extract topics.

[0041] The decoy configuration unit 140 may also generate a decoy folder and issue an instruction to configure a decoy file 191 in the generated decoy folder for the target system 20. The decoy configuration unit 140 may also append information indicating access to the decoy file 191 to the access logs 21 corresponding to each user.

[0042] In addition, in the present disclosure, the decoy file 191 is configured based on the assumption that there are differences in access tendencies according to the presence or absence of malice of each user. As a specific example, the difference in access tendency means that, in addition to accessing the business file group corresponding to the insider, the insider also accesses various files unrelated to the business file group, and legitimate users without malice (hereinafter, normal users) basically only access the business file group corresponding to the normal users and the peripheral file group corresponding to the business file group. A legitimate user is a user who is legally registered in the target system 20. Sometimes, a legitimate user is also referred to as a "user". The business file group corresponding to each user consists of at least one file related to the business of each user. The peripheral file group corresponding to the business file group consists of files other than the files constituting the business file group, and consists of at least one file that can be reached from each file constituting the business file group in a relatively small number of steps in the file tree.

[0043] The decoy file 191 is a file that has no direct relation to the business of each user. The file name, file format, etc. of the decoy file 191 may be generated in a way that arouses the interest of the insider based on the results obtained by analyzing the access tendencies of the insider, etc., or may be generated by AI (Artificial Intelligence).

[0044] Figure 2 It is a diagram for explaining the processing of the normal business analysis unit 130 and the decoy configuration unit 140. In Figure 2 it, the S surrounded by a circle indicates confidentiality. Use Figure 2 to explain the processing of the normal business analysis unit 130 and the decoy configuration unit 140.

[0045] The normal business analysis unit 130 analyzes the file access tendencies of normal users, and based on the analysis results, estimates the folders that each user may access within the range of no malice. Specifically, the normal business analysis unit 130 respectively estimates the normal access areas of normal users and the normal access areas of high-risk users. The normal access area of normal users corresponds to the second out-of-target area. The normal access area of high-risk users corresponds to the first out-of-target area.

[0046] The decoy configuration unit 140 selects a folder for configuring the decoy file 191 based on the result speculated by the normal operation analysis unit 130. At this time, the decoy configuration unit 140 can also predict the future file access of high-risk users based on the anomalies detected by monitoring the behaviors of each user, and configure the decoy file 191 in the folder storing the file corresponding to the predicted file access. As a specific example, as Figure 2 shown, the decoy configuration unit 140 predicts the future file access of high-risk users, and selects a folder for configuring the decoy file 191 based on the predicted result.

[0047] The decoy monitoring unit 150 monitors the access to the decoy file 191 shown in the decoy file information 141 for each high-risk user shown in the high-risk user information 121, generates decoy file access information 151 corresponding to the monitored result, and outputs the generated decoy file access information 151. As a specific example, when there is a high-risk user who has accessed the decoy file 191 more than a predetermined number of times, the decoy file access information 151 is information indicating that the high-risk user has accessed the decoy file 191 more than the predetermined number of times. The high-risk user information 121 may also be information indicating that a user other than the high-risk user has accessed the decoy file 191.

[0048] The analyst can screen high-risk users based on the decoy file access information 151 and the high-risk user information 121, and reflect the screened result in the high-risk user information 121. As a specific example, the analyst is a person or a computer that analyzes security attacks in the target system 20.

[0049] The access log DB 180 is a database that stores information representing the access log in the target system 20.

[0050] The decoy file DB 190 is a database that stores one or more decoy files 191.

[0051] Figure 3 An embodiment of the configuration location selection system 90 of the present embodiment is shown. Use Figure 3 to describe the embodiment of the configuration location selection system 90. In Figure 3 it, the configuration location selection device 100 is divided and illustrated according to each function. Here, it is assumed that the internal illegal person investigates the files in the target system 20 and avoids the decoy file 191.

[0052] The risk benchmark authentication function uses risk benchmark authentication technology to receive the access log 21 of each user from the target system 20, and calculates a risk value corresponding to each user based on the received log. In addition, when the decoy file 191 has already been configured, the risk value calculation unit 120 refers to the access log for the decoy file 191 when calculating the risk value of each user.

[0053] The internal illegal person countermeasure system is a system with an internal illegal person countermeasure function, having a bait dynamic distribution function and a file access function.

[0054] The bait dynamic distribution function is as follows: select the folder for configuring the bait file 191, select the bait file 191, and configure the selected bait file 191 in the selected folder.

[0055] The bait configuration unit 140 instructs the internal illegal person countermeasure plug-in to configure the bait file 191.

[0056] The internal illegal person countermeasure plug-in is a software module that implements additional functions for file access tools. The function of the bait monitoring unit 150 is implemented by the internal illegal person countermeasure plug-in.

[0057] The file access tool that implements the file access function, based on the instruction of the bait dynamic distribution function, uses the internal illegal person countermeasure plug-in to configure the bait file 191. The internal illegal person countermeasure plug-in can actually configure the bait file 191 in the target system 20, or instead of actually configuring the bait file 191 in the target system 20, when each user accesses the folder where the bait file 191 should be configured, display the bait file 191 on the operation screen of the file access tool.

[0058] Figure 4 Shows an example of the hardware structure of the configuration location selection device 100 of this embodiment. The configuration location selection device 100 is composed of a general computer. The configuration location selection device 100 can also be composed of multiple computers. The target system 20 and the configuration location selection device 100 can also be integrally formed.

[0059] As shown in this figure, the configuration location selection device 100 is a computer equipped with hardware such as a processor 11 and a storage device 12. These hardware are appropriately connected via signal lines.

[0060] The processor 11 is an IC (Integrated Circuit) that performs arithmetic processing and controls the hardware of the computer. As a specific example, the processor 11 is a CPU (Central Processing Unit), a DSP (Digital Signal Processor), or a GPU (Graphics Processing Unit).

[0061] The configuration location selection device 100 can also be equipped with multiple processors to replace the processor 11. The multiple processors share the role of the processor 11.

[0062] The storage device 12 is constituted by at least either a volatile storage device or a non-volatile storage device. As a specific example, the volatile storage device is a RAM (Random Access Memory). As a specific example, the non-volatile storage device is a ROM (Read Only Memory), an HDD (Hard Disk Drive), or a flash memory. The data stored in the storage device 12 is loaded into the processor 11 as needed.

[0063] The configuration location selection device 100 may also include hardware such as an input / output IF (Interface) and a communication device.

[0064] The input / output IF is a port that connects an input device and an output device. As a specific example, the input / output IF is a USB (Universal Serial Bus) terminal. As a specific example, the input device is a keyboard and a mouse. As a specific example, the output device is a display.

[0065] The communication device is a receiver and a transmitter. As a specific example, the communication device is a communication chip or a NIC (Network Interface Card).

[0066] When each part of the configuration location selection device 100 communicates with other devices, etc., the input / output IF and the communication device can be appropriately used.

[0067] The storage device 12 stores a configuration location selection program. The configuration location selection program is a program that enables a computer to implement the functions of each part of the configuration location selection device 100. The configuration location selection program is loaded into the storage device 12 and executed by the processor 11. The functions of each part of the configuration location selection device 100 are implemented by software.

[0068] The storage device 12 may also store files managed by the object system 20.

[0069] Data used when executing the configuration location selection program and data obtained by executing the configuration location selection program, etc., are appropriately stored in the storage device 12. Each part of the configuration location selection device 100 appropriately utilizes the storage device 12. In addition, terms such as data and terms such as information sometimes have equivalent meanings.

[0070] The storage device 12 may be independent of the computer. Each database may also be stored in an external server or the like.

[0071] The configuration location selection program can also be recorded in a computer-readable non-volatile recording medium. As a specific example, the non-volatile recording medium is an optical disc or a flash memory. The configuration location selection program can also be provided as a program product.

[0072] ***Explanation of the operation***

[0073] The operation process of the configuration location selection device 100 corresponds to the configuration location selection method. In addition, the program that implements the operation of the configuration location selection device 100 corresponds to the configuration location selection program.

[0074] Figure 5 It is a flowchart showing an example of the operation of the configuration location selection device 100. Refer to Figure 5 The operation of the configuration location selection device 100 will be described.

[0075] (Step S101: Risk value calculation process)

[0076] The risk value calculation unit 120 refers to the access log DB 180 and calculates the risk value related to the behavior of each user based on the log of file access.

[0077] (Step S102: First non-target area determination process)

[0078] The normal business analysis unit 130 determines the area including the folder group that high-risk users access with a relatively high frequency in normal normal business as the first non-target area, and this area is an area corresponding to a part of the file tree.

[0079] (Step S103: Second non-target area determination process)

[0080] The normal business analysis unit 130 determines the area including the folder that the following users access with a relatively high frequency in normal business as the second non-target area. This user accessed the folder in the folder group accessed by the high-risk user that the high-risk user does not use in normal normal business, and this area is an area corresponding to a part of the file tree.

[0081] (Step S104: Bait file configuration process)

[0082] The bait configuration unit 140 selects the bait file 191 from the bait file DB 190 and configures the selected bait file 191 at a location that avoids the first non-target area and the second non-target area determined by the normal business analysis unit 130.

[0083] (Step S105: Bait monitoring process)

[0084] The decoy monitoring unit 150 monitors access to the decoy file 191, generates decoy file access information 151 representing the result of the monitoring, and outputs the generated decoy file access information 151.

[0085] (Step S106: High-risk user information correction process)

[0086] The risk value calculation unit 120 corrects the high-risk user information 121 based on the output decoy file access information 151.

[0087] ***Explanation of the effects of Embodiment 1***

[0088] As described above, according to this embodiment, in a deception system using decoy data, the decoy file 191 is configured avoiding folders normally accessed by legitimate users. Therefore, the chance of legitimate users accessing the decoy file 191 can be reduced. Thus, according to this embodiment, the risk of hindering the operations of legitimate users without malicious intent can be reduced.

[0089] In addition, according to this embodiment, the decoy file 191 is configured avoiding the first excluded area. Therefore, even when a high-risk user is actually a normal user, the risk of hindering the normal operations of the high-risk user can be reduced.

[0090] ***Other configurations***

[0091] <Modification Example 1>

[0092] Figure 6 Shows a hardware configuration example of the configuration location selection device 100 of this modification example.

[0093] The configuration location selection device 100 includes a processing circuit 18 instead of the processor 11 or the processor 11 and the storage device 12.

[0094] The processing circuit 18 is hardware that implements at least a part of each unit included in the configuration location selection device 100.

[0095] The processing circuit 18 may be dedicated hardware, or may also be a processor that executes a program stored in the storage device 12.

[0096] In the case where the processing circuit 18 is dedicated hardware, as a specific example, the processing circuit 18 is a single circuit, a composite circuit, a programmed processor, a parallel programmed processor, an ASIC (Application Specific Integrated Circuit), an FPGA (Field Programmable Gate Array), or a combination thereof.

[0097] The placement location selection device 100 may also include a plurality of processing circuits instead of the processing circuit 18. The plurality of processing circuits share the functions of the processing circuit 18.

[0098] In the placement location selection device 100, a part of the functions may be implemented by dedicated hardware, and the remaining functions may be implemented by software or firmware.

[0099] As a specific example, the processing circuit 18 is implemented by hardware, software, firmware, or a combination thereof.

[0100] The processor 11, the storage device 12, and the processing circuit 18 are collectively referred to as the "processing line". That is, the functions of the respective functional structural elements of the placement location selection device 100 are implemented by the processing line.

[0101] Regarding the placement location selection device 100 of other embodiments, it may have the same structure as this modification example.

[0102] Embodiment 2.

[0103] Hereinafter, with reference to the drawings, the differences mainly from the above-described embodiment will be described.

[0104] ***Explanation of the structure***

[0105] Figure 7 A structural example of the placement location selection device 100 of this embodiment is shown. As Figure 7 shown, the placement location selection device 100 further includes an access pattern analysis unit 210. In addition, the placement location selection device 100 also stores an access pattern DB 280 and a configuration rule DB 290.

[0106] When an internal intruder attempts to collect the files to be stolen by using an automatic program such as a script instead of opening and visually confirming the files one by one, at the time point when the risk value corresponding to the internal intruder becomes high, placing the decoy file 191 near the file being accessed by the internal intruder may be too late because the access to the vicinity of the file has ended at the time of placing the decoy file 191. In addition, when placing the decoy file 191 near the file, the possibility that a legitimate user without malice accesses the decoy file 191 increases.

[0107] Figure 8 This is a diagram for explaining the configuration of the decoy file 191 in the case where file access based on malware is detected as an anomaly. As Figure 8 shown, even if the decoy file 191 is configured near the file being accessed by the malware, it is too late, but it is not too late to configure the decoy file 191 outside the vicinity of the file.

[0108] In addition, when the decoy files 191 are configured over a large range in advance, the possibility of legitimate users without malicious intent accessing the decoy files 191 increases.

[0109] Here, it is considered that the appropriate placement locations of the decoy files 191 vary depending on the access patterns of internal intruders. As a specific example, the access patterns of internal intruders include a mode in which an internal intruder makes a manual access and a mode in which an internal intruder makes an automatic access through malware. Thus, in the present embodiment, a method for more effectively configuring the decoy files 191 according to the types of access patterns is proposed.

[0110] The access pattern analysis unit 210 analyzes the access patterns of each user in the target system 20 in the target system 20 based on the access logs 21. Specifically, the access pattern analysis unit 210 determines the access pattern 281 corresponding to each high-risk user by comparing the logs of the most recent file accesses, etc., of each high-risk user shown in the high-risk user information 121 with the respective access patterns 281 stored in the access pattern DB 280.

[0111] After that, the access pattern analysis unit 210 determines the configuration rule 291 corresponding to the determined access pattern 281 from the configuration rule DB 290, generates configuration guideline information 211 based on the determined result, and outputs the generated configuration guideline information 211. Here, appropriate configuration rules 291 are predefined for each access pattern 281 stored in the access pattern DB 280. In addition, there are also access patterns 281 that cannot be detected by the access pattern analysis unit 210.

[0112] The configuration guideline information 211 is information indicating the guidelines for configuring the respective decoy files 191.

[0113] The access pattern DB 280 stores data showing each of one or more access patterns 281.

[0114] As a specific example, each access pattern 281 may also be a classification corresponding to at least any one of the type of user, the area where the user has made a file access, and the frequency of file access by the user. As a specific example, the types of users are external attackers, high-risk users, and low-risk users. Low-risk users are users other than high-risk users. External attackers may also be treated as part of high-risk users.

[0115] Each access mode 281 corresponds to a classification of file access corresponding to the characteristics of assumed file access. Data related to a detection rule for determining whether it corresponds to each access mode 281 may also be included in each access mode 281. As a specific example, the data related to the detection rule represents at least any one of a reference value of the number of files accessed by a user within a certain time period and a reference value of the number of directories accessed by the user within a certain time period.

[0116] Each access mode 281 may also be a mode obtained by the following method: Logs of file accesses when manually simulating the file accesses of an insider or file accesses when executing an automatic program such as malware are collected in advance, and the collected logs are used and learned using techniques such as machine learning to obtain the mode.

[0117] The configuration rule DB 290 stores data showing each of one or more configuration rules 291.

[0118] The configuration rule 291 is a rule indicating the area where each decoy file 191 is configured. As a specific example, it is a rule indicating that the decoy file 191 is configured in an area within x hops or more and less than y hops from an area outside the configuration target. Here, a hop is a unit indicating the distance between two directories, and the distance between two directories separated by one level is 1 hop. x and y are natural numbers, and the value of y is greater than the value of x. The configuration rule 291 corresponding to the access mode corresponding to the case where a high-risk user uses malware may also be the following rule: One or more decoy files 191 are configured in an area in the file tree that is at a reference distance or more from the following file, which is a file accessed by a high-risk user within a past reference time from the time point when one or more decoy files 191 are configured. The past reference time from the time point when one or more decoy files 191 are configured means the period from the time point obtained by tracing back the past reference time from the time point when one or more decoy files 191 are configured to the time point when one or more decoy files 191 are configured.

[0119] In addition, the configuration rule 291 may also be the following rule: It shows a drive different from the drive accessed by each high-risk user as the configuration target of the decoy file 191. The configuration target may be a file system on a cloud system or a network drive.

[0120] Figure 9 and Figure 10 are diagrams illustrating specific examples of each access mode 281 and the configuration rule 291 corresponding to each access mode 281. As Figure 9 and Figure 10As shown, for each access pattern 281, a detection rule for detecting the access pattern 281 and a configuration rule 291 for the decoy file 191 are defined respectively.

[0121] "Characteristics of the access pattern" are matters characteristic in each access pattern 281.

[0122] "Detection rule" is a rule for detecting each access pattern 281, and is a rule defined based on the "characteristics of the access pattern".

[0123] "Future predicted actions" are file accesses predicted as future actions of users or tools.

[0124] The configuration rule 291 is a rule defined based on the "future predicted actions".

[0125] In addition, the access pattern DB 280 may not store information representing the "characteristics of the access pattern" and information representing the "future predicted actions" separately.

[0126] The decoy configuration unit 140 of the present embodiment configures one or more decoy files 191 in the configuration target area according to the configuration rule 291 corresponding to the access pattern in the target system 20 of the high-risk user. Specifically, the decoy configuration unit 140 instructs the internal intruder countermeasure plug-in to configure the decoy file 191 according to the configuration policy shown in the configuration policy information 211. In addition, the decoy configuration unit 140 has the following function: according to the configuration policy of the decoy file 191 corresponding to the access pattern 281 corresponding to the high-risk user, the decoy file 191 is configured not only near the outside of the configuration target area, but also in a wide range outside the vicinity of the outside of the configuration target area.

[0127] ***Explanation of the operation***

[0128] Figure 11 It is a flowchart showing an example of the operation of the configuration location selection device 100. Use Figure 11 to explain the operation of the configuration location selection device 100.

[0129] (Step S201: Access pattern determination process)

[0130] The access pattern analysis unit 210 determines the access pattern 281 of the high-risk user based on the access log of the high-risk user shown in the access log DB 180 and the access pattern DB 280, determines the configuration rule 291 corresponding to the determined access pattern 281 from the configuration rule DB 290, and generates the configuration policy information 211 based on the determined configuration rule 291.

[0131] (Step S202: Decoy file configuration process)

[0132] The decoy configuration unit 140 selects a decoy file 191 from the decoy file DB 190, and configures the selected decoy file 191 at a location that avoids the first out-of-scope area and the second out-of-scope area according to the configuration guideline information 211 generated in step S201.

[0133] ***Explanation of the effects of Embodiment 2***

[0134] As described above, according to this embodiment, the decoy file 191 is configured according to the access pattern 281 of high-risk users. Therefore, the decoy file 191 can be configured more effectively according to the types of illegal file accesses.

[0135] ***Other embodiments***

[0136] Free combinations of the above-described embodiments or modifications of any structural elements of the embodiments can be made, or any structural elements can be omitted in each embodiment.

[0137] In addition, the embodiments are not limited to the embodiments shown in Embodiments 1 to 2, and various changes can be made as needed. The processes described using flowcharts and the like can also be changed as appropriate.

[0138] Explanation of reference numerals

[0139] 11 Processor, 12 Storage device, 18 Processing circuit, 20 Target system, 21 Access log, 90 Configuration location selection system, 100 Configuration location selection device, 110 Log collection unit, 120 Risk value calculation unit, 121 High-risk user information, 130 Normal business analysis unit, 131 Out-of-scope area information, 140 Decoy configuration unit, 141 Decoy file information, 150 Decoy monitoring unit, 151 Decoy file access information, 180 Access log DB, 190 Decoy file DB, 191 Decoy file, 210 Access pattern analysis unit, 211 Configuration guideline information, 280 Access pattern DB, 281 Access pattern, 290 Configuration rule DB, 291 Configuration rule.

Claims

1. A configuration location selection device, wherein, the configuration location selection device includes a decoy configuration unit that configures one or more decoy files in a configuration target area, the configuration target area is an area other than the first non-target area and the second non-target area, and is an area corresponding to a part of the file tree managed by the target system, the first non-target area is an area corresponding to a part of the file tree, and this area includes one or more files among the files included in the target file group that are estimated to be used by high-risk users, who are users of the target system, in their normal operations. Here, the target file group consists of multiple files shown in the access logs in the target system that have been accessed by the high-risk users, the second non-target area consists of an area corresponding to a part of the file tree, and this area includes one or more files that are estimated to be accessed by each user included in the target normal user group in their normal operations. Here, the target normal user group consists of one or more users of the target system, and these one or more users are users other than the high-risk users who have accessed at least one file among the files included in the target file group that is outside the first non-target area, 2. The configuration location selection device according to claim 1, wherein, the configuration target area includes an area predicted to be accessed by the high-risk users.

3. The configuration location selection device according to claim 1 or 2, wherein, the configuration location selection device further includes a risk value calculation unit that calculates a risk value corresponding to each user based on the access patterns of each user in the target system in the target system, the high-risk users are users in the target system whose corresponding risk values are equal to or higher than the risk reference value.

4. The configuration location selection device according to claim 3, wherein, when a target user, who is a user in the target system, accesses at least one of the one or more decoy files, the risk value calculation unit increases the risk value corresponding to the target user.

5. The configuration location selection device according to any one of claims 1 to 4, wherein, the configuration location selection device further includes a normal operation analysis unit that estimates the first non-target area and the second non-target area respectively based on the access logs in the target system.

6. The configuration location selection device according to any one of claims 1 to 5, wherein, the decoy configuration unit configures the one or more decoy files in the configuration target area according to a configuration rule corresponding to the access pattern of the high-risk users in the target system.

7. The configuration location selection device according to claim 6, wherein, The configuration rule corresponding to the access pattern corresponding to the situation where the high-risk user has used malware is as follows: Configure the one or more decoy files in an area in the file tree that is at a reference distance or more from the following file, which is a file accessed by the high-risk user within a past reference time from the time point when the one or more decoy files are configured.

8. The configuration location selection device according to claim 6 or 7, wherein, The configuration location selection device further includes an access pattern analysis unit that analyzes the access pattern of each user in the target system in the target system based on the access logs in the target system.

9. A configuration location selection method, wherein, A computer configures one or more decoy files in a configuration target area, The configuration target area is an area other than the first out-of-object area and the second out-of-object area, and is an area corresponding to a part of the file tree managed by the target system, The first out-of-object area is an area corresponding to a part of the file tree, and this area includes one or more files among the files included in the object file group that are estimated to be used by a high-risk user, who is a user of the target system, in the normal business of the high-risk user. Here, the object file group is composed of a plurality of files shown in the access logs in the target system that have been accessed by the high-risk user. The second out-of-object area is composed of an area corresponding to a part of the file tree, and this area includes one or more files that are estimated to be accessed by each user included in the object normal user group in the normal business of each user. Here, the object normal user group is composed of one or more users of the target system, and these one or more users are users other than the high-risk user who have accessed at least one file among the files included in the object file group that is outside the first out-of-object area.

10. A configuration location selection program, wherein, The configuration location selection program causes a configuration location selection device, which is a computer, to execute a decoy configuration process, In the decoy configuration process, one or more decoy files are configured in a configuration target area, The configuration target area is an area other than the first out-of-object area and the second out-of-object area, and is an area corresponding to a part of the file tree managed by the target system, The first out-of-object area is an area corresponding to a part of the file tree, and this area includes one or more files among the files included in the object file group that are estimated to be used by a high-risk user, who is a user of the target system, in the normal business of the high-risk user. Here, the object file group is composed of a plurality of files shown in the access logs in the target system that have been accessed by the high-risk user. The second out-of-object area is composed of an area corresponding to a part of the file tree, and this area includes one or more files that are estimated to be accessed by each user included in the normal user group of the object in each user's normal business. Among them, the normal user group of the object is composed of one or more users of the object system, and the one or more users are users other than the high-risk users who have accessed at least one file existing outside the first out-of-object area among the files included in the object file group.

Citation Information

Patent Citations

  • Alternate files returned for suspicious processes in a compromised computer network

    US9773109B2