Information processing device, information processing method, and information processing program
By analyzing access logs through information processing devices, bait files matching high-risk users are automatically configured, solving the problem of large amount of bait data and low effectiveness in the existing technology and enhancing the security of the system.
Patent Information
- Application Number
- CN202380092955.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-02-17
- Publication Date
- 2025-09-12
AI Technical Summary
The existing technology cannot automatically configure bait files associated with the information sought by internal criminals, resulting in a large amount of bait data and reduced effectiveness, making it easy for internal criminals to identify the bait files.
Through information processing devices, the behavior of high-risk users is analyzed based on access logs, bait topics are estimated, and bait files that match them are automatically configured. Bait files are generated using natural language processing and machine learning technologies.
It realizes automatic configuration of bait files that match the information sought by internal illegal users, improves the effectiveness of bait data, reduces the risk of identifying internal illegal users, and enhances the security of the bait data management system.
Smart Images

Figure CN120641900A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to an information processing device, an information processing method, and an information processing program. Background Art
[0002] Patent Document 1 discloses the following technology: Bait data (a specific example is a bait email) is generated as bait data for third parties who monitor emails on the Internet. This bait data contains information (a specific example is information indicating a URL (Uniform Resource Locator), an ID (Identification), and a password) to induce access to a bait server, and the generated bait data is placed on the Internet. Here, an arbitrary bait file is placed on the bait server. Furthermore, the bait file preferably contains performance information, new product information, confidential information, new technology information, and personal information.
[0003] Prior art literature
[0004] Patent Literature
[0005] Patent Document 1: Japanese Patent Application Laid-Open No. 2010-134832 Summary of the Invention
[0006] Problems to be solved by the invention
[0007] If the attacker is a malicious third party, it is sufficient to prepare decoy data related to information of interest to the attacker and commonly known specific information that is attractive to the attacker, and then deploy the prepared decoy data on the network as in conventional techniques. Specifically, the specific information is information indicating at least one of an ID, a password, a system configuration, personal information, and funds.
[0008] However, if we consider the information outflow caused by an illegal internal actor, the information contained in various documents produced in daily business operations may also become the information of theft targets. As a specific example, the illegal internal actor is a malicious employee. Here, if bait data is prepared for all files, the amount of bait data will be huge. In addition, it is believed that the illegal internal actor has the intention to cause the outflow of information matching certain topics. Therefore, it is ineffective to prompt the illegal internal actor with bait files that do not match the topic of the illegal internal actor. As a specific example, the topic is "defense related", "machine learning related" or "design document related". In addition, if a large number of bait files that do not match the topic of the illegal internal actor are prompted, or the content of the bait files deviates from the company's business, the possibility of the illegal internal actor realizing that they are bait files becomes higher. Therefore, it is necessary to work on the content of the bait files.
[0009] An object of the present disclosure is to automatically configure a decoy file that matches a subject matter of information estimated to be leaked to the outside by an insider in a spoofing system using decoy data.
[0010] Means used to solve problems
[0011] The information processing device disclosed in the present invention comprises: a bait topic estimation unit that estimates the topic of information to be leaked to the outside by a high-risk user as a user of the target system, i.e., a bait topic, based on an access log indicating access by the high-risk user in the target system; and a bait configuration unit that configures a bait file matching the estimated bait topic in the target system.
[0012] Effects of the Invention
[0013] According to the present disclosure, a decoy theme estimation unit estimates the theme of information that a high-risk user intends to leak externally based on access logs, and a decoy configuration unit deploys a decoy file matching the estimated theme in the target system. In some cases, high-risk users are also illegal insiders. Therefore, according to the present disclosure, a decoy system using decoy data can automatically deploy a decoy file matching the theme of information estimated to be leaked externally by an illegal insider. BRIEF DESCRIPTION OF THE DRAWINGS
[0014] Figure 1 This diagram explains file access by an illegal internal user.
[0015] Figure 2 This is a diagram showing a configuration example of the information processing device 100 according to the first embodiment.
[0016] Figure 3 This is a diagram showing a configuration example of an information processing system 90 according to the first embodiment.
[0017] Figure 4 This is a diagram showing a hardware configuration example of the information processing device 100 according to the first embodiment.
[0018] Figure 5 This is a flowchart showing the operation of the information processing device 100 according to the first embodiment.
[0019] Figure 6 This is a flowchart showing the operation of the decoy theme estimation unit 130 according to the first embodiment.
[0020] Figure 7 This is a flowchart showing the operation of the decoy theme estimation unit 130 according to the first embodiment.
[0021] Figure 8 This is a flowchart showing the operation of the bait placement unit 140 according to the first embodiment.
[0022] Figure 9 This is a flowchart showing the operation of the bait placement unit 140 according to the first embodiment.
[0023] Figure 10 This is a diagram showing a hardware configuration example of an information processing device 100 according to a modification of the first embodiment.
[0024] Figure 11 This is a diagram showing a configuration example of an information processing device 100 according to a second embodiment.
[0025] Figure 12 This is a flowchart showing the operation of the information processing device 100 according to the second embodiment.
[0026] Figure 13 This is a diagram showing a configuration example of an information processing device 100 according to a third embodiment.
[0027] Figure 14 This is a diagram showing a configuration example of an information processing device 100 according to a fourth embodiment. DETAILED DESCRIPTION
[0028] In the description of the embodiments and the accompanying drawings, identical or corresponding elements are denoted by the same reference numerals. The description of elements denoted by the same reference numerals is omitted or simplified as appropriate. The arrows in the figures primarily illustrate data flow or processing flow. Furthermore, the term "unit" may be appropriately rewritten as "circuit," "process," "procedure," "processing," or "circuit."
[0029] Implementation method 1.
[0030] Hereinafter, this embodiment will be described in detail with reference to the drawings.
[0031] Even for an insider, it is difficult to browse only the files containing the information they are looking for. Therefore, it is considered that the process of checking various files involves searching for files containing the information they are looking for. An insider is a subject that operates within an organization with the purpose of stealing data from the organization. As a specific example, an insider is an internal criminal in the target system 20, or malware that has stolen legitimate credentials and infects a PC (Personal Computer) used by the organization that manages the target system 20. An insider is a user with legitimate access rights who participates in security attacks within the organization. An insider is also a user with malicious intent. As a specific example, malware is software that operates autonomously as a single entity, or software that operates according to instructions from an attacker outside the organization via a Command & Control server on the Internet.
[0032] Figure 1This figure explains file access by an illegal internal user. Figure 1 In the example, the circle S represents confidentiality. Figure 1 As shown, when an insider searches for files containing the information they are looking for, they typically access files related to the information they are trying to leak, as well as files unrelated to the information they are trying to leak. Therefore, it is preferable to predict the information a certain employee is looking for based on several files they viewed before being identified as an insider, and to prepare a decoy file based on this predicted information.
[0033] It's impractical to pre-label all documents created during daily operations with a subject. A specific example would be "defense-related," "machine learning-related," or "design document-related." Furthermore, pre-labeling each new document created or revised could disrupt normal operations.
[0034] Therefore, in this embodiment, a staff member who is considered to be an illegal internal person is identified, and the files viewed by the identified staff member are used as objects to confirm the subject. Based on the confirmed subject, the subject that the identified staff member is interested in is estimated, a bait file matching the estimated subject is prepared, and the prepared bait file is configured.
[0035] ***Structure description***
[0036] Figure 2 FIG. 1 shows an example of the configuration of the information processing device 100 according to the present embodiment. Figure 2 As shown, the information processing device 100 includes a log collection unit 110, a risk value calculation unit 120, a lure theme estimation unit 130, a lure placement unit 140, and a lure monitoring unit 150. The information processing device 100 also stores an access log DB (Database) 180 and a lure file DB 190.
[0037] The log collection unit 110 collects the access log 21 and the access log for the decoy file 191 and records the collected logs in the access log DB 180. The access log 21 is a log of file access in the target system 20.
[0038] Bait file 191 is a file used to detect illegal insiders. Specifically, it is a presentation document or a dataset used for image processing. Bait file 191 is generated to match the various topics that may be output as bait topics by bait topic estimation unit 130. Bait file 191 can be manually generated, created by modifying a regular file, generated according to a prescribed rule, generated using natural language processing, or generated using AI (artificial intelligence) technology.
[0039] The decoy file 191 is a file generated in a manner that substantially minimizes suspicion from an insider. Specifically, the file name of the decoy file 191 follows a prescribed naming convention, the icon of the decoy file 191 is identical to that of a legitimate file, and the content of the decoy file 191 superficially resembles that of a legitimate file.
[0040] The target system 20 is a computer system used by multiple users in their business operations and is a system that stores multiple files. As a specific example, the target system 20 is a system operated based on zero trust and is composed of at least one of an on-premises system and a cloud system. The target system 20 manages each of the multiple files as part of a file tree. A file tree is a file system that manages multiple files in a hierarchical manner. In the target system 20, each file is stored in an arbitrary folder, and each user uses a file access tool to access each file managed by the target system 20. A folder is also called a directory. A file access tool is a tool used by each user to access each file, and as a specific example, it is a resource manager or a browser. Each user is a user of the target system 20. Each user can be a human or a computer.
[0041] The risk value calculation unit 120 calculates a risk value for each user based on logs of file access and other data in the target system 20. If no decoy file 191 is configured, the risk value calculation unit 120 typically calculates a risk value for each user based on the access pattern of each user in the target system 20. Even if a decoy file 191 is configured, the risk value calculation unit 120 can calculate a risk value for each user based on the access pattern of each user in the target system 20. If a decoy file 191 is configured in the target system 20, the risk value calculation unit 120 can also use access logs for the decoy file 191 when calculating the risk value for each user. The risk value calculation unit 120 can also increase the risk value for a target user if the target user accesses at least one of one or more decoy files 191.
[0042] The risk value associated with each user is calculated based on the behavior of each user in the target system 20 and corresponds to the likelihood that each user is actually an illegal insider. The behavior of each user in the target system 20 refers to the actions of each user in the target system 20. Specifically, the components of each user's behavior include the files accessed by each user, the order in which each user accessed files, the time period during which each user accessed files, and the number of file accesses per unit time by each user.
[0043] The risk value calculation unit 120 may also pre-model normal behavior patterns in the target system 20 for each user based on file access logs, etc., and calculate the degree to which each user's actual behavior in the target system 20 deviates from the modeled normal behavior pattern as a risk value corresponding to each user. The risk value calculation unit 120 may utilize techniques such as machine learning to model normal behavior patterns, or may employ techniques that detect behavioral anomalies for each user based on access logs, such as User and Entity Behavior Analytics (UEBA).
[0044] Furthermore, the risk value calculation unit 120 generates high-risk user information 121 and outputs the generated high-risk user information 121. High-risk user information 121 is information that indicates each high-risk user and the characteristics of each high-risk user. Specifically, high-risk user information 121 includes data indicating each high-risk user, the risk value associated with each high-risk user, and one or more files accessed by each high-risk user. A high-risk user is a user of the target system 20 whose corresponding risk value is above a predetermined risk baseline value, representing a high likelihood of being an insider. Furthermore, if at least one of the access log 21 and the decoy file access information 151 is updated, the high-risk user information 121 may be updated based on the updated information.
[0045] The decoy topic estimation unit 130 estimates decoy topics based on access logs indicating high-risk users' access to the target system 20, generates decoy topic information 131 indicating the estimated decoy topics, and outputs the generated decoy topic information 131. The decoy topic estimation unit 130 may also estimate decoy topics using at least one of natural language processing and a topic list consisting of multiple topics that are candidate decoy topics. The topic list is a list of multiple topics that are candidate decoy topics. Each topic may also be a word. As a specific example, the topics included in the topic list are "traffic," "defense," and "communication" as words.
[0046] Decoy topics are topics that are estimated to be of interest to high-risk users and are the topics of information that high-risk users intend to leak externally. Specifically, decoy topics can include business-level topics such as "transportation," "defense," and "communications," technology-level topics such as "AI," "image processing," and "behavior detection," document-level topics such as "system design documents" and "planning documents," and format-level topics such as "text documents" and "presentation materials," or a combination thereof.
[0047] Furthermore, the decoy topic need not be a linguistic topic as described above. As a specific example, files selected based on the high degree of similarity between documents analyzed using natural language processing can also be used as decoy topics. As a more specific example, the decoy topic estimation unit 130 uses clustering technology to classify files accessed by high-risk users and estimates the cluster with the largest number of files as the decoy topic. Then, the decoy file 191 most similar to the cluster corresponding to the decoy topic estimated by the decoy topic estimation unit 130 is selected from the decoy file DB 190.
[0048] As a specific example, the decoy topic estimation unit 130 analyzes topics based on the folder names of folders viewed by high-risk users, as well as the file names and contents of files viewed by high-risk users, thereby estimating decoy topics. Furthermore, the decoy topic estimation unit 130 may estimate multiple decoy topics as decoy topics corresponding to a high-risk user. Furthermore, high-risk users do not necessarily only access files related to the information they wish to leak. Therefore, topics unrelated to the topics in which the high-risk user is actually interested may be estimated as decoy topics.
[0049] The bait configuration unit 140 selects one or more bait files 191 from the bait file DB 190 based on the bait theme estimated by the bait theme estimation unit 130, and configures the one or more selected bait files 191 in the configuration target area. Configuring the bait file 191 includes configuring the bait file 191 with an instruction plug-in, etc. The configuration target area is an area corresponding to a portion of the file tree managed by the target system 20. The configuration target area can be an area containing folders containing files matching the bait theme estimated by the bait theme estimation unit 130, an area surrounding an area visited by a high-risk user, or an area containing an area that is expected to be visited by a high-risk user in the future. The bait configuration unit 140 can also select the bait file 191 from the bait file DB 190 using at least one of natural language processing and a theme list.
[0050] Specifically, the bait placement unit 140 selects one or more bait files 191 from the bait file DB 190 that match the bait theme estimated by the bait theme estimation unit 130, executes an instruction to the target system 20 to place each of the selected bait files 191 in the placement target area, generates bait file information 141 corresponding to the executed instruction, and outputs the generated bait file information 141. The bait file information 141 corresponding to a particular bait file 191 is information indicating the file name and placement location of the particular bait file 191. Instead of executing an instruction to the target system 20 to place the bait file 191, the bait placement unit 140 may place the bait file 191 in the target system 20.
[0051] Alternatively, the decoy configuration unit 140 may extract topics from the content and file names of files accessed by high-risk users, further filter areas containing files or directories associated with the extracted topics, and then configure the decoy files 191 within the filtered areas. In this case, the decoy configuration unit 140 may also utilize a topic model such as Top2Vec to extract topics.
[0052] The bait placement unit 140 may create a bait folder and instruct the target system 20 to place the bait file 191 in the created bait folder. The bait placement unit 140 may also add information indicating that the bait file 191 has been accessed to the access log 21 corresponding to each user.
[0053] The bait monitoring unit 150 monitors access to each bait file 191 indicated in the bait file information 141 by each high-risk user indicated in the high-risk user information 121, generates bait file access information 151 corresponding to the monitoring results, and outputs the generated bait file access information 151. Specifically, if a high-risk user has accessed bait file 191 a predetermined number of times or more, bait file access information 151 indicates that the high-risk user has accessed bait file 191 a predetermined number of times or more. Bait file access information 151 may also indicate that a user other than a high-risk user has accessed bait file 191. Specific examples of methods for selecting bait files 191 based on the estimated bait theme include methods using a rule base or methods using natural language processing technology.
[0054] The analyst may screen high-risk users based on the decoy file access information 151 and the high-risk user information 121 and may reflect the screening results in the high-risk user information 121. As a specific example, the analyst is a person or computer that analyzes security attacks in the target system 20.
[0055] The access log DB 180 is a database that stores information indicating access logs in the target system 20 .
[0056] The bait file DB 190 is a database storing one or more bait files 191 and storing files that are candidates for the bait files 191. The bait file DB 190 stores bait files 191 corresponding to each bait theme that the bait theme estimation unit 130 may output.
[0057] Figure 3 An example of the information processing system 90 of this embodiment is shown. Figure 3 An embodiment of the information processing system 90 is described. Figure 3 In FIG, the information processing device 100 is divided into sections according to the functions and is shown in FIG. Here, the files in the internal illegal person investigation target system 20 are assumed.
[0058] The risk-based authentication function utilizes risk-based authentication technology to receive each user's access log 21 from the target system 20 and calculates a risk value for each user based on the received log. Furthermore, if a decoy file 191 has been deployed, the risk value calculation unit 120 refers to the access log for the decoy file 191 when calculating the risk value for each user.
[0059] The internal illegal agent response platform is a system with internal illegal agent response functions, which has bait dynamic distribution functions and file access functions.
[0060] The bait dynamic distribution function is a function of selecting a folder for arranging the bait file 191 , selecting the bait file 191 , and arranging the selected bait file 191 in the selected folder.
[0061] The decoy configuration unit 140 instructs an internal malicious actor to configure a decoy file 191 for the plug-in.
[0062] The internal attacker prevention plug-in is a software module that implements additional functions for the file access tool. The functions of the bait monitoring unit 150 are implemented by the internal attacker prevention plug-in.
[0063] The file access tool implementing the file access function uses the internal attacker response plug-in to deploy the bait file 191 based on the instructions of the dynamic bait distribution function. The internal attacker response plug-in may actually deploy the bait file 191 on the target system 20, or it may not actually deploy the bait file 191 on the target system 20 but instead display the bait file 191 on the operation screen of the file access tool when each user accesses the folder where the bait file 191 should be deployed.
[0064] Figure 4The following shows an example of the hardware configuration of the information processing device 100 according to this embodiment. The information processing device 100 is configured by a common computer. The information processing device 100 may also be configured by multiple computers. The target system 20 and the information processing device 100 may also be configured integrally.
[0065] As shown in the figure, the information processing device 100 is a computer including hardware such as a processor 11 and a storage device 12. These hardware are connected via signal lines as appropriate.
[0066] The processor 11 is an IC (Integrated Circuit) that performs calculations and controls the hardware included in the computer. Specific examples of the processor 11 include a CPU (Central Processing Unit), a DSP (Digital Signal Processor), or a GPU (Graphics Processing Unit).
[0067] The information processing device 100 may include a plurality of processors instead of the processor 11. The plurality of processors share the role of the processor 11.
[0068] The storage device 12 is composed of at least one of a volatile storage device and a non-volatile storage device. A specific example of a volatile storage device is a RAM (Random Access Memory). A specific example of a non-volatile storage device is a ROM (Read Only Memory), an HDD (Hard Disk Drive), or a flash memory. Data stored in the storage device 12 is loaded into the processor 11 as needed.
[0069] The information processing device 100 may include hardware such as an input / output IF (Interface) and a communication device.
[0070] The input / output interface is a port that connects input devices and output devices. Specifically, the input / output interface is a USB (Universal Serial Bus) terminal. Specifically, the input device is a keyboard and a mouse. Specifically, the output device is a display.
[0071] The communication device is a receiver and a transmitter. As a specific example, the communication device is a communication chip or a NIC (Network Interface Card).
[0072] When communicating with other devices, each component of the information processing device 100 may appropriately use an input / output IF and a communication device.
[0073] The storage device 12 stores an information processing program. The information processing program is a program that causes a computer to implement the functions of each component of the information processing device 100. The information processing program is loaded into the storage device 12 and executed by the processor 11. The functions of each component of the information processing device 100 are implemented by software.
[0074] The storage device 12 may also store files managed by the target system 20 .
[0075] Data used when executing the information processing program and data obtained by executing the information processing program are appropriately stored in the storage device 12. Each component of the information processing device 100 appropriately utilizes the storage device 12. The term "data" and the term "information" may have the same meaning.
[0076] The storage device 12 may be a device independent of the computer, and each database may be stored in an external server or the like.
[0077] The information processing program may also be recorded on a computer-readable nonvolatile recording medium. As a specific example, the nonvolatile recording medium is an optical disc or a flash memory. The information processing program may also be provided as a program product.
[0078] ***Action description***
[0079] The operation procedure of the information processing device 100 corresponds to the information processing method. In addition, the program that realizes the operation of the information processing device 100 corresponds to the information processing program.
[0080] Figure 5 1 is a flowchart showing an example of the operation of the information processing device 100. Figure 5 The operation of the information processing device 100 will be described.
[0081] (Step S101: Risk Value Calculation Process)
[0082] The risk value calculation unit 120 refers to the access log DB 180 and calculates a risk value related to each user's behavior based on the file access log.
[0083] (Step S102: Decoy Theme Estimation Process)
[0084] The decoy topic estimation unit 130 estimates a decoy topic based on the log of file access by high-risk users.
[0085] Figure 6This is a flowchart showing an example of the processing of the bait topic estimation unit 130 when the bait topic is estimated using the natural language processing technology in step S102. Figure 6 The processing of the decoy topic estimation unit 130 will be described. In this example, a word embedding model is prepared in advance. The word embedding model may be a generally available model, a model created using files located within the target system 20, or a model obtained by adding information from files located within the target system 20 to a publicly available word embedding model.
[0086] (Step S121)
[0087] The decoy topic estimation unit 130 selects one file that has been accessed by the target user and is indicated by the high-risk user information 121 .
[0088] (Step S122)
[0089] The decoy topic estimation unit 130 extracts words whose part of speech is noun from the file name and description content of the file selected in step S121 .
[0090] (Step S123)
[0091] The decoy topic estimation unit 130 vectorizes each word extracted in step S122 using a word embedding model and clusters the generated vectors.
[0092] (Step S124)
[0093] The decoy topic estimation unit 130 extracts words that exist near the center of gravity of the cluster where the most words are concentrated.
[0094] (Step S125)
[0095] The decoy topic estimation unit 130 records the word extracted in step S124 as a topic.
[0096] (Step S126)
[0097] The decoy topic estimation unit 130 repeats the processing from step S121 to step S125 until all files accessed by the target user among the files indicated in the high-risk user information 121 are confirmed.
[0098] (Step S127)
[0099] After confirming all files accessed by the target user, the decoy topic estimation unit 130 clusters all topics recorded in step S125 .
[0100] (Step S128)
[0101] The decoy topic estimation unit 130 estimates a word that exists near the center of gravity of a cluster where the most topics are concentrated as a decoy topic.
[0102] Figure 7 This is a flowchart showing an example of the processing of the bait topic estimation unit 130 when the rule base and natural language processing are used together to estimate the bait topic in step S102. Figure 7 The following describes the processing of the decoy topic estimation unit 130. In this example, a word embedding model is prepared in advance, and a topic list is created in advance.
[0103] (Step S131)
[0104] The decoy topic estimation unit 130 selects one file that is indicated by the high-risk user information 121 and has been accessed by the target user.
[0105] (Step S132)
[0106] The decoy topic estimation unit 130 extracts words whose part of speech is noun from the file name and description content of the file selected in step S131 .
[0107] (Step S133)
[0108] The decoy topic estimation unit 130 vectorizes each word extracted in step S132 using a word embedding model. Thereafter, the decoy topic estimation unit 130 calculates the similarity between each generated vector and the vector corresponding to each word included in the topic list.
[0109] (Step S134)
[0110] Based on the similarity calculated in step S133 , the decoy topic estimation unit 130 records a topic with relatively more words corresponding to a similarity greater than or equal to a predetermined threshold value among the topics included in the topic list as the topic of the document selected in step S131 .
[0111] (Step S135)
[0112] The decoy topic estimation unit 130 repeats the processing from step S131 to step S134 until all files accessed by the target user among the files indicated in the high-risk user information 121 are confirmed.
[0113] (Step S136)
[0114] After processing all files accessed by the target user, the decoy topic estimation unit 130 estimates the most frequently appearing topic among all topics recorded in step S134 as a decoy topic.
[0115] (Step S103: Bait file configuration processing)
[0116] The bait placement unit 140 selects a bait file 191 that matches the bait theme estimated by the bait theme estimation unit 130 from the bait file DB 190 , and places the selected bait file 191 in the target system 20 .
[0117] Figure 8 This is a flowchart showing an example of the process of the bait configuration unit 140 when the bait file 191 is selected using the natural language processing technology in step S103. Figure 8 The following describes the processing of the decoy placement unit 140. In this example, a word embedding model is prepared in advance.
[0118] (Step S141)
[0119] The bait configuration unit 140 selects a bait file 191 from the bait file DB 190 .
[0120] (Step S142)
[0121] The bait configuration unit 140 extracts words whose part of speech is noun from the file name and description content of the bait file 191 selected in step S141 .
[0122] (Step S143)
[0123] The bait configuration unit 140 vectorizes each word extracted in step S142 using a word embedding model. Thereafter, the bait configuration unit 140 calculates the similarity between each generated vector and the vector corresponding to the word estimated as the bait theme.
[0124] (Step S144)
[0125] Based on the similarity calculated in step S143 , the bait placement unit 140 calculates the number of words extracted in step S142 whose corresponding similarity exceeds a predetermined threshold.
[0126] (Step S145)
[0127] If the number of words whose corresponding similarity exceeds a predetermined threshold exceeds a predetermined threshold, the bait configuration unit 140 selects the bait file 191 selected in step S141 as the bait file 191 to be configured. The selected bait file 191 is the bait file 191 that matches the bait theme.
[0128] (Step S146)
[0129] The bait configuration unit 140 repeats the process from step S141 to step S145 until all the bait files 191 matching the bait theme among the bait files 191 stored in the bait file DB 190 are confirmed.
[0130] Figure 9 This is a flowchart showing an example of the process of the bait configuration unit 140 when the bait file 191 is selected using both the rule base and the natural language processing in step S103. Figure 9 The following describes the processing of the bait placement unit 140. In this example, a theme list is created in advance.
[0131] (Step S151)
[0132] The lure configuration unit 140 receives information indicating the lure theme from the lure theme estimation unit 130 .
[0133] (Step S152)
[0134] The bait configuration unit 140 selects a bait file 191 that matches the bait theme indicated by the received information from the bait file DB 190. In addition, the bait file 191 is created for each theme indicated in the theme list.
[0135] (Step S104: Bait Monitoring Process)
[0136] The bait monitoring unit 150 monitors access to the bait file 191 , generates bait file access information 151 indicating the monitoring result, and outputs the generated bait file access information 151 .
[0137] (Step S105: High-risk user information correction processing)
[0138] The risk value calculation unit 120 corrects the high-risk user information 121 based on the output decoy file access information 151 .
[0139] **Description of the effects of the first embodiment**
[0140] Conventional technology has a problem in that, even if there is an illegal insider who attempts to leak information contained in documents created in daily work, it is impossible to automatically select a bait file related to the information the illegal insider is seeking and deploy the selected bait file.
[0141] On the other hand, according to this embodiment, based on the high-risk user information 121, the subjects of the files and folders viewed by the high-risk user are analyzed to infer the subjects of interest to the high-risk user, and a bait file 191 matching the inferred subjects is deployed in the target system 20. Therefore, according to this embodiment, the subjects of the files and folders viewed by the insider can be analyzed to infer the subjects of interest to the insider, and based on the inferred subjects, a bait file 191 associated with the information sought by the insider can be automatically selected and deployed.
[0142] **Other structures**
[0143] <Variation 1>
[0144] Figure 10 A hardware configuration example of the information processing device 100 according to this modification is shown.
[0145] The information processing device 100 includes a processing circuit 18 instead of the processor 11 , or includes the processor 11 and the storage device 12 .
[0146] The processing circuit 18 is hardware that realizes at least a part of each unit included in the information processing device 100 .
[0147] The processing circuit 18 may be dedicated hardware, or may be a processor that executes a program stored in the storage device 12 .
[0148] When the processing circuit 18 is dedicated hardware, as a specific example, the processing circuit 18 is a single circuit, a complex circuit, a programmed processor, a parallel programmed processor, an ASIC (Application Specific Integrated Circuit), an FPGA (Field Programmable Gate Array), or a combination thereof.
[0149] The information processing device 100 may include a plurality of processing circuits instead of the processing circuit 18. The plurality of processing circuits may share the role of the processing circuit 18.
[0150] In the information processing device 100 , a part of the functions may be implemented by dedicated hardware, and the remaining functions may be implemented by software or firmware.
[0151] As a specific example, the processing circuit 18 is implemented by hardware, software, firmware, or a combination thereof.
[0152] The processor 11 , the storage device 12 , and the processing circuit 18 are collectively referred to as a “processing circuit.” That is, the functions of the functional components of the information processing device 100 are implemented by the processing circuit.
[0153] The information processing apparatus 100 according to other embodiments may also have the same configuration as that of this modification.
[0154] Implementation method 2.
[0155] Hereinafter, with reference to the drawings, mainly points different from the above-described embodiment will be described.
[0156] ***Structure description***
[0157] Figure 11 FIG. 1 shows an example of the configuration of the information processing device 100 according to the present embodiment. Figure 11 As shown, the information processing device 100 further includes a bait content generating unit 160 compared to the information processing device 100 of the first embodiment.
[0158] Based on the bait theme estimated by the bait theme estimation unit 130, the bait content generation unit 160 selects a file from the bait file DB 190 as a bait file 191 that matches the bait theme. Based on the bait theme estimated by the bait theme estimation unit 130, the bait content generation unit 160 generates a file name for the selected bait file 191 as a bait file name using natural language processing techniques, and outputs the selected bait file 191 and information indicating the generated bait file name. The bait file name is carefully designed to increase the likelihood that an internal malicious actor will identify the bait file 191 corresponding to the bait file name.
[0159] As a specific example, a method for generating a bait file name based on a bait theme is a method using a rule base or natural language processing technology. Specifically, a method is given of adding text to the file name of each file accessed by a high-risk user corresponding to the bait theme according to a rule base. As a specific example, the text added to the file name is "_update" or "_(date)". In addition, the following method is given: using natural language processing, words that serve as nouns are extracted from multiple file names corresponding to the bait theme, common words are extracted from the extracted words, and the nouns contained in the file name of the existing bait file 191 are modified in a manner that includes the extracted words, thereby generating a bait file name.
[0160] The bait configuration unit 140 of this embodiment uses the bait file 191 and file name output by the bait content generation unit 160. That is, the bait configuration unit 140 uses the file selected by the bait content generation unit 160 as the bait file 191 and sets the file name of the bait file 191 to the file name generated by the bait content generation unit 160.
[0161] ***Action description***
[0162] Figure 12This is a flowchart showing an example of the operation of the information processing device 100. Figure 12 The operation of the information processing device 100 will be described.
[0163] (Step S201: Bait content generation process)
[0164] The bait content generation unit 160 selects a bait file 191 matching the bait theme estimated by the bait theme estimation unit 130 from the bait file DB 190 , generates a bait file name based on the bait theme, and sets the generated bait file name as the file name of the selected bait file 191 .
[0165] (Step S202: Bait File Configuration Processing)
[0166] The bait placement unit 140 places the bait file 191 selected by the bait content generation unit 160 in the target system 20. At this time, the bait placement unit 140 sets the file name of the bait file 191 to the bait file name generated by the bait content generation unit 160.
[0167] **Description of the effects of the second embodiment**
[0168] According to this embodiment, the bait content generator 160 generates the file name of the bait file 191 based on the bait theme. Therefore, according to this embodiment, the bait file 191 with a high probability of being recognized by an internal illegal person can be automatically generated and placed in the target system 20.
[0169] Implementation method 3.
[0170] Hereinafter, with reference to the drawings, mainly points different from the above-described embodiment will be described.
[0171] ***Structure description***
[0172] Figure 13 FIG. 1 shows an example of the configuration of the information processing device 100 according to the present embodiment. Figure 13 As shown, the information processing device 100 includes a bait content generating unit 160 , compared to the information processing device 100 of the first embodiment, and does not store the bait file DB 190 .
[0173] The bait content generation unit 160 generates a bait file 191 based on the bait theme using natural language processing technology. Specifically, the bait content generation unit 160 generates the content and file name of the bait file 191. The content and file name of the bait file 191 are carefully designed to increase the likelihood that an insider will identify the bait file 191.
[0174] The bait configuration unit 140 of this embodiment uses the file generated by the bait content generation unit 160 as the bait file 191 .
[0175] ***Action description***
[0176] Each element of the flowchart showing the operation of the information processing device 100 of this embodiment is the same as each element of the flowchart showing the operation of the information processing device 100 of Embodiment 2. The differences from Embodiment 2 will be described below.
[0177] (Step S201: Bait content generation process)
[0178] The bait content generating unit 160 generates the content and file name of the bait file 191 based on the bait theme estimated by the bait theme estimating unit 130 .
[0179] (Step S202: Bait File Configuration Processing)
[0180] The bait placement unit 140 places the bait file 191 generated by the bait content generation unit 160 in the target system 20 .
[0181] **Description of the effects of Embodiment 3**
[0182] According to this embodiment, the bait content generation unit 160 generates the bait file 191 based on the bait theme. Therefore, according to this embodiment, the bait file 191 with a high possibility of being confirmed by an internal illegal person can be automatically generated and placed in the target system 20.
[0183] **Other structures**
[0184] <Variation 2>
[0185] It is assumed that the reading time of each file by the target user varies depending on the depth of the target user's interest, etc. Specifically, it is assumed that the target user spends more time reading files related to topics that he or she is more interested in. Therefore, in this modification, the reading time of each file by the target user is taken into consideration.
[0186] The configuration of the information processing device 100 of this modification is the same as that of the information processing device 100 of the third embodiment.
[0187] The decoy topic estimation unit 130 of this modified example estimates the decoy topics corresponding to the target user based on the files accessed by the target user, as indicated by the high-risk user information 121, and the target user's browsing time for each file stored in the target system 20. The decoy topic estimation unit 130 may also estimate the decoy topics corresponding to the target user based on the difference between the standard browsing time for each file and the target user's browsing time for each file. Furthermore, the decoy topic estimation unit 130 may estimate the decoy topics corresponding to the target user based on the time the target user spends in each folder, or may consider the number or frequency of the target user's access to each folder or file. When estimating the decoy topics corresponding to the target user, the decoy topic estimation unit 130 may not utilize files whose browsing time by the target user is below a threshold.
[0188] The decoy theme estimation unit 130 uses Figure 7 When estimating decoy topics corresponding to a target user using a topic list as described above, instead of simply counting the number of occurrences of each topic, when each topic is used as a target topic, the decoy topic estimation unit 130 can count the number of occurrences of the topic corresponding to the target file based on the time the target user has viewed each file corresponding to the target topic. As a specific example, if the target user's viewing time of the target file is below a threshold, the decoy topic estimation unit 130 sets the number of occurrences of the topic corresponding to the target file to 0.5. If the viewing time of the target file is greater than the threshold, the decoy topic estimation unit 130 sets the number of occurrences of the topic corresponding to the target file to 1.5. Here, the target file is a file that the target user has accessed. Alternatively, the decoy topic estimation unit 130 can set a larger coefficient for counting the number of occurrences of the topic corresponding to each file, with the longer the viewing time of the file.
[0189] The bait content generating unit 160 of this modification generates the content and file name of the bait file 191 based on the bait theme and the browsing time of each file.
[0190] When the bait content generation unit 160 uses natural language processing technology to generate the content of the bait file 191 that matches the bait theme corresponding to the target user, as a specific example, the files among the files matching the bait theme whose browsing time by the target user is above a threshold are used as input for natural language processing.
[0191] When generating the file name of the bait file 191 that matches the bait theme corresponding to the target user, the bait content generation unit 160 specifically uses the file name of a file matching the bait theme that has been viewed by the target user for at least a threshold value as the basis for the file name. Alternatively, the bait content generation unit 160 may select the top X files from the files matching the bait theme, in descending order of the target user's viewing time, and use the file name of each selected file as the basis for the file name.
[0192] According to this modification, the bait file 191 is generated based on the browsing time of the high-risk user. Therefore, according to this modification, the bait file 191 that is highly likely to be accessed by the high-risk user can be placed in the target system 20.
[0193] Furthermore, the method for estimating the bait theme of this modification example may be appropriately combined with the method for selecting or generating the bait file 191 of other embodiments.
[0194] Implementation method 4.
[0195] Hereinafter, with reference to the drawings, mainly points different from the above-described embodiment will be described.
[0196] ***Structure description***
[0197] Figure 14 FIG. 1 shows an example of the configuration of the information processing device 100 according to the present embodiment. Figure 14 As shown, the information processing device 100 includes a bait content generating unit 160 compared to the information processing device 100 of the first embodiment, and stores a template file DB 200 instead of the bait file DB 190 .
[0198] Based on the bait theme estimated by the bait theme estimation unit 130, the bait content generation unit 160 selects a template file from the template file DB 200, modifies the selected template file based on the bait theme estimated by the bait theme estimation unit 130, and outputs the modified template file as the bait file 191. In this case, as a specific example, the bait content generation unit 160 modifies the content and file name of the template file to be appropriate for the bait theme. The bait content generation unit 160 may also select a template file based on the bait theme.
[0199] The bait configuration unit 140 of this embodiment uses the template file modified by the bait content generation unit 160 as the bait file 191 .
[0200] The template file DB 200 is a database that stores candidates for template files corresponding to the bait file 191. The template file corresponding to the bait file 191 is a file used as a template for the bait file 191. The template file DB 200 may also store template files corresponding to various bait themes that the bait theme estimation unit 130 may output.
[0201] ***Action description***
[0202] Each element of the flowchart showing the operation of the information processing apparatus 100 according to the present embodiment is the same as each element of the flowchart showing the operation of the information processing apparatus 100 according to the second embodiment.
[0203] (Step S201: Bait content generation process)
[0204] The bait content generation unit 160 selects a template file from the template file DB200, modifies the content and file name of the selected template file to be suitable for the bait theme estimated by the bait theme estimation unit 130, and outputs the template file with the modified content and file name as a bait file 191.
[0205] (Step S202: Bait File Configuration Processing)
[0206] The bait placement unit 140 places the bait file 191 generated by the bait content generation unit 160 in the target system 20 .
[0207] **Description of the effects of Embodiment 4**
[0208] According to this embodiment, the bait content generator 160 generates the bait file 191 based on the bait theme and the template file. Therefore, according to this embodiment, the bait file 191 with a high probability of being recognized by an internal illegal person can be automatically generated and placed in the target system 20.
[0209] ***Other implementation methods***
[0210] The above-described embodiments can be freely combined, arbitrary components of the embodiments can be modified, or arbitrary components can be omitted in the embodiments.
[0211] The embodiments are not limited to those described in Embodiments 1 to 4, and various modifications can be made as needed. The processes described using flowcharts and the like can also be modified as appropriate.
[0212] Description of Reference Numerals
[0213] 11 processor, 12 storage device, 18 processing circuit, 20 object system, 21 access log, 90 information processing system, 100 information processing device, 110 log collection unit, 120 risk value calculation unit, 121 high-risk user information, 130 bait topic estimation unit, 131 bait topic information, 140 bait configuration unit, 141 bait file information, 150 bait monitoring unit, 151 bait file access information, 160 bait content generation unit, 180 access log DB, 190 bait file DB, 191 bait file, 200 template file DB.
Claims
1. An information processing device, wherein: The information processing device comprises: a decoy topic estimation unit that estimates a decoy topic, which is a topic of information to be leaked to the outside by a high-risk user, based on an access log indicating access to the target system by the high-risk user as a user of the target system; as well as A bait configuration unit configures a bait file that matches the estimated bait theme in the target system.
2. The information processing device according to claim 1, wherein The information processing device further includes a risk value calculation unit that calculates a risk value corresponding to each user of the target system based on an access pattern of each user of the target system in the target system. The high-risk user is a user whose corresponding risk value is greater than or equal to a risk reference value among users of the target system.
3. The information processing device according to claim 2, wherein: The risk value calculation unit increases the risk value corresponding to the target user when the target user, who is a user of the target system, accesses the decoy file.
4. The information processing device according to any one of claims 1 to 3, wherein: The bait configuration unit selects a file as the bait file from a database storing files that are candidates for the bait file based on the estimated bait theme.
5. The information processing apparatus according to claim 4, wherein: The bait topic estimation unit estimates the bait topic using at least one of natural language processing and a topic list consisting of a plurality of topics that are candidates for the bait topic. The bait configuration unit selects the bait file from the database using at least one of natural language processing and the topic list.
6. The information processing apparatus according to any one of claims 1 to 3, wherein: The information processing device further includes a bait content generating unit that selects a file as the bait file from a database storing files that are candidates for the bait file based on the estimated bait theme, and generates a file name for the bait file based on the estimated bait theme. The bait configuration unit uses the selected file as the bait file and sets the file name of the bait file to the generated file name.
7. The information processing apparatus according to any one of claims 1 to 3, wherein: The information processing device further includes a bait content generating unit that generates a file as the bait file based on the estimated bait theme. The bait configuration unit uses the generated file as the bait file.
8. The information processing apparatus according to any one of claims 1 to 3, wherein: The information processing device further includes a bait content generating unit, which selects a template file from a database storing candidates of template files corresponding to the bait file based on the estimated bait theme, and modifies the selected template file based on the estimated bait theme. The bait configuration unit uses the modified template file as the bait file.
9. The information processing apparatus according to any one of claims 1 to 8, wherein: The decoy theme estimation unit estimates the decoy theme based on a browsing time of each file stored in the target system by the high-risk user.
10. An information processing method, wherein: The computer estimates a decoy subject, which is a subject of information to be leaked to the outside by a high-risk user who is a user of the target system, based on an access log indicating access to the target system by the high-risk user. The computer deploys a bait file matching the estimated bait theme to the target system.
11. An information processing program, wherein: The information processing program causes an information processing device serving as a computer to execute: a decoy topic estimation process of estimating, based on an access log indicating access by a high-risk user, who is a user of the target system, to the target system, a decoy topic that is a topic of information to be leaked to the outside by the high-risk user; as well as The bait configuration process configures a bait file that matches the estimated bait theme in the target system.
Citation Information
Patent Citations
Information processor and program
JP2010134832A