Attack analysis device, attack analysis method, and attack analysis program
By introducing an analysis priority change unit into the honeypot system, the analysis priority is adjusted according to the impact and content of the attack on the product, which solves the problem of low analysis efficiency of the honeypot system and enables timely analysis of attacks on high-priority devices and response to multi-stage attacks.
Patent Information
- Application Number
- CN202380099537.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-06-27
- Publication Date
- 2026-01-23
AI Technical Summary
In existing technologies, honeypot systems suffer from low analysis efficiency and are unable to dynamically adjust priorities based on the impact and content of attacks on products when receiving a large number of network attacks, resulting in the inability to analyze high-priority device attacks in a timely manner.
The attack analysis device dynamically adjusts the analysis priority based on the impact and content of network attacks on the product, and uses the analysis priority change unit to prioritize the analysis of attacks on high-priority devices among multiple devices.
It enables dynamic adjustment of analysis priority based on attack content and impact, improving the analysis efficiency of honeypot systems against high-priority device attacks and enabling timely response to multi-stage attacks.
Smart Images

Figure CN121399602A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present disclosure relates to an attack analysis apparatus, an attack analysis method, and an attack analysis program. BACKGROUND
[0002] A honeypot refers to a system that induces a cyber attack by publicly exposing a terminal intentionally set to be vulnerable to an attack on the Internet, and observes and analyzes the induced cyber attack.
[0003] A honeypot generally receives a large amount of attack communications, and thus it takes time to analyze the received attack communications. The attack communications are communications indicating a cyber attack. On the other hand, in a case where a cyber attack having a large impact on a product is observed, it is necessary to quickly analyze the observed cyber attack in order to immediately study countermeasures.
[0004] PRIOR ART DOCUMENTS
[0005] PATENT DOCUMENTS
[0006] Patent Document 1: Japanese Patent Application Publication No. 2022-191649 SUMMARY
[0007] PROBLEMS TO BE SOLVED BY THE INVENTION
[0008] A honeypot simulating a system continuously receives a large amount of cyber attack communications. In addition, there are cyber attacks composed of a plurality of stages such as "further cyber attack after information is collected". Therefore, it takes a lot of time and effort to analyze all the cyber attacks along the time series.
[0009] Patent Document 1 discloses a technology of calculating a priority related to a cyber attack based on a time-dependent parameter and a non-time-dependent parameter. However, according to this technology, an analysis priority prepared considering an impact of a cyber attack on a product is not used, and in addition, the analysis priority is not changed according to the content of the observed cyber attack. Therefore, in this technology, there is a problem that a cyber attack against a device corresponding to which the analysis priority is high cannot be analyzed preferentially.
[0010] An object of the present disclosure is to use an analysis priority prepared considering an impact of a cyber attack on a product, and in addition, to change the analysis priority according to the content of the observed cyber attack, whereby a cyber attack against a device corresponding to which the analysis priority is high can be analyzed preferentially.
[0011] MEANS FOR SOLVING THE PROBLEMS
[0012] The attack analysis device of the present disclosure is provided with an analysis priority changing section that changes an analysis priority corresponding to an object device in accordance with contents of an object attack that is a network attack when the object device is subjected to the object attack, the object device being a device possessed by an attack object system that possesses a plurality of devices each of which is provided with an analysis priority, wherein when the plurality of devices possessed by the attack object system are set as an attack object device group, each device included in the attack object device group is subjected to a network attack, and the network attack against each device included in the attack object device group is sequentially analyzed in accordance with the analysis priority corresponding to each device included in the attack object device group.
[0013] Effects of Invention
[0014] According to the present disclosure, the analysis priority changing section changes the analysis priority in accordance with the contents of the network attack. Here, the analysis priority can also be prepared in consideration of the influence of the network attack on the product. Therefore, according to the present disclosure, the analysis priority prepared in consideration of the influence of the network attack on the product is used, and in addition, the analysis priority is changed in accordance with the contents of the observed network attack, whereby the network attack against the device corresponding to the high analysis priority can be preferentially analyzed. BRIEF DESCRIPTION OF DRAWINGS
[0015] Figure 1 is a diagram showing a configuration example of the attack analysis system 90 of Embodiment 1.
[0016] Figure 2 is a diagram illustrating the process of the analysis priority changing section 130 of Embodiment 1, (a) is a diagram showing Example 1, and (b) is a diagram showing Example 2.
[0017] Figure 3 is a diagram showing a hardware configuration example of the attack analysis device 100 of Embodiment 1.
[0018] Figure 4 is a flowchart showing the process of the asset information creating section 120 of Embodiment 1.
[0019] Figure 5 is a diagram showing a specific example of data stored in the asset DB 191 of Embodiment 1.
[0020] Figure 6 is a diagram showing a specific example of data stored in the relationship information DB 192 of Embodiment 1.
[0021] Figure 7 is a flowchart showing the process of the attack analysis system 90 of Embodiment 1.
[0022] Figure 8is a diagram showing a specific example of data stored in the attack information DB 190 of Embodiment 1.
[0023] Figure 9 is a diagram illustrating the processing of the analysis priority changing section 130 of Embodiment 1.
[0024] Figure 10 is a diagram showing a hardware structure example of the attack analysis apparatus 100 of Embodiment 1.
[0025] Figure 11 is a diagram showing a structure example of the attack analysis system 90 of Embodiment 2.
[0026] Figure 12 is a diagram showing a specific example of data stored in the asset DB 191 of Embodiment 2.
[0027] Figure 13 is a diagram showing a specific example of data stored in the vulnerability information DB 193 of Embodiment 2.
[0028] Figure 14 is a flowchart showing the processing of the attack analysis system 90 of Embodiment 2.
[0029] Figure 15 is a diagram showing a specific example of data stored in the attack information DB 190 of Embodiment 2.
[0030] Figure 16 is a diagram illustrating the processing of the analysis priority changing section 130 of Embodiment 2. DETAILED DESCRIPTION
[0031] In the description of the embodiments and the drawings, the same reference numerals are assigned to the same elements and corresponding elements. The description of the elements assigned with the same reference numerals is appropriately omitted or simplified. The arrows in the drawings mainly indicate the flow of data or the flow of processing. In addition, "section" can be appropriately rewritten as "circuit", "process", "step", "processing", or "line".
[0032] In this specification, a cyber attack is also simply referred to as "attack".
[0033] Embodiment 1.
[0034] Hereinafter, the present embodiment will be described in detail with reference to the drawings.
[0035] ***Explanation of Structure***
[0036] Figure 1 A structure example of the attack analysis system 90 of the present embodiment is shown. As shown in FIG. 9, the attack analysis system 90 of the present embodiment includes an attack analysis apparatus 100, an attack information DB 190, and an analysis priority changing section 130. Figure 1As shown, the attack analysis system 90 includes an attack analysis device 100, a honeypot 200, and an external security mechanism 300. All components of the attack analysis system 90 are communicatively connected via a network.
[0037] The attack analysis system 90 uses a method that prioritizes attack analysis based on the analysis priority corresponding to each device when an attack is observed within the honeypot 200. In the attack analysis system 90, the analysis priority corresponding to devices with a high probability of future attacks is changed through attack analysis, thereby efficiently analyzing attacks consisting of multiple stages.
[0038] As a specific example, device 1 contains important information; therefore, we consider the case where the analysis priority corresponding to device 1 is relatively high. In this case, if device 1 is attacked, we quickly analyze the attack targeting device 1.
[0039] As another specific example, device 2 does not possess particularly important information; therefore, we consider the case where the analysis priority corresponding to device 2 is relatively low. In this case, if device 2 is attacked, the priority of attack countermeasures against device 2 is relatively reduced.
[0040] As another specific example, if information related to device 3 is leaked due to an attack, it is possible to execute subsequent attacks based on the leaked information. Therefore, in order to prepare for subsequent attacks, the analysis priority corresponding to device 3 is relatively increased.
[0041] like Figure 1 As shown, the attack analysis device 100 includes an attack analysis unit 110, an asset information creation unit 120, and an analysis priority modification unit 130. Additionally, the attack analysis device 100 stores attack information DB (Database) 190, asset DB 191, and relationship information DB 192.
[0042] Honeypot 200 includes an attack detection unit 210 and various devices. These devices can also be emulators for other devices. Honeypot 200 is equivalent to the target system. Honeypot 200 can also be a system corresponding to a product. Alternatively, "devices" can be replaced with "terminals." The target system has multiple devices, each with an assigned analysis priority. When any device in the target device group is subjected to a network attack, the network attack on each device in the target device group is analyzed sequentially according to the analysis priority corresponding to that of the device in the target device group. The target device group consists of multiple devices possessed by the target system.
[0043] Further, the attack analysis system 90 can also have a system actually used as an attack target system instead of the honeypot 200. That is, the present embodiment can also be applied as a technique used in a security analysis product for an actually used system.
[0044] The attack analysis section 110 analyzes attacks against each device possessed by the honeypot 200, and stores data indicating the analysis result as attack information to the attack information DB 190. At this time, as a specific example, the attack analysis section 110 analyzes where and what kind of attack exists to which terminal by analyzing a communication log. The attack analysis section 110 can also analyze information stolen by an attack, abnormality of each device generated by an attack, and the like.
[0045] The asset information production section 120 produces the asset DB 191.
[0046] In a case where the target device is subjected to a target attack, the analysis priority change section 130 changes the analysis priority corresponding to the target device according to the content of the target attack. The target device is a device possessed by an attack target system. The target attack is a network attack. The analysis priority change section 130 can also change the analysis priority corresponding to the target device according to the importance of data stored in the target device in a case where the target device is subjected to the target attack. The analysis priority change section 130 can also change the analysis priority corresponding to each device of a plurality of devices possessed by the target system which is considered to be subjected to an attack based on information stolen in the target attack. The stolen information is information illegally accessed.
[0047] As a specific example, the analysis priority change section 130 appropriately refers to the attack information DB 190, the asset DB 191, and the relationship information DB 192, and changes the analysis priority corresponding to each device as necessary. Generally, the amount of attacks against the honeypot 200 is large, and thus, attacks as an analysis target are filtered by setting the analysis priority to each device. The number of devices having a relatively high analysis priority can also be determined according to the amount of computing resources and the time that can be spent for analysis of attacks.
[0048] The attack information DB 190 stores data indicating attack information.
[0049] The asset DB 191 stores data indicating assets. As a specific example, the assets are constituted by each device and data stored in each device.
[0050] The relationship information DB 192 stores data indicating relationship information. The relationship information is information having a relationship with assets.
[0051] The attack detection section 210 detects attacks against each device possessed by the honeypot 200, and notifies the attack analysis device 100 of the result of the detection.
[0052] Figure 2 Fig. 12 is a diagram illustrating a specific example of the processing of the analysis priority changing section 130. Here, each client corresponds to a device, and each server corresponds to a device. In addition, before an attack against each device is detected, the analysis priority corresponding to each client is set to "small", and the analysis priority corresponding to each server is set to "medium".
[0053] Figure 2 (a) of Fig. 12 illustrates a specific example in a case where account information of a service is leaked from the client 1 due to an attack. In this example, the analysis priority changing section 130 considers that the possibility of performing an illegal login to the server 1 in the future is high because the service is running in the server 1, and further increases the analysis priority corresponding to the server 1.
[0054] Figure 2 (b) of Fig. 12 illustrates a specific example in a case where address information (path information) of a file server is leaked from the client 1 due to an attack. In this example, the analysis priority changing section 130 considers that the possibility of performing an illegal login to the server 2 in the future is high because the file server is running in the server 2, and further increases the analysis priority corresponding to the server 2. In addition, the analysis priority changing section 130 can also determine that there is no future attack based on the stolen document data in a case where the document data is stolen, and not change the analysis priority corresponding to each device.
[0055] Figure 3 Fig. 13 illustrates a hardware structure example of the attack analysis apparatus 100 of the present embodiment. The attack analysis apparatus 100 is constituted by a computer. The attack analysis apparatus 100 can also be constituted by a plurality of computers.
[0056] As illustrated in this figure, the attack analysis apparatus 100 is a computer provided with a processor 11, a memory 12, an auxiliary storage device 13, an input / output IF (Interface) 14, and a communication device 15, and the like. These hardware are appropriately connected via a signal line 19.
[0057] The processor 11 is an IC (Integrated Circuit) that performs arithmetic processing, and controls the hardware provided in the computer. As a specific example, the processor 11 is a CPU (Central Processing Unit), a DSP (Digital Signal Processor), or a GPU (Graphics Processing Unit).
[0058] The attack analysis apparatus 100 can also be provided with a plurality of processors instead of the processor 11. The plurality of processors share the role of the processor 11.
[0059] The memory 12 is typically a volatile storage device, and as a specific example, is a RAM (Random Access Memory). The memory 12 is also referred to as a main storage device or a main memory. Data stored in the memory 12 is saved in the auxiliary storage device 13 as necessary.
[0060] The auxiliary storage device 13 is typically a non-volatile storage device, and as a specific example, is a ROM (Read Only Memory), an HDD (Hard Disk Drive), or a flash memory. Data stored in the auxiliary storage device 13 is loaded into the memory 12 as necessary.
[0061] The memory 12 and the auxiliary storage device 13 can also be integrally configured.
[0062] The input / output IF 14 is a port that connects input devices and output devices. As a specific example, the input / output IF 14 is a USB (Universal Serial Bus) terminal. As a specific example, the input devices are a keyboard and a mouse. As a specific example, the output devices are a display.
[0063] The communication device 15 is a receiver and a transmitter. As a specific example, the communication device 15 is a communication chip or a NIC (Network Interface Card).
[0064] The input / output IF 14 and the communication device 15 can also be appropriately used when each part of the attack analysis device 100 communicates with other devices and the like.
[0065] The auxiliary storage device 13 stores an attack analysis program. The attack analysis program is a program that causes a computer to realize the functions of each part of the attack analysis device 100. The attack analysis program is loaded into the memory 12 and executed by the processor 11. The functions of each part of the attack analysis device 100 are realized by software.
[0066] Data used when the attack analysis program is executed, data obtained by executing the attack analysis program, and the like are appropriately stored in a storage device. Each part of the attack analysis device 100 appropriately uses the storage device. As a specific example, the storage device is constituted by at least one of the memory 12, the auxiliary storage device 13, a register in the processor 11, and a cache memory in the processor 11. Furthermore, the term "data" and the term "information" sometimes have the same meaning. The storage device can also be independent of the computer.
[0067] The functions of the memory 12 and the auxiliary storage device 13 can also be realized by other storage devices.
[0068] The attack analysis program can also be recorded on a nonvolatile recording medium that is readable by a computer. As a specific example, the nonvolatile recording medium is an optical disk or a flash memory. The attack analysis program can also be provided as a program product.
[0069] ***Explanation of Actions***
[0070] The action steps of the attack analysis apparatus 100 correspond to the attack analysis method. In addition, the program that realizes the actions of the attack analysis apparatus 100 corresponds to the attack analysis program.
[0071] Figure 4 is a flowchart showing an example of the processing of the asset information production section 120 in advance. The processing of the asset information production section 120 is executed by the computer 100. Figure 4 The processing of the asset information production section 120 is explained.
[0072] (Step S101)
[0073] The asset information production section 120 produces the asset DB 191 and the relationship information DB 192, respectively. In addition, the asset information production section 120 can produce a plurality of DBs as each DB according to the kind of information.
[0074] Figure 5 A specific example of the data stored in the asset DB 191 is shown. In this example, the asset information is constituted by information indicating each device, information indicating the structure of each device, information indicating the data held by each device, and information indicating the analysis priority corresponding to each device. The asset information production section 120 stores the asset information in the asset DB 191. In addition, the asset information production section 120 sets the analysis priority corresponding to each device, and stores the set analysis priority in the asset DB 191. The analysis priority can also be set by an analyst or the like. The analysis priority can also be an analysis priority set in consideration of the influence of a cyber attack on a product.
[0075] Figure 6 A specific example of the data stored in the relationship information DB 192 is shown. The relationship information DB 192_1 indicates the relationship information of the account information. The relationship information DB 192_2 indicates the relationship information related to the address of the file server.
[0076] In addition, in the case where the data held by each device is also shared in other devices, the asset information production section 120 stores information indicating the shared data in the relationship information DB 192.
[0077] Figure 7 is a flowchart showing an example of the processing of the attack analysis system 90 at the time of use. The processing of the attack analysis system 90 is executed by the computer 100. Figure 7 The processing of the attack analysis system 90 is explained.
[0078] (Step S111)
[0079] The attack detection unit 210 detects attacks against the honeypot 200 and sends data indicating the detected attacks to the attack analysis device 100.
[0080] (Step S112)
[0081] The attack analysis unit 110 receives data representing an attack from the honeypot 200, analyzes the logs of each attack shown in the received data to determine the data illegally accessed by each attack, and stores the data representing the determined data in the attack information DB190.
[0082] Then, the attack analysis unit 110 determines whether there is a possibility of future attacks based on asset information stored in the asset DB191 that corresponds to the illegal access destinations in each attack, and attack information from the external security agency 300. The attack analysis unit 110 stores the data representing the determination result in the attack information DB190.
[0083] Figure 8 This shows a specific example of the data stored in the attack information DB190. This data indicates the attacked device, the data that was illegally accessed, and the likelihood of future attacks for each attack.
[0084] Furthermore, in the asset DB191, the potential for future attacks can be pre-defined for each piece of information. For example, in the asset DB191, information indicating the potential for future attacks is set for the information representing an account. In this case, if unauthorized access to the information representing the account occurs, the attack analysis unit 110 determines that the device corresponding to the information representing that account is likely to be attacked in the future.
[0085] (Step S113)
[0086] If an attack is identified as potentially threatening in attack information DB190, then proceed to step S114. Otherwise, proceed to step S116.
[0087] (Step S114)
[0088] The analysis priority change unit 130 extracts data from the relationship information DB192 from other devices that share data that has been illegally accessed due to attacks that are set as potentially vulnerable to future attacks in the attack information DB190. Figure 8 In the attack information DB190, the attacks that are set as potentially vulnerable in the future are unauthorized access to the account information of service X and unauthorized access to the address information of server 2.
[0089] As a specific exampleFigure 8 The account information of the service X of the client 1 shown is data used in the server 1 as shown in the relationship information DB 192_1. Therefore, the analysis priority change part 130 determines that the server 1 is likely to be attacked in future.
[0090] As another specific example, Figure 8 The address information of the server 2 shown is data for accessing a file server in the server 2 as shown in the relationship information DB 192_2. Therefore, the analysis priority change part 130 determines that the server 2 is likely to be attacked in future.
[0091] (Step S115)
[0092] The analysis priority change part 130 appropriately changes the analysis priority corresponding to each of the devices of which the possibility of attack in future is set in the attack information DB 190, and the analysis priority corresponding to each of the devices extracted from the relationship information DB 192 in step S114.
[0093] Figure 9 is a graph corresponding to Figure 5 , Figure 6 and Figure 8 is a graph illustrating a specific example of the process of changing the analysis priority.
[0094] As a specific example, the client 1 corresponds to the device of which the possibility of attack in future is set in the attack information DB 190. Therefore, the analysis priority change part 130 increases the analysis priority corresponding to the client 1. In addition, the server 1 uses the service X using the account information leaked due to the attack on the client 1. Therefore, the analysis priority change part 130 increases the analysis priority corresponding to the server 1.
[0095] In addition, as another specific example, the analysis priority change part 130 increases the analysis priority corresponding to the client 1 of which the illegal access is received, and the analysis priority corresponding to the server 2 which can access using the address information leaked due to the attack on the client 1.
[0096] (Step S116)
[0097] In the case where the attack analysis system 90 continues the attack observation, step S111 is executed again. In the case other than this, the attack analysis system 90 ends the process of the present flowchart.
[0098] Further, the analysis priority changing section 130 can change the analysis priority as needed. As a specific example, in a case where the risk of the possibility of future attacks against a certain device is reduced by applying a countermeasure to the certain device, the analysis priority changing section 130 changes the analysis priority corresponding to the certain device to the original value.
[0099] *Explanation of effects of Embodiment 1*
[0100] According to the present embodiment, the analysis priority set in accordance with the asset content can be used, and in addition, the analysis priority can be changed in accordance with the attack content. By setting the analysis priority corresponding to each device that is an object of attack analysis, the work of analyzing attacks can be made efficient. In addition, by changing the analysis priority in accordance with the attack content, the priority order of analysis and countermeasures can be decided in accordance with the attack situation.
[0101] By applying the present embodiment, among a plurality of attacks observed, attacks against devices for which the analysis priority is relatively high can be analyzed preferentially.
[0102] Further, according to the present embodiment, in a case where it is ascertained based on the observed attacks that a device that is highly likely to be targeted in future attacks, the analysis priority corresponding to the device that is highly likely to be targeted can be changed. Thus, according to the present embodiment, attacks composed of a plurality of stages such as attacks in which a certain attack is the basis for other attacks can be dealt with. As a specific example, for attacks composed of a plurality of stages such as "further attacks after information is collected", by increasing the analysis priority corresponding to a device that is likely to be targeted in the next stage of attacks in the stage in which it is detected that information has been collected, attacks against the device can be analyzed quickly when the device is attacked in the next stage.
[0103] *Other structures*
[0104] (Modified example 1)
[0105] Figure 10 A hardware structure example of the attack analysis device 100 of the present modified example is shown.
[0106] The attack analysis device 100 is provided with a processing circuit 18 instead of the processor 11, the processor 11 and the memory 12, the processor 11 and the auxiliary storage device 13, or the processor 11 and the memory 12 and the auxiliary storage device 13.
[0107] The processing circuit 18 is hardware that realizes at least a part of each section with which the attack analysis device 100 is provided.
[0108] The processing circuit 18 can be a dedicated hardware, and in addition, can be a processor that executes a program stored in the memory 12.
[0109] In a case where the processing circuit 18 is a dedicated hardware, as a specific example, the processing circuit 18 is a single circuit, a composite circuit, a programmed processor, a parallel programmed processor, an ASIC (Application Specific Integrated Circuit), an FPGA (Field Programmable Gate Array), or a combination thereof.
[0110] The attack analysis apparatus 100 can also be provided with a plurality of processing circuits instead of the processing circuit 18. The plurality of processing circuits share the role of the processing circuit 18.
[0111] In the attack analysis apparatus 100, a part of the functions can be implemented by a dedicated hardware, and the remaining functions can be implemented by a software or a firmware.
[0112] As a specific example, the processing circuit 18 is implemented by a hardware, a software, a firmware, or a combination thereof.
[0113] The processor 11, the memory 12, the auxiliary storage device 13, and the processing circuit 18 are collectively referred to as a "processing line". That is, the functions of each functional element of the attack analysis apparatus 100 are implemented by the processing line.
[0114] The attack analysis apparatus 100 of the other embodiments can also be the same structure as the present modification example.
[0115] Embodiment 2.
[0116] Hereinafter, the differences from the above-described embodiments are mainly described with reference to the drawings.
[0117] ***Description of Structure***
[0118] Figure 11 A structure example of the attack analysis system 90 of the present embodiment is shown. As shown in the drawing, the attack analysis apparatus 100 of the present embodiment also stores a vulnerability information DB 193. The attack analysis apparatus 100 can also store a relationship information DB 192. Figure 11
[0119] The attack analysis apparatus 100 of the present embodiment has a function of changing the analysis priority of other devices having the same vulnerability in a case where each device in the honeypot 200 is given a vulnerability and attacked. As a specific example, in a case where an attack that breaches the vulnerability of the software a mounted on the client 1 is detected, it is considered that the client 2 mounted with the same software a has a high possibility of being attacked in the future, and the analysis priority corresponding to the client 2 is increased.
[0120] The analysis priority changing section 130 of this embodiment changes the analysis priority corresponding to each device having the object vulnerability other than the object device among the plurality of devices possessed by the attacked system, in the case where the object attack is caused by the object vulnerability. The object vulnerability is a vulnerability possessed by the object device.
[0121] The vulnerability information DB 193 stores information indicating a vulnerability of a device or software, and the like.
[0122] ***Explanation of Actions***
[0123] Hereinafter, differences from Embodiment 1 will be described with respect to the processing of the asset information creating section 120 in advance.
[0124] (Step S101)
[0125] In addition to the processing of Step S101 of Embodiment 1, the asset information creating section 120 also performs the following processing.
[0126] The asset information creating section 120 stores, in the asset DB 191, in addition to the asset information, information indicating each version of each FW (firmware) and each SW (software) mounted on each device. Figure 12 A specific example of data stored in the asset DB 191 is shown.
[0127] In addition, the asset information creating section 120 creates the vulnerability information DB 193 based on information of the external security organization 300. Figure 13 A specific example of data stored in the vulnerability information DB 193 is shown. The data indicates a vulnerability of each version of the FW and SW mounted on each device.
[0128] Figure 14 is a flowchart showing an example of the processing of the attack analysis system 90 at the time of use. The processing of the attack analysis system 90 is described using Figure 14 The processing of the attack analysis system 90 is described. In addition, the attack analysis system 90 can perform the following processing in addition to the processing of the attack analysis system 90 of Embodiment 1.
[0129] (Step S212)
[0130] The attack analysis section 110 receives data indicating attacks from the honeypot 200, determines data illegally accessed by each attack by analyzing logs of each attack indicated by the received data, and stores data indicating the determined data in the attack information DB 190.
[0131] Then, the attack analysis section 110 determines the vulnerability utilized in each attack based on the asset information corresponding to the illegal access destinations in each attack stored in the asset DB 191, the attack information of the external security agency 300, and the like. The attack analysis section 110 stores data indicating the determination result in the attack information DB 190.
[0132] Figure 15 A specific example of data stored in the attack information DB 190 is shown.
[0133] (Step S213)
[0134] The analysis priority change section 130 refers to the attack information DB 190 and the vulnerability information DB 193, and determines whether the vulnerability determined by the attack analysis section 110 also exists in other devices.
[0135] In a case where it is determined that the vulnerability also exists in other devices, step S214 is executed next. In other cases, step S116 is executed next.
[0136] (Step S214)
[0137] The analysis priority change section 130 refers to the attack information DB 190 and the vulnerability information DB 193, and extracts each of other devices having the vulnerability determined by the attack analysis section 110 as a related device.
[0138] As a specific example, as shown in Figure 13 and Figure 15 , the software a mounted on the client 1 has been subjected to illegal access by the vulnerability. In addition, the software a of the same version as the version of the software a mounted on the client 1 is mounted on the client 2. Therefore, the analysis priority change section 130 determines that the client 2 is likely to be subjected to the same attack as the attack against the client 1 in the future, and extracts the client 2 as a related device.
[0139] (Step S215)
[0140] The analysis priority change section 130 appropriately changes the analysis priority corresponding to each of the related devices extracted in step S214.
[0141] Figure 16 is a diagram corresponding to Figure 12 , Figure 13 and Figure 15 , and is a diagram illustrating a specific example of the process of changing the analysis priority. In this example, the analysis priority change section 130 increases the analysis priority corresponding to the client 1 subjected to illegal access and the analysis priority corresponding to the client 2 having the same vulnerability as the client 1 subjected to illegal access, respectively.
[0142] Explanation of effects of Embodiment 2
[0143] According to the present embodiment, it is possible to improve the analysis priority corresponding to each device having the same vulnerability as the object device subjected to the attack before observing the attack against each device.
[0144] ***Other Embodiments***
[0145] Furthermore, the above-described embodiments can be freely combined, or any of the constituent elements of the embodiments can be modified or omitted.
[0146] In addition, the embodiments are not limited to the modes shown in Embodiments 1 and 2, and various changes can be made as needed. The steps explained using flowcharts and the like can also be appropriately changed.
[0147] Explanation of Reference Signs
[0148] 11: processor; 12: memory; 13: auxiliary storage device; 14: input / output IF; 15: communication device; 18: processing circuit; 19: signal line; 90: attack analysis system; 100: attack analysis device; 110: attack analysis section; 120: asset information production section; 130: analysis priority change section; 190: attack information DB; 191: asset DB; 192: relationship information DB; 193: vulnerability information DB; 200: honeypot; 210: attack detection section; 300: external security organization.
Claims
1. An attack analysis apparatus comprising an analysis priority changing unit, wherein, when a target device is subjected to an attack as a target of a network attack, the analysis priority changing unit changes the analysis priority corresponding to the target device according to the content of the target attack, wherein the target device is a device present in an attack target system having multiple devices, and each of the multiple devices is assigned an analysis priority, wherein... When the multiple devices in the target system are defined as a target device group, and each device in the target device group is subjected to a network attack, the network attacks against each device in the target device group are analyzed sequentially according to the analysis priority corresponding to each device in the target device group.
2. The attack analysis apparatus according to claim 1, wherein, In the event that the target device has been attacked by the target, the analysis priority change unit changes the analysis priority corresponding to the target device according to the importance of the data stored in the target device.
3. The attack analysis apparatus according to claim 1 or 2, wherein, The analysis priority change unit changes the analysis priority of each device among the multiple devices in the target system that is considered to be subjected to an attack based on information stolen in the target attack.
4. The attack analysis apparatus according to any one of claims 1 to 3, wherein, When the target attack is caused by a vulnerability in the target device, the analysis priority change unit changes the analysis priority of each device with the vulnerability other than the target device among the multiple devices in the target system.
5. The attack analysis apparatus according to any one of claims 1 to 4, wherein, The system targeted by the attack is a honeypot.
6. An attack analysis method, wherein when a target device is subjected to an attack as a target of a network attack, a computer changes the analysis priority corresponding to the target device according to the content of the target attack, wherein the target device is a device possessed by an attack target system having multiple devices, and each of the multiple devices is assigned an analysis priority, wherein... When the multiple devices in the target system are defined as a target device group, and each device in the target device group is subjected to a network attack, the network attacks against each device in the target device group are analyzed sequentially according to the analysis priority corresponding to each device in the target device group.
7. An attack analysis program that causes an attack analysis device, which is a computer, to perform an analysis priority change process, wherein, in the analysis priority change process, when a target device is subjected to an attack as a target of a network attack, the analysis priority corresponding to the target device is changed according to the content of the target attack, wherein the target device is a device present in an attack target system having multiple devices, and each of the multiple devices is assigned an analysis priority, wherein... When the multiple devices in the target system are defined as a target device group, and each device in the target device group is subjected to a network attack, the network attacks against each device in the target device group are analyzed sequentially according to the analysis priority corresponding to each device in the target device group.
Citation Information
Patent Citations
Cybersecurity management device, cybersecurity management method and cybersecurity management system
JP2022191649A