Control device, detection system, control method, and program

The detection system addresses the inadequacies of existing fake site detection methods by generating and displaying comprehensive information about fake sites, thereby enhancing computer security and facilitating timely takedowns.

JP2025076751APending Publication Date: 2025-05-16NEC CORP
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2023188566
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-11-02
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

Existing methods for detecting fake sites, such as web crawling and DNS record monitoring, are inadequate in ensuring computer security for companies, as they fail to provide comprehensive and timely information about fake sites.

Method used

A controller and detection system that generates and displays information about fake sites, including first information about each fake site disguising a managed site and aggregated status information related to takedowns, allowing administrators to accurately grasp computer security.

Benefits of technology

The system effectively enhances computer security by providing real-time and comprehensive information about fake sites, enabling timely takedowns and improving the overall security posture of managed sites.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025076751000001_ABST
    Figure 2025076751000001_ABST
Patent Text Reader

Abstract

To provide a control device which can recognize computer security of a fake site or the like.SOLUTION: The control device comprises: a display information generation unit which generates display information including first information about each of at least one fake site impersonating a management object site and second information into which status about take-down relating to each of at least one fake site is aggregated; and a display control unit which controls the control device to display the generated display information on a screen.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] The present disclosure relates to a control device, a detection system, a control method, and a program. [Background technology]

[0002] Damage caused by websites (fake sites) that copy information displayed on corporate websites is increasing. Fake sites can be exploited as phishing sites and can damage the reputation of groups. Therefore, it is necessary to accurately detect fake sites.

[0003] Patent Document 1 discloses an information processing system including a fake site detection device. The fake site detection device of Patent Document 1 detects fake sites using pre-registered scenario information. For example, methods such as web crawling and DNS (Domain Name System) record monitoring can be used to detect fake sites. [Prior art documents] [Patent documents]

[0004] [Patent Document 1] JP 2015-187779 A Summary of the Invention [Problem to be solved by the invention]

[0005] Using techniques such as those described in Patent Document 1, Web crawling, and DNS record monitoring, it is possible to detect fake sites in operation. However, even if fake sites can be detected using these techniques, it is difficult to ensure computer security for a company.

[0006] An object of the present disclosure is to provide a control device, a detection system, a control method, and a program capable of grasping the computer security of fake sites and the like. [Means for solving the problem]

[0007] A control device of one embodiment of the present disclosure includes a display information generation unit that generates display information including first information regarding each of at least one fake site that impersonates a managed site and second information that aggregates takedown status regarding each of the at least one fake site, and a display control unit that controls the generated display information to be displayed on a screen.

[0008] In one embodiment of the control method of the present disclosure, display information including first information regarding each of at least one fake site disguised as a managed site and second information that aggregates takedown status regarding each of the at least one fake site is generated, and the generated display information is controlled to be displayed on a screen.

[0009] A program of one embodiment of the present disclosure causes a computer to execute a process of generating display information including first information regarding each of at least one fake site that impersonates a managed site and second information that aggregates takedown status regarding each of the at least one fake site, and a process of controlling the generated display information to be displayed on a screen. Effect of the Invention

[0010] According to the present disclosure, it is possible to provide a control device, a detection system, a control method, and a program capable of grasping the computer security of fake sites and the like. [Brief description of the drawings]

[0011] [Figure 1] 1 is a conceptual diagram for explaining an example of a configuration of a detection system according to the present disclosure. [Diagram 2] 1 is a conceptual diagram illustrating an example of a site image displayed on a managed site according to the present disclosure. [Diagram 3] 1 is a conceptual diagram illustrating an example of source code of a site image displayed on a managed site according to the present disclosure. [Figure 4] 1 is a conceptual diagram for explaining an example of detection of a fake site by the detection system according to the present disclosure. FIG. [Diagram 5] 1 is a conceptual diagram illustrating an example of a configuration of a detection device included in a detection system according to the present disclosure. [Figure 6] 1 is a table showing an example of a whitelist used by a detection device included in a detection system according to the present disclosure. [Figure 7] 1 is a table illustrating an example of a blacklist used by a detection device included in a detection system according to the present disclosure. [Figure 8] FIG. 2 is a conceptual diagram illustrating an example of a configuration of a control device provided in the detection system according to the present disclosure. [Figure 9] 10 is a conceptual diagram illustrating an example of a template of display information generated by a control device included in the detection system according to the present disclosure. FIG. [Figure 10] 1 is a conceptual diagram illustrating an example of display information generated by a control device included in a detection system according to the present disclosure. [Figure 11] 1 is a conceptual diagram illustrating an example of display information generated by a control device included in a detection system according to the present disclosure. [Figure 12] 10 is a flowchart for explaining an example of an operation of a detection device included in the detection system according to the present disclosure. [Figure 13] 11 is a flowchart illustrating an example of a fake site detection process performed by a detection device included in a detection system according to the present disclosure. [Figure 14] 10 is a flowchart for explaining an example of an operation of a control device included in the detection system according to the present disclosure. [Figure 15] FIG. 2 is a block diagram showing an example of a configuration of a control device according to the present disclosure. [Figure 16] 5 is a flowchart for explaining an example of an operation of the control device according to the present disclosure. [Figure 17] FIG. 2 is a block diagram showing an example of a hardware configuration for executing control and processing according to the present disclosure. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS

[0012] Hereinafter, the embodiments for carrying out the present disclosure will be described with reference to the drawings. In this disclosure, the drawings used in the description of each embodiment relate to one or more embodiments. In addition, the elements included in each drawing may apply to one or more embodiments. The embodiments described below are limited in a manner that is technically preferable for carrying out the present disclosure, but the scope of the disclosure is not limited to the following. In all the drawings used in the description of the following embodiments, the same reference numerals are used for similar parts unless otherwise specified. In the following embodiments, repeated description of similar configurations and operations may be omitted.

[0013] (First embodiment) First, the configuration of a detection system according to a first embodiment will be described with reference to the drawings. The detection system according to this embodiment detects websites (fake sites) that copy information displayed on a company's homepage (corporate site). Fake sites may be used for phishing scams. The detection system according to this embodiment presents display information that enables an administrator of a corporate site (managed site) to be managed to accurately grasp information about the fake site.

[0014] In the following, an example will be given in which a fake site of a managed site is detected using an access to the source code of an image displayed on the managed site as a trigger. The method according to this embodiment can be applied to detect a fake site of a managed site using not only an image but also copying of information (contents) such as text, video, and audio as a trigger. The method according to this embodiment can be applied not only to detecting a corporate site but also to detecting a fake site that copies information (contents) of an arbitrary website. The method according to this embodiment may be, for example, a method for detecting an access from a fake site to obtain the content of the managed site when the fake site is established. The method according to this embodiment may also be, for example, a method for detecting an access to the content of the managed site caused by an operation performed on the fake site.

[0015] (composition) Fig. 1 is a block diagram for explaining an example of the configuration of a detection system according to the present disclosure. The detection system 10 includes a detection device 11 and a control device 13. Fig. 1 shows a legitimate site server 18 and a fake site server 19. The legitimate site server 18 is a server used for operating a managed site. The fake site server 19 is a server used by an operator who intends to set up a fake site of the managed site. In the following, it is assumed that unauthorized links to managed sites are prohibited.

[0016] The legitimate site server 18 generates information to be displayed on the managed site in accordance with settings made by the administrator of the managed server. In the following, an image (site image) is assumed as the information to be displayed on the managed site. The site image may include information such as characters and symbols. The legitimate site server 18 is connected to a network NW such as the Internet. The site image generated using the legitimate site server 18 can be displayed on the screen of a terminal device connected to the network NW. The legitimate site server 18 is also connected to a site information database 16. The legitimate site server 18 stores information about the managed site (including the site image) in the site information database 16.

[0017] The site information database 16 is connected to a legitimate site server 18 and an access log database 17. The site information database 16 is also connected to a network NW such as the Internet. The site information database 16 can be accessed via the network NW. Information about managed sites is stored in the site information database 16. The information stored in the site information database 16 includes files of site images (site image files). The site image files are files of site images displayed on managed sites.

[0018] For example, the image format of the site image file is PNG (Portable Network Graphics). The image format of the site image file is not limited to PNG as long as the image can be displayed on a website. For example, the image format of the site image file may be JPEG (Joint Photographic Experts Group) or GIF (Graphics Interchange Format). For example, the image format of the site image file may be WebP or Scalable Vector Graphics (SVG).

[0019] Fig. 2 is a conceptual diagram showing an example of a site image displayed on a managed site. Fig. 2 is an example of a portion of a site image displayed on a managed site. Fig. 2 shows display information (site image 161) including text information "Orchestrating···world" as an example of the site image of the managed site.

[0020] Site image files are written with absolute paths in image tags (img tags) in the source code of the managed site. In other words, site image files are written with absolute paths, not relative paths. Furthermore, unauthorized linking to managed sites is prohibited. Therefore, site images displayed on managed sites do not include images that function as hyperlinks displayed without the administrator's permission.

[0021] 3 is a conceptual diagram for explaining an example of an absolute path of a site image displayed on a managed site. The source code 162 includes an absolute path which is a reference destination of the site image 161 (FIG. 2). The source code 163 includes information related to the site image 161. For example, the source code 163 includes information related to the size of the rendered site image 161, the aspect ratio of the rendered site image 161, the file size of the site image 161, and the link destination of the site image 161. The detection device may have a function of setting the path indicating the site image in the source code 162 as an absolute path, or may have a function of updating the relative path to an absolute path when the path is described as a relative path.

[0022] When an access to a fake site where the source code of the display part of the site image displayed on the managed site is copied is detected, a site image file is read from the site information database 16 via the absolute path of the site image. When the site image file is read, an access log showing the access situation to the site information database 16 is stored in the access log database 17. That is, in response to an access to the site image file stored in the site information database 16, domain information of the access source is recorded in the access log database 17 as a referrer (reference source). For example, the access log includes domain information related to the domain of the device that copied the site image. For example, the access log includes the date of detection of the access, the domain of the access source, the domain registrant, the IP (Internet Protocol) location, and the IP address. By using the access log recorded in the access log database 17, a fake site can be detected almost at the same time as the fake site is launched.

[0023] The fake site server 19 is one of the servers connected to the network NW. The fake site server 19 is used by an operator who intends to operate a fake site. The fake site server 19 is connected to the site information database 16 via the network NW. The fake site server 19 can access site images stored in the site information database 16 via the managed site. When an access to the source code of a site image displayed on the managed site is detected, an access log including domain information of the fake site server 19 is stored in the access log database 17.

[0024] The detection device 11 is connected to the access log database 17. The detection device 11 detects access to the source code of the site image displayed on the managed site by using the access log stored in the access log database 17. The site image file displayed on the managed site is not link-free. Therefore, the detection device 11 can detect the access to the source code of the site image in response to the access to the access log database 17. The detection device 11 searches the access log stored in the access log database 17 at a timing preset by the administrator of the managed site. The detection device 11 detects the access to the source code of the site image by using the searched access log at a timing preset by the administrator of the managed site.

[0025] The timing for detecting access to the source code of the site image is set by the administrator of the managed site. For example, the timing for detecting access to the source code of the site image is set to a specific time that is set in advance. For example, the specific time is set to late at night or early in the morning when there is little access to the managed site. If it is a time period with little access, delays in obtaining access logs are less likely to occur. For example, the specific time may be set to midday when there is a lot of access to the managed site. If it is a time period with a lot of access, access to the source code of the site image can be detected in real time.

[0026] The detection device 11 refers to a whitelist in which domain information permitted to access the site image is recorded, and verifies whether the domain information recorded as a referrer in the access log database 17 is a legitimate domain. If the domain information recorded as a referrer is recorded in the whitelist, the detection device 11 determines that the access from the fake site server 19 established in that domain is normal. If the domain information recorded as a referrer is not recorded in the whitelist, the detection device 11 determines that the access from the fake site server 19 established in that domain is unauthorized. When the detection device 11 detects unauthorized access, it generates detection information including domain information of the domain from which the access originates. The detection information includes display information regarding fake sites that disguise the managed site. The detection information is information for each fake site. The detection device 11 outputs the generated detection information to the control device 13.

[0027] The detection information includes details of the operation status of the fake site. For example, the details of the operation status of the fake site include the detection date, domain, domain registrant, and IP location of the fake site. For example, the details of the operation status of the fake site may include an IP address. For example, the detection information may include a site image copied to the fake site. The detection information may include a source code such as html (Hyper Text Markup Language) describing the fake site. The source code does not necessarily have to be html, and may be any language that can describe a homepage. The detection information may also include a screen dump in which an image displayed on the fake site is captured. The screen dump can prevent access to the fake site when displaying an overview such as that illustrated in FIG. 11 described later. If information such as the detection date, status, domain, domain registrant, and IP location of the fake site is displayed side by side, the administrator can intuitively grasp the details of the operation status of each fake site. For example, if information such as the detection date, status, domain, domain registrant, and IP location of the fake site is displayed on the screen in a format that is aggregated on one screen, the administrator can more intuitively grasp the details of the operation status of each fake site. A format that consolidates information such as the date a fake site was detected, its status, domain, domain registrant, and IP location on one screen is also called a dashboard format.

[0028] Taking down the detected fake site is entrusted to, for example, an external organization. In the present disclosure, takedown refers to making the fake site inaccessible through the network NW, such as deleting fake sites that contain content that may damage the corporate image or malicious content. Taking down the detected fake site is entrusted to, for example, a contracting organization such as a security professional organization, a hosting company, or a domain registrar. If the takedown of the fake site is at a stage before the request, the takedown status is expressed as before takedown or unprocessed. If the takedown of the fake site is at a stage during which the request is being made, the takedown status is expressed as taking down or processing. If the takedown of the fake site by the contracting organization is at a stage where it is completed, the takedown status is expressed as taken down or processed. Note that the expression of the takedown status is not limited to the above example. The takedown status of the fake site is used to generate display information by the control device 13.

[0029] The status includes an overview of the operation status of the detected fake sites. For example, the overview of the operation status of the fake sites includes the number of fake sites currently in operation, the number of fake sites being taken down, and the number of fake sites that have been taken down. If the number of fake sites currently in operation, the number of fake sites being taken down, and the number of fake sites that have been taken down are displayed on the screen in dashboard format, the administrator can intuitively grasp the overview of the operation status of the fake sites.

[0030] The management terminal 15 is a terminal device used by the administrator of the managed site. The managed site is a website on which company information is posted. The administrator uses the management terminal 15 to manage the managed site. For example, the administrator of the managed site is an employee of the company that operates the managed site. Note that the administrator of the managed site is not limited to an employee of the company that operates the managed site. For example, the administrator of the managed site may be a company that has been commissioned to create and manage the managed site. The management terminal 15 is connected to the control device 13. The administrator uses the management terminal 15 to input the takedown status of the fake site into the control device 13.

[0031] The control device 13 is connected to the management terminal 15. The control device 13 acquires the detection information generated by the detection device 11. The control device 13 also acquires the takedown status of the fake site input using the management terminal 15. The control device 13 generates display information including the operation status of the fake site using the acquired detection information and status. The control device 13 displays the generated display information on the screen of the management terminal 15. The administrator who views the display information displayed on the screen of the management terminal 15 can accurately grasp the operation status of the fake site. For example, the control device 13 may output the generated display information to an external system. The use of the display information output to the external system is not particularly limited. For example, the operation status of the fake site can be remotely confirmed by using the display information output to the external system.

[0032] Fig. 4 is a conceptual diagram for explaining the flow of detection of a fake site by the detection system according to the present disclosure. Fig. 4 shows an example in which the establishment of a fake site of a managed site (legitimate site) published via the legitimate site server 18 is detected. Note that Fig. 4 is only an example and does not limit the flow of detection of a fake site according to the present disclosure.

[0033] In FIG. 4, first, the fake site server 19 copies the html (site image file) of the legitimate site. When the fake site is set up on the fake site server 19, the html causes access to the absolute path (full path) of the legitimate site. In response to the access to the absolute path of the site image file, the domain of the fake site is logged as a referrer in the access log database 17. By referring to the referrer, the legitimate site can determine that the access source is not the legitimate site, and therefore can determine that the site from which the access originates is a fake site. The detection system 10 detects the domain of the fake site using the referrer logged in the access log database 17. The detection system 10 presents information including the detected domain to the management terminal 15. The information presented to the management terminal 15 is displayed on the screen of the management terminal 15. The administrator can detect the establishment of the fake site by referring to the information displayed on the screen of the management terminal 15. According to the method of this embodiment, the establishment of the fake site can be detected at the stage when the fake site is set up. Therefore, according to the method of this embodiment, for example, information about the fake site can be grasped before the fake site is fully operational. That is, according to the method of this embodiment, it is possible to grasp the computer security of fake sites and the like.

[0034] As shown in the example of FIG. 4, the detection system 10 can detect access to the source code of a site image according to an action (copy) to the absolute path of the site image file. In the case of a dead copy via an absolute path, an access occurs from a fake site server 19, which is an external site, to a legitimate site server, which is a legitimate site. Therefore, the detection system 10 can detect the establishment of a fake site by using access to the absolute path as a trigger. In the case of an image file such as a site image, access to the absolute path can be logged without being noticed by the operator of the fake site. The method of this embodiment can also be applied to the detection of fake sites other than dead copies. For example, the method of this embodiment can be used to detect any Web page that uses a site image of a managed site (legitimate site) without permission.

[0035] [Detection device] Next, the detection device 11 included in the detection system 10 of the present embodiment will be described with reference to the drawings. Fig. 5 is a block diagram showing an example of the configuration of the detection device according to the present disclosure. The detection device 11 includes an access log acquisition unit 111, a list storage unit 112, a detection unit 113, a detection information generation unit 115, and an output unit 117.

[0036] The access log acquiring unit 111 is connected to the access log database 17. The access log acquiring unit 111 acquires the access logs stored in the access log database 17. The access log includes domain information of the access source of the detected access. The domain information included in the access log is used to detect a fake site.

[0037] The list storage unit 112 stores a whitelist in which domain information that is permitted to access site images of managed sites is registered. Domains registered in the whitelist are permitted to access site images of managed sites. On the other hand, domains not registered in the whitelist are not permitted to access site images of managed sites. Domains not registered in the whitelist are subject to detection as fake sites.

[0038] 6 is a table showing an example of a whitelist. In the whitelist 130, domain information including a domain ID (identifier), a registration date, a domain name, a domain registrant, ..., and an IP location is registered for each domain. The whitelist 130 may include information other than the domain ID, the registration date, the domain name, the domain registrant, ..., and an IP location. Furthermore, the whitelist 130 may register an IP address. The information registered in the whitelist 130 is updated in response to an operation using the management terminal 15.

[0039] For example, the list storage unit 112 may store a blacklist. In this case, domains registered in the blacklist are targets for detection as fake sites. Domains not registered in the blacklist are permitted to access site images if they are registered in the whitelist. For example, domains not registered in the blacklist may be permitted to access source codes of site images. For example, a configuration may be adopted in which, in response to detection of a new fake site, domain information of the fake site is added to the blacklist.

[0040] 7 is a table showing an example of a blacklist. In the blacklist 140, domain information including a domain ID (identifier), a registration date, a domain name, a domain registrant, ..., and an IP location is registered for each domain. The blacklist 140 may include information other than the domain ID, the registration date, the domain name, the domain registrant, ..., and an IP location. Furthermore, the blacklist 140 may register an IP address. The information registered in the blacklist 140 may be updated in response to the detection of a new fake site.

[0041] The detection unit 113 extracts the domain of the access source from the domain information of the access log. The detection unit 113 refers to the whitelist stored in the list storage unit 112 and searches for a domain that matches the domain extracted from the domain information of the access log. If there is no domain that matches the domain extracted from the domain information of the access log, the detection unit 113 detects that domain as a fake site domain. On the other hand, if there is a domain that matches the domain extracted from the domain information of the access log, the detection unit 113 determines that the domain is a permitted domain. In this case, the detection unit 113 may be configured to output the determination result, or may be configured not to execute any particular process. The detection unit 113 may also be configured to exclude domains included in the whitelist from detection targets. This configuration can prevent overdetection of fake site domains.

[0042] The detection unit 113 may refer to the blacklist stored in the list storage unit 112 and search for a domain that matches the domain extracted from the domain information of the access log. If there is a domain that matches the domain extracted from the domain information of the access log, the detection unit 113 detects that domain as a fake site domain. On the other hand, if there is no domain that matches the domain extracted from the domain information of the access log, the detection unit 113 determines that the domain is an allowed domain. In this case, the detection unit 113 may be configured to output the determination result, or may be configured not to execute any particular process. For example, the detection unit 113 may add domain information of a new fake site to the blacklist. Adding domain information of a new fake site to the blacklist improves the accuracy of detecting fake sites using the blacklist.

[0043] The detection information generation unit 115 generates detection information including domain information of the detected fake site. For example, the detection information includes information such as the detection date, domain, domain registrant, and IP location of the detected fake site. The detection date is the date and time when the domain of the fake site was detected. The domain indicates the name of the domain of the fake site. The domain registrant indicates the registrant of the domain of the fake site. The IP location indicates the location where the fake site server 19 is located. For example, the IP location indicates the country or region where the fake site server 19 is located. The detection information may include an IP address.

[0044] Some fake sites resemble legitimate sites, while others are completely different from legitimate sites. Fake sites with completely different appearances from legitimate sites include sites that have been copied from legitimate sites and then have their body of code changed to arbitrary code. There have also been cases where a fake site that appears to have different content was built by overlaying another page on a page called an iframe after the dead copy. The detection unit 113 detects fake sites according to access to site images displayed on the managed site. Therefore, the detection unit 113 can detect fake sites that resemble legitimate sites, and can also detect fake sites that are completely different from legitimate sites. For example, headers and footers are difficult to process by operators of fake sites, so they often remain even if they are dead copied. Therefore, if absolute paths are included in the images of the header and footer, the possibility of preventing fake sites from being overlooked can be increased even if the site is completely different from the legitimate site.

[0045] The output unit 117 is connected to the control device 13. The output unit 117 outputs detection information related to the fake site to the control device 13. The detection information output to the control device 13 is processed by the control device 13 into image information in a display format that makes it easy to accurately grasp information related to the fake site. The processed display information is displayed on the screen of the management terminal 15. An administrator who views the display information displayed on the screen of the management terminal 15 can clearly grasp information related to the fake site.

[0046] The system may be configured so that a notification is sent to an administrator in response to the detection of a fake site. For example, a notification in the form of an email, instant message, or the like is sent to management terminal 15 in response to the detection of a fake site. The notification of the detection of a fake site may be displayed on the screen of management terminal 15. The notification of the detection of a fake site may be issued as an audio message from a speaker of management terminal 15. For example, the notification of the detection of a fake site may be sent to a mobile terminal (not shown) carried by the administrator. The administrator who receives the notification in response to the detection of a fake site can detect the operation of the fake site sooner than by viewing the display information displayed on the screen of management terminal 15.

[0047] The output unit 117 may be configured to transmit the detection information regarding the fake site to an external organization. In that case, the output unit 117 is connected to a system or device of the external organization via the Internet. For example, the external organization is an organization contracted to take down the fake site. The takedown organization is an organization such as a security professional organization, a hosting company, or a domain registrar. If the takedown of the fake site is at a stage before being requested to a contracting organization, the status of the takedown is expressed as before takedown or unprocessed. If the takedown of the fake site is at a stage where it is being requested to a contracting organization, the status of the takedown is expressed as taking down or processing. If the takedown of the fake site by the contracting organization is completed, the status of the takedown is expressed as taken down or processed. The status of the takedown is not limited to the above expressions as long as the status of the takedown of the fake site by the contracting organization can be determined.

[0048] [Control device] Next, the control device 13 included in the detection system 10 of the present embodiment will be described with reference to the drawings. Fig. 8 is a block diagram showing an example of the configuration of the control device according to the present disclosure. The control device 13 includes a detection information acquisition unit 131, a status acquisition unit 132, a storage unit 133, a display information generation unit 135, and a display control unit 137.

[0049] The detection information acquisition unit 131 is connected to the detection device 11. The detection information acquisition unit 131 acquires the detection information from the detection device 11. The detection information includes information about the domain of the fake site. The timing of acquiring the detection information is set arbitrarily. For example, the detection information acquisition unit 131 acquires the detection information from the detection device 11 at a predetermined acquisition timing. For example, the detection information acquisition unit 131 may be configured to acquire the detection information from the detection device 11 in response to an operation of the management terminal 15 by the administrator.

[0050] The status acquisition unit 132 is connected to the management terminal 15. The status acquisition unit 132 acquires the status of the takedown of the fake site. The takedown status is input via the management terminal 15. If the takedown of the fake site has not yet been requested to the contracting institution, the takedown status is input as "before takedown" or "not processed." If the takedown of the fake site has been requested to the contracting institution, the takedown status is input as "taking down" or "processing." If the takedown of the fake site by the contracting institution has been completed, the takedown status is input as "taken down" or "processed." The takedown status is not limited to the above expressions as long as it is possible to determine the response status of the takedown of the fake site by the contracting institution. The takedown status may also be configured to be input from an external institution. In that case, the status acquisition unit 132 acquires the takedown status via a network NW such as the Internet.

[0051] The storage unit 133 stores a template of display information to be presented to the administrator. The template of display information is a model for displaying the takedown status of the fake site and the domain information of the fake site in a dashboard format. For example, the template of display information includes an area in which an overview of the operation status of the fake site is set. For example, the template of display information includes an area in which details of the operation status of the fake site are set. For example, the template of display information includes an area in which an overview of the operation status of the fake site is set and an area in which details of the operation status of the fake site are set.

[0052] FIG. 9 is a conceptual diagram showing an example of a template of display information. The template 150 includes an overview region 151 and a detail region 152. The overview region 151 is set to an overview of the operation status of the fake site. The detail region 152 is set to the details of the operation status of the fake site. There is no limitation on the positional relationship between the overview region 151 and the detail region 152. In the example of FIG. 9, the detail region 152 is set below the overview region 151. For example, the detail region 152 may be set above the overview region 151. For example, the overview region 151 and the detail region 152 may be set to be arranged side by side. For example, the positional relationship between the overview region 151 and the detail region 152 may be set to be changeable according to an operation using the management terminal 15. The shapes of the overview region 151 and the detail region 152 are not limited to a rectangle. For example, the shapes of the overview region 151 and the detail region 152 may be set arbitrarily, such as a trapezoid, a circle, or an ellipse. It is preferable that overview region 151 and detail region 152 are set to a layout and shape optimized for the administrator to grasp the operation status of the fake site. Furthermore, regions other than overview region 151 and detail region 152 may be set in template 150. Information corresponding to the detection information may be set in the regions other than overview region 151 and detail region 152, or information unrelated to the detection information may be set. For example, information or a warning notifying the detection of a fake site may be set in the regions other than overview region 151 and detail region 152.

[0053] Furthermore, the storage unit 133 stores the detection information. The detection information of the detected fake site is accumulated in the storage unit 133. For example, the detection information stored in the storage unit 133 is erased in response to an operation of the management terminal 15 by an administrator. The detection information stored in the storage unit 133 may be automatically erased at a preset timing.

[0054] The display information generating unit 135 acquires the detection information of the fake site from the detection information acquiring unit 131. The display information generating unit 135 also acquires the takedown status of the fake site from the status acquiring unit 132. The display information generating unit 135 also acquires a template of the display information from the storage unit 133. The template of the display information is a format for displaying a plurality of pieces of information included in the detection information and the status in a dashboard format in a display format optimized for grasping the risk of the fake site. The display information generating unit 135 generates display information in which the information included in the detection information and the information on the takedown status of the fake site are arranged in the dashboard format in the template of the display information. For example, the display information generating unit 135 sets detailed information (also called first information) including the detection date, status, domain, domain registrant, IP location, and screen dump of the fake site in the details area 152. The detailed information (first information) is information on each of at least one fake site disguised as a managed site. For example, the display information generating unit 135 sets summary information (also called second information) including the number of fake sites currently in operation, the number of fake sites being taken down, and the number of fake sites that have been taken down in the summary area 151. The summary information (second information) is information in which the status of each takedown of at least one fake site is tallied. The combination of information set in the summary area 151 and the details area 152 is not limited to the examples given here.

[0055] The display control unit 137 is connected to the management terminal 15. The display control unit 137 causes the display information generated by the display information generation unit 135 to be displayed on the screen of the management terminal 15. The display information is displayed on the screen of the management terminal 15 in a dashboard format, which displays the takedown status and domain information of the fake site so that the administrator can easily grasp the operation status of the fake site. That is, the screen of the management terminal 15 displays a plurality of pieces of information included in the detection information in a display format optimized for grasping the risk of the fake site, in association with each other. For example, the display information may be output to an external system. In this case, the display control unit 137 outputs the display information to the external system via a network NW such as the Internet.

[0056] Fig. 10 is a conceptual diagram showing an example of display information displayed on the screen of the management terminal 15. In the example of Fig. 10, information on the detection of the fake site and information on the takedown status are displayed in an overview area 151 and a details area 152 on the screen of the management terminal 15.

[0057] In the example of Fig. 10, summary area 151 displays summary information including the number of fake sites currently in operation, the number of fake sites being taken down, and the number of fake sites that have been taken down. According to the example of Fig. 10, the summary information displayed in summary area 151 allows the user to accurately grasp that there are zero fake sites currently in operation, one fake site being taken down, and 30 fake sites that have been taken down. According to the example of Fig. 10, the user can intuitively grasp the transition of the operation status of the multiple detected fake sites, such as "in operation," "taking down," and "taken down."

[0058] In the example of FIG. 10, the details area 152 displays detailed information including the detection date, status, domain, domain registrant, and IP location of the fake site. In the example of FIG. 10, the detailed information is displayed in descending order of the detection date of the fake site. According to the example of FIG. 10, the detailed information displayed in the details area 152 allows the detection date, status, domain, domain registrant, and IP location of the fake site to be accurately understood. For example, by checking the detection date and status of the fake site together, the delay in the takedown of the fake site can be understood. For example, by checking the domain, domain registrant, and IP location together, it becomes easier to select an external agency to entrust the takedown to.

[0059] The detailed information displayed in the details area 152 may be configured to be selectable according to the status. For example, a check box may be displayed to select each status of "in operation," "taking down," and "taken down," and detailed information for the status selected by the check box may be displayed. The details area 152 may also be configured to sort detailed information on fake sites detected during a specific period. For example, the details area 152 may be configured to display detailed information on approximately the most recent 10 fake sites. The details area 152 may also be configured to allow the number of fake sites to be displayed to be specified.

[0060] The details area 152 may also be configured to sort the fake site details by IP location (country). If multiple fake sites are established in a particular country, contractors in that country may be asked to take steps to combat the frequent establishment of fake sites in that country. In such a case, contractors in that country may be asked to take steps to prevent future fake site establishments.

[0061] In the example of Fig. 10, the summary information displayed in summary area 151 and the detailed information displayed in detail area 152 can be viewed in combination. For example, by confirming that the number of takedowns displayed in summary area 151 is one, and by referring to the domains whose statuses are in process displayed in summary area 151, it is possible to ascertain which domain's fake site is being taken down. If the IP location of the fake site being taken down can be identified, it is possible to identify the external organization to which that IP location is entrusted. For example, depending on the number of days that have passed since the detection date, it is possible to determine whether or not to notify the external organization to which the takedown progress is entrusted.

[0062] FIG. 11 is a conceptual diagram showing an example of display information displayed on the screen of the management terminal. In the example of FIG. 11, in addition to the detection information of the fake site and the takedown status, a screen dump in which an image displayed on the fake site is captured is displayed in the details area 152 of the screen of the management terminal 15. In FIG. 11, information other than the detection date, status, domain, and site image of the fake site is omitted. In addition, in FIG. 11, an overview of the operation status of the fake site is omitted. If the screen dump of the fake site can be referred to, it becomes easier to search for the fake site on the Internet. If the fake site can be accessed, it is possible to directly request the operator of the fake site to close the fake site. In addition, by publishing the screen dump of the fake site, it is possible to encourage Internet users not to access the fake site. For example, the screen dump image may be configured to be enlarged by clicking on the area of ​​the screen dump of the fake site. If configured in this way, it becomes easier to check the details of the tampered content.

[0063] The display examples of Figs. 10 and 11 are merely examples and do not limit the display information displayed by the detection system of this embodiment. The positional relationship and arrangement of information such as detection information and status can be set arbitrarily as long as it is displayed in a dashboard format. In addition, the display format of information such as detection information and status may be changed according to the takedown status. For example, information such as detection information and status may be displayed in different colors, sizes, and fonts according to the takedown status and urgency. For example, information such as detection information and status may be displayed in different colors and sizes according to the takedown status.

[0064] (operation) Next, the operation of the detection system 10 of this embodiment will be described with reference to the drawings. In the following, the detection device 11 and the control device 13 included in the detection system 10 will be described individually.

[0065] [Detection device] Fig. 12 is a flowchart for explaining an example of the operation of the detection device according to the present disclosure. In explaining the process according to the flowchart of Fig. 12, the components of the detection device 11 will be described as the subject of the operation. The subject of the operation of the process according to the flowchart of Fig. 12 may be the detection device 11.

[0066] 12, first, the access log acquiring unit 111 acquires an access log from the access log database 17 (step S111). For example, the access log acquiring unit 111 acquires an access log at a preset timing. The access log acquiring unit 111 may acquire the access log at the timing when the access log is recorded in the access log database 17.

[0067] Next, the detection unit 113 executes a fake site detection process (step S112). In the fake site detection process, the detection unit 113 detects a fake site by using an access log. A detailed example of the fake site detection process in step S112 will be described later.

[0068] Next, the detection unit 113 identifies the domain of the detected fake site (step S113). For example, the detection unit 113 identifies the date of detection of the fake site, the domain registrant of the identified domain, and the IP location.

[0069] Next, the detection information generating unit 115 generates detection information including the domain of the identified fake site (step S114). For example, the detection information includes the date of detection of the fake site, the domain registrant of the identified domain, and the IP location.

[0070] Next, the output unit 117 outputs the generated detection information to the control device 13 (step S115). The detection information output to the control device 13 is used to generate display information for grasping information related to the fake site. After step S115, the process proceeds to step S131 in FIG. 14.

[0071] <Fake site detection process> FIG. 13 is a flowchart for explaining an example of the fake site detection process (step S112 in FIG. 12) according to the present disclosure. In explaining the process according to the flowchart in FIG. 13, the components of the detection device 11 will be described as the subject of operations. The detection device 11 may be the subject of operations of the process according to the flowchart in FIG. 13. Note that the flowchart in FIG. 13 is an example of the fake site detection process and is not intended to limit the fake site detection process.

[0072] In FIG. 13, first, the detection unit 113 searches the access log for the absolute path of the image file written in the source code of the site image of the managed site (step S121).

[0073] Next, the detection unit 113 excludes domains registered in the whitelist from the searched access logs as overdetection logs (step S122).

[0074] Next, the detection unit 113 detects a referrer log that referenced a site image of the managed site from the access log excluding the overdetection log (step S123). The reference source domain of the detected referrer log corresponds to the domain of the fake site. After step S123, the process proceeds to step S113 in FIG. 12.

[0075] [Control device] Fig. 14 is a flowchart for explaining an example of the operation of the control device according to the present disclosure. In the explanation of the process according to the flowchart of Fig. 14, the components of the control device 13 will be explained as the subject of the operation. The subject of the operation of the process according to the flowchart of Fig. 14 may be the control device 13.

[0076] In FIG. 14, first, the detection information acquisition unit 131 acquires the detection information from the detection device 11 (step S131).

[0077] Next, the status acquisition unit 132 acquires the takedown status of the domain included in the detection information (step S132). For example, if a fake site has just been detected and the takedown has not yet been entrusted to an external agency, the status is set to "unprocessed."

[0078] Next, the display information generating unit 135 generates display information including information about the fake site using the detection information and the status (step S133). For example, the display information includes summary information and detailed information about the fake site. The display information generating unit 135 generates display information showing the operation status of the fake site in a dashboard format that is easy for the administrator to understand.

[0079] Next, the display control unit 137 displays the generated display information on the screen of the management terminal 15 (step S134). The operating status of the fake site is displayed on the screen of the management terminal 15 in a display format that is easy for the administrator to understand. The control device 13 may be configured to output the generated display information to an external system.

[0080] As described above, the detection system of the present embodiment includes a detection device and a control device. The detection device includes an access log acquisition unit, a list storage unit, a detection unit, a detection information generation unit, and an output unit. The access log acquisition unit acquires an access log for a site information database in which an image described in an absolute path in a managed site is stored. The list storage unit stores a whitelist in which domains permitted to access the site information database are listed. The detection unit detects a domain that has accessed the site information database. The detection information generation unit generates detection information including information about the domain detected from the access log. The output unit outputs the generated detection information to the control device. The control device includes a detection information acquisition unit, a status acquisition unit, a storage unit, a display information generation unit, and a display control unit. The detection information acquisition unit acquires detection information of a fake site detected in response to an access to a source code of an image described in an absolute path in a managed site. The status acquisition unit acquires a status regarding the takedown of a fake site established in a domain included in the detection information of the fake site. The storage unit stores a template of display information to be presented to an administrator. The display information generating unit generates display information including first information about each of the at least one fake site disguised as the managed site and second information in which a status about takedowns about each of the at least one fake site is compiled. The display control unit controls the generated display information to be displayed on a screen.

[0081] The control device of this embodiment detects a fake site in response to access to the source code of an image written in an absolute path. Therefore, according to this embodiment, a fake site can be detected before it is fully operational. Furthermore, the control device of this embodiment displays the detection information of the detected fake site and the status of the takedown of the fake site in a dashboard format. Therefore, according to this embodiment, information about the fake site can be presented in a visually easy-to-understand manner. In other words, according to this embodiment, it is possible to accurately grasp information about the fake site before the fake site is fully operational.

[0082] In one aspect of this embodiment, the display information generation unit generates display information including the operation status of the fake site based on the status regarding the takedown of the fake site and the detection information of the fake site. The display control unit displays the display information including the operation status of the fake site on the screen of the management terminal. According to this aspect, the information displayed on the screen can be accurately understood for each fake site.

[0083] In one aspect of this embodiment, the display information generation unit generates display information including the number of fake sites in operation, the number of fake sites being taken down, and the number of fake sites that have been taken down as the operation status of the fake sites. The display control unit displays the display information including the number of fake sites in operation, the number of fake sites being taken down, and the number of fake sites that have been taken down on a screen. According to this aspect, the number of fake sites in operation, the number of fake sites being taken down, and the number of fake sites that have been taken down can be accurately grasped from the information displayed on the screen of the management terminal. In one aspect of this embodiment, the display information generation unit generates display information including at least one of the detection date, status, domain, domain registrant, and IP location of the fake site as the operation status of the fake site. The display control unit displays the display information including at least one of the detection date, status, domain, domain registrant, and IP location of the fake site on a screen. According to this aspect, the detection date, status, domain, domain registrant, and IP location of the fake site can be accurately grasped from the information displayed on the screen.

[0084] In one aspect of this embodiment, the display information generating unit generates display information including a screen dump of a captured image displayed on the fake site as the operation status of the fake site. The display control unit displays the display information including the image of the fake site on the screen. If the screen dump of the fake site can be referenced, it becomes easier to search for the fake site on the Internet. If the fake site can be accessed, it is possible to directly request the operator of the fake site to close the fake site. Furthermore, by publishing the screen dump of the fake site, it is possible to encourage Internet users not to access the fake site.

[0085] A control device according to one aspect of the present embodiment includes a detection information acquisition unit and a status acquisition unit. The detection information acquisition unit acquires detection information of a fake site detected in response to an access to source code of an image described in an absolute path on a managed site. The status acquisition unit acquires a status regarding the takedown of a fake site established in a domain included in the detection information of the fake site. This aspect clarifies the acquisition of detection information and status.

[0086] In one aspect of this embodiment, the detection device compares a domain detected from an access log with a domain registered in a whitelist that lists domains that are permitted to access the site information database. If there is a mismatch between a domain registered in the whitelist and a domain detected from the access log, the detection device determines that the domain detected from the access log is a fake site domain. According to this aspect, a domain not registered in the whitelist can be detected as a fake site domain by referring to the whitelist.

[0087] Second embodiment Next, an example of a control device according to the second embodiment will be described with reference to the drawings. The control device of this embodiment is a simplified configuration of the control device included in the detection system of the first embodiment. The control device of this embodiment generates display information using detection information output from the detection device included in the detection system of the first embodiment.

[0088] (composition) 15 is a block diagram showing an example of the configuration of a control device according to the present disclosure. The control device 23 includes a display information generating unit 235 and a display control unit 237.

[0089] The display information generating unit 235 generates display information including first information on at least one fake site disguised as a managed site and second information in which the takedown status of at least one fake site is collected. The display control unit 237 controls the generated display information to be displayed on the screen.

[0090] (operation) Fig. 16 is a flowchart for explaining an example of the operation of the control device according to the present disclosure. In the explanation of the process according to the flowchart of Fig. 16, the components of the control device 23 will be explained as the subject of the operation. The subject of the operation of the process according to the flowchart of Fig. 16 may be the control device 23.

[0091] 16, first, the display information generating unit 235 generates display information including the first information and the second information (step S231). The first information is information about at least one fake site that impersonates a managed site. The second information is information that aggregates the takedown status of at least one fake site.

[0092] Next, the display control unit 237 controls so that the generated display information is displayed on the screen (step S232).

[0093] The display information generating unit 235 can be realized, for example, by using the function of the display information generating unit 135 in Fig. 8. The display control unit 237 can be realized, for example, by using the function of the display control unit 137 in Fig. 8.

[0094] As described above, the control device of this embodiment displays on a screen display information including first information about at least one fake site disguised as a managed site and second information that compiles the takedown status of at least one fake site. Therefore, according to this embodiment, it is possible to grasp the computer security of fake sites, etc.

[0095] (Hardware) Next, a hardware configuration for executing the control and processing in the present disclosure will be described with reference to the drawings. Here, an information processing device 90 (computer) in Fig. 17 is given as an example of such a hardware configuration. The information processing device 90 in Fig. 17 is an example of a configuration for executing the control and processing in the present disclosure, and does not limit the scope of the present disclosure.

[0096] As shown in Fig. 17, an information processing device 90 includes a processor 91, a memory 92, an auxiliary storage device 93, an input / output interface 95, and a communication interface 96. In Fig. 17, the interface is abbreviated as I / F (Interface). The processor 91, the memory 92, the auxiliary storage device 93, the input / output interface 95, and the communication interface 96 are connected to each other via a bus 98 so as to be able to communicate data with each other. In addition, the processor 91, the memory 92, the auxiliary storage device 93, and the input / output interface 95 are connected to a network such as the Internet or an intranet via the communication interface 96.

[0097] The processor 91 loads a program (instructions) stored in an auxiliary storage device 93 or the like into the memory 92. For example, the program is a software program for executing the control and processing in the present disclosure. The processor 91 executes the program loaded into the memory 92. The processor 91 executes the program to execute the control and processing in the present disclosure.

[0098] The memory 92 is a storage device having an area in which a program is loaded. The processor 91 loads a program stored in an auxiliary storage device 93 or the like in the memory 92. The memory 92 is realized by a volatile memory such as a dynamic random access memory (DRAM). Alternatively, a non-volatile memory such as a magnetoresistive random access memory (MRAM) may be used as the memory 92.

[0099] The auxiliary storage device 93 stores various data such as programs. For example, the auxiliary storage device 93 is realized by a local disk such as a hard disk or a flash memory. Note that it is also possible to store various data in the memory 92 and omit the auxiliary storage device 93.

[0100] The input / output interface 95 is an interface for connecting the information processing device 90 to peripheral devices based on standards and specifications. The communication interface 96 is an interface for connecting to an external system or device through a network such as the Internet or an intranet based on standards and specifications. The input / output interface 95 and the communication interface 96 may be a common interface for connecting to an external device.

[0101] Input devices such as a keyboard, a mouse, and a touch panel may be connected to the information processing device 90 as necessary. These input devices are used to input information and settings. When a touch panel is used as the input device, a screen having the function of the touch panel becomes the interface. The processor 91 and the input devices are connected via an input / output interface 95.

[0102] The information processing device 90 may be equipped with a display device for displaying information. When the display device is equipped, the information processing device 90 is equipped with a control device (not shown) for controlling the display of the display device. The information processing device 90 and the display device are connected via an input / output interface 95.

[0103] The information processing device 90 may be provided with a drive device. The drive device mediates between the processor 91 and a recording medium (program recording medium) in reading data and programs stored in the recording medium and writing the processing results of the information processing device 90 to the recording medium. The information processing device 90 and the drive device are connected via an input / output interface 95.

[0104] The above is an example of a hardware configuration for enabling the control and processing in the present disclosure. The hardware configuration in FIG. 17 is an example of a hardware configuration for executing the control and processing in the present disclosure, and does not limit the scope of the present disclosure. A program for causing a computer to execute the control and processing in the present disclosure is also included in the scope of the present disclosure.

[0105] A program recording medium on which a program for executing the processing in this embodiment is recorded is also included in the scope of the present invention. For example, the program recording medium is a computer-readable non-transient recording medium. The recording medium can be realized by an optical recording medium such as a CD (Compact Disc) or a DVD (Digital Versatile Disc). The recording medium may be realized by a semiconductor recording medium such as a USB (Universal Serial Bus) memory or an SD (Secure Digital) card. The recording medium may also be realized by a magnetic recording medium such as a flexible disk or other recording medium.

[0106] The components in the present disclosure may be combined in any manner. The components in the present disclosure may be realized by software. The components in the present disclosure may be realized by a circuit.

[0107] Although the present disclosure has been described above with reference to the embodiments, the present disclosure is not limited to the above-mentioned embodiments. Various modifications that can be understood by a person skilled in the art can be made to the configuration and details of the present disclosure within the scope of the present disclosure. Furthermore, each embodiment can be appropriately combined with other embodiments.

[0108] A part or all of the above-described embodiments can be described as, but is not limited to, the following supplementary notes. (Appendix 1) A display information generating unit that generates display information including first information regarding at least one fake site that is a fake site of a management target and second information that is a compilation of a status regarding the takedown of each of the at least one fake site; A control device comprising: a display control unit that controls the generated display information to be displayed on a screen. (Appendix 2) The display information generation unit generating the display information including the operation status of the fake site based on a status regarding the takedown of the fake site and the detection information of the fake site; The display control unit is A control device as described in Appendix 1, which displays the display information including the operation status of the fake site on a screen. (Appendix 3) The display information generation unit generating the display information including, as the operation status of the fake sites, the number of the fake sites that are in operation, the number of the fake sites that are being taken down, and the number of the fake sites that have been taken down; The display control unit is The control device according to claim 2, which displays on a screen the display information including the number of fake sites that are in operation, the number of fake sites that are being taken down, and the number of fake sites that have been taken down. (Appendix 4) The display information generation unit generating the display information including at least one of the following operational statuses of the fake site: a detection date, a status, a domain, a domain registrant, or an Internet Protocol (IP) location of the fake site; The display control unit is A control device as described in Appendix 2, which displays on a screen the display information including at least one of the detection date, status, domain, domain registrant, or IP location regarding the fake site. (Appendix 5) The display information generation unit generating the display information including a screen dump of an image displayed on the fake site as the operation status of the fake site; The display control unit is 5. The control device according to claim 4, wherein the display information including the screen dump is displayed on a screen. (Appendix 6) a detection information acquisition unit that acquires detection information of the fake site detected in response to an access to a source code of an image written in an absolute path in the managed site; A control device as described in Appendix 1, comprising: a status acquisition unit that acquires a status regarding the takedown of the fake site established in a domain included in the detection information of the fake site. (Appendix 7) The domain of the fake site is: The control device according to claim 1, wherein the domain detected from the access log for the site information database is a domain that does not match a domain registered in a whitelist that lists domains that are permitted to access the site information database in which images described with absolute paths on managed sites are stored. (Appendix 8) A control device according to any one of claims 1 to 7; a detection device that detects a domain that has accessed a site information database from an access log for the site information database in which images described with absolute paths on managed sites are stored, generates detection information including information about the domain detected from the access log, and outputs the generated detection information to the control device. (Appendix 9) The computer Generate display information including first information regarding each of at least one fake site that impersonates a managed site and second information in which a status regarding the takedown of each of the at least one fake site is aggregated; A control method for controlling the generated display information to be displayed on a screen. (Appendix 10) A process of generating display information including first information regarding each of at least one fake site that impersonates a managed site and second information in which a status regarding the takedown of each of the at least one fake site is compiled; and a process of controlling the generated display information to be displayed on a screen.

[0109] Some or all of the configurations described in Supplements 2 to 8 that are dependent on Supplementary Note 1 above may also be dependent on Supplements 9-10 in the same dependent relationship as Supplements 2 to 8. Not limited to Supplements 1 and 9-10, various hardware, software, various recording devices for recording software, or systems may also be made to be dependent on some or all of the configurations described as Supplements within the scope of each of the above-mentioned embodiments. [Explanation of symbols]

[0110] 10. Detection System 11 Detection device 13, 23 Control device 15 Management terminal 16 Site Information Database 17 Access Log Database 18 Official site server 19 Fake site server 111 Access log acquisition unit 112 List storage unit 113 Detection unit 115 Detection information generation unit 117 Output section 131 Detection information acquisition unit 132 Status Acquisition Section 133 Storage section 135, 235 Display information generation section 137, 237 Display control unit

Claims

1. a display information generating unit that generates display information including first information regarding at least one fake site that is a fake site of a management target and second information that is a compilation of a status regarding the takedown of each of the at least one fake site; A control device comprising: a display control unit that controls the generated display information to be displayed on a screen.

2. The display information generating unit generating the display information including the operation status of the fake site based on a status regarding the takedown of the fake site and the detection information of the fake site; The display control unit is The control device according to claim 1 , wherein the display information including the operation status of the fake site is displayed on a screen.

3. The display information generation unit generating the display information including, as the operation status of the fake sites, the number of the fake sites that are in operation, the number of the fake sites that are being taken down, and the number of the fake sites that have been taken down; The display control unit is The control device according to claim 2 , wherein the display information including the number of fake sites currently in operation, the number of fake sites being taken down, and the number of fake sites that have been taken down is displayed on a screen.

4. The display information generating unit generating the display information including at least one of the following operational statuses of the fake site: a detection date, a status, a domain, a domain registrant, or an Internet Protocol (IP) location of the fake site; The display control unit is The control device according to claim 2 , wherein the display information including at least one of the detection date, status, domain, domain registrant, and IP location of the fake site is displayed on a screen.

5. The display information generating unit generating the display information including a screen dump of an image displayed on the fake site as the operation status of the fake site; The display control unit is The control device according to claim 4 , wherein the display information including the screen dump is displayed on a screen.

6. a detection information acquisition unit that acquires detection information of the fake site detected in response to an access to a source code of an image written in an absolute path in the managed site; The control device according to claim 1 , further comprising: a status acquisition unit that acquires a status regarding the takedown of the fake site established in a domain included in the fake site detection information.

7. The domain of the fake site is: The control device according to claim 1, wherein the domain detected from the access log for the site information database is a domain that does not match a domain registered in a whitelist that lists domains that are permitted to access a site information database in which images described with absolute paths on managed sites are stored.

8. A control device according to any one of claims 1 to 7; a detection device that detects a domain that has accessed a site information database from an access log for the site information database in which images described with absolute paths on managed sites are stored, generates detection information including information about the domain detected from the access log, and outputs the generated detection information to the control device.

9. The computer generating display information including first information on at least one fake site that impersonates a managed site and second information in which a status regarding the takedown of each of the at least one fake site is compiled; A control method for controlling the generated display information to be displayed on a screen.

10. A process of generating display information including first information regarding each of at least one fake site that impersonates a managed site and second information in which a status regarding the takedown of each of the at least one fake site is compiled; and a process of controlling the generated display information to be displayed on a screen.

Citation Information

Patent Citations

  • Information processing system, information processing method, and program

    JP2015187779A