Control device, detection system, control method, and program

The control device and detection system address the limitations of existing methods by generating and displaying comprehensive information about potentially fraudulent emails, enhancing computer security and improving the detection of BEC threats.

JP2025077498APending Publication Date: 2025-05-19NEC CORP
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2023189735
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-11-07
Publication Date
2025-05-19

AI Technical Summary

Technical Problem

Existing methods, such as those described in Patent Document 1, struggle to effectively ensure computer security against fraudulent emails, particularly in Business Email Compromise (BEC) scenarios, as they primarily focus on detecting fraudulent emails at the client terminal level without providing comprehensive computer security measures.

Method used

A control device and detection system that generate and display comprehensive information regarding potentially fraudulent emails sent to a management target company, utilizing a display information generation unit to arrange and display multiple pieces of information, and a display control unit to show this information on a screen, thereby enhancing computer security awareness.

Benefits of technology

The solution enables accurate detection and display of information related to fraudulent emails, thereby improving computer security by providing administrators and employees with a clear understanding of potential threats, facilitating proactive measures against BEC attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025077498000001_ABST
    Figure 2025077498000001_ABST
Patent Text Reader

Abstract

To provide a control device, a detection system, a control method, and a program that grasp computer security against fraudulent email etc.SOLUTION: There is provided a detection system that detects fraudulent email by using header information of email and makes a management terminal 14 display display information associated with the detected fraudulent email on its screen, and a control device 13 comprises: a display information generation part 135 which generates display information having a plurality of pieces of information, associated with email which may be fraudulent email sent to an enterprise to be managed, represented, side by side; and a display control part 137 which performs control to display the generated display information on the screen.SELECTED DRAWING: Figure 8
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to a control device, a detection system, a control method, and a program.

Background Art

[0002] Business E-mail Compromise (BEC) is a fraud in which an electronic mail (fraudulent mail) containing fraud content is sent to an employee of a target company to deceive the employee of the target company. The method of sending malicious fraudulent mails pretending to be a management executive of the target company to employees has a high risk of expanding damage. Therefore, it is required to accurately detect fraudulent mails.

[0003] Patent Document 1 discloses an information processing apparatus for identifying a sender of an electronic mail. When the apparatus of Patent Document 1 receives an electronic mail from an external mail server, it extracts, based on settings, the sender's mail address, the mail address of the mail address, the IP (Internet Protocol) address of the mail server, the route information of the mail server, and the like. The apparatus of Patent Document 1 determines, from the value obtained by inputting the information extracted from the mail into a hash function, the color or the like to be assigned. The apparatus of Patent Document 1 attaches and displays the determined color or the like to the mail address or the like.

Prior Art Documents

Patent Documents

[0004]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0005] In the method of Patent Document 1, when an e-mail arrives at the client terminal, the color of the e-mail address or the like is changed according to the change in the sender address of the sender. According to the method of Patent Document 1, at the stage when an e-mail arrives at the client terminal, it is possible to detect a fraudulent e-mail that can be used in business e-mail fraud. In the method of Patent Document 1, even if a fraudulent e-mail received by a client terminal used by an employee of a company can be detected, it is difficult to ensure computer security regarding the company.

[0006] One of the objects of the present disclosure is to provide a control device, a detection system, a control method, and a program capable of grasping computer security such as fraudulent e-mails.

Means for Solving the Problems

[0007] A control device according to an aspect of the present disclosure includes a display information generation unit that generates display information in which a plurality of pieces of information regarding an e-mail that may be a fraudulent e-mail sent to a management target company are arranged and displayed, and a display control unit that controls to display the generated display information on a screen.

[0008] In a display control method according to an aspect of the present disclosure, display information in which a plurality of pieces of information regarding an e-mail that may be a fraudulent e-mail sent to a management target company are arranged and displayed is generated, and control is performed to display the generated display information on a screen.

[0009] A program according to an aspect of the present disclosure causes a computer to execute a process of generating display information in which a plurality of pieces of information regarding an e-mail that may be a fraudulent e-mail sent to a management target company are arranged and displayed, and a process of controlling to display the generated display information on a screen.

Effects of the Invention

[0010] According to the present disclosure, it becomes possible to provide a control device, a detection system, a control method, and a program capable of grasping computer security such as fraudulent e-mails.

Brief Description of the Drawings

[0011]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Figure 12

Figure 13

Figure 14

Figure 15

Figure 16

Figure 17

Embodiments for Carrying Out the Invention

[0012] Hereinafter, embodiments for carrying out the present disclosure will be described with reference to the drawings. In the present disclosure, the drawings used in the description of each embodiment are associated with one or more embodiments. Further, the elements included in each drawing may apply to one or more embodiments. The embodiments described below have technically preferable limitations for carrying out the present disclosure, but do not limit the scope of the disclosure below. In all the drawings used in the description of the following embodiments, the same reference numerals are given to the same parts unless otherwise specified. In the following embodiments, repeated descriptions of the same configuration and operation may be omitted.

[0013] (First Embodiment) First, the configuration of the detection system according to the first embodiment will be described with reference to the drawings. The detection system according to the present embodiment detects an irregular email (irregular mail) that has been sent by impersonating a legitimate sender from among the emails sent to the enterprise to be managed. For example, the irregular mail may include a fraudulent email intended to deceive an employee of the enterprise to be managed. The detection system according to the present embodiment causes a management terminal used by an administrator or the like to display display information that enables accurate grasping of information regarding the detected irregular mail on the screen of the management terminal. Hereinafter, for convenience of explanation, it is assumed that the irregular mail is an email that may be a fraudulent email.

[0014] The following gives an example of detecting fraud emails pretending to be a company's manager. For example, fraud emails used in business email fraud are difficult to detect because they do not have a URL (Uniform Resource Locator) or malware attachment. In the present embodiment, fraud emails are detected using the header information of the email. The method according to the present embodiment can be applied not only to the detection of fraud emails pretending to be a company's manager but also to the detection of fraud emails pretending to be any person.

[0015] (Configuration) FIG. 1 is a block diagram for explaining an example of the configuration of a detection system according to the present disclosure. The detection system 10 includes a detection device 11 and a control device 13. FIG. 1 shows a management terminal 14, a monitoring device 15, a mail log database 16, a company-side mail server 17, and an attacker-side mail server 19. Also, FIG. 1 shows an employee terminal 170 and an attacker terminal 190. In FIG. 1, among the configurations of systems and devices used for sending and receiving emails, the configurations according to the present disclosure are illustrated.

[0016] The monitoring device 15 is connected to a network NW such as the Internet. Also, the monitoring device 15 is connected to the mail log database 16 and the company-side mail server 17. The monitoring device 15 may be configured to monitor the company-side mail server 17 connected to the network NW in the cloud without being disposed between the network NW and the company-side mail server 17. The monitoring device 15 may be configured as hardware or software.

[0017] The monitoring device 15 monitors the emails transmitted and received via the enterprise-side email server 17. The monitoring device 15 monitors the header information of the emails transmitted to the enterprise-side email server 17. For example, the header information of an email includes the sender address, the sender display name, the recipient address, the subject, and the sending date and time. For example, the header information of an email includes the route through which the email was delivered, the reply address of the email, and the return address in case of an error in email delivery. For example, the header information of an email includes the identification number of the email, information about the software of the email used by the sender, and the authentication result of the sending email address. Note that the information included in the header information of an email is not limited to the above examples.

[0018] The monitoring device 15 detects the header information that contains information with the characteristics of fraudulent emails. For example, the monitoring device 15 detects information with the characteristics of fraudulent emails from the sender display name and the subject. Examples of the sender display name to be detected include the names of the managers, management staff, and employees of the enterprise under management. In particular, for fraudulent emails that deceive the executive level (C-Suite) of the enterprise under management, there is a risk that employees will blindly follow the instructions. Therefore, it is required that fraudulent emails that deceive the executive level be accurately detected. Also, for fraudulent emails that deceive the representatives of domestic affiliated companies or overseas affiliated companies, there may be a situation where employees do not recognize the names of the affiliated companies or representatives. Therefore, it is required that fraudulent emails that deceive the representatives of domestic affiliated companies or overseas affiliated companies be accurately detected. Examples of the subject to be detected include merger, acquisition, Brief call, Urgent Request, etc. Also, for fraudulent emails that contain character information such as merger or acquisition in the subject, there is a possibility that a large amount of money will be transferred to the sender. Therefore, it is required that fraudulent emails that contain character information such as merger or acquisition in the subject be accurately detected. For fraudulent emails that contain information such as Urgent Request in the subject, there is a possibility of responding anxiously. Therefore, it is required that fraudulent emails that contain information such as Urgent Request in the subject be accurately detected.

[0019] In addition, the monitoring device 15 may be configured to monitor the header information of the e-mails transmitted from the company-side e-mail server 17. If configured in such a manner, the monitoring device 15 can monitor the e-mails transmitted from the employee terminal 170. For example, it becomes possible to prevent remittance for phishing e-mails in accordance with characteristic expressions included in the header information of the e-mails transmitted from the employee terminal 170. For example, it is possible to detect an event in which remittance has been made to the attacker who is the sender of the phishing e-mail in accordance with characteristic expressions included in the header information of the e-mails transmitted from the employee terminal 170. For example, it is possible to detect the employee terminal 170 that has transmitted an e-mail including a violation of the business regulations in accordance with characteristic expressions included in the header information of the e-mails transmitted from the employee terminal 170.

[0020] The monitoring device 15 stores the header information of the e-mail to be detected in the mail log database 16. For example, the e-mail to be detected is an e-mail that may be a phishing e-mail (also referred to as an irregular e-mail). When the e-mail that may be a phishing e-mail is the e-mail to be detected, it is possible to narrow down the determination target as to whether it is a phishing e-mail. For example, the e-mail to be detected may be all the e-mails transmitted to the company-side e-mail server 17. When all the e-mails transmitted to the company-side e-mail server 17 are the e-mails to be detected, it is possible to reduce the detection omission of phishing e-mails. The monitoring device 15 may be configured to store the body of the e-mail to be detected in the mail log database 16. In addition, the monitoring device 15 may be configured to store the attached file of the e-mail to be detected in the mail log database 16. The body of the e-mail to be detected, the file name of the attached file of the e-mail to be detected, and the attached file of the e-mail to be detected may also be used for detecting phishing e-mails.

[0021] The enterprise-side mail server 17 is a mail server through which emails transmitted and received via terminal devices used by the enterprise under management pass. Usually, the enterprise-side mail server 17 is connected to a plurality of employee terminals 170. The enterprise-side mail server 17 is connected to the network NW via the monitoring device 15. The enterprise-side mail server 17 may be connected to the network NW without passing through the monitoring device 15. Emails sent to the enterprise-side mail server 17 are distributed to the employee terminals 170 designated by the destination addresses included in the header information of those emails. Emails sent from the enterprise-side mail server 17 are distributed toward the destinations designated by the destination addresses included in the header information of those emails.

[0022] The attacker-side mail server 19 is a mail server connected to the attacker terminal 190. The attacker-side mail server 19 is one of the servers connected to the network NW. The attacker terminal 190 is a terminal device used by an attacker who commits fraud using fraudulent emails. The attacker terminal 190 sends fraudulent emails in response to operations by the attacker. The fraudulent emails are sent toward the destination address via the attacker-side mail server 19 and the network. Fraudulent emails sent toward the destination address of the enterprise under management reach the enterprise-side mail server 17 after being monitored by the monitoring device 15. The fraudulent emails that reach the enterprise-side mail server 17 are distributed to the employee terminals 170 of the destinations of those fraudulent emails.

[0023] FIG. 2 is a conceptual diagram for explaining an example of a typical pattern of business email compromise (BEC). An attacker uses an attacker terminal 190 to send a fraudulent email that deceives a management executive in the sender display name to an employee of the company to which the management executive belongs. In the example of FIG. 2, assume that the fraudulent email is attached with a fake invoice instructing a transfer to the attacker posing as a management executive. When an employee who uses an employee terminal 170 as the recipient of the fraudulent email views the fraudulent email, the employee verifies the content of the fraudulent email. If the sender display name of the sent fraudulent email is a management executive, the employee may blindly follow the instructions of the fraudulent email. In the example of FIG. 2, the employee has transferred money to the account designated by the attacker according to the instructions of the fraudulent email. In order to prevent the occurrence of cases like FIG. 2, the detection system 10 of the present embodiment uses the header information of the email to detect a fraudulent email and displays the display information related to the detected fraudulent email on the screen of the management terminal 14. The display information related to the fraudulent email may be configured to be displayed on the screen of the employee terminal 170.

[0024] The detection device 11 is connected to the mail log database 16. The detection device 11 uses the mail logs stored in the mail log database 16 to detect a detection target email including a fraudulent email from the emails sent to the employees of the enterprise to be managed. The detection device 11 detects the detection target email using the header information of the mail logs stored in the mail log database 16. Specifically, the detection device 11 compares the email address of the sender included in the header information of the mail log with the normal sender address of the sender. For example, the detection device 11 detects an email in which the normal sender address of the sender included in the header information of the mail log is different from the email address of the sender included in the header information as a detection target email. For example, the detection device 11 refers to a white list that is a list of normal email addresses to detect a detection target email (fraudulent email). For example, the detection unit 113 detects an email not included in the white list as a detection target email (fraudulent email).

[0025] Figures 3 to 4 are conceptual diagrams for explaining detection examples of fraudulent emails using a white list. Figure 3 shows a detection example of an email (regular email) sent from a regular management executive A belonging to a company to be managed. Figure 4 shows a detection example of an email (fraudulent email) sent from an attacker posing as management executive A belonging to a company to be managed.

[0026] In the example of Figure 3, the header information of the received email includes information indicating that the sender is "Management Executive A" and the sender address is "aaa@n**.com". The detection device 11 refers to the white list and searches for "Management Executive A" displayed as the sender of the email. The regular address "aaa@n**.com" of "Management Executive A" is registered in the white list. The detection device 11 compares the sender address included in the header information of the received email with the regular address retrieved from the white list for "Management Executive A". In the example of Figure 3, the sender address included in the header information of the received email matches the regular address retrieved from the white list. Therefore, the detection device 11 determines that the received email is an email sent from a regular address.

[0027] In the example of FIG. 4, the header information of the received e-mail includes information indicating that the sender is "Executive A" and the sender address is "aaa@m**.com". The detection device 11 refers to the whitelist and searches for "Executive A" displayed as the sender of the e-mail. The legitimate address "aaa@n**.com" of "Executive A" is registered in the whitelist. The detection device 11 compares, for "Executive A", the sender address included in the header information of the received e-mail with the legitimate address retrieved from the whitelist. In the example of FIG. 4, the domain name of the sender address included in the header information of the received e-mail does not match the domain name of the legitimate address retrieved from the whitelist. Therefore, the detection device 11 determines that the received e-mail is suspected of being a fraudulent e-mail.

[0028] The detection device 11 searches the mail log database 16 for mail logs at a timing preset by the administrator. The detection device 11 uses the retrieved mail logs to detect fraudulent e-mails at a timing preset by the administrator. The detection timing of fraudulent e-mails is set by the administrator. For example, the detection timing of fraudulent e-mails is set at a specific preset time. For example, the specific time is set in the late night or early morning when the traffic is low. If it is a time period with low traffic, the impact on the sending and receiving of e-mails is less likely to occur. For example, the specific time may be set during the day when the traffic is high. If it is a time period with high traffic, fraudulent e-mails can be detected in real time.

[0029] For example, the detection device 11 refers to the whitelist and verifies whether the e-mail in the mail log recorded in the mail log database 16 is a fraudulent e-mail. The whitelist records the legitimate e-mail addresses of the executives, managers, and employees of the enterprise under management. The detection device 11 searches for the sender's email address included in the header information of the mail log by referring to the whitelist. The detection device 11 compares the searched sender's email address with the sender address included in the header information of the mail log. If the searched sender's email address does not match the sender address included in the header information, the detection device 11 detects the email in the mail log as a fraudulent email. The detection device 11 outputs detection information indicating that a fraudulent email has been detected to the control device 13. The detection information includes the header information of the detected fraudulent email. On the other hand, if the searched sender's email address matches the sender address included in the header information, the detection device 11 detects the email in the mail log as a normal email. For example, the detection device 11 outputs a detection result indicating that the email in the mail log is a normal email. In this case, the detection device 11 may be configured not to perform a specific process.

[0030] The detection information includes information regarding the detection status of fraudulent emails. For example, the information regarding the detection status of fraudulent emails includes the number of detected fraudulent emails. For example, the number of detected fraudulent emails includes the number of fraudulent emails detected within the most recent week, within the most recent month, and within the most recent year. For example, the number of fraudulent emails detected within the most recent week, the number of fraudulent emails detected within the most recent month, and the number of fraudulent emails detected within the most recent year are displayed side by side. For example, a plurality of pieces of information regarding the detection status of fraudulent emails are displayed adjacent to each other. For example, a plurality of pieces of information regarding the detection status of fraudulent emails may be displayed on the screen of the management terminal 14 in a format aggregated on one screen. The format in which a plurality of pieces of information are displayed side by side is also called the dashboard format. If a plurality of pieces of information regarding the detection status of fraudulent emails are displayed on the screen in the dashboard format, the trend of the detection status of fraudulent emails can be intuitively grasped.

[0031] In addition, the information on the detection status of fraudulent emails includes detection information for each email that may be a fraudulent email. For example, the detection information for each email includes the detection date and time, the sender display name, the recipient address, the subject line, the number of recipients, etc. The detection date and time indicates the date and time when an email that may be a fraudulent email was detected by the monitoring device 15. If the detection date and time, the sender display name, the recipient address, the subject line, and the number of recipients are displayed on the screen in a dashboard format, it is possible to intuitively grasp each individual email that may be a fraudulent email. For example, if the trend of the number of detected fraudulent emails and the detection information for each possible email are displayed on the screen in a dashboard format, it is possible to intuitively grasp the detection status of fraudulent emails. For example, the trend of the number of detected fraudulent emails is expressed in a format where the numerical values of the number of detections in a plurality of predetermined periods with different lengths of time, such as the most recent one week, one month, and one year, are arranged in the order of the length of time. For example, the trend of the number of detected fraudulent emails may be expressed in a graph format showing the trends of the number of detections in a plurality of predetermined periods with different lengths of time.

[0032] The management terminal 14 is a terminal device used by an administrator who manages the operation of the emails of the enterprise to be managed. The administrator manages the emails of the enterprise to be managed using the management terminal 14. For example, the administrator is an employee of the enterprise to be managed. Note that the administrator is not limited to being an employee of the enterprise to be managed. For example, the administrator may be a contractor entrusted with the management of the emails of the enterprise to be managed. The management terminal 14 is connected to the control device 13. For example, it may be configured so that the administrator can input information regarding fraudulent emails into the control device 13 using the management terminal 14.

[0033] The control device 13 is connected to the management terminal 14. The control device 13 acquires the detection information generated by the detection device 11. The control device 13 uses the acquired detection information to generate display information including the detection status of fraudulent emails. The control device 13 causes the generated display information to be displayed on the screen of the management terminal 14. The administrator who has viewed the display information displayed on the screen of the management terminal 14 can accurately grasp the detection status of fraudulent emails. That is, the administrator can grasp computer security such as fraudulent emails by viewing the display information displayed on the screen of the management terminal 14. For example, the display information regarding fraudulent emails may be configured to be displayed on the screen of the employee terminal 170. The employee can pay attention to fraudulent emails by viewing the display information displayed on the screen of the employee terminal 170. For example, the control device 13 may output the generated display information to an external system. The use of the display information output to the external system is not particularly limited. For example, by using the display information output to the external system, the detection status of fraudulent emails can be confirmed remotely.

[0034] 〔Detection Device〕 Next, the detection device 11 included in the detection system 10 of the present embodiment will be described with reference to the drawings. FIG. 5 is a block diagram showing an example of the configuration of the detection device according to the present disclosure. The detection device 11 includes a mail log acquisition unit 111, a list storage unit 112, a detection unit 113, a detection information generation unit 115, and an output unit 117.

[0035] The mail log acquisition unit 111 is connected to the mail log database 16. The mail log acquisition unit 111 acquires the mail logs stored in the mail log database 16. The mail logs include header information for each mail. The header information included in the mail logs is used for the detection of fraudulent emails.

[0036] The list storage unit 112 stores a white list in which the official email addresses used by employees such as management executives, managers, and employees of the enterprise to be managed are registered in association with the names of the employees. An email with an official address registered in the white list is a target to be detected as an official email. The white list includes the email addresses of the company emails used by employees such as management executives, managers, and employees of the enterprise to be managed. The white list may include the personal email addresses of employees such as management executives, managers, and employees of the enterprise to be managed. On the other hand, an email with an email address not registered in the white list is a target to be detected as a fraudulent email.

[0037] FIG. 6 is a table showing an example of the white list. In the white list 130, for each official mail ID (Identifier), header information including information such as the registration date, name, and email address is registered. The white list 130 may include information other than the mail ID, registration date, name, and email address. The information registered in the white list 130 is updated according to an operation using the management terminal 14.

[0038] For example, the list storage unit 112 may store a black list. An email address registered in the black list is a target to be detected as an unofficial email. For example, unofficial emails include fraudulent emails. For example, unofficial emails include emails containing fake information. Hereinafter, for the sake of convenience of explanation, assuming that an unofficial email is an email that may be a fraudulent email, the processing of the detection device 11 will be described. An email address not registered in the black list is an official address if it is registered in the white list. For example, in response to the detection of an email that may be a new fraudulent email, the header information of the email may be configured to be added to the black list.

[0039] FIG. 7 is a table showing an example of a blacklist. In the blacklist 140, for each mail ID of an email that may be a fraudulent email, header information including information such as the registration date, display name, and email address is registered. The blacklist 140 may include information other than the mail ID, registration date, name, and email address. For example, the blacklist 140 includes email addresses whose account names are the same as the legitimate address but whose domain names are different. For example, the blacklist 140 may include email addresses whose domain names are the same as the legitimate address but whose account names (user names) are different. For example, the blacklist 140 may include email addresses whose both account names and domain names are different. For example, the blacklist 140 may also include email addresses with account names or domain names that have nothing to do with the legitimate email address of the sender. The information registered in the blacklist 140 may be updated according to an operation using the management terminal 14.

[0040] The detection unit 113 extracts the sender and the sender address from the header information of the mail log. The detection unit 113 refers to the whitelist stored in the list storage unit 112 and searches for the legitimate address of the sender extracted from the header information of the mail log. The detection unit 113 detects an email not included in the whitelist as an irregular email. For example, the detection unit 113 compares the sender address extracted from the header information of the mail log with the legitimate address of the sender searched. If the sender address extracted from the header information of the mail log does not match the legitimate address of the sender searched, the detection unit 113 detects the email in that mail log as an email that may be a fraudulent email. On the other hand, if the sender address extracted from the header information of the mail log matches the legitimate address of the sender searched, the detection unit 113 determines that the email address is a legitimate address. In this case, the detection unit 113 may be configured to output the determination result, or may be configured not to execute any particular processing.

[0041] The detection unit 113 may be configured to search for fraudulent emails by referring to the blacklist stored in the list storage unit 112. The detection unit 113 detects the emails included in the blacklist as unauthorized emails. For example, the detection unit 113 compares the sender address extracted from the header information of the mail log with the email address of the email retrieved from the blacklist. If the sender address extracted from the header information of the mail log matches the email address of the email retrieved from the blacklist, the detection unit 113 detects the email in that mail log as an email that may be a fraudulent email. In this case, the detection unit 113 may be configured to output the determination result, or may be configured not to execute any particular processing. For example, the detection unit 113 may add the header information of the newly detected fraudulent email to the blacklist. By adding the header information of the new fraudulent email to the blacklist, the detection accuracy of fraudulent emails using the blacklist can be improved.

[0042] The detection unit 113 may be configured to detect fraudulent emails by referring to the body or attachment files of the emails. For example, the detection unit 113 detects an email that contains typical expressions used in fraud in the body as an email that may be a fraudulent email. For example, the detection unit 113 detects an email that contains typical expressions used in fraud in the file name of the attachment file as an email that may be a fraudulent email.

[0043] The detection unit 113 may be configured to detect fraudulent emails according to the content of a plurality of emails between an employee and an attacker. If configured in this way, it may be possible to detect fraudulent emails that cannot be detected by a single email. For example, in the first email, the reaction of the employee to a fraudulent email with the sender display set to a management executive is measured. Then, through multiple email exchanges, the employee is made to trust, and a method of deceiving the employee can be assumed. If configured to detect fraudulent emails according to the content of a plurality of emails, such a method of fraud can also be detected.

[0044] The detection information generation unit 115 generates detection information including the header information of an email that may be a detected fraudulent email. For example, the detection information includes information such as the detection date and time of an email that may be a fraudulent email, the sender display name, the sender address, the subject line, and the number of recipients. The detection date and time is the date and time when information regarding an email that may be a fraudulent email is detected. The detection date may be the date and time when information regarding an email that may be a fraudulent email was last detected (the last detection date and time). The sender display name indicates the sender included in the header information of an email that may be a fraudulent email. The sender address indicates the email address of the sender included in the header information of an email that may be a fraudulent email. The subject line indicates the subject line included in the header information of an email that may be a fraudulent email. The number of recipients indicates the number of recipients of an email that may be a fraudulent email in the enterprise to be managed.

[0045] The output unit 117 is connected to the control device 13. The output unit 117 outputs the detection information regarding the fraudulent email to the control device 13. The detection information output to the control device 13 is processed in the control device 13 into image information in a display format that makes it easy to accurately grasp the information regarding the fraudulent email. The processed display information is displayed on the screen of the management terminal 14. The administrator who views the display information displayed on the screen of the management terminal 14 can clearly grasp the information regarding the fraudulent email. That is, the administrator who views the display information displayed on the screen of the management terminal 14 can grasp computer security such as fraudulent emails.

[0046] It may be configured to notify the administrator in response to the detection of fraudulent emails. For example, in response to the detection of fraudulent emails, a notification in the form of an email or an instant message is sent to the management terminal 14. The notification informing of the detection of fraudulent emails may be displayed on the screen of the management terminal 14. The notification informing of the detection of fraudulent emails may be emitted as sound from the speaker of the management terminal 14. For example, the notification informing of the detection of fraudulent emails may be sent to a mobile terminal (not shown) carried by the administrator. The administrator who receives the notification in response to the detection of fraudulent emails can recognize the detection of fraudulent emails earlier than browsing the display information displayed on the screen of the management terminal 14.

[0047] The output unit 117 may be configured to transmit detection information regarding fraudulent emails to the monitoring device 15 or the enterprise-side mail server 17. For example, the monitoring device 15 or the enterprise-side mail server 17 blocks an email sent from the sender address included in the detection information of the fraudulent email. For example, the monitoring device 15 or the enterprise-side mail server 17 may be configured to send a warning email to the sender address included in the detection information of the fraudulent email. If configured in this way, a direct warning can be given to the sender of the fraudulent email. For example, the monitoring device 15 or the enterprise-side mail server 17 may be configured to report the sender address included in the detection information of the fraudulent email to an agency such as the police in charge of cyber security. If configured in this way, an agency such as the police can respond to the sender of the fraudulent email. For example, the monitoring device 15 or the enterprise-side mail server 17 may be configured to send the sender address included in the detection information of the fraudulent email to a news agency that reports information regarding cyber security. If configured in this way, through the report on the fraudulent email, it is possible to raise awareness of the fraudulent email to the public.

[0048] For example, it may be configured to display information indicating the status of the treatment for fraudulent emails on the screen of the management terminal 14. If the treatment for fraudulent emails is at the stage before corresponding, the status is expressed as "before treatment" or "untreated". If the treatment for fraudulent emails is at the stage of being in progress, the status is expressed as "being treated". If the treatment for fraudulent emails is at the stage of being completed, the status is expressed as "treated". The status of the treatment for fraudulent emails is not limited to the above expressions as long as the situation of the treatment for fraudulent emails can be determined.

[0049] 〔Control device〕 Next, the control device 13 included in the detection system 10 of the present embodiment will be described with reference to the drawings. FIG. 8 is a block diagram showing an example of the configuration of the control device according to the present disclosure. The control device 13 includes a detection information acquisition unit 131, a storage unit 133, a display information generation unit 135, and a display control unit 137.

[0050] The detection information acquisition unit 131 is connected to the detection device 11. The detection information acquisition unit 131 acquires detection information from the detection device 11. The detection information includes the header information of the email. The acquisition timing of the detection information is set arbitrarily. For example, the detection information acquisition unit 131 acquires detection information from the detection device 11 at a predetermined acquisition timing. For example, the detection information acquisition unit 131 may be configured to acquire detection information from the detection device 11 in response to an operation of the management terminal 14 by the administrator.

[0051] The storage unit 133 stores templates of display information to be displayed on the screen of the management terminal 14. The template of the display information is a prototype for displaying information such as the number of detected fraud emails, information on emails that may be fraud emails, and reported cases of fraud emails in a dashboard format. In other words, the template of the display information is a format for displaying in a display form optimized for grasping the risk of fraud emails. For example, the template of the display information includes an area where the trend of the number of detected fraud emails is set. In that area, for example, the number of detected fraud emails in a predetermined period such as the most recent one week, one month, or one year is arranged and displayed. For example, the template of the display information includes an area where information regarding each of the emails that may be fraud emails is set. In that area, for example, for each email that may be a fraud email, information such as the detection date and time, sender display name, sender address, subject, and number of recipients is arranged and displayed. For example, the template of the display information includes an area where information regarding reported cases of fraud emails is set. In that area, for example, for each reported case of a fraud email, information such as the detection or reporting date and time, sender display name, sender address, subject, screen dump of the fraud email, and features is arranged and displayed. These areas may be set individually or in combination with other areas. For example, the area where the trend of the number of detected fraud emails is set and the area where information regarding individual emails that may be fraud emails is set may be set to be displayed side by side.

[0052] Also, the storage unit 133 stores detection information. Detection information of the detected fraud emails is accumulated in the storage unit 133. The detection information accumulated in the storage unit 133 is used for calculating the fraud emails detected in a predetermined period. For example, the predetermined period is an institution such as the most recent one week, one month, or one year. The detection information stored in the storage unit 133 may be deleted according to the operation of the management terminal 14 by the administrator. For example, the detection information stored in the storage unit 133 may be automatically deleted according to the elapse of a preset period.

[0053] The display information generation unit 135 acquires fraud email detection information from the detection information acquisition unit 131. Also, the display information generation unit 135 acquires a template of display information from the storage unit 133. The display information generation unit 135 generates display information in which the information included in the detection information is arranged in a dashboard format. For example, the display information generation unit 135 generates display information in which the transition of the number of detected fraud emails is displayed. For example, the display information generation unit 135 generates display information in which the number of detected fraud emails in a predetermined period such as the most recent one week, one month, or one year is arranged and displayed. For example, the display information generation unit 135 generates display information in which information regarding each electronic mail that may be a fraud email is displayed. For example, for each electronic mail that may be a fraud email, the display information generation unit 135 generates display information in which information such as the detection date and time, sender display name, sender address, subject, and number of recipients is arranged and displayed. The number of recipients indicates the number of recipient addresses. When a single email contains multiple recipient addresses, the number of recipient addresses corresponds to the number of recipients. For example, the display information generation unit 135 generates display information in which information regarding reported cases of fraud emails is displayed. For example, for each reported case of a fraud email, the display information generation unit 135 generates display information in which information such as the date and time of detection or report, sender display name, sender address, subject, screen dump (appearance), features, etc. is arranged and displayed. These display informations may be set individually or may be set in combination with other areas. For example, a display area in which the transition of the number of detected fraud emails is displayed and display information regarding individual electronic mails that may be fraud emails may be set to be displayed side by side. The display information generated by the display information generation unit 135 is not limited to the examples given here.

[0054] The display control unit 137 is connected to the management terminal 14. The display control unit 137 causes the display information generated by the display information generation unit 135 to be displayed on the screen of the management terminal 14. The display control unit 137 causes the display information in which a plurality of pieces of information regarding fraudulent emails are arranged side by side to be displayed on the screen of the management terminal 14. That is, on the screen of the management terminal 14, the display information in which a plurality of pieces of information regarding fraudulent emails are displayed in a dashboard format is displayed. By being displayed in a dashboard format, the plurality of pieces of information regarding fraudulent emails are displayed so that the administrator can easily grasp the detection status of fraudulent emails. That is, on the screen of the management terminal 14, the information regarding the detection status of fraudulent emails is displayed in a display format optimized for grasping the risk of fraudulent emails, with the information being associated with each other. For example, the display information may be output to an external system. In that case, the display control unit 137 outputs the display information to the external system via a network NW such as the Internet.

[0055] FIG. 9 is a conceptual diagram showing an example of the display information displayed on the screen of the management terminal. In the example of FIG. 9, on the screen of the management terminal 14, display information 141 showing the transition of the number of detected fraudulent emails and display information 142 including a list of electronic mails that may be fraudulent emails are displayed.

[0056] In the example of FIG. 9, on the screen of the management terminal 14, as the transition of the number of detected fraudulent emails, display information 141 including the number of detected fraudulent emails in the most recent one week, one month, and one year is displayed. The display information including the transition of the number of detected fraudulent emails is referred to as first information. According to the display information 141, it is possible to accurately grasp that 0 fraudulent emails were detected in the most recent one week, 10 fraudulent emails were detected in the most recent one month, and 303 fraudulent emails were detected in the most recent one year. Also, according to the display information 141, it is possible to intuitively grasp the transition of the number of detected fraudulent emails in the most recent one week, one month, and one year regarding the plurality of detected fraudulent emails.

[0057] Also, in the example of FIG. 9, on the screen of the management terminal 14, as information for each email that may be a fraudulent email, display information 142 including the detection date and time of the fraudulent email, the sender display information, the sender address, the subject, and the number of recipients is displayed. The information for each email that may be a fraudulent email is referred to as second information. In the display information 142, the information for each email that may be a fraudulent email is listed in descending order of the detection date and time of the fraudulent email. According to the display information 142, for each fraudulent email, information including the detection date and time, the sender display information, the sender address, the subject, and the number of recipients can be accurately grasped. Also, according to the display information 142, for a plurality of fraudulent emails, information including the detection date and time, the sender display information, the sender address, the subject, and the number of recipients can be compared. For example, by clicking on the parts of the detection date and time, the sender display information, the sender address, the subject, and the number of recipients at the top of the display information 142, those pieces of information may be configured to be sorted. For example, as information for each email that may be a fraudulent email, the position held by the person set as the sender may be displayed.

[0058] The display information displayed on the screen of the management terminal 14 may be configured to be sortable by the detection date and time of the fraudulent email, the sender display information, the sender address, the subject, and the number of recipients. For example, the display information may be configured such that information regarding fraudulent emails detected within a specific period is sorted. For example, the display information displayed on the screen of the management terminal 14 may be configured such that information regarding approximately the latest 10 fraudulent emails is displayed. According to the example of FIG. 9, the transition of the number of detected fraudulent emails and the list information of emails that may be fraudulent emails can be referred to in combination. For example, by confirming that the number of detected fraudulent emails in the most recent month is 1 and sorting by the detection date and time within one month, it is possible to grasp what kind of fraudulent emails have been detected.

[0059] FIG. 10 is a conceptual diagram showing an example of display information displayed on the screen of the management terminal. In the example of FIG. 10, display information 145 in which reported cases of fraudulent emails are listed is displayed on the screen of the management terminal 14. In FIG. 10, on the screen of the management terminal 14, for each reported case of a fraudulent email, information such as the date and time of detection or report, the sender display name, the sender address, the subject, the screen dump, and features are arranged and displayed. By providing the employee with the screen dump of the fraudulent email to raise awareness of the fraudulent email, the risk that the employee will follow the instructions in the fraudulent email can be reduced. For example, the features of the fraudulent email are described as features included in the header information and the body text. For example, the features of the header information of the fraudulent email include information such as the name of a management executive being described in the sender header of the email. For example, the features of the body text of the fraudulent email include the attacker's fraud method and the countermeasure method when receiving the fraudulent email.

[0060] FIG. 11 is a conceptual diagram showing an example of screen transition of display information displayed on the screen of the management terminal. In the display information 145 regarding the reported case in FIG. 11, an enlarged image 146 of the screen dump is displayed according to the selection of the screen dump of the fraudulent email. According to the example of FIG. 11, the enlarged image 146 of the screen dump makes it easier to confirm the details of the content of the fraudulent email. In FIG. 11, the portions corresponding to personal information such as the destination are blacked out and concealed. For example, the process of blacking out the destination and other parts is performed manually. For example, it may be configured such that the name of an individual extracted by language analysis technology is automatically blacked out. For example, the enlarged image 146 may be enlarged and displayed with an increased resolution. The higher the resolution of the enlarged image 146, the easier it is to visually recognize the information contained in the fraudulent email.

[0061] The display examples in FIGS. 9 to 11 are merely examples and do not limit the display information to be displayed by the detection system of this embodiment. The positional relationship and arrangement of the information included in the display information can be arbitrarily set as long as it is displayed in a dashboard format. Also, the display format of the display information may be changed according to the treatment status of the fraudulent email. For example, the information included in the display information may be displayed in different colors, sizes, and fonts according to the risk and urgency of the fraudulent email. For example, the information included in the display information may be displayed in different colors and sizes according to the risk and urgency of the fraudulent email. Also, according to the analysis result of the destination information of the recipient set for the transmission destination of the fraudulent email, the department and person targeted by the fraudulent email may be displayed in a table format.

[0062] (Operation) Next, the operation of the detection system 10 of this embodiment will be described with reference to the drawings. In the following, the detection device 11 and the control device 13 included in the detection system 10 will be individually described.

[0063] [Detection Device] FIG. 12 is a flowchart for explaining an example of the operation of the detection device according to the present disclosure. In the description of the process along the flowchart of FIG. 12, the components of the detection device 11 will be described with the operation subject. The operation subject of the process along the flowchart of FIG. 12 may be the detection device 11.

[0064] In FIG. 12, first, the mail log acquisition unit 111 acquires a mail log from the mail log database 16 (step S111). For example, the mail log acquisition unit 111 acquires a mail log at a preset timing. The mail log acquisition unit 111 may be configured to acquire a mail log at the timing when the mail log is recorded in the mail log database 16.

[0065] Next, the detection unit 113 executes fraud email detection processing (step S112). In the fraud email detection processing, the detection unit 113 detects fraud emails using the header information of the email logs. A detailed example of the fraud email detection processing in step S112 will be described later.

[0066] Next, the detection information generation unit 115 generates detection information including information regarding the detected fraud emails (step S113). For example, the detection information includes the header information of the fraud emails. The detection information may include the body and attachment files of the fraud emails.

[0067] Next, the output unit 117 outputs the generated detection information to the control device 13 (step S114). The detection information output to the control device 13 is used to generate display information for grasping information regarding the fraud emails. After step S114, the process proceeds to the process of step S131 in FIG. 14.

[0068] <Fraud Email Detection Processing> FIG. 13 is a flowchart for explaining an example of the fraud email detection processing (step S112 in FIG. 12) according to the present disclosure. In the description of the processing along the flowchart of FIG. 13, the components of the detection device 11 will be described as the operating entities. The operating entity of the processing along the flowchart of FIG. 13 may be the detection device 11. Note that the flowchart of FIG. 13 is an example of the fraud email detection processing and does not limit the fraud email detection processing.

[0069] In FIG. 13, first, the detection unit 113 acquires an email transmission / reception log from the email log (step S121).

[0070] Next, the detection unit 113 formats the acquired transmission / reception log (step S122). The detection unit 113 formats the transmission / reception log so that the sender display included in the header information is easily detected.

[0071] Next, the detection unit 113 detects a log in which the name of the person to be detected is set in the sender display (step S123). For example, the person to be detected is an executive or manager of the enterprise to be managed. The person to be detected may be an executive or manager of an affiliated company of the enterprise to be managed.

[0072] Next, it is determined whether the email address of the person to be detected set in the sender display is registered in the whitelist (step S124). If the email address of the person to be detected set in the sender display is not registered in the whitelist (No in step S124), the detection unit 113 detects the email of that log as a fraudulent email. After step S125, the process proceeds to the process of step S113 in FIG. 12. If the email address of the person to be detected set in the sender display is registered in the whitelist (Yes in step S124), the process along the flowchart of FIG. 12 ends.

[0073] 〔Control device〕 FIG. 14 is a flowchart for explaining an example of the operation of the control device according to the present disclosure. In the description of the process along the flowchart of FIG. 14, the components of the control device 13 will be described with the operation subject. The operation subject of the process along the flowchart of FIG. 14 may be the control device 13.

[0074] In FIG. 14, first, the detection information acquisition unit 131 acquires detection information from the detection device 11 (step S131).

[0075] Next, the display information generation unit 135 generates display information including information related to the fraudulent email using the information included in the detection information (step S132). The display information generation unit 135 generates display information indicating the detection status of the fraudulent email in a dashboard format that is easy for the administrator to understand.

[0076] Next, the display control unit 137 causes the generated display information to be displayed on the screen of the management terminal 14 (step S133). On the screen of the management terminal 14, the detection status regarding the fraudulent mail is displayed in a display format that is easy for the administrator to grasp. The control device 13 may be configured to output the generated display information to the employee terminal 170 or an external system. Further, the control device 13 may be configured to issue an instruction to the monitoring device 15 or the company-side mail server 17 to block the e-mail sent from the sender address of the detected fraudulent mail.

[0077] As described above, the detection system of the present embodiment includes a detection device and a control device. The detection device includes a mail log acquisition unit, a list storage unit, a detection unit, a detection information generation unit, and an output unit. The mail log acquisition unit acquires a mail log including the header information of the e-mail sent to the employees of the company to be managed. The list storage unit stores a white list in which the regular addresses of the company to be managed are listed. The detection unit detects a fraudulent mail in response to a mismatch between the regular address of the sender included in the header information and the sender address included in the header information. The detection information generation unit generates detection information including information regarding the detected fraudulent mail. The output unit outputs the generated detection information to the control device.

[0078] The control device includes a detection information acquisition unit, a storage unit, a display information generation unit, and a display control unit. The detection information acquisition unit acquires detection information including the header information of the e-mail sent to the company to be managed. The storage unit stores a template of the display information presented to the administrator. The display information generation unit generates display information in which a plurality of pieces of information regarding the e-mail that may be a fraudulent mail sent to the company to be managed are arranged and displayed. The display control unit controls to display the generated display information on the screen.

[0079] As described above, the control device of the present embodiment causes a screen to display display information in which a plurality of pieces of information regarding an email that may be a fraudulent email sent to an employee of a company to be managed are arranged. Therefore, according to the present embodiment, it becomes possible to grasp computer security such as fraudulent emails.

[0080] In one aspect of the present embodiment, the display information generation unit generates display information including information indicating the transition of the number of detected fraudulent emails and a list of information of emails that may be fraudulent emails. The display control unit causes a screen to display display information including information indicating the transition of the number of detected fraudulent emails and a list of information of emails that may be fraudulent emails. According to this aspect, it is possible to accurately grasp information regarding an email that may be a fraudulent email displayed on the screen of the management terminal for each fraudulent email.

[0081] In one aspect of the present embodiment, the display information generation unit generates display information including the display name of the sender and the source address for each email that may be a fraudulent email in a list of information of emails that may be fraudulent emails. The display control unit causes a screen to display display information including the display name of the sender and the source address for each email that may be a fraudulent email in a list of information of emails that may be fraudulent emails. According to this aspect, it is possible to accurately grasp the display name of the sender and the source address of an email that may be a fraudulent email based on the information for each email displayed on the screen of the management terminal.

[0082] In one aspect of the present embodiment, the display information generation unit generates display information including the subject line for each email that may be a fraudulent email in a list of information of emails that may be fraudulent emails. The display control unit causes a screen to display display information including the subject line for each email that may be a fraudulent email in a list of information of emails that may be fraudulent emails. It is possible to accurately grasp the subject line of an email that may be a fraudulent email.

[0083] In one aspect of the present embodiment, the display information generation unit generates display information including a list of reported cases for each fraudulent email containing a combination of at least two of the sender display, the sender address, the subject, the screen dump, and the features. The display control unit causes the screen to display the display information including a list of reported cases for each fraudulent email containing a combination of at least two of the sender display, the sender address, the subject, the screen dump, and the features. According to this aspect, the features included in the fraudulent email can be accurately grasped from the reported cases displayed on the screen of the management terminal.

[0084] The control device according to one aspect of the present embodiment includes a detection information acquisition unit that acquires detection information including the header information of an email sent to a company to be managed. This aspect clarifies the acquisition of detection information.

[0085] In one aspect of the present embodiment, the detection device compares the legitimate address of the sender registered in the white list in which the legitimate addresses of the employees of the company to be managed are listed with the sender address extracted from the header information. When the legitimate address of the sender registered in the white list and the sender address extracted from the header information do not match, the email in the mail log is detected as a fraudulent email. According to this aspect, by referring to the white list, an email sent from a sender with a sender address not registered in the white list can be detected as a fraudulent email.

[0086] (Second Embodiment) Next, an example of the control device according to the second embodiment will be described with reference to the drawings. The control device of the present embodiment has a simplified configuration of the control device included in the detection system of the first embodiment. The control device of the present embodiment generates display information using the detection information output from the detection device included in the detection system of the first embodiment.

[0087] (Configuration) FIG. 15 is a block diagram showing an example of the configuration of the control device according to the present disclosure. The control device 23 includes a display information generation unit 235 and a display control unit 237. The display information generation unit 235 generates display information in which a plurality of pieces of information regarding an electronic mail that may be a fraud mail sent to the enterprise to be managed are arranged and displayed. The display control unit 237 controls to display the generated display information on the screen.

[0088] (Operation) FIG. 16 is a flowchart for explaining an example of the operation of the control device according to the present disclosure. In the description of the process along the flowchart of FIG. 16, the components of the control device 23 will be described as the operation subject. The operation subject of the process along the flowchart of FIG. 16 may be the control device 23.

[0089] In FIG. 16, first, the display information generation unit 235 generates display information in which a plurality of pieces of information regarding an electronic mail that may be a fraud mail sent to the enterprise to be managed are arranged and displayed (step S231).

[0090] Next, the display control unit 237 controls to display the generated display information on the screen (step S232).

[0091] The display information generation unit 235 can be realized by using, for example, the functions of the display information generation unit 135 in FIG. 8. The display control unit 237 can be realized by using, for example, the functions of the display information control unit 137 in FIG. 8.

[0092] As described above, the control device of the present embodiment causes the screen to display display information in which a plurality of pieces of information regarding an electronic mail that may be a fraud mail sent to an employee of the enterprise to be managed are arranged and displayed. Therefore, according to the present embodiment, it becomes possible to grasp computer security such as fraud mails.

[0093] (Hardware) Next, a hardware configuration for executing control and processing in the present disclosure will be described with reference to the drawings. Here, as an example of such a hardware configuration, the information processing apparatus 90 (computer) in FIG. 17 is given. The information processing apparatus 90 in FIG. 17 is a configuration example for executing control and processing in the present disclosure, and does not limit the scope of the present disclosure.

[0094] As shown in FIG. 17, the information processing apparatus 90 includes a processor 91, a memory 92, an auxiliary storage device 93, an input / output interface 95, and a communication interface 96. In FIG. 17, the interface is abbreviated as I / F (Interface). The processor 91, the memory 92, the auxiliary storage device 93, the input / output interface 95, and the communication interface 96 are connected to each other via a bus 98 so as to be capable of data communication. Further, the processor 91, the memory 92, the auxiliary storage device 93, and the input / output interface 95 are connected to a network such as the Internet or an intranet via the communication interface 96.

[0095] The processor 91 expands a program (instruction) stored in the auxiliary storage device 93 or the like into the memory 92. For example, the program is a software program for executing control and processing in the present disclosure. The processor 91 executes the program expanded in the memory 92. The processor 91 executes control and processing in the present disclosure by executing the program.

[0096] The memory 92 is a storage device having an area where a program is expanded. In the memory 92, a program stored in the auxiliary storage device 93 or the like is expanded by the processor 91. The memory 92 is realized by a volatile memory such as a DRAM (Dynamic Random Access Memory), for example. Further, a non-volatile memory such as an MRAM (Magnetoresistive Random Access Memory) may be applied as the memory 92.

[0097] The auxiliary storage device 93 stores various data such as programs. For example, the auxiliary storage device 93 is realized by a local disk such as a hard disk or a flash memory. Note that it is also possible to configure to store various data in the memory 92 and omit the auxiliary storage device 93.

[0098] The input / output interface 95 is an interface for connecting the information processing device 90 and peripheral devices based on standards and specifications. The communication interface 96 is an interface for connecting to an external system or device through a network such as the Internet or an intranet based on standards and specifications. The input / output interface 95 and the communication interface 96 may be shared as an interface for connecting to an external device.

[0099] Input devices such as a keyboard, a mouse, and a touch panel may be connected to the information processing device 90 as necessary. Those input devices are used for inputting information and settings. When a touch panel is used as the input device, a screen having the function of the touch panel becomes the interface. The processor 91 and the input device are connected via the input / output interface 95.

[0100] The information processing device 90 may be equipped with a display device for displaying information. When a display device is equipped, the information processing device 90 is equipped with a control device (not shown) for controlling the display of the display device. The information processing device 90 and the display device are connected via the input / output interface 95.

[0101] The information processing device 90 may be equipped with a drive device. The drive device mediates the reading of data and programs stored in the recording medium and the writing of the processing results of the information processing device 90 to the recording medium between the processor 91 and the recording medium (program recording medium). The information processing device 90 and the drive device are connected via the input / output interface 95.

[0102] The above is an example of a hardware configuration for enabling control and processing in the present disclosure. The hardware configuration of FIG. 17 is an example of a hardware configuration for executing control and processing in the present disclosure, and does not limit the scope of the present disclosure. A program for causing a computer to execute control and processing in the present disclosure is also included in the scope of the present disclosure.

[0103] A program recording medium recording a program for executing the processing in the present embodiment is also included in the scope of the present invention. For example, the program recording medium is a non-transitory computer-readable recording medium. The recording medium can be realized by, for example, an optical recording medium such as a CD (Compact Disc) or a DVD (Digital Versatile Disc). The recording medium may be realized by a semiconductor recording medium such as a USB (Universal Serial Bus) memory or an SD (Secure Digital) card. Further, the recording medium may be realized by a magnetic recording medium such as a flexible disk or other recording media.

[0104] The components in the present disclosure may be arbitrarily combined. The components in the present disclosure may be realized by software. The components in the present disclosure may be realized by a circuit.

[0105] The present disclosure has been described above with reference to the embodiments, but the present disclosure is not limited to the above-described embodiments. Various changes that can be understood by those skilled in the art can be made to the configuration and details of the present disclosure within the scope of the present disclosure. And each embodiment can be combined with other embodiments as appropriate.

[0106] Some or all of the above embodiments may be described as follows in the appended claims, but are not limited thereto. (Appended Claim 1) A display information generation unit that generates display information in which a plurality of pieces of information regarding an electronic mail that may be a fraud mail sent to a company to be managed are arranged and displayed; A control device including a display control unit that controls to display the generated display information on a screen. (Appendix 2) The display information is The control device according to Appendix 1, including information indicating the transition of the number of detected fraud mails and a list of information on electronic mails that may be fraud mails. (Appendix 3) The display information is The control device according to Appendix 2, wherein the information included in the list of information on electronic mails that may be fraud mails is the sender display name and the sender address for each electronic mail that may be a fraud mail. (Appendix 4) The display information is The control device according to Appendix 3, wherein the information included in the list of information on electronic mails that may be fraud mails is the subject line for each electronic mail that may be a fraud mail. (Appendix 5) The display information is The control device according to Appendix 1, including a list of reported cases for each fraud mail, which includes at least two combinations of the sender display, the sender address, the subject line, the screen dump, and the features. (Appendix 6) The control device according to Appendix 1, including a detection information acquisition unit that acquires detection information including the header information of the electronic mails sent to the enterprise to be managed. (Appendix 7) The fraud mail is The control device according to Appendix 1, which is an electronic mail in which the regular address of the sender registered in the white list in which the regular addresses of the employees of the enterprise to be managed are listed does not match the sender address extracted from the header information of the electronic mail sent to the enterprise to be managed. (Appendix 8) The control device according to any one of Appendices 1 to 7, and A detection system comprising: a detection device that acquires a mail log including header information of an email sent to an employee of a target company, detects a fraudulent email in response to a mismatch between the legitimate address of the sender included in the header information and the source address included in the header information, generates detection information including information about the detected fraudulent email, and outputs the generated detection information to the control device. (Appendix 9) The computer generates display information in which a plurality of pieces of information regarding an email that may be a fraudulent email sent to a target company are arranged and displayed, and a control method for controlling to display the generated display information on a screen. (Appendix 10) a process of generating display information in which a plurality of pieces of information regarding an email that may be a fraudulent email sent to a target company are arranged and displayed, and a program for causing a computer to execute a process of controlling to display the generated display information on a screen.

[0107] Part or all of the configurations described in Appendices 2 to 8 that are subordinate to Appendix 1 described above may be subordinate to Appendices 9 - 10 in the same subordinate relationship as Appendices 2 to 8. Not limited to Appendices 1, 9 - 10, within the scope not departing from the above-described embodiments, similarly, for various hardware, software, various recording devices for recording software, or systems, part or all of the configurations described as appendices may be made subordinate.

Explanation of Reference Numerals

[0108] 10 Detection system 11 Detection device 13, 23 Control device 14 Management terminal 16 Mail log database 17 Company-side mail server 19 Attacker-side mail server 111 Mail log acquisition unit 112 List storage unit 113 Detection unit 115 Detection information generation unit 117 Output unit 131 Detection information acquisition unit 133 Memory unit 135, 235 Display information generation unit 137, 237 Display control unit 170 Employee terminal 190 Attacker terminal

Claims

1. a display information generating unit that generates display information in which a plurality of pieces of information related to potentially fraudulent e-mails sent to a managed company are displayed side by side; A control device comprising: a display control unit that controls the generated display information to be displayed on a screen.

2. The display information includes:

2. The control device according to claim 1, further comprising information indicating a trend in the number of fraudulent emails detected and a list of information on emails that may be fraudulent emails.

3. The display information includes:

3. The control device according to claim 2, wherein the list of information on emails that may be fraudulent emails includes a sender display name and a sender address for each email that may be fraudulent email.

4. The display information includes:

4. The control device according to claim 3, wherein the list of information on emails that may be fraudulent emails includes a subject of each email that may be fraudulent email.

5. The display information includes: The control device according to claim 1 , wherein the information includes a list of reported cases of fraudulent emails, each of which includes a combination of at least two of a sender display, a sender address, a subject, a screen dump, and characteristics.

6. The control device according to claim 1 , further comprising a detection information acquisition unit for acquiring detection information including header information of an e-mail sent to the managed company.

7. The fraudulent email is The control device described in claim 1, wherein the legitimate address of the sender registered on a whitelist that lists the legitimate addresses of employees of the managed company does not match the source address extracted from the header information of the email sent to the managed company.

8. A control device according to any one of claims 1 to 7; A detection system comprising: a detection device that acquires a mail log including header information of e-mails sent to employees of a managed company, detects fraudulent e-mails based on a mismatch between the sender's legitimate address included in the header information and the sender address included in the header information, generates detection information including information about the detected fraudulent e-mails, and outputs the generated detection information to the control device.

9. The computer generating a side-by-side display of multiple pieces of information about potentially fraudulent e-mails sent to the managed enterprise; A control method for controlling the generated display information to be displayed on a screen.

10. generating a display of multiple pieces of information about potentially fraudulent e-mails sent to the managed enterprise; and a process of controlling the generated display information to be displayed on a screen.

Citation Information

Patent Citations

  • Information processing device, information processing method, and program

    JP2021009464A