Internal fraud detection device, internal fraud detection method, and program
The internal fraud detection system addresses the inefficiencies of UEBA in OT systems by using multiple machine-learning models to analyze user operation histories, detecting fraud with minimal data and time, and ensuring reliable detection with aggregated results.
Patent Information
- Application Number
- JP2023198446
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-11-22
- Publication Date
- 2025-06-03
AI Technical Summary
Existing User & Entity Behavior Analysis (UEBA) systems require a large amount of learning data and a significant learning period, making them inefficient for detecting internal fraud in Operational Technology (OT) systems, which have fewer devices and stricter time constraints.
An internal fraud detection device and method that utilize multiple machine-learning models to analyze operation histories of users in an OT system. The system acquires behavior information, extracts feature quantities, and uses these models to determine abnormality, with the results aggregated to detect presumed internal fraud. Each learning model inputs different parts of the operation histories.
Enables efficient detection of internal fraud with a small amount of learning data and a short learning period, ensuring reliable fraud detection while minimizing false positives and reducing the need for extensive data collection and learning times.
Smart Images

Figure 2025084496000001_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to an internal fraud detection device, an internal fraud detection method, and a program.
Background Art
[0002] As a system for detecting fraudulent acts (internal fraud) committed by internal offenders, it is known to use UEBA (User & Entity Behavior Analysis).
[0003] For example, in UEBA, machine learning is performed using data in which various event logs generated by each terminal are accumulated. As a result, UEBA can detect fraudulent acts (such as taking out electronic materials and changing PC settings for the purpose of obstructing business) committed by internal offenders as behavior different from normal, and can also raise an alert and notify the user at the time of detection. Here, since normal UEBA which is well-known is regarded as the prior art, no specific individual patent documents are cited as related ones.
Summary of the Invention
Problems to be Solved by the Invention
[0004] Normal UEBA is a tool assuming an IT (Information Technology) system composed of a large number of user terminals or devices, and due to its configuration, it requires a large amount of learning data and a learning period. As a result, the learning model of UEBA learns the normal behavior of many users and can accurately detect internal fraud. However, in an OT (Operational Technology) system that operates control devices such as those in factories and plants, compared with IT, there are fewer constituent devices such as user terminals and connected devices, and it is often required to detect internal fraud with a small amount of learning data and a short learning period.
[0005] An object of the present disclosure is to provide an internal fraud detection device, an internal fraud detection method, and a program that solve the above-described problems.
Means for Solving the Problems
[0006] The internal fraud detection device of the present disclosure includes an acquisition unit that acquires behavior information summarizing the operation histories of a plurality of users involved in a control system, a plurality of learning models that are machine-learned to determine the abnormality from the tendencies of the operation histories of the plurality of users, with the input being a part of the operation histories among the behavior information and the output being the determination result of the abnormality with respect to the part of the operation histories, an aggregation unit that aggregates the determination results of the abnormality output by the plurality of learning models, and a detection unit that detects presumed internal fraud based on the aggregation of the determination results of the abnormality. In the plurality of learning models, the part of the operation histories input to each learning model is different.
[0007] The internal fraud detection method of the present disclosure includes a step of acquiring behavior information summarizing the operation histories of a plurality of users involved in a control system, a step of aggregating the determination results of the abnormality output by the plurality of learning models using the plurality of learning models that are machine-learned to determine the abnormality from the tendencies of the operation histories of the plurality of users, with the input being a part of the operation histories among the behavior information and the output being the determination result of the abnormality with respect to the part of the operation histories, and a step of detecting presumed internal fraud based on the aggregation of the determination results of the abnormality. In the plurality of learning models, the part of the operation histories input to each learning model is different.
[0008] The program of the present disclosure causes a computer to execute steps of: obtaining behavior information that summarizes operation histories of a plurality of users involved in a control system; using a plurality of learning models that are machine-learned to determine the abnormality from tendencies of the operation histories of the plurality of users, with an input being a part of the operation histories among the behavior information and an output being a determination result of an abnormality with respect to the part of the operation histories, and aggregating the determination results of the abnormality output by the plurality of learning models; and detecting presumed internal fraud based on the aggregation of the determination results of the abnormality, wherein in the plurality of learning models, the part of the operation histories input to each learning model is different.
Advantages of the Invention
[0009] According to the internal fraud detection device, internal fraud detection method, and program according to the present disclosure, internal fraud can be detected with a small amount of learning data and a short learning period.
Brief Description of the Drawings
[0010]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Modes for Carrying Out the Invention
[0011] Hereinafter, each embodiment according to the present disclosure will be described with reference to the drawings. Note that the drawings and the specific configurations used in each embodiment shall not be used for interpreting the disclosure. The same or corresponding components are denoted by the same reference numerals in all the drawings, and common descriptions are omitted.
[0012] Hereinafter, the internal fraud detection device in the present disclosure will be described with reference to FIGS. 1 to 6.
[0013] (Configuration of the internal fraud detection system) The internal fraud detection system 1 is used to detect abnormalities in the behavior (hereinafter also referred to as "internal fraud") different from normal by some users existing on the OT system, and to detect the internal fraud estimated from the detected abnormalities. The OT system assumed in the present disclosure is assumed to have a smaller number of device configurations than the IT system. As shown in FIG. 1, the internal fraud detection system 1 includes an internal fraud detection device 11, a network 12, and a work terminal 13. The internal fraud detection device 11 is communicably connected to one or more work terminals 13 (denoted as "work terminal 13-C") via the network 12. In the internal fraud detection device 11, an acquisition unit 111 described later communicates with the work terminal 13-C via the network 12. The work terminal 13-C communicates with the internal fraud detection device 11 via the network 12. Users are respectively assigned to the work terminals 13-C, and the work terminals 13-C respectively record the operation histories of the users. For example, as shown in FIG. 1, the operation history of the user recorded includes operations on the virtual environment constructed on the work terminal 13-3. For example, as the virtual environment constructed on the work terminal 13-3, there is a virtual machine. There is also a method of virtualizing the execution environment of the application on the work terminal 13-3 by means of a container engine. The operation history of each user includes at least one of event logs or metric information. Examples of event logs include Windows event logs and syslogs, and examples of metric information include CPU (Central Processing Unit) usage rate and memory usage rate.
[0014] (Configuration of the information processing apparatus) As shown in FIG. 1, the internal fraud detection device 11 includes an acquisition unit 111, an extraction unit 112, a aggregation unit 113, a plurality of learning models MX (denoted as learning model "MX-N"), a detection unit 114, a notification unit 115, a storage unit 116, and an update unit 117. The operations of each unit in the internal fraud detection device 11 described below correspond to at least a part of the information processing method of the present disclosure.
[0015] (Acquisition unit) The acquisition unit 111 acquires behavior information that summarizes the operation histories of a plurality of users involved in the control system (OT system). The acquisition unit 111 communicates with the work terminal 13-C via the network 12. For example, the operation history of the user generated on the work terminal 13-C is acquired via the network 12. Note that the timing at which the acquisition unit 111 acquires the information is arbitrary. In the present disclosure, the information obtained by the acquisition unit 111, which summarizes the operation histories of a plurality of users, is referred to as "behavior information". Since it is used for the extraction of "feature quantities" or "normal information" described later, the behavior information includes at least one of event logs or metric information. Further, the acquisition unit 111 may store the acquired behavior information in the storage unit 116.
[0016] (Extraction unit) The extraction unit 112 extracts some of the operation histories as feature quantities from the behavior information acquired by the acquisition unit 111. The timing of extraction is arbitrary. For example, in the present disclosure, the extraction unit 112 extracts feature quantities every 15 minutes. For example, the extraction unit 112 extracts part of the information including event logs and / or metric information from the behavior information. Examples of the partially extracted information include information on the event log and the occurrence frequency of the event, information on the event log and the occurrence time of the event, information on the event log and the duration from the occurrence to the end of the event, information on the event log and the metric information at the time of the event, or information on the software and the metric information during the use of the software (including the start time, end time, or duration from the start to the end). These pieces of information are those in which at least one of the event log or metric information is incorporated. The partial operation history thus extracted is referred to as "feature quantity" in the present disclosure.
[0017] (Overview of Multiple Learning Models MX) The learning model MX-N takes part of the operation history in the behavior information as the input and outputs the determination result of abnormality for the part of the operation history, and each is machine-learned to determine abnormality from the tendencies of the operation histories of multiple users. However, the information for identifying users is not used in the machine learning. First, an overview of the learning model MX-N is shown. As shown in FIG. 2, NO.X (in this figure, "X = 9") is labeled for the internal fraud estimated from the input feature quantity, and it is assumed that there are three learning models (M9-1, M9-2, M9-3) for detecting this internal fraud. For each of the three learning models, the feature quantity extracted by the extraction unit 112 is input. Examples of the feature quantity in FIG. 2 are "total number of daily login failures", "shortest login time within one hour", and "total daily disk write amount". Each feature quantity includes at least one of the event log or metric information. Each of the three learning models outputs a determination result of abnormality for the input feature quantity. Examples of the determination of the presence or absence of abnormality in FIG. 2 are as follows. For example, the learning model M9-1 outputs "determination result of whether there is an abnormality in the daily login failures" for "total number of daily login failures". For example, the learning model M9-2 outputs the determination result of whether there is an abnormality depending on whether there is no login that is too short within one hour with respect to the "shortest login time within one hour". For example, the learning model M9-3 outputs the determination result of whether there is an abnormality with respect to the "total daily disk write amount" with respect to the "daily disk write amount". In the learning model MX-N, the feature amounts input to each learning model are different from each other. Thereafter, the aggregation unit 113 described later aggregates the abnormality determination results output by each of the three learning models. Based on the aggregation, the detection unit 114 detects internal fraud (No. 9) estimated from each feature amount. Note that internal fraud is estimated and labeled in advance by an operator from the normal information described later that has been clustered. The relationship between the internal fraud and the learning model for detecting the internal fraud is stored in the storage unit 116 in advance.
[0018] (Multiple learning models MX: Details of processing) The details of the processing in the learning model MX-N are shown. As shown in FIG. 3, as internal fraud, unauthorized login is labeled as NO.X (in this figure, "X = 1"). Assume that there are eight (M1-1, ···, M1-8) learning models for detecting this internal fraud. For the input feature amount, a determination value (probability value in the probability density function described later) is calculated for the learning model MX-N that respectively determines the abnormality of the event, and a threshold value is further applied. For example, as an anomaly detection algorithm for the learning model MX-N, there is KDE (Kernel Density Estimation). In the present disclosure, KDE, which is a Probability Approach that estimates a probability distribution using normal-time feature quantities without anomalies (hereinafter also referred to as "normal information") as learning data and regards events with a low occurrence probability as anomalies, is used. Other examples of the Probability Approach include Hotelling's T2 method and GMM (Gaussian Mixture Model). The learning method of the learning model MX-N is unsupervised learning. In this way, a threshold is applied to the probability density function of the KDE model learned using normal information as learning data. The threshold is set for the probability value in the probability density function. For example, the threshold is calculated after approximate calculation such that the occurrence probability of an event that is below the threshold in the probability density function is 1% or less. In other words, the threshold is set such that the area of the event that is below the threshold in the probability density function of the KDE model is 1% or less of the total area of the probability density function. That is, in the present disclosure, an event that exceeds the threshold and exceeds the probability density function is regarded as an anomaly by the KDE model and the threshold. Conversely, even if the probability density function is exceeded, an event that does not exceed the threshold is not regarded as an anomaly. Note that there is Bandwidth as a parameter of the KDE model, which may be set by an operator or may be stored in the storage unit 116 as the Bandwidth corresponding to the learning data.
[0019] Note that in the "abnormal time login success" which is the event determined by the learning model M1-1, the "abnormal time" may be different for each user in an OT system that often operates 24 hours a day. Also, even for the same user, the "abnormal time" may change depending on the time period (for example, there are day shifts and night shifts, and they change regularly, etc.). In such a case, if learning is performed using information that identifies the user, it may be determined as an anomaly when the role of that user is changed. Therefore, information that identifies the user is not used in machine learning.
[0020] Shown in FIG. 4 is a learning model M1-3 that is labeled as unauthorized login (No. 1), which is an internal unauthorized act described in FIG. 5 to be described later, and for detecting this internal unauthorized act. Examples of determining the presence or absence of abnormality in FIG. 4 are as follows. For example, the learning model M1-3 outputs a determination result as to whether there is an abnormality with respect to the "frequency of successful logins" for the "abnormal frequency of successful logins". In this figure, the vertical axis represents the "number of times of feature extraction", the horizontal axis represents the "number of occurrences of target events within the aggregation period", and the probability density function created by the KDE model is shown. Learning of the learning model M1-3 is performed based on normal information obtained by extracting the "frequency of successful logins" from the behavior information. The "frequency of successful logins" is counted for each event with the "within 24 hours from the start time of the determination of the presence or absence of abnormality" as the aggregation period every 15 minutes when the extraction unit 112 extracts features. Since the count is performed every 15 minutes, the count is performed 96 times within 24 hours from the start time. Note that this count may be aggregated by a moving average in order to grasp the overall trend. Assuming a moving average, when the normal information is aggregated for 27 days, the feature extraction is performed 2592 times by the extraction unit 112, the maximum number of login success events within 24 hours among users is 25, and the probability density function has the peak shown in FIG. 4. In this case, the number of times of extraction of the "feature that the number of login success events within 24 hours is 25 within the user" in the normal information was 1500 out of a total of 2592 times. When determining whether there is an abnormality using this normal information, the feature in this figure is the number of times of extraction of the "feature that the number of login success events within 24 hours is 30 within the user", and it was approximately 180 out of a total of 2592 times. Although the event of the feature in this figure exceeds the threshold with respect to the probability density function by the KDE model, since it is below the value of the probability density function assuming that "the number of login success events within 24 hours is 30 within the user", the "feature that the number of login success events within 24 hours is 30 within the user" is not detected as an abnormality. In this figure, when the Bandwidth, which is a parameter of the KDE model, is changed, the shape of the probability density function changes. For example, when the Bandwidth is increased from the shape in Figure 4, the graph of the probability density function becomes smoother. Conversely, when the Bandwidth is decreased, the graph of the probability density function becomes a complex shape.
[0021] When an anomaly is determined by the learning model MX-N, a value weighted for the learning model MX-N is output as a score. The weighting for the learning model MX-N is stored in the storage unit 116 and is updated at an arbitrary timing. The learning model MX-N uses the weighting stored in the storage unit 116. Note that the weighting is updated by an operator at an arbitrary timing. By being able to update the weighting at an arbitrary timing, the operator can suppress false detection and over-detection of internal fraud based on user feedback.
[0022] (Aggregation unit) The aggregation unit 113 aggregates the anomaly determination results output by the learning model MX-N. Examples of aggregation include a method of adding the scores output by the learning model MX-N, a method of deriving relationships from the correlations of each event determined by the learning model MX-N summarized in a table, and the like.
[0023] (Detection unit) The detection unit 114 detects the presumed internal fraud based on the aggregation of the anomaly determination results. For example, a threshold value is set for the aggregation result of the aggregation unit 113. If the aggregation result exceeds the threshold value, the detection unit 114 detects the presumed internal fraud as internal fraud. The threshold value set for the aggregation result (hereinafter, also referred to as the "threat threshold value") is stored in the storage unit 116, and the detection unit 114 uses the threat threshold value stored in the storage unit 116. Note that the threat threshold value is updated by an operator at an arbitrary timing. By being able to update the threat threshold value at an arbitrary timing, the operator can suppress false detection and over-detection of internal fraud based on user feedback.
[0024] (Notification unit) The notification unit 115 notifies the operator of the internal fraud detected by the detection unit 114 as a sound alert or a display alert to be displayed on a GUI (Graphical User Interface) provided inside or outside the internal fraud detection device 11. For example, the notification unit 115 may display a stacked bar graph on the GUI, with the horizontal axis being the time axis and the vertical axis being the number of detections for each labeled internal fraud, stacking the internal fraud detected at a certain time. Also, instead of the vertical axis being the count of the determination results determined as abnormal, a stacked bar graph stacking each determination result determined as abnormal at a certain time may be displayed.
[0025] (Memory unit) For example, the memory unit 116 stores the relationship between internal fraud and the learning model for detecting internal fraud, the weighting for the learning model MX-N, and the threat threshold. Also, the memory unit 116 may store the acquired behavior information and the Bandwidth corresponding to the learning data.
[0026] (Update unit) The update unit 117 updates some or all of the learning models of the learning model MX-N. For example, at an arbitrary timing when the acquisition unit 111 acquires behavior information, the update unit 117 updates some or all of the learning models of the learning model MX-N. Since the determination process of each learning model is independent, the update unit 117 can update some of the learning models of the learning model MX-N. The update unit 117 updates the learning model MX-N using the normal feature amounts (normal information) without abnormality among the behavior information acquired by the acquisition unit 111 as learning data.
[0027] (Multiple learning models MX: Initial learning and learning during update) The learning model MX-N learns using normal information as learning data. The same applies to the initial learning of the learning model MX-N. As shown in FIG. 5, assume that No. 1 - NO. X are labeled as internal frauds, and there are learning models for detecting each of these internal frauds. As described above, in the learning model MX - N, the feature quantities input to each learning model are different from each other. Also, the normal information used for each learning model as learning data is different from each other. Therefore, the learning periods of the learning models may be partially or entirely different from each other. The learning period varies widely depending on the normal information used as learning data, such as 15 minutes, 30 minutes, 1 hour, 24 hours, 1 week, 2 weeks, 1 month, etc. For example, assume that the internal fraud is "illegal use of user accounts" (in this figure, "X = 3"). Among the 10 learning models for detecting this internal fraud, M3 - 7 and M3 - 9 may require a long learning period. In M3 - 7 and M3 - 9, the occurrence of event logs, which are feature quantities for determining the abnormality of events, may be less respectively, and a long learning period is required to include these feature quantities in the behavior information. For example, for the event determined by the learning model M3 - 7: "changing password with abnormal numerical values", it is conceivable to change the password regularly to ensure the security within the system, but it is not considered to be at a frequency such as daily. The learning period is considered to be about 6 months. For example, for the event determined by the learning model M3 - 9: "deleting account with abnormal numerical values", it is conceivable to delete the account when an employee leaves among multiple users, but this is also not considered to be at a frequency such as daily. The learning period is considered to be about 1 year. Also, as shown in FIG. 5, the events for which the learning model MX - N determines whether it is abnormal are simple events. By using these simple events that do not include information for identifying users, it is possible to prevent false detection due to changes in an individual's role. For example, there are users on day shift and night shift, and even if they change regularly, the total number of each does not change significantly. Also, even when the user with administrative privileges changes regularly, the total number remains generally constant.
[0028] (Internal Fraud Detection Method) The internal fraud detection method of the internal fraud detection device 11 in this embodiment will be described. The internal fraud detection method of the internal fraud detection device 11 in this embodiment is implemented according to the flow shown in FIG. 6.
[0029] First, the acquisition unit 111 of the internal fraud detection device 11 acquires behavior information that summarizes the operation histories of a plurality of users involved in the control system (step ST01).
[0030] Next, the extraction unit 112 of the internal fraud detection device 11 extracts some of the operation histories from the behavior information as feature quantities (step ST02).
[0031] Next, the internal fraud detection device 11 determines anomalies from the tendencies of the users' operation histories using each learning model (step ST03). Specifically, the learning model MX-N determines anomalies from the tendencies of the operation histories of a plurality of users, taking the input as the feature quantity and the output as the determination result of anomalies for the feature quantity.
[0032] Next, the aggregation unit 113 of the internal fraud detection device 11 aggregates the anomaly determination results output by the learning model MX-N (step ST04).
[0033] Next, the detection unit 114 of the internal fraud detection device 11 detects the presumed internal fraud based on the aggregation of the anomaly determination results by the aggregation unit 113 (step ST05).
[0034] Next, the notification unit 115 of the internal fraud detection device 11 notifies the operator of the internal fraud detected by the detection unit 114 as a sound alert or a display alert to be displayed on a GUI (Graphical User Interface) provided inside or outside the internal fraud detection device 11 (step ST06).
[0035] Next, the operator updates at least one of the weighting or threat threshold for the learning model MX-N as necessary and newly stores it in the storage unit 116 (step ST07).
[0036] Next, the update unit 117 of the internal fraud detection device 11 periodically determines whether it is necessary to update the learning model (step ST08). When it is necessary to update the learning model (step ST08: YES), the update unit 117 updates some or all of the learning models of the learning model MX-N (step ST10).
[0037] On the other hand, when it is not necessary to update the learning model (step ST08: NO), the internal fraud detection device 11 determines whether to end the internal fraud detection process (step ST09). Ending the internal fraud detection process means, for example, interrupting the operation of the OT system. When ending the internal fraud detection process (step ST09: YES), the internal fraud detection device 11 ends the process shown in FIG. 6. When not ending the internal fraud detection process (step ST09: NO), the internal fraud detection device 11 sequentially performs the processes from step ST01 again.
[0038] (Operation and Effect) According to the internal fraud detection device 11 of the present embodiment, for each feature amount that is a part of the operation history in the behavior information, it is possible to perform abnormality determination respectively with the learning model MX-N that determines whether it is abnormal with a simple event. In addition, since the internal fraud detection device 11 detects internal fraud after aggregating the determination results of the learning model MX-N, the reliability of internal fraud detection is ensured by the aggregation. Therefore, in some of the learning models MX-N, the learning period can be intentionally shortened. Alternatively, the internal fraud detection device 11 can reduce the learning data of the entire learning model MX-N. Also, false detection due to a change in the role of the user can be suppressed. Therefore, the internal fraud detection device 11 according to the present disclosure can detect internal fraud with a small amount of learning data and a learning period.
[0039] In addition, the internal fraud detection device 11 according to the present disclosure aims to determine an abnormal situation from normal operations in the entire OT system by machine learning. For example, the following cases can be considered. Case 1: Login was successful, but it was at an abnormal time (e.g., at night). Case 2: It was an authorized app, but the days when the app was used during the aggregation period were days when it is not normally used (it is used every Thursday for file uploads, but not on other days). All of the above may be considered abnormal when judged separately from the overall operation flow of the OT system. Typically, when determining the presence or absence of abnormalities, a determination may be made that is separated from the overall operation flow of the OT system by including information identifying the user.
[0040] However, in Case 1, there is a sufficient possibility that the working hours of the user within the OT system may suddenly change. In that case, since the normal login time changes between day shift and night shift, it will be regarded as abnormal as it is. Also, in Case 2, even for an app that is normally only used on Fridays, if there are holidays or days off before and after, depending on the operation status of the OT system, it is quite possible to operate it before and after the days when the external app is normally used. In that case, it will be regarded as abnormal when judged separately from the overall operation flow of the OT system. In Case 2, in addition, there are also cases where an app that can originally only be used by administrators may have a change in the number of administrators who can use it or the administrators themselves due to promotion or organizational changes.
[0041] Also, considering that user login errors are likely to occur after a long vacation, there is also a need to judge as normal at a specific time even for abnormal operations.
[0042] Regarding the problems occurring on the OT system exemplified above, it is difficult to presume internal fraud after considering the overall operation flow of the OT system. Furthermore, if internal fraud is to be estimated by machine learning that combines anomalies that can be determined by learning with a few days of information and anomalies that require one year of information for learning and determination, it is necessary to align the learning periods for the determination events that require the longest learning period. As a result, the amount of learning data becomes enormous, and the period for acquiring data also becomes long.
[0043] The internal fraud detection device 11 according to the present disclosure prepares a plurality of determination events for each learning model for one estimated internal fraud, and estimates internal fraud by aggregating the determination results regarded as anomalies by each learning model. Depending on the content of the determination event, the period required for learning and determination can be varied. Therefore, it is not necessary to align the learning periods for the determination events that require the longest learning period. That is, it is possible to reduce unnecessary data prepared for aligning the learning periods. Furthermore, by estimating internal fraud by aggregating the determination results, it is easier to determine whether internal fraud is estimated for the entire OT system.
[0044] In addition, since simple events are used for the determination events, it is possible to prevent false detection of anomalies due to changes in individual roles. That is, information such as the authority of an individual or role is not used for determination by machine learning. For example, there are users who work during the day and at night, and even if their working hours are regularly swapped, the total number of working hours in each working hour period rarely changes significantly. Also, even when the user with administrative authority changes regularly, the total number remains generally constant. Also, the internal fraud detection device 11 of the present disclosure can perform operations such as not determining internal fraud if the total number of uploads is not abnormal even when a file that is usually uploaded on Thursday is uploaded on Friday.
[0045] Note that depending on the internal fraud, it may take a long learning period for estimation. However, since the determination events are prepared separately for each learning model, first, the OT system is released based on the results of learning during the preparation period, and then, while operating, learning data is collected and the learning models can be updated as appropriate.
[0046] As a comparative example, in UEBA, while the UEBA tool was updated using vulnerability scans and patches during the operation of the IT system, it was difficult to update the UEBA tool while continuing to operate the OT system. In the internal fraud detection device 11 of the present embodiment, since the determination processes of the respective learning models are independent, it is possible to update some of the learning models of the learning model MX-N without stopping the operation of the OT system. Therefore, the internal fraud detection device 11 according to the present disclosure can update the internal fraud detection process without affecting the continuous operation of the OT system.
[0047] (Other Embodiments) As described above, the embodiments of the present disclosure have been described in detail with reference to the drawings. However, the specific configuration is not limited to this embodiment, and design changes and the like within the scope not departing from the gist of the present disclosure are also included.
[0048] For example, the internal fraud detection device 11 may be directly communicably connected to the work terminal 13-C.
[0049] For example, the anomaly determination algorithms of the learning models MX-N may all be the same. Thereby, even if the total number of the learning models MX-N becomes enormous, the operation can be made lightweight as compared with the case where the anomaly determination algorithms are different for each of the learning models MX-N.
[0050] For example, the extraction unit 112 may extract normal information from the behavior information stored in the storage unit 116, and the update unit 117 may update the learning model MX-N using this normal information as learning data. That is, when the extracted feature amount already includes an anomaly, the update unit 117 can use the normal information extracted from the behavior information stored in the storage unit 116 as learning data.
[0051] Note that, among the learning models MX-N, there are learning models that generate few event logs, which are feature quantities for determining abnormalities in each event, and require a long learning period. However, for application to a new OT system, it is conceivable that the required learning period cannot be sufficiently taken for the learning models. However, since the internal fraud detection device 11 detects internal fraud after aggregating the determination results of the learning model MX-N, the reliability of internal fraud detection is ensured by the aggregation. Therefore, even if there is a learning model for which the learning period has not been sufficiently taken, the reliability of internal fraud detection is ensured by the aggregation. Thus, the internal fraud detection device 11 can use the determination results of the learning model for which the learning period has not been sufficiently taken.
[0052] FIG. 7 is a hardware configuration diagram showing the configuration of the computer 90 according to the present embodiment. The computer 90 includes, for example, a processor 91, a main memory 92, a storage 93, and an interface 94.
[0053] Each functional unit of the above-described internal fraud detection device 11 is implemented in the computer 90. The operations of the above-described functional units are stored in the storage 93 in the form of a program. The processor 91 reads the program from the storage 93, expands it in the main memory 92, and executes the above processing according to the program. Further, the processor 91 secures a storage area used by each of the above-described functional units in the main memory 92 according to the program.
[0054] The program may be for realizing a part of the functions to be exerted on the computer 90. For example, the program may exert functions by combining with other programs already stored in the storage 93 or other programs implemented in other devices. Further, in addition to or instead of the above configuration, the computer 90 may be provided with a custom LSI (Large Scale Integrated Circuit) such as a PLD (Programmable Logic Device). Examples of the PLD include PAL (Programmable Array Logic), GAL (Generic Array Logic), CPLD (Complex Programmable Logic Device), and FPGA (Field Programmable Gate Array). In this case, part or all of the functions realized by the processor 91 may be realized by the integrated circuit.
[0055] Examples of the storage 93 include a magnetic disk, a magneto-optical disk, and a semiconductor memory. The storage 93 may be an internal medium directly connected to the bus of the computer 90, or may be an external medium connected to the computer 90 via the interface 94 or a communication line. Further, when this program is distributed to the computer 90 via a communication line, the computer 90 that has received the distribution may expand the program in the main memory 92 and execute the above processing. Also, the program may be for realizing a part of the functions described above. Furthermore, the program may be a so-called difference file (difference program) that realizes the above-described functions in combination with other programs already stored in the storage 93.
[0056] <Appendix> The internal fraud detection device 11 described in each embodiment is understood as follows, for example.
[0057] Some or all of the above embodiments may be described as follows in the appended claims, but are not limited thereto.
[0058] (Appendix 1) (1) The internal fraud detection device 11 according to the first aspect includes an acquisition unit 111 that acquires behavior information summarizing the operation histories of a plurality of users involved in a control system (OT system), and uses an input as a part of the operation histories (feature amounts) of the behavior information and an output as a determination result of an abnormality with respect to the part of the operation histories (feature amounts). A plurality of learning models MX that are machine-learned to determine the abnormality from the tendencies of the operation histories of the plurality of users, an aggregation unit 113 that aggregates the determination results of the abnormality output by the plurality of learning models MX, and based on the aggregation of the determination results of the abnormality, A detection unit 114 for detecting an estimated internal fraud, and in the plurality of learning models MX, the part of the operation histories (feature amounts) input to each learning model are different from each other.
[0059] According to such a configuration, for each of the feature amounts that are a part of the operation histories in the behavior information, the determination of whether or not there is an abnormality can be performed respectively by a learning model MX-N that determines the abnormality with a simple event. In addition, since the internal fraud detection device 11 performs detection of internal fraud after aggregating the determination results of the learning model MX-N, the reliability of internal fraud detection is ensured by the aggregation. Therefore, in some of the learning models MX-N, the learning period can be intentionally shortened. Alternatively, the internal fraud detection device 11 can reduce the learning data of the entire learning model MX-N. Therefore, the internal fraud detection device 11 according to the present disclosure can detect internal fraud with a small amount of learning data and a learning period.
[0060] (Appendix 2) (2) The internal fraud detection device 11 according to the second aspect is the internal fraud detection device described in (1), and in the plurality of learning models, the learning periods of each learning model are partially or all different from each other.
[0061] According to such a configuration, since the internal fraud detection device 11 detects internal fraud after aggregating the determination results of the learning model MX-N, the reliability of internal fraud detection is ensured by the aggregation. Therefore, in some of the learning models MX-N, the learning period can be intentionally shortened. Therefore, the internal fraud detection device 11 according to the present disclosure can detect internal fraud with a small amount of learning data and a short learning period.
[0062] (Appendix 3) (3) The internal fraud detection device 11 according to the third aspect is the internal fraud detection device according to (1) or (2), and at least one of the event log or metric information is included in the partial operation history.
[0063] According to such a configuration, in the internal fraud detection device 11, the behavior information serving as the feature amount includes at least one of the event log or metric information. Thereby, even if the amount of the acquired behavior information is suppressed, the learning model MX-N can be learned with the minimum amount of data. Therefore, the internal fraud detection device 11 according to the present disclosure can detect internal fraud with a small amount of learning data and a short learning period.
[0064] (Appendix 4) (4) The internal fraud detection device 11 according to the fourth aspect is the internal fraud detection device according to any one of (1) or (3), and the learning method of the learning model is unsupervised learning.
[0065] According to such a configuration, the internal fraud detection device 11 can determine an abnormality that is difficult to prepare correct answer data during learning, in other words, an abnormality that is difficult to uniquely rule out, and it becomes easier to detect internal fraud. The internal fraud detection device 11 according to the present disclosure can detect internal fraud with a small amount of learning data and a short learning period. In addition, the internal fraud detection device 11 according to the present disclosure can determine an abnormality that is difficult to uniquely rule out from the feature amount, and it is easy to detect internal fraud.
[0066] (Appendix 5) (5) The internal fraud detection device 11 according to the fifth aspect is the internal fraud detection device described in any one of (1) to (3), and for the machine learning of the learning model, operation histories of a plurality of users that do not include information for identifying users are used.
[0067] According to such a configuration, false detection due to a change in the role of the user can be suppressed. The internal fraud detection device 11 according to the present disclosure can detect internal fraud with a small amount of learning data and a learning period.
[0068] (Appendix 6) (6) The internal fraud detection method according to the sixth aspect includes a step of obtaining behavior information that summarizes the operation histories of a plurality of users involved in a control system, a step of using part of the operation histories among the behavior information as an input and using a plurality of learning models that are machine-learned to determine the abnormality from the tendency of the operation histories of the plurality of users with the output being the determination result of the abnormality for the part of the operation histories, and a step of aggregating the determination results of the abnormality output by the plurality of learning models, and a step of detecting the presumed internal fraud based on the aggregation of the determination results of the abnormality. In the plurality of learning models, the part of the operation histories input to each learning model is different.
[0069] According to such a configuration, for each feature amount that is part of the operation histories among the behavior information, the determination of the abnormality can be performed respectively by the learning model MX-N that determines whether it is abnormal with a simple event. In addition, since the internal fraud detection method performs the detection of internal fraud after aggregating the determination results of the learning model MX-N, the reliability of the internal fraud detection is ensured by the aggregation. Therefore, in some of the learning models MX-N, the learning period can be intentionally shortened. Alternatively, the internal fraud detection method can reduce the learning data for the entire learning model MX-N. Therefore, the internal fraud detection method according to the present disclosure can detect internal fraud with a small amount of training data and a short training period.
[0070] (Appendix 7) (7) The program according to the seventh aspect causes a computer to execute: a step of obtaining behavior information summarizing operation histories of a plurality of users involved in a control system; a step of using, as input, a part of the operation histories among the behavior information and, as output, a determination result of abnormality with respect to the part of the operation histories, and aggregating the determination results of abnormality output by the plurality of learning models that are machine-learned to determine the abnormality from the tendency of the operation histories of the plurality of users; and a step of detecting presumed internal fraud based on the aggregation of the determination results of abnormality, wherein in the plurality of learning models, the part of the operation histories input to each learning model is different.
[0071] According to such a configuration, for each feature amount that is a part of the operation histories in the behavior information, it is possible to respectively determine whether it is abnormal using the learning model MX-N that determines whether it is abnormal with a simple event. In addition, since this program detects internal fraud after aggregating the determination results of the learning model MX-N, the reliability of internal fraud detection is ensured by the aggregation. Therefore, in some of the learning models MX-N, the training period can be intentionally shortened. Alternatively, this program can reduce the training data for the entire learning model MX-N. Therefore, the program according to the present disclosure can detect internal fraud with a small amount of training data and a short training period.
Description of Reference Numerals
[0072] 1 Internal fraud detection system 11 Internal fraud detection device 12 Network 13-C Work terminal 111 Acquisition unit 112 Extraction unit 113 Aggregation unit 114 Detection unit 115 Notification unit 116 Memory unit 117 Update unit MX-N learning model
Claims
1. An acquisition unit that acquires behavior information summarizing the operation histories of a plurality of users involved in a control system; A plurality of learning models that are machine-learned to determine the abnormality from the tendencies of the operation histories of the plurality of users, with the input being a part of the operation histories among the behavior information and the output being the determination result of the abnormality with respect to the part of the operation histories; An aggregation unit that aggregates the determination results of the abnormality output by the plurality of learning models; A detection unit that detects presumed internal fraud based on the aggregation of the determination results of the abnormality; Comprising; In the plurality of learning models, the part of the operation histories input to each learning model is different; Internal fraud detection device.
2. In the plurality of learning models, the learning periods of each learning model are partly or all different from each other; The internal fraud detection device according to Claim 1.
3. The part of the operation histories includes at least one of event logs or metric information; The internal fraud detection device according to Claim 1 or Claim 2.
4. The learning method of the learning model is unsupervised learning; The internal fraud detection device according to Claim 1 or Claim 2.
5. For the machine learning of the learning model, the operation histories of a plurality of users that do not include information for identifying the users are used; The internal fraud detection device according to Claim 1 or Claim 2.
6. A step of acquiring behavior information summarizing the operation histories of a plurality of users involved in a control system; Using a plurality of learning models that are machine-learned to determine the abnormality from the tendencies of the operation histories of the plurality of users, with the input being a part of the operation histories among the behavior information and the output being the determination result of the abnormality with respect to the part of the operation histories; A step of aggregating the determination results of the abnormality output by the plurality of learning models; A step of detecting presumed internal fraud based on the aggregation of the determination results of the abnormality; Including; In the plurality of learning models, the part of the operation histories input to each learning model is different; Internal fraud detection method.
7. A step of acquiring behavior information summarizing the operation histories of a plurality of users involved in a control system; Using a plurality of learning models that are machine-learned to determine the abnormality from the tendencies of the operation histories of the plurality of users, with the input being a part of the operation histories among the behavior information and the output being the determination result of the abnormality with respect to the part of the operation histories; A step of aggregating the determination results of the abnormality output by the plurality of learning models; Based on the aggregation of the determination results of the anomalies, detecting the presumed internal fraud; causing a computer to execute; In the plurality of learning models, the partial operation histories input to each learning model are different from each other; program.