Information processing device, information processing method, and program

The information processing device collects and combines security risk information from the dark web, cybersecurity products, and surface web to provide a comprehensive security risk score, addressing the limitations of existing technologies in incorporating dark web data.

JP2025085944APending Publication Date: 2025-06-06SMS DATATECH CO LTD

Patent Information

Application Number
JP2023199662
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-11-27
Publication Date
2025-06-06

AI Technical Summary

Technical Problem

Existing technologies struggle to present comprehensive security risk information to businesses, as they primarily focus on surface web data, neglecting critical information available on the dark web.

Method used

An information processing device and method that collect security risk information from three sources: the dark web, cybersecurity countermeasure products, and the surface web, using specialized browsers and search engines, and calculate a unified security risk score.

Benefits of technology

Enables the presentation of a complete security risk profile to businesses, including dark web data, thereby enhancing their cybersecurity posture and risk management capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025085944000001_ABST
    Figure 2025085944000001_ABST
Patent Text Reader

Abstract

To provide a technique for presenting security risk information including information present in a Dark Web.SOLUTION: An information processing device is configured to: collect first security risk information by making a search in a Dark Web; collect second security risk information from a product having a cyber-security measure; collect third security risk information by making a search in a Surface Web by using a normal browser; and calculate a security risk score of an object person on the basis of the first security risk information, the second security risk information, and the third security risk information.SELECTED DRAWING: Figure 2B
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] The present disclosure relates to an information processing device, an information processing method, and a program. [Background technology]

[0002] Conventionally, there is technology that monitors multiple websites and monitors information about a customer, and based on the results of the monitoring over a specified period of time, calculates a score of the danger to the customer as a risk score and presents it to the customer (for example, Patent Document 1).

[0003] There is also a technique for obtaining a plurality of publicly available pieces of information about devices connected to a communication network by using OSINT (Open-Source Intelligence) (for example, Patent Literature 2). [Prior art documents] [Patent documents]

[0004] [Patent Document 1] Patent Publication No. 2023-111350 [Patent Document 2] Patent No. 2022-162273 Summary of the Invention [Problem to be solved by the invention]

[0005] By using such technology, it is possible to discover weaknesses in the networks and software vulnerabilities of business organizations, etc., and to investigate whether employees are disclosing more information than necessary on social media.

[0006] However, while the above technology makes it possible to present security risk information to businesses and the like based on information present on the surface web, which can be accessed by ordinary search engines, it has been difficult to present security risk information to businesses and the like that also includes information present on the dark web.

[0007] The present disclosure aims to provide a technique for presenting security risk information, including information present on the dark web. [Means for solving the problem]

[0008] In order to solve the above problem, the information processing device disclosed herein comprises a first information collection means for collecting first security risk information related to a subject by accessing a dark web, which is inaccessible with a normal browser but accessible through encrypted communication using a special browser, and searching within the dark web using a search engine corresponding to the dark web; a second information collection means for collecting second security risk information related to the subject from a cybersecurity countermeasure product used by the subject; a third information collection means for collecting third security risk information related to the subject by accessing a surface web using a normal browser and searching within the surface web using a search engine corresponding to the surface web; and a risk score calculation means for calculating a security risk score of the subject based on the first security risk information, the second security risk information, and the third security risk information.

[0009] In addition, the information processing method disclosed herein is an information processing method executed by a computer, and includes a first information collection step of collecting first security risk information related to the subject by accessing a dark web that is inaccessible with a normal browser and accessible through encrypted communication using a special browser and searching within the dark web using a search engine corresponding to the dark web; a second information collection step of collecting second security risk information related to the subject from a cybersecurity countermeasure product used by the subject; a third information collection step of collecting third security risk information related to the subject by accessing a surface web using a normal browser and searching within the surface web using a search engine corresponding to the surface web; and a risk score calculation step of calculating a security risk score for the subject based on the first security risk information, the second security risk information, and the third security risk information.

[0010] In addition, the information processing program disclosed herein causes a computer to execute a first information collection step of collecting first security risk information related to the subject by accessing a dark web, which is inaccessible with a normal browser but is accessible through encrypted communication using a special browser, and searching within the dark web using a search engine corresponding to the dark web; a second information collection step of collecting second security risk information related to the subject from a cybersecurity countermeasure product used by the subject; a third information collection step of collecting third security risk information related to the subject by accessing a surface web using a normal browser and searching within the surface web using a search engine corresponding to the surface web; and a risk score calculation step of calculating a security risk score for the subject based on the first security risk information, the second security risk information, and the third security risk information. Effect of the Invention

[0011] According to the present disclosure, it is possible to provide a technology for presenting security risk information, including information present on the dark web. [Brief description of the drawings]

[0012] [Figure 1] FIG. 1 is a diagram illustrating an example of an information processing system according to an embodiment of the present disclosure. [Figure 2A] FIG. 13 is a diagram showing an example of the layout of a risk score management table. [Figure 2B] 13 is a diagram showing an example of security risk information displayed in a risk score management table. [Figure 2C] 13 is a diagram showing an example of security risk information displayed in a risk score management table. [Diagram 3] 13 is a flowchart illustrating an example of a risk score process. [Figure 4] 13 is a flowchart showing an example of a first information collection process in the risk score process. [Diagram 5] 13 is a flowchart showing an example of a second information collection process in the risk score process. [Figure 6] 13 is a flowchart showing an example of a third information collection process in the risk score process. [Figure 7] 13 is a flowchart showing an example of a current score counting process in the risk score process. [Figure 8] 13 is a flowchart showing an example of a post-countermeasure score counting process in the risk score process. [Figure 9] A figure showing an example of a method for calculating an enterprise's risk score in the current situation score counting process. [Figure 10] A figure showing an example of a method for calculating the risk score of each employee in the current situation score aggregation process. [Figure 11] FIG. 13 is a diagram showing an example of a measure for lowering a risk score. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS

[0013] Hereinafter, embodiments of the present disclosure will be described in detail with reference to the drawings. However, more detailed explanations than necessary, such as detailed explanations of already well-known matters and duplicate explanations of substantially the same configurations, may be omitted.

[0014] It should be noted that the following description and the drawings referred to are provided to enable those skilled in the art to understand the present disclosure, and are not intended to limit the scope of the claims of the present disclosure.

[0015] [Information Processing System] First, an example of an information processing system according to an embodiment of the present disclosure will be described with reference to FIG.

[0016] The information processing system 10 according to the embodiment of the present disclosure is configured by, for example, an information processing device 100 owned by a service provider, a user terminal 211... used by an employee of the provider 200 at a business 210, a user terminal 221... used by an employee of the provider 200 at a telework site, a user terminal 231... used by an employee of the provider 200 away from the office, and a CASB (Cloud Access Security Broker) 300, which is a cybersecurity countermeasure product that centrally manages multiple cloud services that can be used by an employee of the provider 200 from the user terminals 211, 221, and 231 (hereinafter referred to as "user terminals 211, etc."). The provider 200 is a company such as a joint stock company, a country, a prefecture, a city, a town, a village, a corporation such as a public corporation or a public interest corporation such as a medical corporation, and an association or a foundation, and an employee is a person who works for these corporations, etc.

[0017] The information processing device 100, the user terminal 211, etc., and the CASB 300 may be, for example, a personal computer, a server computer, a smartphone, a tablet terminal, etc., as appropriate, and these are information processing devices that include a CPU, storage, ROM, RAM, an input / output I / F, a communication unit, a display unit, etc. Note that information processing devices are well-known technologies, so detailed explanations will be omitted.

[0018] The communication network is composed of, for example, the Internet, a LAN (Local Area Network), a wireless base station, a provider device, etc. Since the communication network is a well-known technology, detailed description thereof will be omitted.

[0019] The information processing device 100 communicates with the CASB 300 via a communication network. The information processing device 100 also accesses the surface web 500 via the communication network by using a normal browser.

[0020] Furthermore, the information processing device 100 accesses the dark web 600 via a communication network by using a special browser. Since the dark web 600 is made up of websites that hide IP addresses from the Internet, it cannot be accessed by a normal browser and a special browser must be used to access it. Examples of the special browser include Tor (The Onion Router), I2P (Invisible Internet Project), and Freenet. The information processing device 100 accesses the dark web by connecting to a VPN (Virtual Private Network).

[0021] In addition, when searching within the dark web, a search engine compatible with the dark web 600 is required. Examples of search engines compatible with the dark web 600 include DuckDuckGo and Ahmia. In the dark web, confidential document information, threatening chats, employee account information, and the like related to the business entity 200 may be leaked.

[0022] The confidential document information of the business entity 200 corresponds to confidential documents such as confidential PDF files, log files, and confidential files that employees have accidentally disclosed to the public. Confidential document information may be illegally uploaded or sold on the dark web.

[0023] The threat chats related to business operator 200 include trends before and after cyber attacks by hackers, and slander against the company or products.

[0024] Employee account information is leaked account data contained in data leaked by the SaaS provider, such as name, email address, ID, password, user name, phone number, address, credit card number, etc. Employee account information may be illegally uploaded or bought and sold on the dark web.

[0025] The user terminal 211 or the like uses a normal browser to access the cloud service 400 and the surface web 500 via the CASB 300 over a communication network.

[0026] An employee of the business operator 200 can use various services (cloud services 400) such as SaaS (Software as a Service), PaaS (Platform as a Service), and IaaS (Infrastructure as a Service) by using a normal browser installed on the user terminal 211 or the like. Note that SaaS is a service that provides software functions such as email, groupware, customer management, and financial accounting, PaaS is a service that provides platform functions for application execution such as virtualized application servers and databases, and IaaS is a service that provides hardware and infrastructure functions such as desktop virtualization and shared disks.

[0027] In addition, employees of business 200 can use various services (web services) provided on surface web 500 using a normal browser (e.g., Google Chrome (registered trademark), etc.) installed on user terminal 211, etc.

[0028] When an employee of the business entity 200 uses (accesses) the cloud service 400 or the surface web 500 using the user terminal 211 or the like, the access goes through the CASB 300. The CASB 300 manages the usage status (access status, file upload, download, etc.) of the cloud service 400 or the surface web 500 by the employee of the business entity 200. The CASB 300 also implements highly accurate information leakage countermeasures by identifying confidential information by performing keyword searches within files, etc. It also prevents users and terminals not authorized by the business entity from accessing the cloud service, and prevents the leakage of important information by detecting and isolating malware. It also monitors and controls the cloud service based on the set security policy.

[0029] The CASB 300 generates a log of information related to communication between the cloud service 400 and the surface web 500 of the user terminal 211, etc. (hereinafter referred to as the "CASB log"). The CASB log includes information indicating the usage history and usage status of the cloud service 400 accessed by the user terminal 211, etc., associated with the identification information of the user terminal 211, etc., information indicating the usage history and usage status of the surface web 500 accessed by the user terminal 211, etc., and the usage history and usage status of SaaS.

[0030] [Configuration of information processing device 100] The information processing device 100 functions as a first information collection unit 110, a second information collection unit 120, a third information collection unit 130, a risk score processing unit 140, an enterprise attribute storage unit 150, a log storage unit 160, and a management information storage unit 170. These functions are exercised by a processor such as a CPU executing a corresponding program.

[0031] The first information collection unit 110 (corresponding to the first information collection means) collects leaked information related to the business operator 200 (including employees) by searching for information on the dark web 600 using a special browser and a search engine compatible with the dark web 600. The search contents on the dark web 600 and the collected leaked information are stored in the log storage unit 160.

[0032] The second information collection unit 120 (corresponding to a second information collection means) accesses the CASB 300 to acquire a CASB log, and collects risk information related to the business entity 200 due to the use of the SaaS from the acquired CASB log. The acquired CASB log is stored in the log storage unit 160.

[0033] The third information collection unit 130 (corresponding to a third information collection means) uses a normal browser and a search engine to search for information on the surface web 500, thereby collecting threat information related to the business entity 200. The search contents on the surface web 500 and the collected threat information are stored in the log storage unit 160.

[0034] The risk score processing unit 140 (corresponding to a risk score calculation means) executes a process of scoring the level of security risk in the business entity 200 based on various information (information stored in the log storage unit 160) related to the business entity 200 collected by the first information collection unit 110, the second information collection unit 120, and the third information collection unit 130. Here, by analyzing various information related to the business entity 200 collected by the first information collection unit 110, the second information collection unit 120, and the third information collection unit 130 using AI, a security risk level value is assigned to each piece of information, and the security risk level is scored. The risk score processing unit 140 executes scoring of the current security risk level in the business entity 200 and scoring of the security risk level after countermeasures are taken in the business entity 200 (see FIGS. 7 and 8).

[0035] Furthermore, the risk score processing unit 140 uses a normal browser and search engine to extract threat trend information (news, warnings, etc. relating to information security, etc.) disclosed on the surface web 500. The risk score processing unit 140 also accesses a server, etc. of the business operator 200 to acquire response information indicating the status of measures taken against security risks at the business operator 200, training information indicating the status of training against security risks, etc. Then, the risk score processing unit 140 generates a risk score management table (risk score management image) 700 for the business operator 200 based on these processes. The business operator 200 can be provided with the risk score management table 700 as appropriate via email, web services, etc.

[0036] AI may be used in the processing by the first information collection unit 110, the second information collection unit 120, the third information collection unit 130, and the risk score processing unit 140. When AI is used, for example, it is possible to use an AI search engine as a search engine to collect leaked information related to the business operator 200, to use an AI scoring process to score the security risk level, or to generate text related to countermeasures against security risks to be presented to the business operator 200.

[0037] The business attribute storage unit 150 stores information (hereinafter referred to as "business attribute information") necessary for the first information collection unit 110 to search for information related to the business 200 on the dark web 600, for the second information collection unit 120 to collect risk information related to the business 200 due to the use of SaaS, and for searching for information related to the business 200 on the surface web 500. The business attribute information includes attribute information of the business 200 (business name, corporate number, address, product name, various keyword information related to the business, etc.) and attribute information of each employee (for example, name, employee ID, department name, email address, password, host name, IP address, etc.).

[0038] The log storage unit 160 stores the CASB log, and operation logs by the first information collection unit 110, the second information collection unit 120, the third information collection unit 130, and the like.

[0039] The management information memory unit 170 stores various processing information related to the risk score processing unit 140 up to the present time, various numerical information used for processing by the risk score processing unit 140, information used to generate the risk score management table 700, etc.

[0040] [Risk score management table] Next, the risk score management table 700 generated by the risk score processing unit 140 will be described with reference to FIGS. 2A to 2C.

[0041] 2A is a diagram showing an example of the layout of a risk score management table 700. As shown in this figure, the risk score management table 700 has, as items, an "account leakage" item 710, a "presentation of risk score" item 720, a "latest threats to your company" item 730, a "latest threat trends" item 740, a "targeted email training" item 750, and an "implementation status of recommended measures" item 720.

[0042] Next, the information displayed in the "Account Leakage" item 710 and the "Risk Score Presentation" item 720 will be described with reference to FIG. 2B.

[0043] The "Account Leak" item 710 of the risk score management table 700 displays the leaked account unaddressed status 711, the leaked account addressed status 712, the leaked service history 713, the top 5 leaked data types (714), and the top 5 leaked services (715).

[0044] The leaked account unaddressed status 711 displays a numerical value of the current leaked account unaddressed status at the business entity 200, and also displays a message (advice, etc.) according to the level.

[0045] The status of action taken against compromised accounts 712 displays the status of action taken against compromised accounts by the business entity 200 using a pie chart and numerical values.

[0046] The leakage occurrence service history 713 displays the past leakage status of accounts at the business entity 200 .

[0047] The top 5 leaked data types (714) display the number of leaks according to the type of account at the business entity 200 using a bar graph and numerical values.

[0048] The top 5 services with data leaks (715) displays the number of accounts that have been leaked for each service, such as a cloud service, used by the business entity 200, using a bar graph and numerical values.

[0049] In the "Presentation of risk score" item 720 of the risk score management table 700, the business operator risk score 721 and the top 10 high-risk users (722) who have not taken measures are displayed.

[0050] The business risk score 721 displays, in a meter, the score (average value) of the security risk of employees belonging to the business 200. In addition, the change in the past score of the business 200 is displayed in a line graph, and the standard value (benchmark (BM)) is also displayed.

[0051] The TOP 10 high-risk users with no measures in place (722) displays the email addresses, etc. and score values ​​of the top 10 employees of business 200 who have not taken measures (responses) against security risks (high security risk).

[0052] Next, using FIG. 2C, the information displayed in the “Latest threats to your company” item 730, “Threat trends for your company” item 740, “Targeted email training” item 750, and “Recommended measures: implementation status” item 760 will be explained.

[0053] The “Latest threats to your company” item 730 of the risk score management table 700 displays the contents of chats (threatening chats) that may pose a threat to business 200, and the contents of documents (leaked documents) that have been leaked by business 200 or business partners of business 200, etc.

[0054] The “your company's threat trends” item 740 of the risk score management table 700 displays the contents and links of trend information (threat trends) in information security and the like that can be used as reference by the business entity 200.

[0055] The "Targeted email training" item 750 in the risk score management table 700 displays the implementation status of training (targeted email training) for simulating targeted attack emails at the business operator 200. Here, the number of training sessions each month (number of training sessions per month) and the number of training subjects each month (number of training subjects per month) are displayed in a bar graph. In addition, the total number of targeted email training sessions this year (all training sessions), the number of training sessions currently being conducted (ongoing training sessions), the number of training sessions currently scheduled (scheduled training sessions), and the number of training sessions currently completed (completed training sessions) are displayed.

[0056] The "recommended measures: implementation status" item 760 of the risk score management table 700 displays the implementation status of proposed measures against security risks at the business entity 200. Here, recommended measures (recommended measures 1, 2, ...) and the response status (responded / not responded) for each measure are displayed.

[0057] [Risk score processing] Next, a risk score process executed by the information processing device 100 will be described with reference to Fig. 3. Fig. 3 is a flowchart showing an example of the risk score process.

[0058] First, in step S1, it is determined whether or not to calculate the current risk score. If it is determined that the current risk score is to be calculated (YES), the process proceeds to step S10. On the other hand, if it is determined that the current risk score is not to be calculated (NO), the process proceeds to step S2. The calculation of the current risk score is performed every predetermined period (for example, every week).

[0059] If it is determined in step S1 that the current risk score will not be calculated (NO), then in step S2 it is determined whether or not to calculate the risk score after measures have been taken. If it is determined that the risk score after measures has been calculated (YES), then the process proceeds to step S50. On the other hand, if it is determined that the risk score after measures has not been calculated (NO), then the process proceeds to step S60. The risk score after measures is calculated as appropriate by a person in charge at business operator 200, or is calculated after a certain period of time has passed since the current risk score was presented to business operator 200.

[0060] When it is determined in step S1 that the current risk score is to be calculated (YES), a first information collection process (corresponding to a first information collection means) is executed in step S10.

[0061] Here, the first information collection process executed in the risk score process will be described with reference to Fig. 4. Fig. 4 is a flowchart showing an example of the first information collection process in the risk score process. This first information collection process is executed by the first information collection unit 110.

[0062] In the first information collection process, first, in step S11, the Tor browser (a special browser) is launched. By launching the Tor browser, the dark web is accessed.

[0063] Next, in step S12, a search engine is selected. In this case, a search engine that supports the dark web is selected. For example, DuckDuckGo is selected.

[0064] Next, in step S13, collection of leaked accounts is executed. Here, for example, if an email address of a business entity is present in a group of leaked accounts collected from a leak bulletin board on the dark web, this is detected, and account information related to the business entity 200 and the number of account leaked data included in various information leaked from the SaaS business entity are collected.

[0065] Next, in step S14, a search and collection of threat chats is performed. Here, for example, the AI ​​extracts information related to the business 200, such as the business name, corporate number, product name, and address IR disclosure information, from the business attribute information storage unit 150, and sets the extracted information and keyword information generated by the AI ​​based on the information as search targets in a search engine to perform a search, thereby tracking the contents of conversations on the dark web and Telegram, and when a chat or the like corresponding to the search target information is detected, the chat information and the number of detections found in the threat chats are collected.

[0066] Next, in step S15, a search and collection of confidential documents is executed. Here, for example, the AI ​​extracts information that is considered confidential by the business 200 from the business attribute information storage unit 150, and sets the extracted information and keyword information generated by the AI ​​based on the information as search targets in a search engine to perform a search, thereby collecting information and the number of confidential documents, such as confidential files (PDF files, etc.), log files, confidential files, confidential documents (confidential information) accidentally made public by employees or business partners, and confidential documents intentionally made public by employees or business partners.

[0067] When the process of step S15 ends, a second information collection process (corresponding to a second information collection means) is executed in step S20 (see FIG. 3).

[0068] Here, the second information collection process executed in the risk score process will be described with reference to Fig. 5. Fig. 5 is a flowchart showing an example of the second information collection process in the risk score process. This second information collection process is executed by the second information collection unit 120.

[0069] In the second information collection process, first, in step S21, the CASB 300 is accessed.

[0070] Next, in step S22, logs related to the business entity 200 are acquired. Here, logs recorded after the previously acquired log are acquired.

[0071] Next, the total number of SaaS used by each employee at the business entity 200 is calculated from the log acquired in step S23.

[0072] Next, the total usage time of the SaaS of each employee of the business entity 200 is calculated from the log acquired in step S24.

[0073] Next, in step S25, the average risk value of the SaaS used by each employee of the business operator 200 is calculated. Here, the risk weight for each SaaS is extracted from the business operator attribute information storage unit 150 by AI, and the average risk value of the SaaS is calculated taking into account each extracted risk weight.

[0074] When the process of step S25 ends, a third information collection process (corresponding to a second information collection means) is executed in step S30 (see FIG. 3).

[0075] Here, the third information collection process executed in the risk score process will be described with reference to Fig. 6. Fig. 6 is a flowchart showing an example of the third information collection process in the risk score process. This third information collection process is executed by the third information collection unit 140.

[0076] In the third information collection process, first, in step S21, open ports in the server of the business operator 200, the user terminal 211, etc., and other network devices, etc. are confirmed, and the number of open ports, port numbers, etc. are collected. Here, the AI ​​extracts the designated port number of the host name or IP address designated by the business operator 200 stored in the business operator attribute information storage unit 150, and executes a TCP connection from the information processing device 100 to the designated port number of the host name or IP address designated by the business operator 200, thereby executing a communication check over the Internet.

[0077] Next, in step S32, information on the software used by the business operator 200 is extracted from the business operator attribute information storage unit 150, and it is confirmed whether or not version information for each piece of software has been made public on the Internet. If it has been made public, the number of pieces of software and public version information, etc. are collected.

[0078] Next, in step S33, the domain name used by the business 200 is extracted from the business attribute information storage unit 150, and subdomains are searched for from this domain name. If any are found, the number of subdomains, the subdomain names, etc. are collected.

[0079] Next, in step S34, information on web applications used by employees of business operator 200 is extracted from business operator attribute information storage unit 150, vulnerabilities of these web applications are checked, and if vulnerabilities are confirmed, the number of vulnerabilities, the names of the web applications, etc. are collected. Here, vulnerabilities of the web applications are checked using a vulnerability detection tool, etc.

[0080] Next, in step S35, information on the domain of the business operator 200 is extracted from the business operator attribute information storage unit 150, and domains similar to this domain (domains that may be phishing domains) are searched for, and if found, the number of such domains, domain names, etc. are collected.

[0081] When the process of step S25 is completed, a current situation score counting process (corresponding to a risk score calculation means) is executed in step S40 (see FIG. 3).

[0082] Here, a current status score tallying process executed in the risk score processing will be described with reference to Fig. 7. Fig. 7 is a flowchart showing an example of the current status score tallying process in the risk score processing. This current status score tallying process is executed by the risk score processing unit 140.

[0083] In the current situation score aggregation process, first, in step S41, the results of the first information collection process are extracted. Here, the number of account leaked data leaked on the dark web, the total number of detections found in threatening chats on the dark web, and the number of detections of confidential documents found on the dark web are extracted.

[0084] Next, in step S42, the results of the second information collection process are extracted. Here, the total number of SaaS used by each employee, the total amount of time each employee used SaaS, and the average risk value of SaaS are extracted.

[0085] Next, in step S43, the results of the third information collection process are extracted. Here, the number of open ports, the number of published software versions, the number of subdomains, the number of web applications with confirmed vulnerabilities, and the number of domains (phishing domains) similar to the domain of the business operator 200 are extracted.

[0086] Next, in step S44, a current risk score is calculated. In step S44, first, a risk score is calculated for the business entity 200. Fig. 9 is a diagram showing an example of a method for calculating a risk score for the business entity in the current situation score counting process.

[0087] 9(a) shows the numerical values ​​and explanatory text used in the risk score calculation of the business operator 200 in this embodiment, and shows the risk value, explanatory text of the risk value, weight (× weight) multiplied by the risk value, and weight associated with each category. Each category corresponds to the first information collection process, the second information collection process, and the third information collection process, respectively, and each risk value is a value collected by the first information collection process, the second information collection process, and the third information collection process. In addition, the weight (× weight) multiplied by the risk value is a variable, and the value of each variable is stored in the business operator attribute storage unit 150.

[0088] 9(b) shows a formula for calculating the current risk score of business entity 200 used in step S44. In calculating the current risk score of business entity 200, a total risk value is calculated by multiplying each risk value by the weight value set for each risk value, and the risk score of business entity 200 is calculated by dividing this total risk value by the number of risk items (11 items).

[0089] Next, in step S44, a risk score is calculated for each employee of the business entity 200. Fig. 10 is a diagram showing an example of a method for calculating a risk score for each employee in the current situation score counting process.

[0090] 10(a) shows the numerical values ​​and explanatory text used in calculating the risk score of each employee in this embodiment, and shows the risk value, explanatory text of the risk value, weight (× weight) multiplied by the risk value, and explanatory text of the weight, associated with each category. Each category corresponds to the first information collection process and the second information collection process, respectively, and each risk value is a value collected by the first information collection process and the second information collection process. In addition, the weight (× weight) multiplied by the risk value is a variable, and the value of each variable is stored in the business operator attribute storage unit 150.

[0091] 10(b) shows a formula for calculating the current risk score for each employee of business entity 200 used in step S44. In calculating the risk score, each risk value is multiplied by the weighting value set for each risk value to calculate a total risk value, and this total risk value is divided by the number of risk items (5 items) to calculate the risk score for each employee of business entity 200.

[0092] When the current score counting process is completed in step S40, the process proceeds to step S60.

[0093] Next, in step S60, a threat trend information search process is executed. Here, by using a normal browser and search engine, information related to threat trends (news, warnings, etc. related to information security, etc.) disclosed on the surface web 500 is searched for based on preset sites and keywords, and when new threat trend information is made public, the information, URL, etc. are stored.

[0094] Next, in step S70, a training status aggregation process is executed. Here, a server of the business entity 200 or the like is accessed to acquire the countermeasure status against security risks at the business entity 200 and the training status according to the response training (for example, training against targeted attack emails) against security risks instructed from the information processing device 100 to the business entity 200.

[0095] Next, in step S80, a risk score management table generation process is executed. Here, based on the current score tallying process described above (see FIG. 7) or the post-countermeasure score tallying process described below (see FIG. 8), information and graphs to be displayed in each item (711-715) in the "Account Leakage" item 710 of the risk score management table 700 are generated. Also, information and graphs to be displayed in each item (721, 722) in the "Risk Score Presentation" item 720 of the risk score management table 700 are generated.

[0096] In addition, the contents to be displayed as recommended measures in the "recommended measures: implementation status" item 760 of the risk score management table 700 are generated based on the results of the first information collection process, the second information collection process, and the third information collection process. Here, each tabulation result is analyzed by AI to generate text for a proposed measure to reduce each risk value (corresponding to a means for presenting a proposed measure). For example, if there is an employee whose password has been leaked, text is generated to encourage the employee to change his / her password, or to delete or change account information. In addition, for example, if there is account information leaked due to the use of SaaS, text is generated to encourage the strengthening of security when accessing this SaaS. In addition, for example, if the value of the leaked account unhandled status 711 or the score value of the business operator risk score is high, text is generated to encourage the business operator 200 to implement security training.

[0097] In addition, threatening chats, leaked documents, etc. to be displayed in the "Latest threats to your company" item 730 of the risk score management table 700 are generated based on the results of the first information collection process. In addition, threat trend information to be displayed in the "Threat trends for your company" item 740 of the risk score management table 700 is generated based on the information stored in the threat trend information search process (step S60). In addition, the training status to be displayed in the "Targeted email training" item 750 of the risk score management table 700 is generated based on the information acquired in the training status aggregation process (step S70).

[0098] By executing the above-mentioned processing, the risk score processing generates a current risk score management table 700 (see FIGS. 2A to 2C). The generated risk score management table 700 is provided to the business operator 200 via email, web service, or the like.

[0099] If it is determined in step S1 that the current risk score is not to be calculated (NO), and if it is determined in step S2 that the post-measure risk score is to be calculated (YES), then in step S50, a post-measure score counting process is executed (see FIG. 3). The post-measure score counting process (corresponding to the risk score calculation means) is executed automatically when a certain period of time has elapsed after the current risk score management table 700 is generated, or is executed by the business operator 200 as appropriate.

[0100] Here, a post-countermeasure score tallying process executed in the risk score processing will be described with reference to Fig. 8. Fig. 8 is a flowchart showing an example of the post-countermeasure score tallying process in the risk score processing. This post-countermeasure score tallying process is executed by the risk score processing unit 140.

[0101] In the post-measure score counting process, first, in step S51, the above-mentioned first information collection process (see FIG. 4), second information collection process (see FIG. 5), and third information collection process (see FIG. 6) are executed.

[0102] Next, in step S52, a process is executed to extract the results of the first information collection process, the second information collection process, and the third information collection process (see FIG. 7).

[0103] Next, in step S53, the status of measures taken by business entity 200 against security risks is confirmed. Here, the result of the first information collection process, the result of the second information collection process, and the third information collection process extracted in step S52 are used, and response information indicating the status of measures taken against security risks is obtained by accessing a server of business entity 200 or the like.

[0104] Next, in step S54, a risk score after measures is calculated. In step S54, when measures are taken for each risk value constituting the current risk score calculated by the current score counting process (see FIG. 7), a process for lowering the value of the current risk score is executed. FIG. 11 is a diagram showing an example of measures for lowering the risk score.

[0105] 11(a) shows measures for lowering the risk score of the business operator 200, and shows risk values, descriptions of the risk values, and measures for lowering the risk values ​​in association with each category. Each category corresponds to the first information collection process, the second information collection process, and the third information collection process, respectively, each risk value is a value collected by the first information collection process, the second information collection process, and the third information collection process, and the measures are methods for lowering each risk value. The measures are referred to when generating the content to be displayed as recommended measures in the "recommended measures: implementation status" item 760 of the risk score management table 700 described above.

[0106] In step S54, if the AI ​​confirms that countermeasures have been taken by business operator 200 corresponding to each risk value, the risk value is reduced, and each risk value is multiplied by the weighting value set for each risk value to calculate a total risk value, and this total risk value is divided by the number of risk items (11 items) to calculate business operator 200's risk score after countermeasures have been taken (see Figure 9(b)).

[0107] 11(b) shows measures for lowering an employee's risk score, and shows risk values, descriptions of the risk values, and measures for lowering the risk values ​​in association with each category. Each category corresponds to the first information collection process and the second information collection process, respectively, each risk value is a value collected by the first information collection process and the second information collection process, and the measures are methods for lowering each risk value. The measures are referred to when generating the content to be displayed as recommended measures in the "Recommended measures: implementation status" item 760 of the risk score management table 700 described above.

[0108] In step S54, if it is confirmed that countermeasures have been taken for each employee corresponding to their risk value, the risk value is reduced, and each risk value is multiplied by the weighting value set for each risk value to calculate a total risk value, and this total risk value is divided by the number of risk items (five items) to calculate the risk score of the business operator 200 after countermeasures have been taken.

[0109] When the current score counting process is completed in step S40, the process proceeds to step S60.

[0110] Thereafter, the processes of steps S60, S70, and S80 described above are executed. In step S80, when it is confirmed that measures have been taken for items that have not yet been taken, the display content of the "recommended measures: implementation status" item 760 of the risk score management table 700 is changed to "measures completed."

[0111] By executing the above process, the risk score process generates a risk score management table 700 (risk score management table after measures have been taken) (see Figs. 2A to 2C). When the business entity 200 takes measures, the values ​​of the current leaked account unaddressed status and the number of unaddressed accounts at the business entity 200 displayed in the leaked account unaddressed status 711 decrease, and the number of accounts that have been addressed increases. When the business entity 200 and employees who are deemed to be at high security risk take measures, the risk score values ​​displayed in the business entity risk score 721 and the risk score values ​​displayed in the TOP 10 high-risk users not yet addressed (722) decrease.

[0112] By executing the above-mentioned processing, the risk score processing generates a post-measure risk score management table 700 (see FIGS. 2A to 2C). The generated post-measure risk score management table 700 is provided to the business operator 200 via email, web service, or the like.

[0113] As described above, according to the embodiment of the present disclosure, it is possible to present security risk information including information related to the business entity 200 that exists on the dark web to the business entity 200. In addition, it is possible to present security risk information including information related to SaaS from the CASB 300. In addition, since a countermeasure plan for reducing the security risk score is presented to the business entity 200, it is possible to contribute to strengthening the security risk of the business entity 200.

[0114] Although the embodiments of the present disclosure have been described above, the present disclosure is not limited to the embodiments, and various modifications and changes are possible within the scope of the gist of the present disclosure described in the claims.

[0115] [Variations] In an embodiment of the present disclosure, a function for automatically collecting data leaked on the dark web (a technology for exploiting the dark web, which has strict bot countermeasures) may be provided.

[0116] In addition, in an embodiment of the present disclosure, a function may be provided that automatically formats information leaked onto the dark web into various formats (CSV, JSON, SQL, etc.).

[0117] Also, information on the business entity 200 that exists in the deep web may be searched for, and account information, leaked information, confidential information, etc. related to the business entity 200 may be collected based on the search results. Note that a search in the deep web uses a browser and search engine that are compatible with the deep web.

[0118] In addition, in an embodiment of the present disclosure, an AI that scores comprehensive risks from various security information, or an AI that proposes countermeasures in natural language using a generation AI based on the analysis results, may be used.

[0119] In addition, in the embodiment of the present disclosure, a function for automatically detecting password changes in various SaaS may be provided. As this function, for example, it is possible to determine whether or not a password has been changed based on the access status to the URL corresponding to the password change of each cloud service by monitoring the URL on the browser using CASB300, or to determine whether or not a password has been changed by selecting the SaaS for which the password is to be changed through a SaaS management product and inputting the ID and password of the SaaS.

[0120] In addition, in the embodiment of the present disclosure, a phishing training email distribution service function may be provided as one of the security countermeasures. This function may, for example, be a function for generating new vaccine phishing emails for phishing email training using a model that uses AI to learn data on past phishing emails, or a function for identifying high-risk employees based on attributes such as the age and gender of employees who have fallen for phishing emails and reflecting this in the risk score value of each individual employee.

[0121] In addition, in an embodiment of the present disclosure, a function may be provided in which various latest leak information (e.g., information on attack methods or intentional removal, etc.) present on SNS (social networking services) and news sites is aggregated, and the natural language information is graphed using AI to be visualized on a dashboard such as a risk score management table, or a portal site for information on information leaks specialized for information within Japan is created as an additional service, and threat information (e.g., phishing emails received by the company to which the user belongs) is posted on this site by general Internet users other than service providers, and rewards such as virtual currency are awarded to the users according to the posts.

[0122] The technology of the present disclosure can be embodied in various forms, such as an information processing system, an information processing device, an information processing method, a program, or a recording medium. For example, a program for implementing the software may be provided as a non-transitory recording medium readable by a computer, or may be provided so as to be downloadable from an external server. In addition, the program may be provided by cloud computing, in which an order processing program is started by an external computer (e.g., a cloud server, etc.) and the function of the return assistance processing unit 110 is implemented on a client terminal. [Explanation of symbols]

[0123] 100 Information processing device 110 First information processing section 120 Second Information Processing Section 130 3rd Information Processing Department 140 Risk score processing unit 150 Business attribute storage section 160 Log storage unit 170 Management information storage unit

Claims

1. A first information collection means for collecting first security risk information related to a subject by accessing a dark web that is inaccessible with a normal browser and accessible through encrypted communication using a special browser and searching within the dark web using a search engine corresponding to the dark web; A second information collection means for collecting second security risk information related to the subject from a cybersecurity countermeasure product used by the subject; A third information collection means for collecting third security risk information related to the subject by accessing a surface web using a normal browser and searching within the surface web using a search engine corresponding to the surface web; a risk score calculation means for calculating a security risk score of the subject based on the first security risk information, the second security risk information, and the third security risk information; An information processing device comprising:

2. and a countermeasure proposal presenting means for analyzing the first security risk information, the second security risk information, or the third security risk information, and presenting a countermeasure proposal for reducing the security risk score of the subject based on a result of the analysis. The information processing device according to claim 1 .

3. The first information collecting means is Collecting leaked account information related to a target person as the first security risk information.

3. The information processing device according to claim 1 or 2.

4. The first information collecting means is Collect threat chat information related to the target person as the first security risk information.

3. The information processing device according to claim 1 or 2.

5. The first information collecting means is Collect confidential document information related to the target person as the first security risk information.

3. The information processing device according to claim 1 or 2.

6. The second information collecting means is As the second security risk information, SaaSs usage information related to the subject is collected.

3. The information processing device according to claim 1 or 2.

7. The countermeasure proposal presentation means includes: Visualize the status of countermeasures according to the countermeasure proposals The information processing device according to claim 2 .

8. 1. A computer-implemented information processing method, comprising: a first information collection step of accessing a dark web that is inaccessible with a normal browser and accessible through encrypted communication using a special browser, and searching the dark web using a search engine corresponding to the dark web, thereby collecting first security risk information related to the subject; A second information collection step of collecting second security risk information related to the subject from a cybersecurity countermeasure product used by the subject; a third information collection step of accessing a surface web using a normal browser and searching within the surface web using a search engine compatible with the surface web to collect third security risk information related to the subject; a risk score calculation step of calculating a security risk score of the subject based on the first security risk information, the second security risk information, and the third security risk information; An information processing method comprising the steps of:

9. a first information collection step of accessing a dark web, which is inaccessible with a normal browser but accessible through encrypted communication using a special browser, and searching within the dark web using a search engine corresponding to the dark web, thereby collecting first security risk information related to the subject; A second information collection step of collecting second security risk information related to the subject from a cybersecurity countermeasure product used by the subject; a third information collection step of collecting third security risk information about the subject by accessing a surface web using a normal browser and searching within the surface web using a search engine compatible with the surface web; a risk score calculation step of calculating a security risk score of the subject based on the first security risk information, the second security risk information, and the third security risk information; An information processing program that causes a computer to execute the above.

Citation Information

Patent Citations

  • Program for determining target device information using response of device, apparatus and method, and database construction apparatus

    JP2022162273A

  • Information processing apparatus, information processing method, and program

    JP2023111350A

Cited By

  • Network security monitoring method, device, equipment and medium

    CN121037017A