Information processing system, information processing apparatus, program, and information processing method
The information processing system addresses the inadequacies of conventional phishing prevention by allowing administrators and users to quickly respond to phishing emails through shared information and risk assessment, enhancing fraud prevention and response efficiency.
Patent Information
- Application Number
- JP2023222644
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-12-28
- Publication Date
- 2025-07-10
AI Technical Summary
Conventional systems fail to effectively prevent phishing attacks as they rely solely on sender information checks, which are often deceptive, leading to inadequate fraud prevention and delayed administrator responses.
An information processing system that includes a reception unit for reporting phishing emails, a response unit for generating an information sharing area, and a determination of risk levels, enabling administrators and users to access and share information about phishing emails, facilitating quick and appropriate responses.
Enables rapid and appropriate responses to phishing emails by sharing information and determining risk levels, alerting users, and preventing phishing damage through coordinated user and administrator communication.
Smart Images

Figure 2025104677000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to an information processing system, an information processing apparatus, a program, and an information processing method.
Background Art
[0002] In recent years, cyber security due to phishing (fraud) has become a serious problem. Phishing is an act of disguising an official (legitimate) website and inducing users to a fake website or the like, prompting them to enter personal information (such as email addresses and passwords), and for example, taking over an account or obtaining confidential information. Phishing includes, for example, targeted attacks and SNS phishing.
[0003] As a conventional technique, there is a system that displays a warning when receiving received data suspected of being a targeted attack email. For example, when it is determined that a predetermined condition is not satisfied (for example, when it is determined that the sender information of the received data is the email address of the secretariat), a warning is displayed on the browser of the user terminal (see paragraphs 0034 and 0037 and FIG. 3 of Patent Document 1).
Prior Art Documents
Patent Documents
[0004]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0005] Conventional systems display a warning when receiving received data suspected of being a targeted attack email. However, fraud prevention is often not possible with only checks such as the sender information of the received data. This is because many phishing emails, including targeted attack emails, are crafted cleverly to deceive users.
[0006] In other words, in order to prevent users from falling victim to phishing emails, if the user suspects that the email is a phishing email, it is important for the user to report it to an administrator as soon as possible, for the administrator and the user to share information about the phishing email and resolve the issue without falling victim to a phishing email.
[0007] In addition, it is desirable for administrators to respond quickly and appropriately when they receive a report of a phishing email.
[0008] The present invention has been made in consideration of such problems, and its purpose is to provide an information processing system, etc. that facilitates an administrator's subsequent response to phishing emails and enables the administrator to respond to phishing emails quickly and appropriately. [Means for solving the problem]
[0009] (1) The present invention provides a reception unit that receives report information indicating that a phishing email has been received from a given user belonging to the organization; a response unit that performs a given response process when the report information is received, The corresponding portion is Generate an information sharing area, The administrator and the users belonging to the organization are restricted from accessing the information sharing area. Control, Share information about the phishing email in the information sharing area; The present invention relates to an information processing system that determines the degree of risk of specific information contained in the phishing email.
[0010] The present invention also relates to a program that causes a computer to function as each of the above-mentioned units.The present invention also relates to an information storage medium that stores the program.The present invention also relates to an information processing device that includes each of the above-mentioned units (for example, a server device that includes a storage unit that stores the program and a processor for executing the program).
[0011] In addition, the present invention also includes a step of receiving report information indicating that a phishing email has been received from a given user belonging to an organization; when the report information is received, a step of performing a given corresponding process, and the step of performing the corresponding process includes generating an information sharing area, controlling an administrator and the user belonging to the organization to be able to access the information sharing area, sharing information about the phishing email in the information sharing area, and determining the risk level of specific information included in the phishing email. The present invention relates to an information processing method characterized by the above.
[0012] Here, a "phishing email" is an email that is a fraudulent email for deceiving users. For example, it is a targeted attack email or an SNS phishing email. In addition, a phishing email also includes an email that a user himself / herself determines to be suspected of phishing (fraud).
[0013] In addition, an "information sharing area" is a channel in which users can share information using a communication application such as Slack (registered trademark).
[0014] In addition, "making an administrator and a user able to access" an information sharing area not only means making them able to access the information existing in the information sharing area, but also includes inviting the administrator and the user to the information sharing area. A user invited to the information sharing area can participate (share information) in the information sharing area by performing an acceptance operation of the invitation.
[0015] In addition, the "specific information" included in a phishing email is inquiry information called a URL (Uniform Resource Locator) or a link, an attached file, a phone number, a fixed message requesting a bounce-back reply, a sender address, etc.
[0016] According to the present invention, when receiving report information indicating that a phishing email has been received from a given user belonging to an organization, a given response process is performed, so that the post-response to the phishing email by the administrator can be facilitated.
[0017] In addition, the present invention generates an information sharing area when receiving the report information, controls the administrator and the user who reported the phishing email to be able to access the information sharing area, and shares the information related to the phishing email in the information sharing area. Therefore, the present invention enables the administrator to respond quickly and appropriately to the phishing email. For example, even if a user of an organization encounters a phishing email, the user and the administrator can communicate with each other to calmly respond to fraud.
[0018] In addition, the present invention determines the risk level of specific information included in the phishing email, so that the administrator can respond quickly and appropriately to measures to be taken next, etc., according to the risk level of the phishing email.
[0019] (2) In addition, the information processing system, information processing apparatus, program, and information processing method of the present invention The response unit When indicating that the risk level is high, the user of the organization may be notified of caution information regarding the phishing email.
[0020] Here, the user of the organization may be all users of the organization to which the reporting user belongs, or may be some users such as members of the team to which the user belongs.
[0021] According to the present invention, it is possible to alert the users of the organization to phishing emails.
[0022] (3) In addition, the information processing system, information processing apparatus, program, and information processing method of the present invention The response unit Determine the risk level of the specific information using a plurality of indicators, and when it is shown that the risk level is high in at least one of the plurality of indicators, the attention information may be notified.
[0023] According to the present invention, when it is shown that the risk level is high in at least one of the plurality of indicators, the attention information is notified. Therefore, for a phishing email with even a slightly high risk, it is possible to alert the users of the organization.
[0024] (4) Also, the information processing system, information processing apparatus, program, and information processing method of the present invention The corresponding unit When it is shown that the risk level is high, for each other user of the organization, among the emails received by each user belonging to the organization and stored in a given storage unit, it may be determined whether the specific information exists in the emails received by other users.
[0025] According to the present invention, when it is shown that the risk level is high, for other users, it is also determined whether the specific information exists in the emails already received, so that the security risk can be determined and phishing damage can be prevented.
[0026] (5) Also, the information processing system, information processing apparatus, program, and information processing method of the present invention The storage unit May be a storage area of a server that provides a cloud-based email service, or a storage area that stores and stores emails received by each user belonging to the organization.
[0027] In the storage area of a server that provides a cloud-based email service, or in a storage area that accumulates and stores emails received by each user belonging to the organization, it is determined whether the specific information exists in the emails received by other users among the emails received by each user belonging to the organization and accumulated and stored. Therefore, the present invention can determine whether there is an email in which specific information exists among the emails that have already been received.
[0028] Note that the "cloud-based email service" is, for example, Gmail (registered trademark), etc., and is a service that can save emails on a server on the Internet.
[0029] (6) Further, the information processing system, information processing apparatus, program, and information processing method of the present invention The corresponding part When it indicates that the risk level is high, for each other user of the organization, when the other user receives an email, it may be determined whether the specific information exists in the email.
[0030] According to the present invention, it is possible to quickly alert other users to phishing emails (emails in which specific information exists). That is, according to the present invention, when it indicates that the risk level is high, for other users as well, when receiving an email in the future, it is determined whether the specific information exists in the email, so that the security risk can be determined and phishing damage can be prevented.
[0031] (7) Further, the information processing system, information processing apparatus, program, and information processing method of the present invention The corresponding part When the specific information exists in the email received by another user, attention information regarding the phishing email may be notified to the other user.
[0032] According to the present invention, it is possible to alert other users to phishing emails.
[0033] (8) Further, the information processing system, information processing apparatus, program, and information processing method of the present invention The corresponding unit When the specific information exists in an email received by another user, the other user may be invited to the information sharing area, and the other user may be controlled to be able to access the information sharing area.
[0034] According to the present invention, by sharing information about phishing emails with other users who have received emails containing specific information, it is possible to prevent phishing damage in advance.
[0035] That is, according to the present invention, the other user, the administrator, and the user who reported the phishing email can communicate with each other and calmly respond to fraud.
[0036] (9) Further, the information processing system, information processing apparatus, program, and information processing method of the present invention The corresponding unit When the specific information exists in an email received by another user, information indicating that the specific information exists in the email received by the other user may be shared in the information sharing area.
[0037] According to the present invention, the administrator and the user who reported the phishing email can know the reception status of phishing emails by other users, and can quickly and calmly respond to fraud becomes possible.
[0038] (10) Further, the information processing system, information processing apparatus, program, and information processing method of the present invention The corresponding unit Corresponding processing according to the type of the phishing email may be performed.
[0039] According to the present invention, for example, appropriate countermeasures can be taken according to the type of phishing email.
Brief Description of the Drawings
[0040]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Modes for Carrying Out the Invention
[0041] Hereinafter, this embodiment will be described. Note that the embodiment described below does not unduly limit the content of the present invention described in the claims. Also, not all of the configurations described in this embodiment are essential constituent elements of the present invention.
[0042] [1] Network FIG. 1 shows an example of a network diagram of an information processing system. The information processing system of this embodiment includes a server device 10 and a terminal device 20.
[0043] In the information processing system of this embodiment, the server device 10 and the user's terminal device 20 are connected via a network (such as the Internet or an intranet). Hereinafter, the terminal device 20 represents any one of the terminal devices 20A, 20B, and 20C.
[0044] The server device 10 is an information processing device capable of providing a given service to a terminal device 20 communicatively connected via the Internet.
[0045] The server device 10 provides information regarding phishing emails to the user's terminal device 20. In this embodiment, the server device 10 may be alternatively referred to as a phishing email handling device.
[0046] For example, when a user A (hereinafter also referred to as administrator A), who is an administrator of an organization (e.g., a company), or a user B, who is an employee of the organization reporting phishing emails, is managed to be able to access an information sharing area generated by the server device 10, the terminal device 20A of the administrator A and the terminal device 20B of the user B can access the information sharing area generated by the server device 10. By accessing the information sharing area, the administrator A and the user B can view information regarding phishing emails.
[0047] The terminal device 20 is a client device, which is an information processing device such as a smartphone, a mobile phone, a PHS, a computer, a game device, a PDA, an image generation device, etc., and is a device connectable to the server device 10 via a network such as the Internet (WAN) or a LAN.
[0048] [2] Configuration FIG. 2 is an example of a functional block diagram of the server device 10 and the terminal device 20 of this embodiment. The server device 10 and the terminal device 20 of this embodiment do not necessarily have to include all parts shown in FIG. 2, and may be configured with some parts omitted.
[0049] (1) Functional Configuration of Server Device 10 The storage unit 170 serves as a work area for the processing unit 100 and the like, and the storage unit 170 can store a program (a program for causing a computer to execute the processing of each part) for causing a computer to function as each part of this embodiment.
[0050] The storage unit 170 stores programs, data, etc. for causing the computer of the present embodiment to perform processing. Its functions can be realized by an information storage medium readable by a computer, such as a RAM (VRAM), an optical disk (CD, DVD), a magneto-optical disk (MO), a magnetic disk, a hard disk, a magnetic tape, or a memory (ROM).
[0051] In the storage unit 170 of the present embodiment, a main storage unit 171, a user information storage unit 172, and an e-mail storage unit 173 are stored.
[0052] The main storage unit 171 is used as a work area. User information is stored in the user information storage unit 172. Information on e-mails sent and received by the user is stored in the e-mail storage unit 173.
[0053] In the present embodiment, in the e-mail storage unit 173, e-mails received by the user are accumulated and stored for each user belonging to the organization.
[0054] The information storage medium 180 (a medium readable by a computer) stores programs, data, etc. Its functions can be realized by an optical disk (CD, DVD), a magneto-optical disk (MO), a magnetic disk, a hard disk, a magnetic tape, or a memory (ROM), etc.
[0055] The processing unit 100 performs various processes of the present embodiment based on the programs (data) stored in the information storage medium 180. That is, in the information storage medium 180, programs for causing the computer to function as each part of the present embodiment (programs for causing the computer to execute the processes of each part) are stored.
[0056] The communication unit 196 performs various controls for communication with the outside (for example, the terminal device 20, other server devices, or other network systems). Its functions can be realized by hardware such as various processors or communication ASICs, or programs.
[0057] The processing unit 100 performs various processes of the present embodiment based on programs (data) stored in the storage unit 170 or the information storage medium 180.
[0058] The processing unit 100 (processor) performs various processes using the main storage unit 171 in the storage unit 170 as a work area. The functions of the processing unit 100 can be realized by hardware such as various processors (CPU, DSP, etc.) and programs.
[0059] The processing unit 100 includes at least a communication control unit 110, a reception unit 111, a response unit 112, and a mail gateway unit 113.
[0060] The communication control unit 110 transmits and receives data to and from the terminal device 20, other server devices, etc. For example, the communication control unit 110 receives (accepts) information transmitted from the user's terminal device 20. Also, the communication control unit 110 transmits information (for example, information regarding phishing emails) to the user's terminal device 20.
[0061] The reception unit 111 receives report information indicating that a phishing email has been received from a given user belonging to an organization. An "organization" is a group such as a company, enterprise, school, committee, union, etc. The report information may include the user information of the reporter (the reporter's account and email address), the content of the report (when and from whom the phishing email was received), and the phishing email itself.
[0062] When the response unit 112 receives the report information, it performs given response processing. Details will be described later. When the mail gateway unit 113 receives an email, it performs given processing regarding the email. Details will be described later.
[0063] (2) Functional configuration of the terminal device The storage unit 270 serves as a work area for the processing unit 200 and the like. The storage unit 270 can store a program (a program for causing a computer to execute the processing of each part) for causing a computer to function as each part of the present embodiment.
[0064] The storage unit 270 stores programs, data, etc. for performing the processing of the present embodiment of the computer, and its function can be realized by an information storage medium readable by a computer, such as a RAM (VRAM), an optical disk (CD, DVD), a magneto-optical disk (MO), a magnetic disk, a hard disk, a magnetic tape, or a memory (ROM).
[0065] In the storage unit 270 of the present embodiment, a main storage unit 271 is stored. The main storage unit 271 is used as a work area.
[0066] The information storage medium 280 (a medium readable by a computer) stores programs, data, etc., and its function can be realized by an optical disk (CD, DVD), a magneto-optical disk (MO), a magnetic disk, a hard disk, a magnetic tape, or a memory (ROM).
[0067] The processing unit 200 performs various processes of the present embodiment based on the programs (data) stored in the information storage medium 280. That is, the information storage medium 280 stores a program (a program for causing a computer to execute the processing of each part) for causing a computer to function as each part of the present embodiment.
[0068] The display unit 290 outputs information according to the present embodiment, and its function can be realized by a monitor, a CRT, an LCD, a touch panel type display, or an HMD (head-mounted display).
[0069] The communication unit 296 performs various controls for communication with the outside (for example, the terminal device 20, other server devices, and other network systems), and its functions can be realized by hardware such as various processors or communication ASICs, or programs.
[0070] The processing unit 200 performs various processes of the present embodiment based on programs (data) stored in the storage unit 270 or the information storage medium 280.
[0071] The processing unit 200 (processor) uses the main storage unit 271 in the storage unit 270 as a work area to perform various processes. The functions of the processing unit 200 can be realized by hardware such as various processors (CPU, DSP, etc.) or programs.
[0072] The processing unit 200 includes at least a communication control unit 210 and a display control unit 211.
[0073] The communication control unit 210 transmits and receives data with the terminal device 20, other server devices, etc. For example, the communication control unit 210 receives (accepts) information transmitted from the server device 10 or other users' terminal devices 20.
[0074] For example, the communication control unit 210 transmits report information indicating that a phishing email has been received to the server device 10. Also, the communication control unit 110 receives information regarding the phishing email transmitted from the server device 10.
[0075] The display control unit 211 controls the display unit 290 (for example, a monitor) to display given information. For example, the display control unit 211 controls the display of information in an accessible information sharing area.
[0076] Note that the display control unit 211 may display information via a communication application such as Slack (registered trademark).
[0077] [3] Explanation of Phishing Emails First, phishing emails will be explained. A phishing email is a fraudulent email that deceives users. Examples of phishing emails include targeted attack emails, SNS phishing emails, fake advertisement emails, and romance scam emails, etc.
[0078] Targeted attack emails are also called spear phishing. A targeted attack is a type of cyber attack aimed at people related to an organization (company or school). The fraud method of a targeted attack is to use an email created by pretending to be a person related to the organization or individual to deceive the targeted organization or individual.
[0079] For example, if a user accesses the URL described in a targeted attack email and opens the attached file in the targeted attack email, the user's terminal device may be infected with a computer virus, taken over, or the information associated with the user may be stolen, etc., resulting in damages.
[0080] The administrator of the organization needs to consider countermeasures for users who have suffered from targeted attack emails, such as responding to requests for ransoms for confidential information, preventing being exploited for various network frauds, and preventing other users from being targeted by targeted attack emails.
[0081] There is also a type of targeted attack called whaling that targets the management layer of a company or people with high social status.
[0082] Since targeted attack emails are created by specifically targeting the targeted users or organizations, they are often more skillfully disguised than indiscriminate attack emails. Therefore, administrators need to pay special attention to countermeasures against targeted attack emails.
[0083] SNS phishing emails refer to emails or messages that pretend to be SNS (Social Network Service).
[0084] That is, the attacker (scammer) sends emails or messages that seem to be notifications or warnings from the SNS. Send phishing emails to users and attempt to steal personal information such as login information. Usually, the attacker makes the user click on the link in the message to be redirected to a fake login page to steal information.
[0085] The attacker's purpose is to illegally obtain the user's account information and use it for unauthorized access and other fraudulent acts (such as account hijacking and spreading phishing messages).
[0086] Targeted phishing emails are more sophisticated and are specialized for attacks targeting specific individuals or organizations, while SNS phishing emails differ in that they use common methods to deceive personal information from a wider range of targets.
[0087] Fake advertising emails are emails that promote fake products or services, and romance scam emails are emails that pretend to be in a romantic relationship to deceive personal information or money, etc.
[0088] Note that there are phishing emails that contain malicious software called malware. Malware includes computer viruses, Trojan horses (software that disguises itself as legitimate software to infiltrate the user's system), and spyware (software that steals and monitors the user's information).
[0089] [4] Explanation of countermeasures against phishing emails In this embodiment, an information processing system that takes countermeasures (post - phishing email response) when receiving report information regarding phishing emails is adopted. According to this embodiment, administrators can respond quickly and appropriately to phishing emails.
[0090] Fig. 3 shows an overview diagram of the information processing system of this embodiment. As shown in Fig. 3, a case where user B, an employee of a company (an example of an organization), receives a phishing email from an attacker and reports it to administrator A (the administrator) will be described as an example.
[0091] [4.1] Receiving report information First, when user B notices that the received email M is a phishing email, user B reports it to the server device 10. For example, user B does not necessarily have to determine that it is a phishing email. That is, phishing emails include emails with suspicion of phishing and emails that may be phishing.
[0092] In the present embodiment, the server device 10 receives report information indicating that user B has received a phishing email M. For example, the server device 10 receives report information indicating that user B has received a phishing email. Note that the server device 10 may notify the terminal device 20A of administrator A of the report information indicating that user B has received a phishing email.
[0093] The "report information" includes at least the subject, the sender (From), and the sender's email address.
[0094] For example, the report information may receive the phishing email itself. For example, an email with the phishing email M received by user B as an attached file may be sent to the terminal device 20A of administrator A or the server device 10.
[0095] Also, on the terminal device 20 of each user belonging to the organization, an extension function (add-on) for reporting phishing emails may be installed in an email function such as Gmail (registered trademark) in advance so that reporting can be easily done. In this way, the user can report by simply clicking the report button of the extension function on the display screen of the phishing email M.
[0096] [4.2] Response processing When the response unit 112 of the server device 10 in the present embodiment receives the report information, the response unit 112 performs a given response process. The "response process" may be paraphrased as the words "task" or "action".
[0097] An example of the response processing of the server device 10 according to this embodiment will be described. First, the response unit 112 of the server device 10 generates (1) an information sharing area (for example, the channel name "Alert1").
[0098] (2) The response unit 112 of the server device 10 controls the administrator A and the user B to be able to access the generated information sharing area (for example, the channel name "Alert1"). Controlling to be able to access also includes inviting the administrator A and the user B to the information sharing area (for example, the channel name "Alert1").
[0099] (3) The response unit 112 of the server device 10 shares information about phishing emails in the information sharing area.
[0100] (4) The response unit 112 of the server device 10 determines the risk level of specific information (for example, URLs and attached files) included in phishing emails.
[0101] (5) When it indicates a high risk level, the response unit 112 of the server device 10 notifies users belonging to the organization of caution information regarding phishing emails.
[0102] In this embodiment, since the server device 10 automatically performs a plurality of response processes shown in (1) to (5), the administrator A can easily and promptly perform post-response to phishing emails appropriately.
[0103] Note that it is not necessary to perform all of (1) to (5) for the response process, and at least one response process among (1) to (5) (for example, only the process of generating an information sharing area in (1)) may be performed.
[0104] [5] Explanation of the information sharing area The response unit 112 of the server device 10 according to this embodiment creates (generates) an information sharing area. The "information sharing area" is a "channel" of a communication application such as Slack (registered trademark).
[0105] For example, when the corresponding part 112 of the server device 10 receives reporting information from user B, it issues identification information of a phishing email (for example, ID = 001) and generates an identifiable channel. For example, a channel with the channel name "Alert1" is generated in association with the identification information of the phishing email (for example, ID = 001).
[0106] The communication application is called "collaboration tool", "team collaboration tool", "communication tool" or "chat-based workspace", etc. For example, the information processing system not only supports real-time communication between users, but also provides functions such as file sharing, task management, meeting scheduling, notifications and reminders, and integration with other third-party applications. As a result, users can perform operations in a unified manner and share and manage information.
[0107] In this embodiment, the corresponding part 112 of the server device 10 generates a channel using the API of Slack (registered trademark) (API is the abbreviation of Application Programming Interface). Then, the corresponding part 112 of the server device 10 can receive information from a user (for example, administrator A or user B) and post it to the channel.
[0108] For example, when a user uses the terminal device 20 to send (post) information, the information is sent to the server device 10. The corresponding part 112 of the server device 10 manages and stores the information. Then, the corresponding part 112 of the server device 10 posts the information to the channel via the Slack (registered trademark) API.
[0109] The corresponding part 112 of the server device 10 may store the information in a searchable form and control so that past posts can be searched according to a user's instruction.
[0110] In addition, the corresponding unit 112 of the server device 10 can also edit or delete information as necessary based on the user's instructions.
[0111] The terminal device 20 is a device on which a communication app is installed. The communication app may be a dedicated app or a web browser capable of operating a web application.
[0112] The display control unit 211 of the terminal device 20 transmits information to the corresponding unit 112 of the server device 10 based on the user's operation input and displays the information received from the corresponding unit 112 of the server device 10. That is, when the user inputs and transmits information, the information is transmitted from the terminal device 20 to the server device 10 and sent to the designated channel.
[0113] Note that the information sharing area (channel) is a virtual space for organizing conversations by theme or purpose. Members of a group (team) can use the channel to send messages to each other, share files, and discuss specific topics. Note that the channel may be paraphrased as a "conversation room", "group", "forum", "thread", or "topic".
[0114] The display control unit 211 of the terminal device 20 displays information such as information, files, and notifications from other users sent from the corresponding unit 112 of the server device 10. These information are updated in real time, and the user can keep the information in the latest state.
[0115] Furthermore, the display control unit 211 of the terminal device 20 can also perform operations such as searching for past information by the user, editing or deleting information. Also, the display control unit 211 of the terminal device 20 can customize the user's environment, such as creating a new channel, based on the user's instructions.
[0116] [6] Explanation of determination of risk level of specific information The correspondence unit 112 of the server device 10 will be described in detail regarding the determination of the risk level of the specific information included in the phishing email M.
[0117] "Specific information" is, for example, the query information included in the phishing email M and / or the attached file. Note that "specific information" may be a phone number, a fixed message requesting a folded reply, a sender address, etc.
[0118] Here, the "query information" is, for example, a URL (Uniform Resource Locator) for uniquely specifying a web page on the Internet using a protocol such as HTTP (Hyper Text Transfer r Protocol) or HTTPS (Hyper Text Transfer Protocol Secure). Note that the "query information" may be information about a server capable of transmitting and receiving data using other communication protocols such as FTP (File Transfer Protocol).
[0119] [6.1] Determination of the risk level of query information The correspondence unit 112 of the server device 10 determines whether the phishing email M contains query information. And when the phishing email M contains query information, the query information is extracted.
[0120] For example, by determining whether there is a predetermined character string (for example, http, https, ftp, etc.) in the phishing email M, it is determined whether the phishing email M contains query information.
[0121] And in this embodiment, for example, when the phishing email M contains query information (URL) such as "https: / / XXX··· / test.html", the risk level (security threat) of the query information is calculated using a cyber security tool. The cyber security tool determines the risk level of the specific information based on a plurality of indicators (vendors).
[0122] Then, the corresponding part 112 of the server device 10 determines the risk level of the specific information (for example, the query information) using a plurality of indicators, and notifies the organization's users of caution information when it indicates that the risk level is high in at least one of the plurality of indicators.
[0123] FIG. 4 shows an example of the results of a cyber security tool. For example, regarding the query information of the phishing email M, the result of security vendor SA is "Phishing", indicating that there is a suspicion of phishing and the risk level is high. Also, regarding the query information of the phishing email M, the result of security vendor SB is "Clean", indicating that there is no suspicion of phishing and the risk level is low.
[0124] As described above, in this embodiment, since the risk level of the specific information is determined based on the results of a plurality of security vendors (indicators), an objective and appropriate risk level determination can be made.
[0125] Then, in this embodiment, the number of security vendors that gave a result of "Phishing" for the query information of the phishing email M is counted. In the example of FIG. 4, since security vendors SA and SC have a result of "Phishing", it indicates that the risk level is high in two security vendors (indicators). Note that when there is a plurality of query information in the phishing email M, for each query information, the number of security vendors that gave a result of "Phishing" is counted. Also, for the phishing email M, the total number of the number of security vendors that gave a result of "Phishing" for each query information may be calculated.
[0126] (Determination by Cyber Security Tool for Shortened URL) In the case of a URL that has been shortened (hereinafter referred to as a shortened URL), the shortened URL may be restored to the original normal URL (hereinafter referred to as the normal URL) before performing the determination by the cyber security tool.
[0127] When the URL included in the phishing email M is a shortened URL, the corresponding unit 112 of the server device 10 may perform determination by a cyber security tool for both the shortened URL and the normal URL restored from the shortened URL. If the determination results by the cyber security tool are different, the one with the higher risk level may be prioritized. If the result of the determination by the cyber security tool is "Phishing", indicating a suspicion of phishing and a high risk level, the corresponding unit 112 of the server device 10 may determine that the risk level of the shortened URL is higher than that of the normal URL.
[0128] The corresponding unit 112 of the server device 10 may determine that the risk level of the shortened URL is higher than that of the normal URL when the result of the determination by the cyber security tool after restoring the shortened URL to the normal URL is "Phishing", indicating a suspicion of phishing and a high risk level.
[0129] Whether the URL is a shortened URL is determined as follows. That is, the corresponding unit 112 of the server device 10 enumerates in advance the domains of the providers that provide the shortened URL service and stores them in the storage unit 170, and may determine whether the URL is a shortened URL by determining whether the URL is a URL of the stored domain. That is, when the domain of the URL included in the phishing email M is the domain stored in advance in the storage unit 170, the corresponding unit 112 of the server device 10 determines that it is a shortened URL. On the other hand, when the domain of the URL included in the phishing email M is not the domain stored in advance in the storage unit 170, the corresponding unit 112 of the server device 10 determines that it is not a shortened URL.
[0130] In addition, when the corresponding part 112 of the server device 10 acquires data actually referred to by the shortened URL and it is an instruction (redirect instruction) to cause the acquired data to acquire data referred to by another query information, it may be determined that it is a shortened URL. That is, the corresponding part 112 of the server device 10 determines that it is a shortened URL when the data acquired by referring to the URL included in the phishing email M is an instruction (redirect instruction) to cause the data referred to by another query information to be acquired. On the other hand, the corresponding part 112 of the server device 10 determines that it is not a shortened URL when the data acquired by referring to the URL included in the phishing email M is not an instruction (redirect instruction) to cause the data referred to by another query information to be acquired.
[0131] [6.2] Determination of the risk level of attached files The process in the case where the specific information is an attached file will be described. First, the corresponding part 112 of the server device 10 determines whether an attached file is included in the phishing email M. Then, when an attached file is included in the phishing email M, the attached file is extracted.
[0132] For example, the MIME part of the phishing email M is detected, and the presence or absence of an attached file is confirmed by whether it is a multipart section, whether it is set as an attachment in the Content-Disposition header of the part, and the like.
[0133] In this embodiment, when an attached file is included, the risk level (security threat) of the attached file is calculated using a cyber security tool.
[0134] Although not shown, for example, regarding the attached file of the phishing email M, the result of the security vendor SA is "Clean", indicating that there is no suspicion of phishing and the risk is low. Also, regarding the attached file of the phishing email M, the result of the security vendor SB is "Phishing", indicating that there is suspicion of phishing and the risk is high.
[0135] And in this embodiment, for the attached file of the phishing email M, the number of security vendors that produced a "Phishing" result is counted. Note that when there are multiple attached files in the phishing email M, for each attached file, the number of security vendors that produced a "Phishing" result is counted. Also, for the phishing em ail M, the total number of the number of security vendors that produced a "Phishing" result for each attached file may be calculated.
[0136] [7] Notification of Attention Information In this embodiment, when it is shown that the risk is high in at least one of a plurality of security vendors (indicators) for specific information (for example, specific information included in the phishing email M with ID = 001), attention information is notified to the users belonging to the organization. Note that when there are multiple pieces of specific information (query information and attached files), the corresponding unit 112 of the server device 10 notifies the users belonging to the organization of attention information when it is shown that the risk is high in at least one of a plurality of security vendors (indicators) for at least one piece of specific information.
[0137] For example, in the query information included in the phishing email M, in the example of FIG. 4, it is shown that the risk is high in two security vendors. Therefore, attention information (attention information indicating that the query information is dangerous) is notified to the users belonging to the organization.
[0138] Note that the users (users belonging to an organization) to whom the attention target is to be notified are some or all of the users of the organization to which User B belongs. The users (users belonging to an organization) to whom the attention target is to be notified may include, for example, not only Administrator A and User B, but also other users (such as User C, etc.) belonging to the same organization as User B, and all users belonging to the organization.
[0139] The same applies to the attached files included in the phishing email M. For example, when it is shown that the risk level is high in at least one of a plurality of security vendors (indicators) for the attached file, attention information is notified to the users belonging to the organization.
[0140] [8] Other examples of response processing As the response processing in this embodiment, the following processing may be performed.
[0141] [8.1] Checking of emails received by other users For example, when it is shown that the risk level of the specific information included in the phishing email M with ID = 001 is high, the response unit 112 of the server device 10 may determine whether the specific information of the phishing email with ID = 001 exists in the emails received by other users (such as User C belonging to the same organization as User B).
[0142] Also, when the specific information of the phishing email with ID = 001 exists in the emails received by the other users, the response unit 112 of the server device 10 may notify the other users (such as User C) of the attention information regarding the phishing email.
[0143] Also, when the specific information of the phishing email with ID = 001 exists in the emails received by the other users, the response unit 112 of the server device 10 may invite the other users to the information sharing area and control the other users to be able to access the information sharing area.
[0144] In addition, when the specific information of the phishing email with ID=001 exists in the email received by the other user, the corresponding part 112 of the server device 10 may share information indicating the existence of the specific information in the email received by the other user in the information sharing area.
[0145] Note that the other user is not limited to a single user (for example, user C) belonging to the same organization as user B. There may be multiple other users. For example, the other users may be some or all users other than user B who belong to the same organization as user B.
[0146] In this embodiment, the point in time when it is shown that the risk level of the specific information included in the phishing email M with ID=001 is high is set as the point in time when it is determined that there is suspicion of the phishing email. Then, based on this point in time, the corresponding part 112 of the server device 10 takes corresponding actions for future received emails regarding phishing emails and / or for the emails stored in the storage area.
[0147] [8.1.1] Corresponding actions for future received emails regarding phishing emails When it is shown that the risk level of the specific information included in a phishing email (for example, the phishing email with ID=001) is high, the corresponding part 112 of the server device 10 may determine for each other user in the organization whether the specific information exists in the email when the other user receives the email.
[0148] For example, in this embodiment, based on the point in time when it is determined that there is suspicion of the phishing email, corresponding actions for future received emails regarding phishing emails are taken when it is shown that the risk level of the specific information included in the phishing email M with ID=001 is high. Specifically, the following corresponding actions are taken.
[0149] For example, in the present embodiment, in the mail gateway unit 113 which is one function of the server device 10, it is determined whether specific information exists when an electronic mail is received. The mail gateway unit 113 of the server device 10 is, for example, for management of sending and receiving of electronic mails on the Internet, mail routing, traffic management, security processing, etc. The mail gateway unit may be referred to as a "security management unit", a "traffic management unit", or a "mail routing unit". Also, the mail gateway unit may be a server device separate from the server device 10.
[0150] When the mail gateway unit 113 of the server device 10 receives an electronic mail received by another user (for example, user C belonging to the same organization as user B), it may determine whether specific information of a phishing mail with ID = 001 exists.
[0151] For example, the corresponding unit 112 transmits specific information (for example, specific information included in the phishing mail M with ID = 001) to the mail gateway unit 113. Then, when the mail gateway unit 113 detects an electronic mail M' that matches the specific information received from the corresponding unit 112, it issues identification information of a phishing mail (for example, ID = 002) to the electronic mail M', and transmits the specific information and information of the electronic mail to the corresponding unit 112.
[0152] Then, based on the specific information and information of the electronic mail M' included in the electronic mail M' received from the mail gateway unit 113, the corresponding unit 112 sets the user who received the electronic mail M' (the user to whom the electronic mail is addressed) as the other user. The corresponding unit 112 may invite the other user to an information sharing area corresponding to the specific information. Also, the corresponding unit 112 may control access to the information sharing area for the other user.
[0153] In addition, the specific information transmitted from the corresponding unit 112 to the mail gateway unit 113 may include a unique ID (for example, ID = 002) and the date and time when the specific information is determined to be suspected of being a phishing email, etc.
[0154] Also, at least one of the corresponding unit 112 and the mail gateway unit 113 holds the unique "ID" that was last transmitted or received, or the "date and time" when the specific information is determined to be suspected of being a phishing email. It is retained.
[0155] Also, at least one of the corresponding unit 112 and the mail gateway unit 113 may transmit and receive the "specific information" after the "date and time" when the "ID" or the specific information is determined to be suspected of being a phishing email, between the corresponding unit 112 and the mail gateway unit 113.
[0156] In the corresponding unit 112 and the mail gateway unit 113, if there is a difference in the unique "ID" that was last transmitted or received or the "date and time" when the specific information is determined to be suspected of being a phishing email, between the corresponding unit 112 and the mail gateway unit 113, then, among the corresponding unit 112 and the mail gateway unit 113, the "specific information" after the "date and time" when the unique "ID" or the specific information of either one (for example, the mail gateway unit 113) is determined to be suspected of being a phishing email may be transmitted and received between the corresponding unit 112 and the mail gateway unit 113 to achieve synchronization.
[0157] Further, after the transmission of the specific information (for example, the specific information included in the phishing email M with ID = 001) to the mail gateway unit 113 is completed normally, for each email received by each user belonging to the organization stored in the storage area of the server that provides a cloud-based email service (such as Gmail (registered trademark)), the API provided by the email service may be used to determine whether the specific information exists in the emails of other users in the organization. By performing the processing in such an order, it is possible to appropriately handle phishing emails containing the specific information received by other users even before the specific information (for example, the specific information included in the phishing email M with ID = 001) is transmitted to the mail gateway unit 113.
[0158] Also, there may be a case where it is determined that the specific information is included in both the corresponding unit 112 and the mail gateway unit 113 for the same email M'. In such a case, the determination result of the later-determined party may be skipped (invalidated).
[0159] Further, when the transmission of the specific information (for example, the specific information included in the phishing email M with ID = 001) to the mail gateway unit 113 fails, the corresponding unit 112 may notify the administrator of the specific information that has failed to be transmitted (for example, send an email addressed to the administrator).
[0160] Also, when the transmission of the specific information (for example, the specific information included in the phishing email M with ID = 001) to the mail gateway unit 113 fails, the corresponding unit 112 may retry (re-send) the transmission of the specific information to the mail gateway unit 113 at a predetermined interval (for example, every minute).
[0161] If the correspondence unit 112 has successfully transmitted the specific information (e.g., the specific information included in the phishing email M with ID = 001) to the mail gateway unit 113, the mail gateway unit 113 can determine that the email M' including the specific information is suspected of being a phishing email.
[0162] However, it is possible that the correspondence unit 112 fails to transmit the specific information (e.g., the specific information included in the phishing email M with ID = 001) to the mail gateway unit 113.
[0163] Therefore, when the retry of transmitting the specific information to the mail gateway unit 113 that has failed is successful, the correspondence unit 112 checks the emails received by the users stored in the storage area of the server that provides a cloud-based email service (such as Gmail (registered trademark), etc.) to determine whether the specific information exists in the emails of other users in the organization by using the API provided by the email service. In this way, even for emails that were not determined to be suspected of being phishing emails because the correspondence unit 112 failed to transmit the specific information to the mail gateway unit 113, it is possible to efficiently determine at an appropriate timing that they are suspected of being phishing emails.
[0164] [8.1.2] Correspondence regarding the emails stored in the storage area When the correspondence unit 112 of the server device 10 indicates that the risk level of the specific information included in a phishing email (e.g., the phishing email M with ID = 001) is high, for each other user in the organization, it determines whether the specific information exists in the emails received by each user belonging to the organization and stored in a given storage unit.
[0165] The memory unit is a storage area of a server that provides a cloud-based email service (such as Gmail (registered trademark), etc.), or a storage area (such as the email storage unit 173) that stores and remembers the emails received by each user belonging to the organization.
[0166] For example, when query information (such as the URL "https: / / XXX··· / test.html") of the phishing email M received by user B exists in the email received by user C stored in the storage area of a server that provides a cloud-based email service (such as Gmail (registered trademark), etc.), the corresponding unit 112 of the server device 10 may notify user C of the caution information regarding the phishing email.
[0167] Also, for example, when query information (such as the URL "https: / / XXX··· / test.html") of the phishing email M received by user B exists in the email received by user C stored in the email storage unit 173, the corresponding unit 112 of the server device 10 may notify user C of the caution information regarding the phishing email.
[0168] Note that the corresponding unit 112 of the server device 10 determines whether specific information of the phishing email with ID = 001 exists in the received emails for each user belonging to the organization, not limited to user C. When the specific information exists in the email, the corresponding unit 112 may notify the other user of the caution information regarding the phishing email.
[0169] Also, the corresponding unit 112 of the server device 10 may make a determination with a time limit. For example, the corresponding unit 112 of the server device 10 may determine whether specific information of the phishing email with ID = 001 exists in the emails received by other users during a period (for example, one week before and after the time when user B received the phishing email M with ID = 001).
[0170] [8.2] Control to make other users accessible to the information sharing area When the corresponding part 112 of the server device 10 indicates that the risk level of the specific information included in the phishing email M with ID = 001 is high, and when the specific information of the phishing email with ID = 001 exists in the email received by another user (for example, user C), the other user may be controlled to be accessible to the information sharing area (for example, the channel name "Alert1"). That is, the other user (for example, user C) may be invited to the information sharing area (channel name "Alert1") and controlled to be accessible.
[0171] [8.3] Information sharing in the information sharing area When the corresponding part 112 of the server device 10 indicates that the risk level of the specific information included in the phishing email M with ID = 001 is high, and when the specific information of the phishing email with ID = 001 exists in the email received by another user (for example, user C), information indicating that the specific information of the phishing email with ID = 001 exists in the email received by the other user may be shared in the information sharing area.
[0172] [9] Multiple cyber security tools In this embodiment, one cyber security tool may be used, but multiple cyber security tools may be used to determine the risk level of the specific information. For example, when it is indicated that the risk level is high in at least one of the multiple cyber security tools, attention information may be notified.
[0173]
[10] Timing for performing corresponding processing The corresponding part 112 of the server device 10 may perform corresponding processing at the timing when the report information is received. Also, when the corresponding part 112 of the server device 10 receives a corresponding instruction from the administrator A after receiving the report information from the reporting user B, a given corresponding operation may be performed at the timing when the corresponding instruction is received.
[0174]
[11] Example of Information Sharing Area The corresponding part 112 of the server device 10 manages information sharing areas by organizational unit. Then, when the display control unit 211 of the user's terminal device 20 clicks (indicates) an accessible information sharing area (channel) on the organization's display screen, the information of that information sharing area can be browsed, posted, etc.
[0175] FIG. 5 shows an example of a group of accessible channels 52 of an organization displayed on the display unit 290 by the display control unit 211 of the terminal device 20 of administrator A. When administrator A clicks on the channel name "Alert1" among the channel group 52, information 54 and 55 regarding the channel name "Alert1" can be browsed in the display column 53 of the channel name "Alert1".
[0176] Also, a user (e.g., user B) invited to the channel name "Alert1" can, in the same way as administrator A, browse information 54 and 55 regarding the channel name "Alert1" in the display column 53 when clicking on the channel name "Alert1".
[0177]
[12] Response Processing According to the Type of Phishing Email Also, the corresponding part 112 of the server device 10 may perform response processing according to the type of phishing email.
[0178] FIG. 6 shows a schematic diagram of response processing according to the type of phishing email. For example, when the type of phishing email is a targeted attack email, (1) generation of an information sharing area, (2) invitation, (3) sharing of information regarding the phishing email, (4) determination of the risk level of specific information included in the phishing email, and (5) notification of caution information are performed.
[0179] In the case of an SNS phishing email, in addition to the above (1) to (5), a process of notifying the reporting user to recommend changing the SNS password is performed.
[0180] In this way, in the present embodiment, it is possible to take appropriate measures according to the type of phishing email.
[0181] Note that there may be multiple response processes for targeted attack emails as well. For example, different response processes may be performed when an employee user receives a targeted attack email and when a manager receives a targeted attack email (i.e., when the manager receives a whaling email). For example, when receiving a whaling email, at least one of the response processes such as changing to a strengthened password, two-factor authentication, and stricter access rights may be additionally performed.
[0182] In the present embodiment, based on the input from the administrator, response processing may be determined based on the type of phishing email.
[0183] Also, in the present embodiment, based on the input from the administrator, response processing may be determined based on the attributes of the reporting user (the user who sent the report information). The attribute is the position (job title, role, function) of the user.
[0184] Also, in the present embodiment, based on the input from the administrator, response processing may be determined based on the type of phishing email and the attributes of the reporting user.
[0185]
[13] Flowchart The processing flow of the server device 10 of the present embodiment will be described. As shown in FIG. 7, first, report information indicating that a phishing email has been received is received from the user (step S1). Then, a given response process is performed (step S2). The processing ends here.
[0186] The given response process is, for example, generating an information sharing area, controlling the administrator and the user (the user who reported receiving the phishing email) to be able to access the information sharing area, sharing information about the phishing email in the information sharing area, and determining the risk level of the specific information included in the phishing email.
[0187]
[14] Regarding notifications The server device 10 will be described in detail regarding "notifying" a given piece of information to a user (the user's terminal device 20). "Notification" means presenting information to the user, or in other words, "presentation" or "display".
[0188] Also, when the server device 10 of the present embodiment notifies the user, it means notifying the user's terminal device 20.
[0189] Also, it may be presented via the communication tool provided by the server device 10. When the server device 10 of the present embodiment notifies the user, it is assumed to include such presentation via the communication tool. Examples of the communication tool provided by the communication server include LINE (registered trademark), Slack (registered trademark), Microsoft Teams (registered trademark), etc.
[0190] Also, the server device 10 is connected to the communication server and notifies a message to the terminal device 20 that has installed the application provided by the communication server.
[0191] Note that when the server device 10 notifies the user, it includes notifications and displays via email or web services.
[0192]
[15] Application examples [15.1] Display of risk results When the corresponding unit 112 of the server device 10 determines the risk level of the specific information included in the phishing email M it may post the risk level of the specific information in the information sharing area (for example, the channel "Alert1") associated with the identification information (ID = 001) of the phishing email M, and share the risk level of the specific information among relevant parties (administrator A, user B, etc.).
[0193] [15.2] Risk level In this embodiment, when the result of the security vendor for the specific information included in the phishing email is "Phishing", it is determined that the risk level of the specific information included in the phishing email is high, but it is not limited to this. For example, in this embodiment, when the number of security vendors that have determined "Phishing" for the specific information included in the phishing email is equal to or greater than a predetermined value (for example, 1 or more), it may be determined that the risk level of the specific information is high. The predetermined value may be, for example, "1", or a numerical value of 2 or more.
[0194]
[16] Others The present invention is not limited to that described in the above embodiment, and various modified implementations are possible. For example, terms cited as broad or synonymous terms in the description in the specification or drawings can be replaced with broad or synonymous terms in other descriptions in the specification or drawings.
[0195] The present invention includes a configuration that is substantially the same as the configuration described in the embodiment (for example, a configuration having the same functions, methods, and results, or a configuration having the same objectives and effects). In addition, the present invention includes a configuration in which a non-essential part of the configuration described in the embodiment is replaced. In addition, the present invention includes a configuration that exhibits the same operational effects as the configuration described in the embodiment or a configuration that can achieve the same objective. In addition, the present invention includes a configuration in which a known technique is added to the configuration described in the embodiment.
[0196] As described above, the embodiments of the present invention have been described in detail, but those skilled in the art will easily understand that many modifications can be made without substantially departing from the novel matters and effects of the present invention. Therefore, all such modified examples are intended to be included within the scope of the present invention.
Explanation of Reference Numerals
[0197] 10 Server device, 20 Terminal device, 100 Processing unit, 110 Communication control unit, 111 Reception unit, 112 Corresponding unit, 113 Mail gateway unit, 170 Memory unit, 171 Main memory unit, 172 User information memory unit, 173 E-mail memory unit, 180 Information storage medium, 196 Communication unit, 200 Processing unit, 210 Communication control unit, 211 Display control unit, 270 Memory unit, 280 Information storage medium, 290 Display unit, 296 Communication unit
Claims
1. A receiving unit that receives report information indicating that a phishing email has been received from a given user belonging to an organization, and a corresponding unit that performs a given corresponding process when the report information is received, wherein the corresponding unit generates an information sharing area, controls the administrator and the user belonging to the organization to be able to access the information sharing area, shares information about the phishing email in the information sharing area, and determines the risk level of specific information included in the phishing email, an information processing system characterized by the above.
2. In Claim 1, wherein the corresponding unit notifies the users of the organization of caution information regarding the phishing email when it indicates that the risk level is high, an information processing system characterized by the above.
3. In Claim 2, wherein the corresponding unit determines the risk level of the specific information based on a plurality of indicators, and notifies the caution information when it indicates that the risk level is high in at least one of the plurality of indicators, an information processing system characterized by the above.
4. In Claim 1, wherein the corresponding unit when it indicates that the risk level is high, for each other user of the organization, among the electronic mails received by each user belonging to the organization and stored in a given storage unit, determines whether the specific information exists in the electronic mails received by other users, an information processing system characterized by the above.
5. In Claim 4, wherein the storage unit is a storage area of a server that provides a cloud-based email service, or a storage area that stores and stores the emails received by each user belonging to the organization, an information processing system characterized by the above.
6. In Claim 1, wherein the corresponding unit when it indicates that the risk level is high, for each other user of the organization, determines whether the specific information exists in the email when the other user receives the email, an information processing system characterized by the above.
7. In Claim 4 or 6, wherein the corresponding unit when the specific information exists in the email received by another user, notifies the other user of caution information regarding the phishing email, an information processing system characterized by the above.
8. In Claim 4 or 6, wherein the corresponding unit An information processing system, characterized in that when the specific information exists in an e-mail received by another user, the other user is invited to the information sharing area and the other user is controlled to be able to access the information sharing area.
9. In claim 4 or 6, The corresponding part An information processing system, characterized in that when the specific information exists in an e-mail received by another user, information indicating that the specific information exists in the e-mail received by the other user is shared in the information sharing area.
10. In claim 1 or 2, The corresponding part An information processing system, characterized in that corresponding processing according to the type of the phishing e-mail is performed.
11. A receiving unit that receives report information indicating that a phishing e-mail has been received from a given user belonging to an organization, A corresponding unit that performs a given corresponding process when the report information is received, and The corresponding part Generates an information sharing area, Controls the administrator and the user belonging to the organization to be able to access the information sharing area, Shares information about the phishing e-mail in the information sharing area, An information processing apparatus, characterized by determining the degree of risk of specific information included in the phishing e-mail.
12. A receiving unit that receives report information indicating that a phishing e-mail has been received from a given user belonging to an organization, When the report information is received, a computer functions as a corresponding unit that performs a given corresponding process, The corresponding part Generates an information sharing area, Controls the administrator and the user belonging to the organization to be able to access the information sharing area, Shares information about the phishing e-mail in the information sharing area, A program, characterized by determining the degree of risk of specific information included in the phishing e-mail.
13. A step of receiving report information indicating that a phishing e-mail has been received from a given user belonging to an organization, A step of performing a given corresponding process when the report information is received, and The step of performing the corresponding process Generates an information sharing area, Controls the administrator and the user belonging to the organization to be able to access the information sharing area, Shares information about the phishing e-mail in the information sharing area, An information processing method characterized by determining the risk level of specific information included in the phishing email.
Citation Information
Patent Citations
Message transmission / reception application software, and message transmission / reception system
JP2021117797A
Cited By
Survey equipment, survey program, and survey method
JP7919101B1