Infection notification transmission device, method, and program

The infection notification transmission device, mimicking legitimate devices with the same IP and software, intentionally infects itself with malicious programs to deceive attackers, reducing data breaches and attack frequency by wasting their resources and lowering the value of infected lists.

JP2025114170APending Publication Date: 2025-08-05PREMO INC +2
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2024008688
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-01-24
Publication Date
2025-08-05

AI Technical Summary

Technical Problem

Existing systems fail to effectively protect internal networks from malicious programs by allowing attackers to infiltrate and exploit them, leading to unauthorized access and data theft, as they lack mechanisms to deceive attackers into targeting non-critical systems.

Method used

An infection notification transmission device that mimics legitimate network devices, using the same IP address and software environment, intentionally infects itself with malicious programs, preventing communication with the internal network while transmitting infection notifications to external networks, thereby misleading attackers and reducing their profit and opportunities for further attacks.

Benefits of technology

This approach reduces the value of infected terminal lists, minimizes data breaches, and conserves attacker resources, ultimately decreasing the overall frequency and impact of malicious attacks on internal networks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025114170000001_ABST
    Figure 2025114170000001_ABST
Patent Text Reader

Abstract

To provide an infection notification transmission device, a method, and a program that are permitted to transmit infection notification to an external network when infected with a malicious program.SOLUTION: An infection notification transmission device 140 communicates with an external network 60 using a same global IP address as one or more computers 142a, 142b to 140n in a computer network 160 in an internal network 10. The infection notification transmission device prohibits communication to the computer network. The infection notification transmission device has a same software environment as one or more computers.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an infection notification transmission device, method, and program. [Background technology]

[0002] Patent Document 1 describes "an unauthorized access information collection system that monitors unauthorized access to a honeynet consisting of multiple honeypots (decoy network devices, servers, etc. to lure attackers, viruses, etc.) and collects unauthorized access information." Patent Document 2 describes "attack information management technology that manages information collected by a decoy system." (Prior art document) (Patent document) (Patent Document 1) JP 2008-172548 A (Patent Document 2) JP 2013-85124 A Summary of the Invention

[0003] In a first aspect of the present invention, there is provided an infection notification transmission device. The infection notification transmission device is permitted to transmit an infection notification to an external network when infected with a malicious program. The infection notification transmission device may communicate with the external network using the same global IP address as one or more computers within a computer network. Communication from the infection notification transmission device to the computer network may be prohibited. The infection notification transmission device may have the same software environment as the one or more computers.

[0004] In the infection notification transmission device, the infection notification transmission device may be connected to the computer network via a communication control device, and a transfer policy of the communication control device may prohibit communication from the infection notification transmission device to the computer network and permit communication from the infection notification transmission device to the external network.

[0005] In any of the above infection notification transmitting devices, the operating system of the infection notification transmitting device may be the same as the operating system of the one or more computers.

[0006] In any of the above infection notification transmitting devices, the version of the operating system of the infection notification transmitting device may be the same as the version of the operating system of the one or more computers.

[0007] In any of the above infection notification transmitting devices, when an email with a file attached containing a malicious program is detected, the infection notification transmitting device may become infected with the malicious program by opening the file.

[0008] In any of the infection notification transmitting devices described above, when a file including a RAT type malicious program is detected, the infection notification transmitting device may infect the file with the RAT type malicious program by opening the file.

[0009] In any of the infection notification transmission devices described above, the infection notification transmission device may open the file within a predetermined time period after the email with the file attached is detected.

[0010] In any of the above infection notification sending devices, the infection notification sending device may be prohibited from opening the file if a predetermined time has elapsed after an email containing a malicious program is detected.

[0011] In any of the infection notification transmitters described above, the infection notification transmitter may return to a predetermined operating state in which it is not infected with a malicious program at a predetermined timing.

[0012] In a second aspect of the present invention, a method is provided. The method is executed in an infection notification transmitting device that is permitted to send an infection notification to an external network when infected with a malicious program. The method includes a step of infecting a computer with a malicious program while communicating with the external network using the same global IP address as one or more computers in a computer network and while communication from the infection notification transmitting device to the computer network is prohibited. The method also includes a step of, when infected with the malicious program, sending the infection notification to the external network in accordance with the operation of the malicious program. The infection notification transmitting device has the same software environment as the one or more computers.

[0013] In a third aspect of the present invention, there is provided a program that, when executed by a computer, causes the computer to function as any one of the infection notification transmission devices described above.

[0014] The above summary of the invention does not list all of the features of the present invention, and subcombinations of these features may also be inventions. [Brief explanation of the drawings]

[0015] [Figure 1] 1 illustrates an overall computer network including an infection notification sending device 140 in one embodiment. [Figure 2] 1 shows an example of filtering settings of the communication control device 100. [Figure 3] 10 shows a flowchart illustrating a method performed when the infection notification sending device 140 is installed. [Figure 4] 10 shows a flowchart of a method performed by the infection notification sending device 140. [Figure 5] The behavioral rules of the attacking and defending sides implemented in the simulation model are shown below. [Figure 6] The parameters set in the simulation are shown below. [Figure 7]1 is a first graph showing a simulation result. [Figure 8] 10 is a second graph showing the simulation results. [Figure 9] An example of a computer 2000 is shown. DETAILED DESCRIPTION OF THE INVENTION

[0016] The present invention will be described below through embodiments of the invention, but the following embodiments do not limit the scope of the invention according to the claims. Furthermore, not all of the combinations of features described in the embodiments are necessarily essential to the solution of the invention.

[0017] 1 shows an entire computer network including an infection notification transmission device 140 in one embodiment. The infection notification transmission device 140 is provided within an internal network 10. A router 102 is provided between the internal network 10 and an external network 60. Computers within the internal network 10 communicate with the external network 60, including the Internet 90, via the router 102.

[0018] The internal network 10 is, for example, a network within an organization such as a company. The internal network 10 includes a communication control device 100, a DMZ 130, a computer network 160, and a network segment 170 including an infection notification transmission device 140.

[0019] The computer network 160 is a private network within the internal network 10. The computer network 160 is, for example, an intranet within an organization. The computer network 160 includes the UTM 112, multiple computers including the computer 142a and the computer 142b, and the server 148. The UTM 112 is a Unified Threat Management system and has security functions such as antivirus and VPN.

[0020] The computers 142a and 142b are terminals used by, for example, general users within an organization. In this embodiment, the computers 142a and 142b may be collectively referred to as "computers 142." The computers 142 communicate with the external network 60 via the communication control device 100 and the router 102. The computers 142 communicate with the external network 60 using a global IP address assigned to the router 102.

[0021] The DMZ 130 is a network segment called a demilitarized zone on a network. The DMZ 130 is a network segment different from the computer network 160. The DMZ 130 is separated from the computer network 160 by the communication control device 100. The communication control device 100 may be a firewall device. The DMZ 130 includes a UTM 110 and a server 120. In this embodiment, the server 120 is a mail server. The DMZ 130 may include a server such as a web server in addition to the mail server. The UTM 110 is a Unified Threat Management system and has security functions such as antivirus and VPN. In this embodiment, the UTM 110 includes, as part of its antivirus function, a function for detecting packets containing malicious files and notifying the security operation center 150 of the detection of a threat along with information about the detected packets. For example, the UTM 110 detects packets of emails to which a file containing malicious files is attached and notifies the security operation center 150 of the detection of a threat along with information about the detected packets. Malicious programs are sometimes called malware. A malicious program is a program or code with malicious logic. The malicious program may be a computer virus or a worm. In this embodiment, a case where a malicious program infects a computer by opening a file attached to an e-mail is mainly described. However, the route of intrusion of a malicious program is not limited to e-mail. This embodiment may also be applied to a case where a malicious program infects a computer by a drive-by download attack, or a case where a hacker infiltrates the internal network 10 by exploiting a vulnerability in a VPN or the like and then infects the computer with a malicious program.

[0022] The security operation center 150 is provided with a computer 152. In the security operation center 150, an operator 12 uses the computer 152 to monitor the entire communication infrastructure in the internal network 10 and respond to security incidents. In this embodiment, the security operation center 150 monitors and manages at least the communication control device 100 and responds to incidents related to malicious programs.

[0023] The infection notification transmitter 140 is provided to intentionally infect a computer with a malicious program. The infection notification transmitter 140 communicates with the external network 60 via the communication control device 100 and the router 102. The infection notification transmitter 140 communicates with the external network 60 using a global IP address assigned to the router 102. In this manner, the infection notification transmitter 140 communicates with the external network 60 using the same global IP address as one or more computers 142 within the computer network 160. Meanwhile, the infection notification transmitter 140 is connected to the computer network 160 via the communication control device 100, and communication from the infection notification transmitter 140 to the computer network 160 is prohibited.

[0024] The external network 60 includes an attacker network 50, which is a computer network of an attacker attempting unauthorized access. The attacker network 50 includes an attacker terminal 20, a first server 30, and a second server group 40.

[0025] The attacker terminal 20 is a terminal operated by an attacker 22. The attacker 22 uses the attacker terminal 20 to launch an attack via the first server 30 and the second server group 40. For example, the attacker terminal 20 sends an email with an attached file containing a malicious program via the first server 30 and the second server group 40. The email 24 is sent to a mail server corresponding to the destination email address of the email via the first server 30 and one of the second servers 42 in the second server group 40.

[0026] In this embodiment, a remote access trojan (also called a "RAT") is used as an example of a malicious program. The attacker 22 first sends an email with a subject that pretends to be about business, with the malicious program attached under a file name that pretends to be about business. When a user of a computer that receives the email opens the file attached to the email, malicious commands are executed on the computer, and the computer becomes infected with the malicious program. Once the computer is infected with the malicious program, it becomes possible to remotely control the computer. A computer infected with the malicious program periodically sends an infection notification to the first server 30 via the second server group 40, indicating that the computer has been infected with the malicious program. The attacker 22 uses the attacker terminal 20 to remotely control the infected computer, causing the infected computer to execute arbitrary commands and illegally obtain information from the infected computer. Additionally, the attacker 22 creates a list of IP addresses for accessing the infected computer (sometimes called an infected terminal list) and makes a profit by selling the infected terminal list to others.

[0027] In this embodiment, a case will be described in which the server corresponding to the destination email address of an email 24 sent by an attacker 22 is a server 120 within the internal network 10. The email 24 is sent to the server 120 via the first server 30, the second server group 40, the Internet 90, the router 102, the communication control device 100, and the UTM 110. When the UTM 110 detects the packet of the email 24 as a threat, it notifies the security operation center 150 of information about the detected packet and that a threat has been detected. In the security operation center 150, the operator 12 rejects the email 24 from the server 120.

[0028] In this embodiment, the email 24 stored in the server 120 is provided to the infection notification transmitting device 140. For example, when the infection notification transmitting device 140 acquires information about the email 24 identified as a threat, it acquires the email 24 from the server 120. The email 24 may be provided to the infection notification transmitting device 140 without requiring any operation by the operator 12. The email 24 may be provided to the infection notification transmitting device 140 by connecting a storage medium storing the email 24 to the infection notification transmitting device 140 and having the infection notification transmitting device 140 read the email 24 from the storage medium.

[0029] In response to receiving the email 24, the infection notification transmitting device 140 opens the file attached to the email 24. The operation of the infection notification transmitting device 140 to open the file attached to the email 24 may be performed without requiring operation by the operator 12. The operation of the infection notification transmitting device 140 to open the file attached to the email 24 may be performed by operation by the operator 12. When the infection notification transmitting device 140 opens the file attached to the email 24, the infection notification transmitting device 140 becomes infected with a malicious program.

[0030] The infection notification transmitting device 140 is permitted to transmit an infection notification to the external network 60 when infected with a malicious program. Therefore, an infection notification transmitting device 140 infected with a malicious program periodically transmits an infection notification to the first server 30 via the second server group 40 in accordance with the operation of the malicious program. Upon receiving the infection notification, the attacker 22 uses the attacker terminal 20 to remotely control the infection notification transmitting device 140 and attempt to illegally obtain information from the infection notification transmitting device 140. In addition, the attacker 22 creates a list of infected terminals including global IP addresses for accessing the infection notification transmitting device 140, and attempts to sell the infected terminal list to others.

[0031] The infection notification transmitting device 140 has a computer configuration similar to that of the computer 142 in the computer network 160, except that no important information is stored in the infection notification transmitting device 140. For example, the infection notification transmitting device 140 has the same software environment as the computer 142. Specifically, the operating system of the infection notification transmitting device 140 is the same as the operating system of the computer 142. More specifically, the version of the operating system of the infection notification transmitting device is the same as the version of the operating system of one or more computers 142. Furthermore, as described above, the infection notification transmitting device 140 communicates with the external network 60 using the same global IP address as one or more computers 142 in the computer network 160. Therefore, it is difficult for the attacker 22 to realize that the target of the intrusion is not a computer 142 used by a general user, but an infection notification transmitting device 140 that has been intentionally installed to infect a computer with a malicious program.

[0032] Therefore, the attacker 22 attempts to obtain information by remotely controlling the infection notification transmitting device 140, but because no important information is stored in the infection notification transmitting device 140, the attacker 22 is unable to obtain any substantially useful information from the infection notification transmitting device 140. Furthermore, because communication from the infection notification transmitting device 140 to the computer network 160 is prohibited, the attacker 22 cannot use the infection notification transmitting device 140 as a springboard to infiltrate the computer network 160. Therefore, the attacker 22 is unable to obtain any substantially useful information from the internal network 10. Even if a global IP address for remotely controlling the infection notification transmitting device 140 were included in an infected terminal list and sold to another party, the other party would not be able to obtain any useful information from the infection notification transmitting device 140, and the value of the infected terminal list would decrease in the infected terminal list trading market. This effectively reduces the profits gained by the attacker 22.

[0033] In addition, the attacker 22 will waste human resources by conducting a RAT attack on the infection notification transmitting device 140. This reduces the opportunities for the attacker 22 to attack other networks. In other words, it is possible to reduce the opportunities for attacks by the attacker 22 for society as a whole.

[0034] If the attacker 22 realizes that the target of the intrusion is not computer 142 and changes the network settings of the second server group 40 so that the second server group 40 does not receive the infection notification from the infection notification transmitter 140, the first server 30 will also be unable to receive the infection notification that may be transmitted from the computer 142 in the computer network 160. Therefore, even if the computer 142 is infected with a malicious program, the attacker 22 will be unable to receive the infection notification from the computer 142, and the computer 142 will not be harmed. Therefore, the attacker 22 must choose whether to allow the computer 142 to continue receiving infection notifications from the infection notification transmitter 140, or to change the target of the attack to another network after configuring the network to refuse to receive infection notifications transmitted from the infection notification transmitter 140.

[0035] In this way, the infection notification transmitting device 140 is expected to reduce the opportunities for attacks across society by consuming the human resources of the attacker 22. Furthermore, even if the attacker 22 becomes aware of the presence of the infection notification transmitting device 140, it is possible to make it more difficult for the attacker 22 to attack an organization that has an internal network 10, thereby reducing damage caused by attacks by the attacker 22.

[0036] Fig. 2 shows an example of filtering settings for the communication control device 100. Specifically, Fig. 2 shows settings, displayed using the iptables command, when the communication control device 100 is implemented as a firewall device using Netfilter, a packet filtering function implemented in the Linux (registered trademark) kernel.

[0037] In Fig. 2, "(sandbox)" represents the local IP address of the infection notification transmitting device 140, and "(Internal)" represents the network address of the computer network 160. As shown in Fig. 2, the basic policy for packet forwarding is "DROP" (rejection). Five rules corresponding to line numbers 1 to 5 are set for packet forwarding.

[0038] As shown in line number 1, the transfer of all packets from the infection notification transmitter 140 to the computer network 160 is denied. With respect to packets other than packets from the infection notification transmitter 140 to the computer network 160, as shown in line numbers 2 and 3, the transfer of TCP packets with destination ports http and https from the infection notification transmitter 140 is permitted, and as shown in line number 4, the transfer of packets of communications already established with respect to the infection notification transmitter 140 and packets related to those packets is permitted. As shown in line number 5, the transfer of packets from the infection notification transmitter 140 other than those permitted in line numbers 2 and 3 is denied.

[0039] In this way, the infection notification transmitting device 140 is connected to the computer network 160 via the communication control device 100, and the transfer policy of the communication control device 100 prohibits communication from the infection notification transmitting device 140 to the computer network 160, but permits communication from the infection notification transmitting device 140 to the external network 60. In Fig. 2, http or https communication is permitted for communication from the infection notification transmitting device 140 to the external network 60, but this is not limited to these, and it is necessary to permit at least communication of the port number used for transmitting the infection notification.

[0040] In this embodiment, communication from the infection notification transmitter 140 to the computer network 160 is rejected by the communication control device 100. As an alternative method, it is possible to incorporate network settings into the infection notification transmitter 140 itself that reject communication to the computer network 160. However, if such network settings are incorporated into the infection notification transmitter 140 itself, in the event of a RAT attack from an attacker 22, the attacker 22 may be able to determine that the infection notification transmitter 140 is not a computer used by a general user by referring to the network settings set in the infection notification transmitter 140. For this reason, it is preferable for the communication control device 100 to reject communication from the infection notification transmitter 140 to the computer network 160.

[0041] 3 shows a flowchart of a method executed when introducing the infection notification transmission device 140. In S302, a computer with the same software environment as the computer 142 is prepared as a computer for configuring the infection notification transmission device 140. The OS of the computer prepared in S302 may be the same as the OS of the computer 142, and the OS version may also be the same as the OS version of the computer 142. The computer prepared in S302 may have the same application software installed as the application software installed on the computer 142 installed therein. The computer prepared in S302 may be a virtual machine. When the infection notification transmission device 140 is configured as a physical computer, the computer prepared in S302 may have the same hardware configuration as the computer 142.

[0042] In S304, the infection notification transmission device 140 is configured using the computer prepared in S302. For example, settings such as assigning a local network address to the infection notification transmission device 140 are performed. In S306, the initial state of the infection notification transmission device 140 is saved. For example, if the infection notification transmission device 140 is configured using a virtual machine, a snapshot representing the current operating state is created in S306. If the infection notification transmission device 140 is configured using a physical computer, a restore point for the initial state is set. For example, if software environment restoration software such as Faronics' Deep Freeze is used, the restoration software is enabled. If a storage control device such as Voom's Shadow3 is used, the storage control device is connected to the storage device of the computer prepared in S302.

[0043] In S308, a packet forwarding rule is set for the communication control device 100. Settings are made to permit communication from the infection notification transmitter 140 to the external network 60 and to deny communication from the infection notification transmitter 140 to the computer network 160. In S310, the infection notification transmitter 140 is connected to the communication control device 100.

[0044] 4 shows a flowchart of a method executed by the infection notification transmitting device 140. At the start of this flowchart, the infection notification transmitting device 140 is assumed to be stopped. In S320, the infection notification transmitting device 140 is started. The timing at which the infection notification transmitting device 140 is started may be a predetermined time before the start of business of the organization in which the internal network 10 is located.

[0045] In S322, the infection notification transmission device 140 returns to its initial state. If the infection notification transmission device 140 is configured as a virtual machine, the infection notification transmission device 140 returns to its initial state based on the snapshot saved in S306. If the infection notification transmission device 140 is configured as a physical computer, the infection notification transmission device 140 returns to the restore point set in S306. For example, if software environment restoration software such as Faronics' Deep Freeze is used, the infection notification transmission device 140 is restarted to return to the state it was in when the restoration software was enabled. If a storage control device such as Voom's Shadow3 is used, the infection notification transmission device 140 returns to its initial state before the storage control device was connected by initializing the data written to the storage control device.

[0046] In S324, the infection notification transmitting device 140 determines whether a threatening email has been detected. For example, if the infection notification transmitting device 140 is notified by the UTM 110 that a threatening email has been detected, the infection notification transmitting device 140 determines that a threatening email has been detected. If the infection notification transmitting device 140 determines in S324 that a threatening email has not been detected, the process proceeds to S328. The threatening email may be, for example, an email with a RAT-type malicious program attached.

[0047] If the infection notification transmitting device 140 determines in S324 that a threatening email has been detected, then in S326 the infection notification transmitting device 140 opens the file attached to the email detected in S324. As a result, the infection notification transmitting device 140 may become infected with a malicious program and transmit an infection notification to the first server 30. In this way, when an email with an attached file containing a RAT-type malicious program is detected, the infection notification transmitting device 140 opens the file, becoming infected with the RAT-type malicious program and transmitting an infection notification to the external network 60. It is preferable that the infection notification transmitting device 140 opens the attached file within a predetermined time after the email with the attached file is detected. On the other hand, it is preferable that the infection notification transmitting device 140 prohibits the opening of the attached file if a predetermined time or more has passed after the email containing the malicious program is detected. The predetermined time may be, for example, one to three days. This is because if the first server 30 receives an infection notification from the infection notification transmitting device 140 one to three days or more after receiving the email, the attacker 22 may determine that the infection may have occurred intentionally after taking measures to monitor the attack, and may refrain from attacking.

[0048] In S328, the infection notification transmitter 140 determines whether to stop operation. For example, the infection notification transmitter 140 determines to stop operation when a predetermined time arrives. Specifically, the infection notification transmitter 140 may determine to stop operation when it is closing time for the organization in which the internal network 10 is installed. The infection notification transmitter 140 may determine to stop operation when a predetermined time has passed since closing time for the organization in which the internal network 10 is installed. The predetermined time may be set randomly. By stopping the operation of the infection notification transmitter 140 based on the closing time for the organization, if an attacker 22 infiltrates the infection notification transmitter 140 and references the system log of the infection notification transmitter 140, the infection notification transmitter 140 may appear to be a computer used by a general user.

[0049] The infection notification transmitting device 140 does not need to stop operating at a predetermined time. The infection notification transmitting device 140 may return to its initial state every time a predetermined time has elapsed. The infection notification transmitting device 140 may return to its initial state every time a predetermined number of malware infections occur.

[0050] If the infection notification transmitting device 140 determines to stop operation in S328, it stops operation in S330. If the infection notification transmitting device 140 determines not to stop operation in S328, it returns to S324. In this way, the infection notification transmitting device 140 returns to a predetermined operating state in which it is not infected with a malicious program at a predetermined timing. After the infection notification transmitting device 140 is infected with a malicious program, the attacker 22 may sell an infected terminal list that includes the infection notification transmitting device 140 to another party. However, if the infection notification transmitting device 140 subsequently returns to an operating state in which it is not infected with a malicious program, the attacker 22 will no longer be able to remotely control the infection notification transmitting device 140. This is expected to reduce the value of the infected terminal list sold by the attacker 22, and ultimately to reduce the attacker 22's reputation in the infected terminal list trading market.

[0051] 5 to 8, a simulation conducted to evaluate the effect of providing an infection notification transmitting device 140 that intentionally infects a computer with a malicious program against a RAT attack will be described. In this simulation, the number of attackers is set to 1, and the number of potential attack targets is set to N. In the explanation of this simulation, the attack targets are identified as T1, T2, ...TN. The attacker starts the attack by sending an email with a malicious program attached. The attacker selects one of the N attack targets as the attack target and starts the attack by sending an email to the selected attack target. The attacker's degree of attachment to each attack target, Att Ti is set, and the probability that the defender Ti is selected as the attacker is Att Ti / ΣAtt Tj Here, Σ is Att Tj represents the addition of

[0052] Figure 5 shows the behavioral rules of the attacker and defender implemented in the simulation model.

[0053] In the first step of the behavior rule, an attacker launches an attack by sending an email (A11). In this simulation, a probability is set that the recipient of the email will open the email attachment. As a result, the general user's computer will be infected with a certain probability, and an infection notification will be sent from the general user's computer (S11). If the general user's computer is not infected, the email will be discarded (S12) or a fake infection notification will be sent (S13). Discarding the email corresponds to, for example, a situation in which a general user realizes that they have received an email containing a malicious program and discards the email. In this simulation, a terminal that intentionally allows itself to be infected with a malicious program, such as the infection notification transmission device 140, is called a fake infected terminal, and infection of a fake infected terminal with a malicious program is called a "fake infection." Sending the fake infection notification (S13) corresponds to, for example, a situation in which the UTM 110 detects the email as threatening, or a general user realizes that they have received an email containing a malicious program and contacts the security operation center 150, and the email attachment is opened by the infection notification transmission device 140.

[0054] In the second step of the behavioral rule, the attacker is in one of three states: (i) receiving an infection notification, (ii) receiving a fake infection notification, or (iii) receiving neither an infection notification nor a fake infection notification.

[0055] When an attacker (i) receives an infection notification, the attacker's next action is one of (a) infiltrating the infected terminal (A21), (b) selecting the next target to attack (A22), and (c) blocking the target (A24). Here, "blocking the target" means that the attacker refuses to receive the infection notification sent from the infected terminal. When an attacker infiltrates an infected terminal, the gain value is changed by a predetermined value on both the attacker side and the defender side, and in the next step, the next target to attack is selected.

[0056] The attacker chooses which of the three actions (a), (b), and (c) to take depending on the degree of attachment to the target. Specifically, the probability of blocking the target is (1-Att Ti ), and the probability of selecting the next target to attack is (1-Att Ti )Att Ti The probability of infiltrating an infected terminal is Att Ti 2 Let's say.

[0057] When an attacker (ii) receives a false infection notification, the attacker's actions are the same as when an attacker (i) receives an infection notification: (a) infiltrate a false infected terminal (A23), (b) select a next target and attack (A22), or (c) block the target (A24). This is because, from the attacker's perspective, it is impossible to distinguish whether the infection notification received is from, for example, the infection notification transmitting device 140 in FIG. 1 or the computer 142. However, if an attacker infiltrates a false infected terminal while receiving a false infection notification, the defender's gain remains unchanged because no damage is caused, while the attacker's gain decreases. This is because infiltrating a false infected terminal creates the risk of having their attacking behavior monitored. When an attacker (iii) receives neither an infection notification nor a false infection notification, the attacker's action is to select a next target and attack (A22).

[0058] If the next attack target is selected in the second step, an infection notification will be sent from the general user's computer (S21), the email will be discarded (S22), or a fake infection notification will be sent (S23), just as in the first step. If the attacker selects the next attack target and takes an action other than attacking in the second step, the defender will do nothing (S24), and in the third step the attacker will select the next attack target (A32).

[0059] The next actions of S21, S22, and S23 in the second step are the same as the next actions of S11, S12, and S13 in the first step. That is, the attacker's action following S21 is one of (a) infiltrating an infected terminal (A31), (b) selecting the next target to attack (A32), and (c) blocking the target (A34). The attacker's action following S22 is (b) selecting the next target to attack (A32). The attacker's action following S23 is one of (a) infiltrating a fake infected terminal (A33), (b) selecting the next target to attack (A32), and (c) adding the target to the blocked list (A34).

[0060] The transition of the action in the third step is the same as the transition of the action in the second step. After that, the transition of the action in the second step and the transition of the action from the second step to the third step are repeated.

[0061] Figure 6 shows the parameters set in the simulation. As shown in Figure 6, the number of attackers is 1, and the number of defending targets is 1,000. The number of steps is 5,000. The number of episodes is 100. An episode is the number of simulation trials. Because the behavior of the attacker and target is affected by random numbers, we performed 100 trials with different random number seeds and averaged the results for evaluation.

[0062] The parameters for the defense side include the "initial gain value," "gain fluctuation when the attack is successful," "deployment status of fake infected terminals," "fake infection implementation rate," and "email opening rate." The "initial gain value" was set to 10, and the "gain fluctuation when the attack is successful" was set to -5. As mentioned above, there is no gain fluctuation when a terminal that sent a fake infection notification is infiltrated.

[0063] "Introduction status of fake infected terminal" indicates the introduction status of the terminal that sends the fake infection notification. The introduction status of fake infection is set for each defensive target. As will be described later, the evaluation was performed by performing simulations while changing the introduction rate of the fake infection system for each defensive target.

[0064] The "fake infection rate" indicates the probability of sending a fake infection notification if the email is not opened. The "fake infection rate" was set to 50%. The "email open rate" is the probability of opening an email attachment. The "email open rate" was set to 10%.

[0065] The attacker's parameters include "initial gain," "gain fluctuation when attack is successful," "gain fluctuation when infiltrating a fake infected terminal," "attachment to the defender," and "blocking rate." The "initial gain" was set to 10, and the "gain fluctuation when attack is successful" was set to +5. The "gain fluctuation when infiltrating a fake infected terminal" was set to -1.

[0066] "Attack attachment to the defender" is the attacker's attachment to the defender target Ti. Ti The "attachment to the defense" was determined for each episode based on a pseudorandom number. The "block execution rate" was calculated by 1-Att Ti It was decided.

[0067] Figure 7 is a first graph showing the results of the simulation. The horizontal axis of the graph in Figure 7 represents the introduction rate of fake infected terminals. The vertical axis of the graph in Figure 7 represents the gain, the number of infected people, the number of victims, and the number of blocked people. Reference numeral 610 represents the gain of the attacker, reference numeral 620 represents the amount of decrease in the gain of the defender, reference numeral 630 represents the number of infected people, which indicates the number of defending-side targets who have been infected with malicious programs, reference numeral 640 represents the number of victims, which indicates the number of defending-side targets who have been infiltrated, and reference numeral 650 represents the number of blocked people, which indicates the number of defending-side targets who have been blocked by the attacker.

[0068] Figure 7 shows that the higher the rate of introduction of fake infected terminals, the more blocked users there are, the fewer infected users and victims there are, the smaller the amount of damage (the amount of damage) the defender's gain is, and the smaller the attacker's gain is. In particular, as shown by the line 610, the higher the rate of introduction of fake infected terminals, the greater the decrease in the attacker's gain. In other words, it can be understood that attackers are wasting their human resources by continuing to access fake infected terminals. Therefore, the introduction of fake infected terminals can be expected to reduce the amount of RAT attacks in society.

[0069] Figure 8 is the second graph showing the simulation results. The horizontal axis of the graph in Figure 8 represents the introduction rate of fake infected devices. The vertical axis of the graph in Figure 8 represents the proportion of fake infected devices included in the list of infected devices. Figure 8 shows that the higher the introduction rate of fake infected devices, the higher the proportion of fake infected devices in the list of fake infected devices. In particular, even when the introduction rate of fake infected devices is 20%, fake infected devices still account for approximately 50% of the infected device list. Therefore, introducing fake infected devices into an organization can significantly reduce the value of the infected device list and undermine the attacker's profits.

[0070] 9 shows an example of a computer 2000 in which multiple embodiments of the present invention may be embodied, in whole or in part. A program installed on the computer 2000 may cause the computer 2000 to function as a system or each part of the system according to an embodiment, or as a device such as the infection notification sending device 140 or each part of the device, to perform operations associated with the system or each part of the system, or the device or each part of the device, and / or to perform a process or steps of the process according to an embodiment. Such a program may be executed by the CPU 2012 to cause the computer 2000 to perform specific operations associated with some or all of the processing procedures and blocks of the block diagrams described herein.

[0071] The computer 2000 according to this embodiment includes a CPU 2012 and a RAM 2014, which are interconnected by a host controller 2010. The computer 2000 also includes a ROM 2026, a flash memory 2024, a communication interface 2022, and an input / output chip 2040. The ROM 2026, the flash memory 2024, the communication interface 2022, and the input / output chip 2040 are connected to the host controller 2010 via the input / output controller 2020.

[0072] The CPU 2012 operates according to programs stored in the ROM 2026 and RAM 2014, thereby controlling each unit.

[0073] The communication interface 2022 communicates with other electronic devices via a network. The flash memory 2024 stores programs and data used by the CPU 2012 in the computer 2000. The ROM 2026 stores a boot program and the like executed by the computer 2000 upon activation, and / or programs dependent on the hardware of the computer 2000. The input / output chip 2040 may also connect various input / output units such as a keyboard, mouse, and monitor to the input / output controller 2020 via input / output ports such as a serial port, a parallel port, a keyboard port, a mouse port, a monitor port, a USB port, an HDMI (registered trademark) port, etc.

[0074] The programs are provided via a computer-readable storage medium such as a CD-ROM, a DVD-ROM, or a memory card, or via a network. The RAM 2014, the ROM 2026, or the flash memory 2024 are examples of computer-readable storage media. The programs are installed in the flash memory 2024, the RAM 2014, or the ROM 2026 and executed by the CPU 2012. Information processing described in these programs is read by the computer 2000, and causes cooperation between the programs and the various types of hardware resources described above. An apparatus or a method may be configured by implementing operations or processing of information in accordance with the use of the computer 2000.

[0075] For example, when communication is performed between the computer 2000 and an external device, the CPU 2012 may execute a communication program loaded into the RAM 2014 and instruct the communication interface 2022 to perform communication processing based on the processing described in the communication program. Under the control of the CPU 2012, the communication interface 2022 reads transmission data stored in a transmission buffer processing area provided in a recording medium such as the RAM 2014 or flash memory 2024, transmits the read transmission data to a network, and writes received data received from the network to a reception buffer processing area or the like provided on the recording medium.

[0076] The CPU 2012 may also cause all or a necessary portion of a file or database stored on a recording medium such as the flash memory 2024 to be read into the RAM 2014, and perform various types of processing on the data on the RAM 2014. The CPU 2012 then writes the processed data back to the recording medium.

[0077] Various types of information, such as various types of programs, data, tables, and databases, may be stored on the recording medium and subjected to information processing. The CPU 2012 may perform various types of processing on data read from the RAM 2014, including various types of operations, information processing, conditional judgment, conditional branching, unconditional branching, information search / replacement, etc., as described herein and specified by the instruction sequences of the programs, and write the results back to the RAM 2014. The CPU 2012 may also search for information in a file, database, etc. on the recording medium. For example, if multiple entries each having an attribute value of a first attribute associated with an attribute value of a second attribute are stored on the recording medium, the CPU 2012 may search for an entry that matches a condition specified by the attribute value of the first attribute from among the multiple entries, read the attribute value of the second attribute stored in the entry, and thereby obtain the attribute value of the second attribute associated with the first attribute that satisfies a predetermined condition.

[0078] The above-described programs or software modules may be stored in a computer-readable storage medium on or near the computer 2000. A recording medium such as a hard disk or RAM provided in a server system connected to a dedicated communication network or the Internet can be used as the computer-readable storage medium. The programs stored in the computer-readable storage medium may be provided to the computer 2000 via a network.

[0079] A program that is installed on computer 2000 and causes computer 2000 to function as infection notification transmission device 140 may, when executed by the computer, act on CPU 2012 or the like to cause computer 2000 to function as each unit of infection notification transmission device 140. When the information processing described in these programs is loaded into computer 2000, it functions as each unit of infection notification transmission device 140, which is a specific means formed by software working in cooperation with the various hardware resources described above. These specific means then perform calculations or processing of information according to the intended use of computer 2000 in this embodiment, thereby constructing a unique infection notification transmission device 140 suited to the intended use.

[0080] Various embodiments have been described with reference to block diagrams. In the block diagrams, each block may represent (1) a stage of a process where an operation is performed or (2) a portion of an apparatus responsible for performing the operation. Particular stages and portions may be implemented by dedicated circuitry, programmable circuitry provided with computer-readable instructions stored on a computer-readable storage medium, and / or a processor provided with computer-readable instructions stored on a computer-readable storage medium. Dedicated circuitry may include digital and / or analog hardware circuitry, and may include integrated circuits (ICs) and / or discrete circuits. Programmable circuitry may include reconfigurable hardware circuitry including logical AND, logical OR, logical XOR, logical NAND, logical NOR, and other logic operations, flip-flops, registers, memory elements such as field programmable gate arrays (FPGAs), programmable logic arrays (PLAs), and the like.

[0081] A computer-readable storage medium may include any tangible device capable of storing instructions that are executed by an appropriate device, such that the computer-readable storage medium with instructions stored thereon constitutes at least a portion of an article of manufacture containing instructions that can be executed to provide means for performing the operations specified in a process or block diagram. Examples of computer-readable storage media may include electronic storage media, magnetic storage media, optical storage media, electromagnetic storage media, semiconductor storage media, etc. More specific examples of computer-readable storage media may include floppy disks, diskettes, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), electrically erasable programmable read-only memory (EEPROM), static random access memory (SRAM), compact disc read-only memory (CD-ROM), digital versatile disc (DVD), Blu-ray disc, memory stick, integrated circuit card, etc.

[0082] The computer readable instructions may include either assembler instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state-setting data, or source or object code written in any combination of one or more programming languages, including object-oriented programming languages such as Smalltalk®, JAVA®, C++, etc., and conventional procedural programming languages such as the “C” programming language or similar programming languages.

[0083] The computer-readable instructions may be provided to a processor or programmable circuitry of a general-purpose computer, special-purpose computer, or other programmable data processing apparatus, either locally or over a wide-area network (WAN) such as a local area network (LAN), the Internet, etc., and executed to provide means for performing the operations specified in the process steps or block diagrams described. Examples of processors include computer processors, processing units, microprocessors, digital signal processors, controllers, microcontrollers, etc.

[0084] Although the present invention has been described above using embodiments, the technical scope of the present invention is not limited to the scope described in the above embodiments. It will be apparent to those skilled in the art that various modifications and improvements can be made to the above embodiments. It is clear from the claims that such modifications and improvements can also be included within the technical scope of the present invention.

[0085] It should be noted that the execution order of each process, such as operations, procedures, steps, and stages, in the devices, systems, programs, and methods shown in the claims, specifications, and drawings is not specifically stated as "before," "prior to," etc., and that the processes can be performed in any order unless the output of a previous process is used in a subsequent process. Even if the operational flow in the claims, specifications, and drawings is described using "first," "next," etc. for convenience, this does not mean that the processes must be performed in this order. [Explanation of symbols]

[0086] 10 Internal Network 12 Operators 20 Attacker's terminal 22 Attacker 24. Email 30 First Server 40 Second Server Group 42 Second Server 50 Attacker's Network 60 External Network 90 Internet 100 Communication control device 102 Router 110 UTM 112 UTM 120 servers 130 DMZ 140 Infection notification transmission device 142 Computers 148 servers 150 Security Operations Center 152 Computer 160 Computer Networks 170 network segments 2000 Computer 2010 Host Controller 2012 CPU 2014 RAM 2020 Input / Output Controller 2022 Communication Interface 2024 flash memory 2026 ROM 2040 Input / Output Chip

Claims

1. An infection notification transmitting device that is permitted to transmit an infection notification to an external network when infected with a malicious program, communicating with the external network using the same global IP address as one or more computers within the computer network; communication from the infection notification transmitting device to the computer network is prohibited; have the same software environment as said one or more computers Infection notification sending device.

2. the infection notification transmission device is connected to the computer network via a communication control device; According to the transfer policy of the communication control device, communication from the infection notification transmitting device to the computer network is prohibited; Communication from the infection notification transmitting device to the external network is permitted. The infection notification transmission device according to claim 1 .

3. The operating system of the infection notification sending device is the same as the operating system of the one or more computers. The infection notification transmitting device according to claim 1 or 2.

4. The version of the operating system of the infection notification sending device is the same as the version of the operating system of the one or more computers. The infection notification transmitting device according to claim 3 .

5. When an email with a file containing a malicious program attached is detected, the infection notification transmitting device detects that the file will be opened and the infected device will be infected with the malicious program. The infection notification transmitting device according to claim 1 or 2.

6. When a file including a RAT type malicious program is detected, the infection notification transmitting device is configured to detect that the file is infected with the RAT type malicious program by opening the file. The infection notification transmitting device according to claim 1 or 2.

7. The infection notification transmission device detects an email with the file attached and then opens the file within a predetermined time period. The infection notification transmission device according to claim 5 .

8. The infection notification transmitting device prohibits the opening of the file when a predetermined time has elapsed after the detection of the email containing the malicious program. The infection notification transmitting device according to claim 6 .

9. The infection notification transmitting device returns to a predetermined operating state in which the device is not infected with a malicious program at a predetermined timing. The infection notification transmitting device according to claim 1 or 2.

10. 1. A method executed in an infection notification transmitting device that is permitted to transmit an infection notification to an external network when infected with a malicious program, comprising: a step of infecting the computer with a malicious program while communicating with the external network using the same global IP address as one or more computers within the computer network and while communication from the infection notification transmitting device to the computer network is prohibited; When the computer is infected with the malicious program, transmitting the infection notification to the external network in accordance with the operation of the malicious program; and The infection notification sending device has the same software environment as the one or more computers. method.

11. A program that, when executed by a computer, causes the computer to function as the infection notification transmission device according to claim 1 or 2.