Information processing device, information processing method, and program
The information processing device analyzes statistical bias in member information to tailor countermeasures for unauthorized access, addressing user dissatisfaction and improving security by targeting specific risks and intentions of attackers.
Patent Information
- Application Number
- JP2025095079
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-06-06
- Publication Date
- 2025-08-15
AI Technical Summary
Existing systems uniformly apply countermeasures for unauthorized access, leading to user dissatisfaction and decreased security due to frequent password changes and password reuse, without considering the specific risks and intentions of attackers.
An information processing device that acquires member information from accounts subject to unauthorized access, analyzes statistical bias, and selects tailored countermeasures for each account based on the analysis results.
Enables more appropriate countermeasures for each account, reducing unnecessary password changes and enhancing overall security by addressing the specific risks and intentions of attackers.
Smart Images

Figure 2025120318000001_ABST
Abstract
Description
[Technical Field]
[0001] An embodiment of the present invention relates to an information processing device, an information processing method, and a program. [Background technology]
[0002] With the development of communication technology, online services such as internet banking and online shopping have become widespread. Generally, each user can log in to a system and receive services by entering account identification information, also known as a user ID, and an authentication password.
[0003] With the spread of these online services, there has been a problem of unauthorized third parties being able to use services that have access control functions based on a user ID and password combination. Here, we refer to such actions as "unauthorized access" or "unauthorized login." Unauthorized access can lead to the theft of personal information and the fraudulent use of cash or points.
[0004] To detect such unauthorized access, it is known to perform so-called risk-based authentication (see, for example, Patent Document 1). [Prior art documents] [Patent documents]
[0005] [Patent Document 1] Japanese Patent Application Publication No. 2020-57439 Summary of the Invention [Problem to be solved by the invention]
[0006] Generally, when unauthorized access is detected, countermeasures are taken, such as suspending services for the account that was the target of the unauthorized access. However, for other accounts under management, only uniform countermeasures are taken, such as suspending all services or issuing a notice requesting a password change. Frequent service suspensions can cause dissatisfaction among users (hereinafter also referred to as "members"). Furthermore, frequent password changes are not only cumbersome for users, but also make password management difficult, encouraging the reuse of passwords across multiple services, which may actually lead to a decrease in security.
[0007] The present invention has been made in light of the above circumstances, and its object is to provide a technique that enables more appropriate selection of countermeasures against unauthorized access. [Means for solving the problem]
[0008] In order to solve the above problem, one aspect of the present invention provides an information processing device that includes an information acquisition unit that acquires member information regarding victim members whose accounts have been subject to unauthorized access, among members of a service that manages accounts through password authentication; an analysis unit that analyzes statistical bias in the member information; and a countermeasure selection unit that selects countermeasures against the unauthorized access for each account managed by the service based on the results of the analysis. [Effects of the Invention]
[0009] According to one aspect of the present invention, countermeasures are selected for each account under management based on the statistical bias of the member information of victim members who have actually been subject to unauthorized access among service members. This allows for more appropriate countermeasures to be taken for each account based on the tendency of unauthorized access, rather than taking uniform countermeasures for all accounts, when unauthorized access occurs.
[0010] That is, according to the present invention, it is possible to provide a technique that enables more appropriate selection of countermeasures against unauthorized access. [Brief explanation of the drawings]
[0011] [Figure 1] FIG. 1 is a diagram showing an example of the overall configuration of a system including an information processing device according to an embodiment of the present invention. [Figure 2] FIG. 2 is a block diagram showing an example of a functional configuration of an information processing device according to an embodiment of the present invention. [Figure 3] FIG. 3 is a block diagram showing an example of a hardware configuration of an information processing apparatus according to an embodiment of the present invention. [Figure 4] FIG. 4 is a flowchart showing a first example of a processing procedure and processing content by the information processing device shown in FIG. [Figure 5] FIG. 5 is a diagram illustrating an example of victim data acquired by the information processing device illustrated in FIG. [Figure 6] FIG. 6 is a diagram illustrating a first example of the result of the analysis process performed by the information processing device illustrated in FIG. [Figure 7] FIG. 7 is a diagram illustrating a second example of the result of the analysis process performed by the information processing device illustrated in FIG. [Figure 8] FIG. 8 is a diagram illustrating a third example of the result of the analysis process performed by the information processing device illustrated in FIG. [Figure 9] FIG. 9 is a diagram illustrating a fourth example of the result of the analysis process performed by the information processing device illustrated in FIG. [Figure 10] FIG. 10 is a diagram illustrating a fifth example of the result of the analysis process performed by the information processing device illustrated in FIG. [Figure 11] FIG. 11 is a diagram showing an example of a correspondence table specifying the correspondence between the deviation value and the risk level used by the information processing device shown in FIG. [Figure 12] FIG. 12 is a diagram showing an example of the risk level determined for each type by the information processing device shown in FIG. [Figure 13] FIG. 13 is a diagram showing a first example of a correspondence table specifying correspondence between risk levels and countermeasures used by the information processing device shown in FIG. [Figure 14]FIG. 14 is a flowchart showing a second example of the processing procedure and processing content by the information processing device shown in FIG. [Figure 15] FIG. 15 is a diagram illustrating a first example of the countermeasure selection process performed by the information processing device illustrated in FIG. [Figure 16] FIG. 16 is a diagram showing a second example of a correspondence table specifying the correspondence between the risk level and the countermeasure used by the information processing device shown in FIG. [Figure 17] FIG. 17 is a flowchart showing a third example of the processing procedure and processing content by the information processing device shown in FIG. [Figure 18] FIG. 18 is a diagram illustrating a second example of the countermeasure selection process performed by the information processing device illustrated in FIG. DETAILED DESCRIPTION OF THE INVENTION
[0012] Hereinafter, embodiments of the present invention will be described with reference to the drawings. Hereinafter, elements that are identical or similar to elements already described will be assigned the same or similar reference numerals, and duplicate descriptions will generally be omitted. For example, when there are multiple identical or similar elements, a common reference numeral may be used to describe each element without distinguishing between them, or a subnumber may be used in addition to the common reference numeral to describe each element distinctly.
[0013] [Outline of the embodiment] An information processing device according to an embodiment of the present invention can exchange information with a service that manages member accounts through password authentication. When a member has been subject to unauthorized access, the information processing device collects member information about the member, analyzes statistical bias based on the member information, and selects countermeasures against the unauthorized access based on the analysis results.
[0014] Here, the member information collected by the information processing device may include any information about the member who has been illegally accessed. For example, the member information may include the member's personal information, information associated with the account, and activity history related to services on the network. Personal information may include, for example, name, address, gender, age, telephone number, email address, occupation, annual income, family composition, preferences, etc. Information associated with the account may include, for example, the date and time the account was created, the time elapsed since the account was created, information about the website used to create the account, login history, and password change history. Activity history related to services on the network may include, for example, social networking service (SNS) usage history, SNS posting history, browsing history for specific websites, credit card usage history, online shopping purchase history and payment information, bank account and electronic money account balances and deposit and withdrawal history, point account balances and exchange history, insurance subscriptions and securities trading records, and other activity history for any service.
[0015] In the following description, a point service is assumed as an example of a service that manages member accounts through password authentication, and the information processing device according to the embodiment collects the member information from a server that provides the point service. However, this is merely an example, and it should be noted that the information processing device according to the embodiment can perform similar processing based on member information collected from a wide variety of other information collection sources. For example, the information processing device can collect member information by requesting the unauthorized accessing member to enter the member information. The information processing device can also collect information that the member has posted publicly on social networking sites. Alternatively, with the member's permission, the information processing device can collect information related to savings and purchase history from the servers of financial institutions or credit card companies. The information processing device may collect member information from multiple information collection sources, such as information A from server X and information B from server Y, and integrate the collected information for subsequent processing.
[0016] [One embodiment] (1) Composition (1-1) System FIG. 1 is a diagram showing an example of the overall configuration of a system 1 including an information processing device 10 according to an embodiment of the present invention. The information processing device 10 is capable of communicating with the point management server 20, the service A server 50A, the service B server 50B, ... (hereinafter collectively referred to as the "service providing server 50"), and the user terminals UT1, ..., UTi used by the users (hereinafter collectively referred to as the "user terminals UT") via a network NW such as the Internet.
[0017] The point management server 20 is an example of a member information collection source for the information processing device 10 and is a server computer managed by a business that provides a point service. A point service is a service in which, for example, when a registered user (hereinafter simply referred to as a "member") purchases a product or service (hereinafter simply referred to as a "product"), points are awarded to the user under conditions set by the business based on the purchase amount or the number of visits to the store. The accumulated points can be exchanged for products or services on subsequent visits to the store or used as payment for the purchase of products or services. The point management server 20 manages point data, such as awarded points, redeemed points, and point balances, for each member. Furthermore, while the point management server 20 is described here as providing a common point service shared among multiple services, the present invention is not limited to this, and the point management server 20 may also manage individual or unique points used by individual stores or businesses.
[0018] The service providing server 50 is a server of a business operator that provides affiliated services and is affiliated with the point service provided by the point management server 20. The service providing server 50 may be a server that provides web services such as online shopping or internet banking, or a server that manages sales at physical stores such as convenience stores and gas stations. For example, if the service providing server 50 is a server that provides an online shopping site, when a user purchases a product or other item through the site, the service providing server 50 calculates the number of points to be awarded based on the purchase amount and notifies the point management server 20 of the calculated number of points along with identification information for the user or their point account. Alternatively, when a user purchases a product or other item at a store managed by the service providing server 50, for example, a POS terminal installed in the store calculates the number of points based on the purchase amount and performs a point awarding process on the point card or mobile terminal with the function presented by the user. The service providing server 50 then receives point processing information along with payment information from the POS terminal and also notifies the point management server 20.
[0019] The user terminal UT is any information processing terminal that can be connected to the network NW, such as a smartphone, tablet terminal, laptop or desktop personal computer used by a user. Members of the point service can use the user terminal UT to access their own point accounts, check their balances, and use / exchange points, for example, directly from a website or dedicated application program (hereinafter also referred to as an "application") provided by the point management server 20, or via a website or dedicated application provided by the service providing server 50.
[0020] Here, when each member accesses their point account, password authentication using a combination of ID and password is used. For example, each member accesses a website provided by the point management server 20 via their user terminal UT and sends an authentication request including the ID and password associated with their point account to an authentication server (not shown). If the authentication is successful, the member can access their point account. Alternatively, each member can first successfully complete a first authentication using a combination of a first ID and a first password to access a website provided by the service providing server 50 (e.g., an account for online shopping), and then successfully complete a second authentication using a combination of a second ID and a second password to access their point account via the website. Alternatively, the point management server 20 and the service providing server 50 can use authentication federation for the convenience of members. Here, authentication federation refers to a mechanism that allows a user to access multiple services with a single authentication process. When authentication federation is used, for example, a member can seamlessly access their point account managed by the point management server 20 by logging in to their own account on a website provided by the service providing server 50. However, when authentication federation is used, if unauthorized access occurs, there is a risk that multiple damages will occur between the federated services.
[0021] The information processing device 10 is configured as a server computer or a personal computer, and performs processing to select appropriate measures for each account when unauthorized access occurs to an account under its management. The information processing device 10 can operate in cooperation with a point management server 20. In the following, the information processing device 10 is described as being configured to operate in cooperation with the point management server 20 and managing accounts for a point service provided by the point management server 20, but is not limited to this. The password authentication processing described above may be executed by an authentication server (not shown), by the information processing device 10, or by the point management server 20.
[0022] (1-2) Information processing device (1-2-1) Functional configuration FIG. 2 is a block diagram showing an example of a functional configuration of the information processing device 10 according to an embodiment. The information processing device 10 includes a victim data acquisition unit 11, an analysis unit 12, a countermeasure selection unit 13, a victim data storage unit 14, a grade information storage unit 15, and a countermeasure policy storage unit 16.
[0023] The victim data acquisition unit 11, as an information acquisition unit, acquires member information (hereinafter also referred to as "victim data") relating to members whose accounts have been illegally accessed among the members under the management of the point management server 20 from the point management server 20 or its database (not shown), and stores the information in the victim data storage unit 14. Note that the terms "victim" or "victim member" are used here simply to refer to the member whose account has been illegally accessed, and do not matter whether or not actual monetary damage has occurred.
[0024] The analysis unit 12 reads out a fixed amount of victim data stored in the victim data storage unit 14 and analyzes the statistical bias of the victim data. In one embodiment, the analysis unit 12 analyzes the statistical bias by tallying the number of victimized members for each type of item included in the victim data and calculating statistics based on the tallying results. Here, "statistics" refers to general values obtained by summarizing the target data (e.g., victim data) using a statistical algorithm. In the following, as an example of statistics, we will use standard deviations for each type of item calculated using the number of victimized members of unauthorized access that occurred over a certain period of time as the population. Specific examples of calculation methods will be described later. Note that the present invention is not limited to this, and bias in victim data may be calculated using other statistics, such as the mean, median, maximum, and minimum values.
[0025] Based on the results of the analysis by the analysis unit 12, the countermeasure selection unit 13 selects countermeasures against unauthorized access for each member's account under the management of the point management server 20. The countermeasure selection unit 13 can output the results of the selection to any output destination (for example, the point management server 20, the service providing server 50, the user terminal UT, etc.). The countermeasure selection unit 13 can also analyze the victim data in chronological order to evaluate the effectiveness of the selected countermeasure (such as whether unauthorized access has decreased as a result of the countermeasure being implemented), and use the results in selecting subsequent countermeasures.
[0026] The victim data storage unit 14 stores the victim data acquired by the victim data acquisition unit 11.
[0027] The grade information storage unit 15 stores a correspondence table that specifies the relationship between statistics (for example, deviation values of types) that indicate statistical bias in the victim data and the risk level of password authentication.
[0028] The countermeasure policy storage unit 16 stores a correspondence table that specifies countermeasures according to the risk level of password authentication.
[0029] (1-2-2) Hardware configuration FIG. 3 is a block diagram showing an example of the hardware configuration of the information processing device 10. As shown in FIG. The information processing device 10 includes a CPU (Central Processing Unit) 101, a RAM (Random Access Memory) 102, a ROM (Read Only Memory) 103, an auxiliary storage device 104, an input device 105, an output device 106, and a communication interface (I / F) 107.
[0030] The processing functions of the victim data acquisition unit 11, analysis unit 12, and countermeasure selection unit 13 of the information processing device 10 are realized by the CPU 101 loading a program stored in the ROM 103 or auxiliary storage device 104 into the RAM 102 and executing the program. The CPU 101 is an example of a hardware processor that controls the overall operation of the information processing device 10. The hardware processor is not limited to a general-purpose processor such as the CPU 101, but may also be a dedicated processor such as an ASIC (Application Specific Integrated Circuit) or an FPGA (Field-Programmable Gate Array). The CPU 101 may be a single CPU or multiple CPUs.
[0031] The auxiliary storage device 104 includes a computer-readable storage medium that stores data in a nonvolatile manner, and may be, for example, a hard disk drive (HDD) or a solid state drive (SDD). The auxiliary storage device 104 may function as a storage unit including the victim data storage unit 14, the grade information storage unit 15, and the countermeasure policy storage unit 16 described above.
[0032] The input device 105 includes, for example, a keyboard and a mouse. The output device 106 includes a display device. The input device 105 and the output device 106 may be, for example, an integrated touch panel type device that combines a display device such as a liquid crystal panel with an input device such as a touch pad.
[0033] The communication interface 107 is an interface for communicating with an external device. The communication interface 107 includes, for example, a LAN (Local Area Network) port, is connected to a network NW using, for example, a LAN cable, and transmits and receives data to and from the external device via the network NW. The communication interface 107 may include a wireless module such as a wireless LAN module or a Bluetooth (registered trademark) module.
[0034] Regarding the specific hardware configuration of the information processing device 10, components can be omitted, replaced, or added as appropriate depending on the embodiment.
[0035] In conventional systems, when a malicious third-party attack (act) such as unauthorized access (unauthorized login) to an online service is detected, if ID and password are used as the primary protection method to protect the registered user and their information, 1) There is no way to logically and objectively infer or determine the attacker's intentions and targets based on probability theory. 2) Therefore, there was an issue of the need to uniformly require users to protect themselves by changing their passwords from the perspective of protecting users.
[0036] As a result, attackers end up asking users who were not the original targets of the attack to change their passwords. (a) the (unnecessary) proliferation of passwords that users must remember; or (b) The structure (construction) of the newly set password is complex and diverse, and it is easily conceivable that the user himself / herself will be unable to use the service because he / she will not be able to remember what structure (construction) of the password for which ID to use which service, or (c) By reusing passwords to avoid the above two problems, you increase the possibility (separate or future risk) that an attacker will be able to successfully impersonate you and gain access to another service on another occasion.
[0037] Therefore, a method that focuses on the following points is required. (1) Instead of requiring a widespread change of passwords, such as for everyone, only require the minimum number of users to change their passwords. (2) By not changing passwords for low-risk IDs without thinking, you can maintain security. (3) When changing passwords, we will provide advice (support) on highly secure (strong) structures (construction) to reduce the burden of designing passwords for each user and the risk of forgetting or confusing them. (4) Take multi-stage measures according to the attacker's intentions and goals and the risk (danger level) characteristics of the target (for example, suspending service to everyone at the most, or issuing a warning on the service site's homepage (login screen) at the least, etc.), (5) By understanding and tracking the attacker's attack methods and targets as they change and evolve depending on our defensive response. (6) We will strive to establish the most effective (highly attack-resistant) security for the entire "service and its users."
[0038] When unauthorized access is detected, the information processing device 10 according to the above embodiment analyzes the statistical bias in the member information of the victim member associated with the account that was unauthorizedly accessed, and selects appropriate measures for each account under its management based on the results of the analysis. This allows appropriate measures to be selected for each account based on actual trends in unauthorized access, rather than a uniform measure for all accounts, thereby achieving more effective security for the service and its users as a whole.
[0039] (2) Operation Next, the operation of the information processing device 10 configured as above will be described. Below, the operation of the information processing device 10 will be explained as being divided into a first stage, a second stage, and a third stage, but as will be described later, these do not necessarily have to be executed in order on the same timeline, and may be executed simultaneously, in a different order, or in a combination depending on the damage situation, etc.
[0040] In the following, the explanation is based on the assumption that unauthorized access to the point service member's account is detected by some method in the point management server 20, and that the point management server 20 notifies the information processing device 10. The detection of unauthorized access may be based, for example, on an alert being issued from the risk-based authentication system as described above, or on a report from the member himself / herself that there is a login history or point consumption that he / she does not remember, or on a report from the service providing server 50 that he / she has been subjected to a cyber attack.
[0041] (2-1) First Stage The first stage is mainly an operation that is expected as an "initial response," and involves taking measures at "points." Figure 4 is a flowchart showing an example of such an operation at the first stage.
[0042] First, in step S101, the information processing device 10 causes the victim data acquisition unit 11 to acquire member information (victim data) of the member associated with the account that has been subjected to unauthorized access, and stores the information in the victim data storage unit 14. The victim data acquisition unit 11 may receive victim data transmitted from the point management server 20 each time unauthorized access occurs, or may receive victim data from the point management server 20 periodically (for example, every hour or every day). Similarly, the victim data acquisition unit 11 may read victim data from the database of the point management server 20 at any timing.
[0043] Fig. 5 shows an example of victim data stored in the victim data storage unit 14. As mentioned above, this is merely an embodiment in which the point management server 20 provides a common point service, and the point management server 20 and the service providing server 50 use authentication collaboration. The victim data in Fig. 5 may include information related to the damage caused by unauthorized access, such as the time of occurrence, member ID, registration path, registered email domain, number of points held, number of times the structured password (structured PASS) has been updated, and ID registration date.
[0044] The time of occurrence includes information such as the date (YYYY / MM / DD) and hour, minute, and second (hh:mm:ss), and may be, for example, the time when the unauthorized login occurred or the time when the member reported the incident.
[0045] A member ID is identification information assigned to each member (account), and although a three-digit code is used here, it may be managed using any number of digits and any character string. Note that the member ID and the ID used for password authentication may be the same or different.
[0046] The registration path indicates which service a user used to register as a member to use the common point service. For example, a user can register as a member via a website provided by the point management server 20, or via a website provided by the service providing server 50. Alternatively, a user can request membership registration from one of the servers by asking a store clerk or other representative to enter information via an application form installed in a physical store, or by entering information themselves via a terminal installed in the physical store. Knowledge of the registration path can be useful, for example, in estimating through which path registered information was leaked or at what level an attack occurred (e.g., whether a lower-level store server or a higher-level management server was attacked).
[0047] The registered email domain is the domain information of the email address that the member has designated as the contact point for the common point service. Knowledge of the registered email domain can be useful in determining whether or not measures are required at the server level that manages the domain.
[0048] The number of points held is the balance of points held by each member. Points have economic value, so if the account of a member with a large number of points is accessed illegally, it could cause significant damage not only to the member himself, but also to the point service provider and affiliated businesses. It is also conceivable that members with a large number of points are more likely to be targeted by unauthorized access. Therefore, the number of points held can be an indicator of possible economic damage.
[0049] The number of structured password (structured PASS) updates is a parameter related to a system (not shown) that structures and manages passwords for the purpose of improving security (hereinafter also referred to as the "structured password management system"). The number of structured PASS updates refers to the number of times a password set by the member has been updated as a joint password created by the member and the system, with the system specifying the addition or deletion of some character string. In other words, when a member is requested to change their password for some reason, the system does not leave it up to the member to decide, but instead advises them on a structure with high security (password strength). This reduces the burden on each member in coming up with a new password and improves the security level of all members.
[0050] Here, a PASS update count of "0" means that the member's password remains the password set by the member himself / herself. Even if the password is changed periodically, the update count will be recorded as "0" unless the system is involved. For example, if the member's initial password is "PASSWORD," and the system instructs the member to "add the three-digit string "123" to the end," and the member complies and registers a new password "PASSWORD123," the update count will be "1." If the system then instructs the member (for example, after a certain period of time) to "delete the two-digit string from the beginning," and the member complies and registers a new password "SSWORD123," the update count will be "2." On the other hand, if the member ignores the system's instructions and registers a password of their own choosing, the update count will remain at 0 or be reset to 0. Depending on whether the number of structured PASS updates is "0" or "1 or more," it is possible to distinguish between members who have used the system and those who have not. This can be useful, for example, for inferring the route of information leakage and the attack method (e.g., list attack or brute force attack). Alternatively, it is possible to collect not only the most recent structured PASS update count but also the update history as time-series data. For example, if the update count remains "1" for a certain period of time, it can be assumed that the effectiveness of using the system is being seen. On the other hand, if it is "2 or more," it can be assumed that the member or their registration route has been attacked multiple times, making it a target of attacks. If the number of updates alternates between "0" and "1," it can be inferred that the member chose their own password without following system instructions (thus making it "0"), and then, after being attacked, changed it according to system instructions (thus making it "1"), and then what happened after that (for example, did it become "2" or something else) by aggregating time-series data for each pattern, and selecting countermeasures that take into account the effectiveness of the structured password management system.
[0051] When a structured password management system like the one described above is used, the risk of leaving password updates solely to members is reduced, while the system and members work together to improve diversity and security. Furthermore, by taking the number of structured PASSes into account in statistical bias analysis, it is possible to select countermeasures that take into account the personality and behavioral patterns of members. However, the use of a structured password management system like the one described above is optional, and if a structured password management system is not used, the number of structured PASS updates does not need to be included in the victim data.
[0052] The ID registration date indicates the date of membership registration. It can include not only the year, month, and day, but also the hour, minute, and second. Knowledge of the ID registration date can be useful in predicting the route of information leakage and the target of an attack.
[0053] As described above, the victim data shown in FIG. 5 is merely an example. The victim data may include more information or less information. The victim data may include personal information and network activity history information other than those described above. Also, as described above, the information processing device 10 can collect information about victims from any information collection source.
[0054] Next, in step S102, the analysis unit 12 reads victim data from the victim data storage unit 14 and analyzes the statistical bias of the victim data. More specifically, the analysis unit 12 reads victim data for a pre-specified period or amount, tallies the number of victim members for each type of item included in the read victim data (for example, time of occurrence, member ID, registration route, registered email domain, number of points held, number of structural PASS updates, ID registration date, etc.), and performs processing to calculate the statistics.
[0055] 6 to 10 show examples of the results of analysis processing by the analysis unit 21, each focusing on a different item of victim data.
[0056] FIG. 6 shows, as a first example, the results of an analysis process of statistical bias in victim data according to type regarding registration paths. Here, a standard deviation is calculated based on the number of victim members of each type as a statistic representing the statistical bias. Also, here, six types of services A to F are specified in advance as registration paths. The number of types is not limited to six. Services A to F may include the common point service itself (for example, a service provided by the point management server 20) and its affiliated services (for example, a service provided by the service providing server 50).
[0057] First, the analysis unit 21 extracts victim data ("total") relating to the most recent four days (here, October 28th to October 31st) as the first evaluation target group from the set of victim data that has been read out, and tallies the number of victim members ("number of cases") by type. In Figure 6, the total number of cases is 186 for service A, 126 for service B, 51 for service C, 30 for service D, 10 for service E, and 0 for service F, for a total of 403 cases.
[0058] Next, the analysis unit 21 calculates the deviation value for each type using the following formula, with the above total of 403 cases as the population.
number
number
number
[0059] In the example of FIG. 6, the analysis unit 21 calculated the mean value μ1 and standard deviation σ1 for the first evaluation group ("total") as follows: μ1=(186+126+51+30+10+0) / 6≒67.17 σ1=[{(186-67.17) 2 +(126-67.17) 2 +(51-67.17) 2 +(30-67.17) 2 +(10-67.17) 2 +(0-67.17) 2} / 6]^(1 / 2)≒67.09
[0060] Next, the analysis unit 21 calculates the deviation values of the services A to F using the average value μ1 and the standard deviation σ1 calculated as described above. For example, in the first evaluation target group, the deviation value T 1A , the standard deviation T for service B 1B , the standard deviation T for service C 1C , the deviation value T for service D 1D , the deviation value T for service E 1E , the standard deviation T for service F 1F were calculated as follows: In Figure 6, the highest standard deviation for each evaluation group is highlighted. T 1A ={(186-67.17) / 67.09}×10+50≒67.71 T 1B ={(126-67.17) / 67.09}×10+50≒58.77 T 1C ={(51-67.17) / 67.09}×10+50≒47.59 T 1D ={(30-67.17) / 67.09}×10+50≒44.46 T 1E ={(10-67.17) / 67.09}×10+50≒41.48 T 1F ={(0-67.17) / 67.09}×10+50≒39.99
[0061] The analysis unit 21 also calculates the average, standard deviation, and deviation value for each day's victim data from the data for the most recent four days, using the total number of victimized members (number of cases) for each day as the population, as described above, for the second to fifth evaluation groups. For example, on October 28, there were a total of three victim reports, with the average value being "0.50" and the standard deviation being "0.50," and the deviation values for services A to F were calculated as "60.00," "60.00," "60.00," "40.00," "40.00," and "40.00." Similarly, on October 29, there were a total of 100 victim reports, with service B obtaining the highest deviation value of "71.08." On October 30 and October 31, service A had the highest deviation value.
[0062] Which aspect of the results obtained as described above should be focused on can be specified in advance by an administrator of the information processing device 10, etc. For example, the registered route with the highest daily deviation value may be focused on, and measures may be taken daily for the accounts related to that registered route. In this case, in FIG. 6, the focus would be on services A to C on October 28, service B on October 29, service A on October 30, and service A on October 31. Similarly, the focus may be on the registered route with the highest total deviation value over four days, and measures may be taken. In the example of FIG. 6, the focus would be on service A, and measures would be taken. Furthermore, a determination may be made by combining the daily and total aggregation results. Such a determination can be made by setting in advance the aggregation period and the deviation value range (e.g., whether there is any type with a deviation value exceeding 60 in the four-day aggregation, whether there is any type with a deviation value exceeding 70 in the daily aggregation, etc.).
[0063] As a second example, Figure 7 shows the results of an analysis of statistical bias in victim data according to type, relating to registered email domains. In this example, if we focus on the total over a four-day period, for example, "bbb.ne.jp" in the second row shows the highest deviation value of "70.95," so we can set it up so that accounts that register the "bbb.ne.jp" domain are considered to be at high risk.
[0064] As a third example, Figure 8 shows the results of an analysis of statistical bias in victim data according to the type of points held. For example, when focusing on the total over four days, the second row, "10,001-30,000," shows the highest standard deviation of "68.59." In this case, it is possible to set the system to determine that accounts with point balances between "10,001-30,000" are at high risk, or to determine that the economic damage is low for accounts with point balances of "150,001" or more, since their standard deviation values are low throughout the four days.
[0065] As a fourth example, Figure 9 shows an example of the results of an analysis of statistical bias in victim data according to type regarding the number of times the structured PASS has been updated. As mentioned above, this item is an indicator of whether or not a password created jointly by the user and the system is being used. In this example, the standard deviation value for "0 times" is significantly high, so it can be determined that the security of the joint password is high (passwords other than joint passwords are less secure). If the standard deviation value for the column with the number of times the structured PASS has been updated "1 time" or more is high, a leak from the structured password management system itself is suspected.
[0066] As a fifth example, Figure 10 shows the results of an analysis of statistical bias in victim data according to type and ID registration period. Focusing on the total for four days, the deviation value for "within 361 to 720 days" is slightly higher than the others, so it is possible to set it so that accounts with the same registration period are deemed to be at high risk, or to set it so that the longer the service usage period, the higher the risk of leakage.
[0067] 6 to 10, examples of totaling the most recent four days or counting by day have been described, but these are merely examples, and any other period, such as one week or one month, may be set as the evaluation period. Victim data (data for the entire past period) relating to all unauthorized accesses that occurred under the management of the point management server 20 may be used as the evaluation period. Alternatively, statistics obtained from any recent period and statistics obtained from victim data for the entire past period may be used in combination.
[0068] In step S103, the measure selection unit 13 focuses on one of the items and selects a measure. For example, when focusing on the result of FIG. 7, the measure selection unit 13 selects a pre-specified measure, such as "display a warning message at login," for all accounts that have registered email addresses with the same domain as "bbb.ne.jp," which had the highest deviation value. The item to focus on may be determined by calculating and comparing deviation values for multiple items (for example, the item including the type with the highest deviation value), or may use a pre-specified priority (for example, by looking in the order of registration path, registered domain, number of points held, number of times structure PASS was updated, and time of ID registration).
[0069] As described above, the countermeasure selection unit 13 can focus on any of the items and select a countermeasure for the type with the highest deviation value. Alternatively, the countermeasure selection unit 13 can determine the risk level of the type according to the deviation value and select a countermeasure according to the risk level. As an example of such a method, a method in which the countermeasure selection unit 13 selects a countermeasure using a correspondence table will be described below.
[0070] 11 shows an example of a correspondence table that specifies the correspondence between deviation values and risk levels, which can be used by the countermeasure selection unit 13. According to FIG. 11, if the deviation value exceeds 70, it is defined as "Grade 1," which is the highest level of risk, and if the deviation value is less than 45, it is defined as "Grade 6," which is the lowest level of risk. Such a correspondence table can be arbitrarily set by an administrator of the information processing device 10 or the like, and can be stored in the grade information storage unit 15.
[0071] FIG. 12 shows an example of the risk level (grade) determined by the countermeasure selection unit 13 based on the correspondence table shown in FIG. 11. FIG. 12 focuses on the registered email domain as an item and shows an example different from that shown in FIG. 7. The analysis unit 12 calculated a deviation value for each of six types of registered email domain. Then, the countermeasure selection unit 13 determined the risk level for each based on the correspondence table. For example, the registered email domain "abc.co.jp" has a deviation value of "64.00", which corresponds to "Grade 2" according to the correspondence table in FIG. 11. Thereafter, the countermeasure selection unit 13 selects a countermeasure according to each risk level, again using the correspondence table.
[0072] 13 shows an example of a correspondence table that can be used by the countermeasure selection unit 13 and specifies the correspondence between the risk level and the countermeasure to be taken. According to FIG. 13, for "Grade 1," which is the highest risk level, "account suspension" is selected for the target account. On the other hand, for "Grade 6," which is the lowest risk level, the countermeasure of not taking any particular countermeasure is selected. Such a correspondence table can be arbitrarily set by an administrator of the information processing device 10 or the like, and can be stored in the countermeasure policy storage unit 16.
[0073] Based on the correspondence table of Figure 13, in the example of Figure 12, the countermeasure selection unit 13 selects "Grade 2 = login suspension" for an account having the registered email domain "abc.co.jp". Similarly, the countermeasure selection unit 13 selects "Grade 1 = account suspension" for an account having "def.com", "Grade 3 = point usage suspension" for an account having "ghi.ne.jp", "Grade 6 = no action" for an account having "jkl.co.jp", "Grade 5 = site warning" for an account having "mno.ne.jp", and "Grade 4 = email warning" for other accounts. Note that the correspondence tables of Figures 11 and 13 may be set and stored integrally.
[0074] The countermeasure selection unit 13 can output the results of the above selection to any output destination. For example, the countermeasure selection unit 13 may be configured to send all of the results of the above selection to the point management server 20, which then executes the selected countermeasure. For example, in the example of FIG. 12, the point management server 20 receives the selection results, extracts accounts with the registered email domain "abc.co.jp," and executes the countermeasure "login suspension" for the accounts. The point management server 20 may also notify the service providing server 50 as needed to execute the countermeasure. Alternatively, the countermeasure selection unit 13 may change the output destination of the selection results depending on the selected countermeasure. For example, the countermeasure selection unit 13 may send account information for which "login suspension" has been selected to the point management server 20, and send account information for which "site warning" has been selected to both the point management server 20 and the service providing server 50. If "email warning" is selected, the countermeasure selection unit 13 may be configured to directly send a message to the user terminal UT. Alternatively, the information processing device 10 may be configured to execute the countermeasure selected by the countermeasure selection unit 13.
[0075] While FIG. 12 illustrates the registered email domain, the countermeasure selection unit 13 can also perform the same risk assessment and countermeasure selection for items other than the registered email domain. However, the following exceptional judgment may be made for the "Structured PASS Update Count" item. As described above, "Update Count = 0" indicates that the password belongs to a member who did not use the structured password management system. Therefore, if the deviation value for "0 times" is high, the unauthorized access is likely due to information leakage from an affiliated service that does not use the system. Therefore, the countermeasure selection unit 13 can send a message to the affiliated service warning the affiliated service or urging it to investigate whether there has been an attack or damage, and select the countermeasure specified in FIG. 13 for all accounts corresponding to "0 times." On the other hand, if the deviation value for any of the "1 or more times" items is high, this can be treated as an abnormal situation due to the risk of information leakage from the structured password management system. This corresponds to the situation indicated by "Grade 0" in FIG. 13. When "Grade 0" occurs, the countermeasure selection unit 13 can select the countermeasure of suspending all services, not just for specific accounts.
[0076] As described above, in the first stage, measures can be taken at "points" based on the deviation score results for each item. The first stage is intended as an "initial response" to take immediate action when an issue occurs. If convergence is not expected in the first stage, the system can move on to the second stage. As an example, if the deviation score for the item in question decreases after implementing the above measures, it can be considered convergence. For example, if the deviation score is trending downward, it can be determined to be convergence (or the monitoring stage), and if it is level or trending upward, it can be determined that additional measures are necessary.
[0077] (2-2) Second Stage In the second stage, we identify the subjects with combinations of high standard deviation levels among the selected items and implement measures on a "wide scale." Fig. 14 is a flowchart showing an example of such second stage operation. Note that the same processes as those in Fig. 4 are denoted by the same reference numerals as in Fig. 4, and detailed explanations thereof will be omitted.
[0078] First, in step S101, the information processing device 10 causes the victim data acquisition unit 11 to acquire victim data and stores the victim data in the victim data storage unit 14.
[0079] Next, in step S102, the analysis unit 12 reads out victim data from the victim data storage unit 14, aggregates the data by item, and calculates the deviation value for each type.
[0080] Then, in step S203, the countermeasure selection unit 13 performs cross-tabulation for any number of items and selects a countermeasure.
[0081] Figure 15 shows an example of such a cross-tabulation. As explained in the first stage, the number of victimized members of each type is tallied for each item included in the victim data, and a standard deviation is calculated. Then, any two items (three or more items can be selected). In the example of Figure 15, registration path and registered email domain are selected as the items, and cross-tabulation is performed for each grade. The "Number of Targets" in Figure 15 is an example of a cross-tabulation result, and represents the total number of targets of the same grade for each item. For example, for Grade 1, the sum of the number of accounts (targets) registered via "Service X" and the number of accounts (targets) with the email domain "def.com" is calculated as "300,000." The number of targets represents the range of attack risk.
[0082] In the second stage, the countermeasure selection unit 13 may select a Grade 1 response for the target user "300,000," i.e., a countermeasure of suspending the account. Alternatively, the countermeasure selection unit 13 may calculate the deviation value again based on the number of targets obtained above, and select a countermeasure according to the deviation value after cross-tabulation. Here, in the second stage as well, the countermeasure selection unit 13 may select a countermeasure based on the correspondence table of FIG. 13 as a countermeasure according to the risk grade.
[0083] FIG. 16 shows another example of a correspondence table between risk levels and countermeasures to be taken. The correspondence table in FIG. 16 further subdivides each grade, allowing for selection of whether the countermeasure is high or low. As an example, whether the countermeasure is high or low can be selected based on the number of affected individuals (scope of impact), and the high or low determination can be automatically made by setting a threshold value. Alternatively, the correspondence table in FIG. 16 can be used for evaluation after some time has passed since the unauthorized access occurred and a certain trend in the unauthorized access has become apparent. For example, if the deviation value trend for a certain monitoring cycle (e.g., the average every three days) remains flat, the countermeasure can be selected to be one level higher if it rises, or one level lower if it falls.
[0084] For example, for Grade 1, the standard measure is "1B" - "Suspend only the target account," but if you choose a measure one level higher, "1A" - "Suspend all services," is selected, and if you choose a measure one level lower, "1C" - "Suspend logins only for the target account," is selected.
[0085] Similarly, for Grade 2, if the damage situation remains unchanged after one week, while the standard measure "2B" "Login Suspension" is in place, "2A" "Account Suspension" can be implemented, and if the damage situation has decreased after one week, it can be shifted to "2C" "Point Usage Suspension." Alternatively, if the damage situation further decreases, the measure itself can be lifted.
[0086] It is also possible to make adjustments across grades using the correspondence table of FIG. 16. For example, if there are other options within each grade, the countermeasure selection unit 13 can raise or lower the level within that range. If the conditions for further raising or lowering the highest or lowest level countermeasure for each grade are met while the highest or lowest level countermeasure for each grade is being implemented, the countermeasure can select a higher or lower level countermeasure of the same measure in the grade above or below it. For example, in the example of FIG. 16, if the damage caused by unauthorized access escalates while a countermeasure of grade "2A" is being implemented, there is no higher level option within grade "2," so the countermeasure is upgraded to grade "1." Here, in this example, the countermeasure for grade "2A" and the countermeasure for grade "1B" that are being implemented are both the same, "account suspension (target account only)," so the countermeasure selection unit 13 can select "1A," which is one level above grade "1B." Conversely, if the damage caused by unauthorized access is reduced when a countermeasure of grade "1C" has been selected, the countermeasure can be transitioned to grade "2C," which is one level below grade "2B," which is the same countermeasure (login suspension) as grade "1C." Such logic across grades may be constructed by comparing the value of the target, such as the total number of damage cases, the number of damage cases for that item, or the total number of affected users for that item, with a preset threshold. It is not limited to the above example; it is also possible to simply downgrade from "1C" to "2A" and select countermeasures, or conversely, to upgrade from "2A" to "1C." If the damage caused by unauthorized access escalates, the final result will be "suspension of all services," which is grade "0."
[0087] Needless to say, cross-tabulation using combinations other than "registration path" and "email domain" is also possible. The items to be selected for cross-tabulation may be specified in advance, or the two items with the highest maximum deviation values may be selected.
[0088] As for the second stage, the measure selection unit 13 can also output the selection result to any output destination.
[0089] As described above, in the second stage, cross-tabulation of deviation score results by item allows for "area" countermeasures to be taken. In particular, the second stage, as a "continuous response," evaluates which users are at high risk of attack over time, making it possible to upgrade or downgrade countermeasures depending on the scale of the affected users (scope of impact). For example, if a high deviation score item other than the items addressed above emerges, it can be assumed that the impact of the continuous response is widespread, and the process can proceed to the third stage. Alternatively, a decision can be made based on the progression of changes in the deviation scores, similar to the convergence decision in the first stage.
[0090] (2-3) Third Stage In the third stage, a "depth" measure is taken, in which the total or average points held by the target users are added to the cross-tabulation from the second stage to determine the impact (degree of influence). Fig. 17 is a flowchart showing an example of such a third stage operation. Note that the same processes as those in Fig. 4 are denoted by the same reference numerals as in Fig. 4, and detailed explanations thereof will be omitted.
[0091] First, in step S101, the information processing device 10 causes the victim data acquisition unit 11 to acquire victim data and stores the victim data in the victim data storage unit 14.
[0092] Next, in step S102, the analysis unit 12 reads out victim data from the victim data storage unit 14, tallying the data by item, and calculating the deviation value for each type.
[0093] Next, in step S303, cross-tabulation is performed for any number of items by the measure selection unit 13. This process is the same as that explained as step S203 in the second stage.
[0094] Next, in step S304, the measure selection unit 13 adds another index, determines the impact, and selects a measure.
[0095] FIG. 18 shows an example of adding such an indicator. Here, after cross-tabulation by email domain and registration route, the total number of points (total P) and the average number of points (average P) held by the target person are calculated. The number of targets represents the range of risk of being attacked, the total number of points represents the business impact, and the average number of points represents the personal impact. Here, the countermeasure selection unit 13 is configured to select countermeasures using the number of targets of this business impact and personal impact as the criteria for judgment.
[0096] For example, Grade 6 is considered low risk, but the total and average points are high, so it is possible to raise the countermeasures by one level. For example, a threshold value for the number of points can be set, and if the threshold is exceeded, the countermeasure within the grade can be raised by one level (e.g., raising from Grade 6B to Grade 6A, as in Figure 16). Similarly, Grade 3 is considered medium risk, but the total and average points are low, so it is possible to select a countermeasure such as lowering the countermeasure within the grade by one level. The determination of whether to raise or lower the countermeasure can also be performed automatically by the countermeasure selection unit 13 by setting a threshold value. For example, if there are two Grade 1 types (above 70 standard deviation) in a certain item, a threshold value corresponding to the number of those types can be set and the determination can be made automatically. As an example, the number of subjects can be divided by the number of types corresponding to Grade 1, and a threshold value based on this number can be used to determine whether to raise or lower the countermeasure. In the example of Figure 18, for the items selected for cross-tabulation, "Registration route" and "Email domain," there are three items in Grade 3: "Service Y," "Service W," and "ghi.ne.jp." Therefore, the number of subjects is divided by 3, and the result is judged using a threshold value to determine whether the grade is rising or falling.
[0097] In the above example, the number of points held was focused on as an "indicator" to be added to the cross-tabulation, but other indicators may also be used. Examples of items such as "Structure PASS Update Count" and "Registration Date," which are given as examples in Figures 9 and 10, may also be used, or other information may be used. For example, if purchase data that contributed to each member's point accrual is accumulated, the cumulative purchase amount may be used as an indicator. Alternatively, if the member information includes purchase data for each service, purchase store, and each company brand, the purchase amount (sales amount) for each service, purchase store, and each company brand may be used as an indicator.
[0098] As described above, in the third step, measures can be taken with "depth" by adding information about points held to the cross-tabulation results. In other words, in this example, if the horizontal axis represents the number of subjects by attribute and the vertical axis is weighted based on an arbitrary indicator (for example, point damage, personal information leaks, or a combination of both, as mentioned above), the event with the largest vertical x horizontal area can be quickly determined as a priority and measures can be taken. This allows for detailed evaluation and decisions, including the suspension of services, to prevent the damage from spreading. Needless to say, damage is not limited to economic damage, but also includes personal information leaks and logical damage resulting from personal information leaks. In other words, measures based on a variety of perspectives can be selected depending on what indicators are added to the cross-tabulation as "depth."
[0099] As for the third stage, the measure selection unit 13 can also output the selection result to any output destination.
[0100] Although the first stage of the initial response is described as proceeding to the second stage if no convergence is observed, it is also possible to simultaneously implement the first and second stages depending on the scale of the damage. For example, the first stage may be implemented early as an initial response (symptomatic treatment), the second stage may be implemented by examining the results of the first stage and monitoring trends in unauthorized access (implementing countermeasures), and the third stage may be implemented by examining the impact (impact on business, e.g., a significant increase in the amount of damage or the number of victimized members) of the results of the first and second stages. Therefore, the process is not necessarily limited to the first stage, followed by the second stage, and finally the third stage. The processes may be implemented simultaneously and in parallel, taking into account the responses of the previous stages according to different criteria. In other words, the information processing device 10 can execute each of the above-described processes in parallel as victim data accumulates, i.e., as more information is gathered.
[0101] (3) Effects As described above in detail, information processing device 10 according to one embodiment of the present invention includes victim data acquisition unit 11 that acquires member information of victim members whose accounts have been subject to unauthorized access among members of a service that manages accounts through password authentication, analysis unit 12 that analyzes statistical bias in the member information, and countermeasure selection unit 13 that selects countermeasures against unauthorized access for each account managed by the service based on the results of the analysis. This makes it possible to select more appropriate countermeasures for each account based on actual trends in unauthorized access, rather than a uniform countermeasure for all accounts under management, thereby enabling more effective security to be established for the service and all of its users.
[0102] (4) Other embodiments The present invention is not limited to the above-described embodiment. For example, in the above-described embodiment, the information processing device 10 mainly manages accounts related to a common point service. However, the information processing device 10 may also manage accounts related to a service that is not general or comprehensive but has a limited scope, such as a unique point system. In this case, some of the information included in the victim data illustrated in FIG. 5 may be omitted. Alternatively, the victim data may include other member information (e.g., attribute information such as residence, gender, and age). In this case, statistical bias analysis is also possible. For example, a deviation score may be calculated for each prefecture or municipality registered as an address to determine whether members in specific residences are more likely to be victims. Cross-tabulation based on the gender and age of victim members and further depth tabulation based on activity history related to services on the network (e.g., browsing history of specific websites, frequency of posting on social media, etc.) may enable countermeasures that take into account the purpose and target of unauthorized access. Note that if the victim data includes at least three types of information, processing similar to the first, second, and third stages described above can be performed.
[0103] In the above embodiment, the information processing device 10 is described as operating in cooperation with the point management server 20, but this is not limited thereto. The information processing device 10 can collect victim data from any device that manages personal information and perform processing similar to that described in the above embodiment based on the type of any item included in the victim data. For example, the information processing device 10 can collect information from any institution that manages personal information, such as financial institutions (banks, securities companies, insurance companies, etc.), credit card companies, brick-and-mortar or online shops, membership-based community services, information management services, other online services, transportation facilities, government agencies, medical institutions, and educational institutions. The information processing device 10 may also accept input of personal information from the victim himself / herself.
[0104] The functional units of the information processing device 10 may be distributed across multiple devices, and these devices may perform processing in cooperation with each other. Furthermore, each functional unit may be realized using a circuit. The circuit may be a dedicated circuit for realizing a specific function, or a general-purpose circuit such as a processor.
[0105] Furthermore, the flow of each process described above is not limited to the procedures described, and the order of some steps may be changed, or some steps may be performed simultaneously in parallel. Furthermore, the series of processes described above do not need to be performed consecutively, and each step may be performed at any timing.
[0106] The above-described method can be stored as a program (software means) that can be executed by a computer on a recording medium (storage medium), such as a magnetic disk (floppy disk, hard disk, etc.), optical disk (CD-ROM, DVD, MO, etc.), or semiconductor memory (ROM, RAM, flash memory, etc.), or can be transmitted and distributed via a communication medium. The program stored on the medium also includes a configuration program that configures the software means (including not only execution programs but also tables and data structures) that the computer executes. The computer that realizes the above-described device reads the program stored on the recording medium and, in some cases, configures the software means using the configuration program, and executes the above-described processing by having the operation controlled by this software means. The term "recording medium" as used herein is not limited to a storage medium for distribution, but also includes a storage medium such as a magnetic disk or semiconductor memory installed inside the computer or in a device connected via a network.
[0107] In addition, various modifications can be made to the timing and method of collecting each piece of data, the method of analysis, etc., without departing from the spirit of the present invention.
[0108] It should be noted that this invention is not limited to the above-described embodiments, and various modifications can be made in the implementation stage without departing from the spirit of the invention. Furthermore, the embodiments may be implemented in appropriate combinations, in which case the combined effects can be obtained. Furthermore, the above-described embodiments include various inventions, and various inventions can be extracted by combining selected elements from the disclosed elements. For example, if the problem can be solved and the desired effect can be obtained even if some elements are deleted from all elements shown in the embodiments, the configuration from which these elements are deleted can be extracted as an invention. [Explanation of symbols]
[0109] 1...system, 10...information processing device, 11...victim data acquisition unit, 12...analysis unit, 13...countermeasure selection unit, 14...victim data storage unit, 15...grade information storage unit, 16...countermeasure policy storage unit, 20...point management server, 50...service provision server.
Claims
1. a member information acquisition unit that acquires member information regarding a victim member whose account has been illegally accessed, among members of a service that manages accounts through password authentication; an analysis unit that analyzes statistical bias in the member information; a countermeasure selection unit that selects a countermeasure against the unauthorized access for each account managed by the service based on a result of the analysis; An information processing device comprising:
2. the analysis unit calculates the standard deviation of the number of victimized members for each item included in the member information, thereby analyzing the statistical bias of the member information; the countermeasure selection unit determines a risk level corresponding to the statistical bias of the member information based on the correspondence relationship between the deviation value and the risk level of the password authentication, and selects a countermeasure according to the risk level. The information processing device according to claim 1 .
3. the analysis unit analyzes statistical bias in the member information for each of at least two items included in the member information; the countermeasure selection unit selects the countermeasure by combining a risk level corresponding to a statistical bias of the member information for each of the at least two items. The information processing device according to claim 2 .
4. the countermeasure selection unit selects the countermeasure based on a statistical bias in the member information and an economic value related to the victim member; 4. The information processing device according to claim 2 or 3.
5. the countermeasure selection unit selects, for at least some of the accounts managed by the service, at least one of suspending all or part of the services related to the accounts, suspending password authentication related to the accounts, or notifying information indicating a risk level of password authentication for the accounts, as the countermeasure; The information processing device according to claim 1 .
6. A process of obtaining member information about a victim member whose account has been illegally accessed among members of a service that manages accounts through password authentication; A process of analyzing the statistical bias of the member information; selecting a countermeasure against the unauthorized access for each account managed by the service based on the results of the analysis; An information processing method comprising:
7. A program that causes a computer to execute processing by each unit of the device according to any one of claims 1 to 5.
Citation Information
Patent Citations
Method and device for evaluating security and method and device for aiding preparation of security measure
JP2001101135A
Data protection method and authentication method and program
JP2005275775A
End-user risk management
JP2008507757A
Unit and method for supporting information security measure decision, and computer program
JP2009110177A
Automatic transaction system
JP2009217771A