Information processing device, information processing method, and program
The information processing device and method address the limitation of predefined cyber-attack scenarios by generating features, applying a determination model, and re-learning to adapt to new attacks, enabling effective scenario derivation.
Patent Information
- Application Number
- JP2024034491
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-03-07
- Publication Date
- 2025-09-19
AI Technical Summary
Existing technologies struggle to determine incident scenarios for cyber attacks that have not been predefined, as they require predefining system logs and countermeasures, limiting their applicability to known attack types.
An information processing device and method that generates features from target data using a cyber-attack victim system, applies an incident scenario determination model to derive labels, and performs re-learning to adapt to new attack scenarios through clustering and label association.
Enables the derivation of incident scenarios even for unforeseen cyber attacks, enhancing the ability to respond effectively by clarifying the incident picture.
Smart Images

Figure 2025136207000001_ABST
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to an information processing device, an information processing method, and a program for deriving an incident scenario. [Background technology]
[0002] The damage caused by cyber attacks is becoming increasingly severe worldwide. When a company is attacked by a cyber attack, it can suffer direct damage to its business, such as information leaks and system shutdowns, as well as indirect damage, such as the attacker using the company's servers as a springboard. Furthermore, the cyber attacks mentioned above can cause secondary damage, such as a loss of credibility due to a damaged corporate image and the suspension of business transactions.
[0003] Furthermore, if victim organizations respond ad hoc without clarifying the full picture of the cyberattack (incident scenario), they may be subject to another cyberattack. Furthermore, there is data that shows that 80% of organizations that have been attacked by a cyberattack are attacked a second time. Therefore, it is important for victim organizations to clarify the incident scenario and take appropriate measures.
[0004] As a related technique, Patent Document 1 discloses an incident analysis device that analyzes cyber-attack precursors (incidents) and identifies a predicted attack path that will progress from the time of analysis. The incident analysis device of Patent Document 1 receives an alert including information on an attack source node and an attack destination node, and identifies an attack path including the attack source node and the attack destination node based on the information in the received alert. Next, it searches a response information table for predicted attack paths including the identified attack path, and obtains from the response information table one or more response counts associated with each of one or more searched predicted attack paths. Next, it sets a priority based on the obtained one or more response counts, and selects a predicted attack path from the searched one or more predicted attack paths based on the set priority. [Prior art documents] [Patent documents]
[0005] [Patent Document 1] Japanese Patent Application Publication No. 2019-050477 Summary of the Invention [Problem to be solved by the invention]
[0006] The above-mentioned technology determines and outputs an incident scenario based on information on information leaks, system shutdowns, the final damage, recent events, various system logs at the time the damage occurred, and responses to cyber attacks that were implemented.
[0007] However, the above-mentioned technology requires predefining system logs linked to various cyber-attack methods and collecting in advance the details of countermeasures to be taken when an actual cyber-attack occurs. Therefore, it is not possible to determine an incident scenario from information that includes cyber-attacks that are not predefined or that have not been dealt with in the past.
[0008] One example of the objective of the present disclosure is to derive incident scenarios even when a cyber attack that has not been predefined occurs. [Means for solving the problem]
[0009] In order to achieve the above object, an information processing device according to one aspect of the present disclosure includes: a feature generation unit that generates first features using a group of target data acquired from a victim system that has been subjected to a cyber-attack in an operation phase; a determination unit that inputs the first feature into an incident scenario determination model that outputs a label corresponding to an incident scenario when an input and a feature of an incident are similar, acquires a label corresponding to the first feature from the incident scenario determination model, and determines an incident scenario corresponding to the label based on the acquired label corresponding to the first feature; The present invention is characterized by having the following.
[0010] In order to achieve the above object, an information processing method according to one aspect of the present disclosure includes: The information processing device In the operation phase, a first feature is generated using a set of target data obtained from a system that has been victimized by a cyber attack, inputting the first feature into an incident scenario determination model that outputs a label corresponding to an incident scenario when an input and a feature of an incident are similar, and acquiring a label corresponding to the first feature from the incident scenario determination model; determining an incident scenario corresponding to the label based on the acquired label corresponding to the first feature; It is characterized by:
[0011] Furthermore, in order to achieve the above object, a program according to one aspect of the present disclosure includes: On the computer, In the operation phase, a first feature is generated using a set of target data obtained from a system that has been victimized by a cyber attack, inputting the first feature into an incident scenario determination model that outputs a label corresponding to an incident scenario when an input and a feature of an incident are similar, and acquiring a label corresponding to the first feature from the incident scenario determination model; determining an incident scenario corresponding to the label based on the acquired label corresponding to the first feature; It is characterized by: [Effects of the Invention]
[0012] As described above, according to the present disclosure, an incident scenario can be derived even when a cyber attack that has not been predefined occurs. [Brief explanation of the drawings]
[0013] [Figure 1] FIG. 1 is a diagram illustrating an example of a system according to the first embodiment. [Figure 2]FIG. 2 is a diagram illustrating an example of the configuration of the learning unit according to the first embodiment. [Figure 3] FIG. 3 is a diagram illustrating an example of the event log management information. [Figure 4] FIG. 4 is a diagram illustrating an example of registry management information. [Figure 5] FIG. 5 is a diagram illustrating an example of generating feature amounts. [Figure 6] FIG. 6 is a diagram illustrating an example of incident scenario management information. [Figure 7] FIG. 7 is a diagram illustrating an example of feature amount management information. [Figure 8] FIG. 8 is a diagram illustrating an example of the configuration of the determination unit according to the first embodiment. [Figure 9] FIG. 9 is a diagram for explaining the determination of an incident scenario. [Figure 10] FIG. 10 is a diagram illustrating an example of temporary feature management information. [Figure 11] FIG. 11 is a diagram illustrating an example of the configuration of the relearning unit according to the first embodiment. [Figure 12] FIG. 12 is a diagram illustrating an example of the classification unit and the extraction unit. [Figure 13] FIG. 13 is a diagram illustrating an example of the second teacher data generating unit. [Figure 14] FIG. 14 is a diagram illustrating an example of the operation of the information processing device (learning unit) according to the first embodiment. [Figure 15] FIG. 15 is a diagram illustrating an example of the operation of the information processing device (determination unit) in the first embodiment. [Figure 16] FIG. 16 is a diagram illustrating an example of the operation of the information processing device (relearning) according to the first embodiment. [Figure 17] FIG. 17 is a diagram illustrating an example of a system according to the second embodiment. [Figure 18] FIG. 18 is a diagram illustrating an example of the configuration of the determination unit according to the second embodiment. [Figure 19] FIG. 19 is a diagram illustrating an example of intelligence management information. [Figure 20] FIG. 20 is a diagram illustrating an example of matching and generation of third training data. [Figure 21] FIG. 21 is a diagram illustrating an example of the operation of the information processing device (determination unit) in the second embodiment. [Figure 22] FIG. 22 is a diagram illustrating an example of a computer that realizes the information processing device according to the first and second embodiments. DETAILED DESCRIPTION OF THE INVENTION
[0014] Hereinafter, embodiments will be described with reference to the drawings. In the drawings described below, elements having the same or corresponding functions are denoted by the same reference numerals, and repeated description thereof may be omitted.
[0015] (Embodiment 1) The configuration of a system (security incident scenario determination system) 100 according to the first embodiment will be described with reference to Fig. 1. Fig. 1 is a diagram illustrating an example of the system according to the first embodiment.
[0016] [System Configuration] The system 100 in the first embodiment includes an information processing device 10 and a storage device 20. The information processing device 10 and the storage device 20 are connected via a network.
[0017] The information processing device 10 is, for example, a CPU (Central Processing Unit), a programmable device such as an FPGA (Field-Programmable Gate Array), a GPU (Graphics Processing Unit), or a circuit equipped with one or more of these, a server computer, a personal computer, a mobile terminal, etc.
[0018] The storage device 20 is a database, a server computer, a circuit having a memory, etc. The storage device 20 stores, for example, at least information such as an incident scenario determination model 21, management data 22, etc.
[0019] 1, the storage device 20 is provided outside the information processing device 10, but it may also be provided inside the information processing device 10. The storage device 20 stores an incident scenario determination model 21 and management data 22. The storage device 20 may also be configured using multiple storage devices.
[0020] The network is a general communication network constructed using communication lines such as the Internet, a LAN (Local Area Network), a dedicated line, a telephone line, an in-house network, a mobile communication network, Bluetooth (registered trademark), or Wi-Fi (Wireless Fidelity) (registered trademark).
[0021] [Device configuration] The information processing device 10 includes a learning unit 11, a determination unit 12, and a re-learning unit 13. The learning unit 11 tunes (constructs) an incident scenario determination model (supervised learning model). The determination unit 12 determines an incident scenario using the incident scenario determination model. The re-learning unit 13 re-learns the incident scenario determination model.
[0022] In the example of Figure 1, the information processing device 10 includes a learning unit 11, a judgment unit 12, and a relearning unit 13, but the functions of the learning unit 11, the judgment unit 12, and the relearning unit 13 may be divided among multiple information processing devices.
[0023] Furthermore, the learning unit 11 may be a learning device, the determination unit 12 may be a determination device, and the relearning unit 13 may be a relearning device. Alternatively, the learning unit 11 may be a learning device, and the determination unit 12 and the relearning unit 13 may be separate determination / relearning devices.
[0024] About the learning unit (learning device: incident scenario judgment model learning device) Fig. 2 is a diagram illustrating an example of the configuration of the learning unit in embodiment 1. As shown in Fig. 2, the learning unit 11 includes a feature amount generating unit 11a, a first teacher data generating unit 11b, and a model learning unit 11c.
[0025] The feature generator 11a generates a feature (second feature) using a group of past data previously acquired from a victim system that has been subjected to a cyber-attack. Note that a cyber-attack also includes a pseudo-cyber-attack (pseudo-attack), and the system that has performed the pseudo-attack is also considered a victim system.
[0026] The feature generating unit 11a will be specifically described below. First, the feature generating unit 11a refers to the management data 22 stored in the storage device 20, and acquires a group of past data included in the management data 22.
[0027] In the case of Windows (registered trademark), the data group is, for example, an event log, a registry, etc. In the first embodiment, the event log is managed by event log management information, and the registry is managed by registry management information. In the case of UNIX (registered trademark), the data group is, for example, a system log, a server log, etc.
[0028] FIG. 3 is a diagram illustrating an example of event log management information. The event log management information in FIG. 3 is a table for managing Windows event logs. In the example of event log management information in FIG. 3, each record indicates a Windows event log. The record in FIG. 3 illustrates an event ID "4625" indicating a failed logon attempt and an event ID "4624" indicating a successful logon attempt. However, Windows event logs other than the above-mentioned event IDs are also stored in the event log management information. It is also possible to limit the event IDs to be stored in advance. For example, the event IDs may be limited to those that often appear during an attack.
[0029] Fig. 4 is a diagram illustrating an example of registry management information. The registry management information in Fig. 4 is a table for managing registry information. In the example of registry management information in Fig. 4, each record indicates registry information. In the record in Fig. 4, the registry information includes, for example, time, registry key, registry value, and registry data.
[0030] Next, the feature generator 11a aggregates the acquired data groups, sorts them in chronological order, and generates feature amounts (second feature amounts). The generation of feature amounts will be described with reference to Fig. 5. Fig. 5 is a diagram for explaining an example of the generation of feature amounts. Note that the event log management information 5A in Fig. 5 (the event log management information in Fig. 3) is obtained by dividing the aggregated data groups by time unit.
[0031] In the example of FIG. 5, a feature 5B (one-hot vector) is generated for each record based on the contents of each event ID in the event log management information 5A. Specifically, if the event ID in the event log management information 5A in FIG. 5 is 4624, the feature "value 1" is set to "1." Also, if the event ID is 4625, the feature "value 2" is set to "1." Furthermore, if there are event IDs 4624 and 4625, the feature "value N" is set to "1." As a result, a feature 5B (one-hot vector) corresponding to the event log management information 5A is generated.
[0032] The first teacher data generation unit 11b generates first teacher data by associating the generated feature (second feature) with a label corresponding to a predefined incident scenario. Here, the incident scenario and the label are managed by incident scenario management information.
[0033] Figure 6 is a diagram illustrating an example of incident scenario management information. The incident scenario management information in Figure 6 is a table for managing incident scenarios. In the example of Figure 6, incident scenarios are predefined and managed for each combination of labels: "T1," "T2," "T3," ... "T1, T2," "T1, T2, T3." Also, in the example of Figure 6, the incident scenarios use a comprehensive framework of cyber attack techniques, such as MITRE ATT&CK. However, incident scenarios are not limited to MITRE ATT&CK.
[0034] The first teacher data generation unit 11b will be described in detail. First, the first teacher data generation unit 11b collects the features (second features) generated by the feature generation unit 11a, and generates first teacher data by associating each second feature with a label (for example, T1, T2, etc.). However, the same label is associated with the same collected features. Note that a collection of sets of second features and labels becomes the first teacher data. Next, the first teacher data generation unit 11b stores the generated first teacher data in the storage device 20. The first teacher data is stored as feature management information in the management data 22 of the storage device 20.
[0035] FIG. 7 is a diagram illustrating an example of feature management information. The feature management information in FIG. 7 is a table for managing features. In the example of FIG. 7, the feature management information associates an incident ID, a feature, and a label. The incident ID is information for identifying an incident. In the example of FIG. 7, "A" is assigned to the incident ID. Features are associated with each incident in chronological order. In the example of FIG. 7, features ("Value 1", "Value 2", "Value 3", ..., "Value N") are illustrated as one-hot vectors for each record in chronological order ("ID": "1", "2", "3", "4", "5"). Labels are associated with features. In the example of FIG. 7, labels ("T1", "T1", "T1", "T2", "T3") are associated with each feature in chronological order ("ID": "1", "2", "3", "4", "5").
[0036] The model learning unit 11c uses the first training data to learn the incident scenario determination model 21. Here, the incident scenario determination model 21 is a model that, when a feature generated using a data group (target data group) acquired from a victim system that has been subjected to a cyber-attack in the operation phase is input, outputs a label corresponding to the incident scenario. In other words, the incident scenario determination model 21 is a machine learning model (supervised learning model) that determines whether or not the feature is similar to the feature of the incident, and if so, outputs a label corresponding to the incident scenario.
[0037] The first training data input to the incident scenario determination model 21 may be a single vector or a matrix arranged in chronological order. The incident scenario determination model 21 uses existing algorithms such as support vector machines, logistic regression, and k-nearest neighbor methods. However, the algorithms are not limited to those mentioned above.
[0038] The model learning unit 11c will now be described in detail. First, the model learning unit 11c inputs first training data to the incident scenario determination model 21 and executes learning of the incident scenario determination model. As a result, the incident scenario determination model 21 is tuned.
[0039] ●About the judgment unit (judgment device: incident scenario judgment device) Fig. 8 is a diagram illustrating an example of the configuration of the determination unit in embodiment 1. As shown in Fig. 8, the determination unit 12 includes a feature amount generation unit 12a and a determination unit 12b.
[0040] The feature generator 12a generates a feature (first feature) using a group of target data acquired from a victim system that has been subjected to a cyber-attack. However, the feature generator 12a may use the feature generator 11a of the learning unit 11.
[0041] The feature generator 12a will now be described in detail. First, the operator's terminal device (not shown) acquires a target data group from a victim system that has been subjected to a cyber-attack, and stores the acquired target data group in the management data 22 of the storage device 20. Next, the feature generator 12a generates a feature (first feature) using the target data group.
[0042] The determination unit 12b inputs a first feature into the incident scenario determination model 21, which outputs a label corresponding to an incident scenario when the input and the feature of the incident are similar, acquires the label corresponding to the first feature from the incident scenario determination model 21, and determines the incident scenario corresponding to the label related to the first feature based on the label corresponding to the acquired first feature.
[0043] The determination unit 12b will be described in detail. First, the determination unit 12b inputs the generated feature (first feature) to the incident scenario determination model 21. Next, the determination unit 12b acquires a label corresponding to the first feature having a high degree of similarity (high determination accuracy) from the incident scenario determination model 21. Next, the determination unit 12b refers to the incident scenario management information and determines an incident scenario corresponding to the acquired label.
[0044] FIG. 9 is a diagram for explaining the determination of an incident scenario. In the example of FIG. 9, first, a first feature 9A is input to the incident scenario determination model 21. As a result, the incident scenario determination model 21 outputs a label 9B. Next, since label 9B includes "T1," "T2," and "T3," "T1, T2, T3" are selected from the "Label" of the incident scenario management information 9C. Then, "BruteForce success → persistence," which corresponds to "T1, T2, T3," is determined as the incident scenario.
[0045] Thereafter, output information for outputting (or displaying) the determined incident scenario is transmitted to the operator's terminal device (not shown) via a communication unit (not shown) provided in the information processing device 10. After the operator's terminal device receives the output information, the incident scenario is output (or displayed) on the terminal device or an output device (not shown) connected to the terminal device.
[0046] The terminal device or output device acquires output information for outputting the incident scenario, which has been converted into an outputtable format, and outputs the generated images, sounds, etc. based on the output information. The output unit or output device of the terminal device is, for example, an image display device using a liquid crystal, an organic EL (Electro Luminescence), or a CRT (Cathode Ray Tube). Furthermore, the image display device may also be equipped with an audio output device such as a speaker. The output device may also be a printing device such as a printer.
[0047] Furthermore, the determination unit 12b compares the label output from the incident scenario determination model 21 with all the features included in the first training data, and stores the first feature that has a low similarity (low determination accuracy) in the feature temporary management information of the management data 22 of the storage device 20. Note that even if the first feature is not similar to any of the features, the label is output. However, the determination accuracy will be extremely low. For example, the similarity may be 0.001% (percent).
[0048] FIG. 10 is a diagram illustrating an example of temporary feature management information. The temporary feature management information in FIG. 10 is a table that temporarily manages feature quantities with low determination accuracy. The temporary feature management information is used for re-learning, which will be described later, when a predetermined number of first feature quantities with low determination accuracy have been stored. In the example of FIG. 10, the temporary feature management information is information that associates an incident ID with a feature quantity. The incident ID is information that identifies an incident. In the example of FIG. 10, "B" is assigned to the incident ID. The example also illustrates feature quantities with "ID"s of "5," "6," and "10" ("value 1," "value 2," "value 3," "value 4," "value 5," ... "value N") that have been determined to have low similarity among the feature quantities in chronological order generated from the data group of the incident assigned to incident ID "B."
[0049] About the Re-learning Unit (Re-learning Device: Incident Scenario Judgment Model Re-learning Device) Fig. 11 is a diagram illustrating an example of the configuration of the relearning unit in embodiment 1. As shown in Fig. 11, the relearning unit 13 includes a classification unit 13a, an extraction unit 13b, a second teacher data generation unit 13c, and a model learning unit 11c.
[0050] The classification unit 13a performs a clustering process using third feature quantities determined to be dissimilar to the feature quantities of incidents among the first feature quantities input to the incident scenario determination model 21, and classifies the third feature quantities into clusters. After that, the extraction unit 13b extracts a fourth feature quantity that represents each cluster.
[0051] The classification unit 13a will be described in detail. First, when a predetermined number of third features (first features with low similarity (low determination accuracy)) are stored in the feature temporary management information, the classification unit 13a acquires the third features from the management data 22 of the storage device 20. Next, the classification unit 13a executes, for example, a clustering process using unsupervised learning, and classifies the third features into clusters. As the unsupervised learning, for example, k-means clustering, DBSCAN (Density Based Spatial Clustering of Applications with Noise) clustering, or the like is used. However, the clustering process is not limited to the clustering described above.
[0052] FIG. 12 is a diagram illustrating an example of the classification unit and extraction unit. In the example of FIG. 12, temporary feature management information 12A is acquired, and clustering processing is performed to classify third features (first features with low similarity (low determination accuracy)) into clusters as shown in 12B. In 12B, the classification is represented using cluster labels ("1" and "0"). Next, in the example of FIG. 12, the same clusters are aggregated, and a fourth feature representing the cluster is extracted as shown in 12C.
[0053] The second teacher data generation unit 13c compares the fourth feature with the second feature, and generates second teacher data by associating a label corresponding to the second feature that is most similar to the fourth feature with the fourth feature.
[0054] The second teacher data generation unit 13c will be described in detail. First, the second teacher data generation unit 13c compares the fourth feature with the feature (second feature) generated by the learning unit 11. Next, the second teacher data generation unit 13c extracts the second feature that is most similar to the fourth feature. Next, the second teacher data generation unit 13c associates a label corresponding to the extracted second feature with the fourth feature to generate second teacher data.
[0055] 13 is a diagram illustrating an example of the second teacher data generation unit. In the example of FIG. 13, as shown in 13A, a fourth feature representing an extracted cluster is associated with a label ("T4" or "T5") corresponding to the second feature most similar to the fourth feature (the second teacher data is generated). Thereafter, the second teacher data is stored in the feature management information of the management data of the storage device 20.
[0056] The model learning unit 11c uses the first teacher data and the second teacher data to re-learn (tune) the incident scenario determination model 21. The model learning unit 11c has already been described, so a detailed description thereof will be omitted.
[0057] [Device operation] Next, the operation of the information processing device in embodiment 1 will be described with reference to Figs. 14, 15, and 16. Fig. 14 is a diagram for explaining an example of the operation of the information processing device (learning unit) in embodiment 1. Fig. 15 is a diagram for explaining an example of the operation of the information processing device (determination unit) in embodiment 1. Fig. 16 is a diagram for explaining an example of the operation of the information processing device (relearning unit) in embodiment 1. In the following description, reference will be made to the figures as appropriate. Furthermore, in embodiment 1, the information processing method is implemented by operating the information processing device. Therefore, the description of the information processing method in embodiment 1 will be substituted for the description of the operation of the information processing device below.
[0058] ●About the operation of the learning section As shown in FIG. 14, the feature generator 11a generates a feature (second feature) using a group of past data acquired from a victim system that has been subjected to a cyber attack (step A1).
[0059] Specifically, in step A1, first, the feature generator 11a refers to the management data 22 stored in the storage device 20 and acquires past data groups included in the management data 22. Then, in step A1, the feature generator 11a aggregates the acquired data groups, sorts them in chronological order, and generates feature amounts (second feature amounts).
[0060] Next, the first teacher data generating unit 11b generates first teacher data by associating the generated feature amount (second feature amount) with a label corresponding to a predefined incident scenario (step A2).
[0061] Specifically, in step A2, the first teacher data generation unit 11b collects features (second features) and associates labels with each of the features (second features) to generate first teacher data. The same label is assigned to the same collected features. Next, in step A2, the first teacher data generation unit 11b stores the generated first teacher data in the storage device 20.
[0062] The model learning unit 11c uses the first training data to learn (tune) the incident scenario determination model 21 (step A3).
[0063] ●Operation of the judgment unit As shown in FIG. 15, the feature generator 12a generates a feature (first feature) using a target data group acquired from a victim system that has been subjected to a cyber attack (step B1).
[0064] Specifically, in step B1, first, the operator's terminal device (not shown) acquires a target data group from a victim system that has been subjected to a cyber-attack, and stores the acquired target data group in the management data 22 of the storage device 20. Next, in step B1, the feature generator 12a generates a feature (first feature) using the target data group.
[0065] Next, the determination unit 12b inputs the generated first feature to the incident scenario determination model 21 (Step B2). Next, when the determination unit 12b acquires a label corresponding to the feature (first feature) from the incident scenario determination model 21 (when the determination unit 12b acquires a label corresponding to a first feature with high similarity (high determination accuracy) (Step B3: No)), the determination unit 12b determines an incident scenario corresponding to the label related to the first feature based on the label corresponding to the acquired first feature (Step B4).
[0066] Specifically, in step B2, first, the determination unit 12b inputs the generated feature (first feature) to the incident scenario determination model 21. Next, in step B3, the determination unit 12b acquires a label corresponding to the first feature having a high degree of similarity (high determination accuracy) from the incident scenario determination model 21. Next, in step B4, the determination unit 12b refers to the incident scenario management information and determines an incident scenario corresponding to the acquired label.
[0067] Next, output information for outputting (or displaying) the determined incident scenario is sent to the operator's terminal device (not shown) via a communication unit (not shown) provided in the information processing device 10 (step B5). After the operator's terminal device receives the output information, the incident scenario is output (or displayed) on the terminal device or an output device (not shown) connected to the terminal device.
[0068] Furthermore, if the label output from the incident scenario determination model 21 has a low similarity (low determination accuracy) compared to all features included in the first training data (step B3: Yes), the determination unit 12b stores the first feature in temporary feature management information of the management data 22 of the storage device 20 (step B6).
[0069] ●About the operation of the re-learning section As shown in Figure 16, the classification unit 13a performs clustering processing using third features that are determined to be dissimilar to the features of the incident among the first features input to the incident scenario determination model 21, and classifies the third features into clusters (step C1).
[0070] Specifically, in step C1, first, when a predetermined number of third features (first features with low similarity (low determination accuracy)) are stored in the feature temporary management information, the classification unit 13a acquires the third features from the management data 22 of the storage device 20. Next, in step C1, the classification unit 13a executes a clustering process to which unsupervised learning is applied, for example, to classify the third features into clusters.
[0071] Next, the extraction unit 13b extracts, for each cluster, a fourth feature amount that represents the cluster (step C2).
[0072] Next, the second teacher data generation unit 13c compares the fourth feature with the second feature, and associates the label corresponding to the second feature that is most similar to the fourth feature with the fourth feature, thereby generating second teacher data (step C3).
[0073] Specifically, in step C3, first, the second teacher data generation unit 13c compares the fourth feature with the feature (second feature) generated by the learning unit 11. Next, in step C3, the second teacher data generation unit 13c extracts the second feature that is most similar to the fourth feature. Next, in step C3, the second teacher data generation unit 13c associates a label corresponding to the extracted second feature with the fourth feature to generate second teacher data.
[0074] The model learning unit 11c re-learns (tunes) the incident scenario determination model 21 using the first teacher data and the second teacher data (step C4).
[0075] [Effects of the First Embodiment] As described above, according to the first embodiment, by performing re-learning, an incident scenario can be derived even when a cyber-attack that has not been predefined occurs.
[0076] The processes of storing the data group, learning, determining, and relearning, which have been described in the first embodiment, can be instructed from the user's terminal device.
[0077] [program] The program in the first embodiment may be any program that causes a computer to execute steps A1 to A3, B1 to B6, and C1 to C4 shown in Figures 14 to 16. By installing and executing this program on a computer, the information processing device and information processing method in the first embodiment can be realized. In this case, the processor of the computer functions as a learning unit 11 (feature generation unit 11a, first teacher data generation unit 11b, model learning unit 11c), a determination unit 12 (feature generation unit 12a (11a), decision unit 12b), and a relearning unit 13 (classification unit 13a, extraction unit 13b, second teacher data generation unit 13c, model learning unit 11c), and performs processing.
[0078] The program in embodiment 1 may be executed by a computer system constructed by a plurality of computers. In this case, for example, each computer may function as any one of the learning unit 11 (feature amount generation unit 11a, first teacher data generation unit 11b, model learning unit 11c), the determination unit 12 (feature amount generation unit 12a (11a), decision unit 12b), and the relearning unit 13 (classification unit 13a, extraction unit 13b, second teacher data generation unit 13c, model learning unit 11c).
[0079] (Embodiment 2) The configuration of a system (security incident scenario determination system) 100a according to the second embodiment will be described with reference to Fig. 17. Fig. 17 is a diagram illustrating an example of the system according to the second embodiment.
[0080] [System Configuration] The system 100a in the second embodiment includes an information processing device 10a and a storage device 20a, which are connected to each other via a network.
[0081] The information processing device 10a is, for example, a CPU (Central Processing Unit), a programmable device such as an FPGA (Field-Programmable Gate Array), a GPU (Graphics Processing Unit), or a circuit equipped with one or more of these, a server computer, a personal computer, a mobile terminal, etc.
[0082] The storage device 20a is a database, a server computer, a circuit having a memory, etc. The storage device 20a stores, for example, at least information such as an incident scenario determination model 21 and management data 22a.
[0083] 17, the storage device 20a is provided outside the information processing device 10a, but it may also be provided inside the information processing device 10a. The storage device 20a stores an incident scenario determination model 21 and management data 22a. The storage device 20a may also be configured using multiple storage devices.
[0084] [Device configuration] The information processing device 10a includes a learning unit 11, a determination unit 14, and a re-learning unit 13. The learning unit 11 tunes (constructs) an incident scenario determination model (supervised learning model). The determination unit 14 determines an incident scenario using the incident scenario determination model. The re-learning unit 13 re-learns the incident scenario determination model.
[0085] In the second embodiment, the determination unit 14 further determines whether or not threat intelligence information (e.g., malware, threat actors, etc.) is included in the data group that is the source of the feature with low determination accuracy (third feature). The determination unit 14 also generates third training data by associating the third feature with a label corresponding to malicious information.
[0086] In the example of Figure 1, the information processing device 10 includes a learning unit 11, a judgment unit 14, and a relearning unit 13, but the functions of the learning unit 11, the judgment unit 14, and the relearning unit 13 may be divided among multiple information processing devices.
[0087] Furthermore, the learning unit 11 may be a learning device, the determination unit 14 may be a determination device, and the relearning unit 13 may be a relearning device. Alternatively, the learning unit 11 may be a learning device, and the determination unit 14 and the relearning unit 13 may be a determination / relearning device.
[0088] The learning unit 11 and the relearning unit 13 have already been described in the first embodiment, so a detailed description thereof will be omitted.
[0089] ●About the judgment unit (judgment device: incident scenario judgment device) Fig. 18 is a diagram illustrating an example of the configuration of the determination unit in embodiment 2. As shown in Fig. 18, the determination unit 14 includes a feature generation unit 12a, a determination unit 12b, a matching unit 12c, and a third teacher data generation unit 12d.
[0090] The feature generator 12a and the determiner 12b have already been described in the first embodiment, so a detailed description thereof will be omitted.
[0091] The matching unit 12c acquires a data group corresponding to the third feature (a first feature with low similarity (low judgment accuracy)) and matches the data group to determine whether it contains pre-set threat intelligence.
[0092] Specifically, first, the matching unit 12c acquires a third feature (a first feature having a low degree of similarity (low determination accuracy)) from the feature temporary management information stored in the management data 22a of the storage device 20. Next, the matching unit 12c acquires a data group corresponding to the third feature.
[0093] Next, the collator 12c refers to the intelligence management information stored in the management data 22a of the storage device 20 and determines whether or not the data group corresponding to the third feature amount includes threat intelligence.
[0094] 19 is a diagram illustrating an example of intelligence management information. As an example, FIG. 19 shows intelligence management information 19A, which associates malware family names, malware file names (e.g., xxx.exe), and traces (e.g., system logs, registries, etc.) with labels, and intelligence management information 19B, which associates attacking actor traces with labels.
[0095] When the data group corresponding to the third feature includes threat intelligence contained in the intelligence management information, the third teacher data generation unit 12d generates third teacher data by associating the third feature with a label that is pre-associated with the threat intelligence.
[0096] The determination unit 12b refers to the incident scenario management information and determines an incident scenario corresponding to the acquired label (a label previously associated with threat intelligence). Thereafter, the determination unit 12b transmits output information for outputting (or displaying) the determined incident scenario to the operator's terminal device (not shown) via a communication unit (not shown) provided in the information processing device 10. After the operator's terminal device receives the output information, the incident scenario is output (or displayed) on the terminal device or an output device (not shown) connected to the terminal device.
[0097] FIG. 20 is a diagram illustrating an example of matching and generation of third training data. In the example of FIG. 20, first, a data group 20B corresponding to a third feature (a first feature with low similarity (low determination accuracy)) 20A is acquired. Next, whether or not the data group 20B contains threat intelligence is checked using intelligence management information 20C. In the example of FIG. 20, since the data group 20B contains threat intelligence ("malicious.exe"), a label ("T4, T5") corresponding to the threat intelligence ("malicious.exe") in the intelligence management information 20C is associated with the third feature 20A, and third training data 20D is generated.
[0098] Furthermore, the third teacher data generating unit 12d stores the generated third teacher data in the feature amount management information stored in the management data 22a of the storage device 20.
[0099] Furthermore, the third teacher data generation unit 12d deletes the third feature (the first feature with low similarity (low judgment accuracy)) corresponding to the data group containing threat intelligence information from the temporary feature management information stored in the management data 22a of the memory device 20.
[0100] If the data group corresponding to the third feature does not include threat intelligence included in the intelligence management information, the re-learning unit 13 re-learns using the first teacher data (including the second teacher data) and the third teacher data. Specifically, the model learning 11c re-learns the incident scenario determination model 21 using the first teacher data and the third teacher data.
[0101] [Device operation] Next, the operation of the information processing device in the second embodiment will be described with reference to FIG. 21. FIG. 21 is a diagram for explaining an example of the operation of the information processing device (determination unit) in the second embodiment. In the following description, the diagram will be referenced as appropriate. Furthermore, in the second embodiment, an information processing method is implemented by operating the information processing device. Therefore, the description of the information processing method in the second embodiment will be replaced by the description of the operation of the information processing device below.
[0102] The operations of the learning unit and the relearning unit have already been explained in the first embodiment, so a detailed explanation will be omitted.
[0103] ●Operation of the judgment unit The processes from steps B1 to B5 shown in FIG. 21 have already been described in the first embodiment, so detailed description thereof will be omitted.
[0104] 21, when the label output from the incident scenario determination model 21 has a low similarity (low determination accuracy) compared with all the features included in the first training data (Step B3: Yes), the determining unit 12b causes the matching unit 12c to acquire a data group corresponding to the first feature (third feature) having a low similarity (Step D1). Specifically, in Step D1, the matching unit 12c acquires the third feature (first feature having a low similarity (low determination accuracy)) from the feature temporary management information stored in the management data 22a of the storage device 20, and acquires a data group corresponding to the third feature.
[0105] Next, the matching unit 12c checks whether the data group corresponding to the third feature contains threat intelligence information included in the intelligence management information (step D2). Specifically, in step D1, the matching unit 12c refers to the intelligence management information stored in the management data 22a of the storage device 20 and determines whether the data group corresponding to the third feature contains threat intelligence.
[0106] Next, if the data group corresponding to the third feature includes threat intelligence included in the intelligence management information (step D3: Yes), the third teacher data generation unit 12d obtains a label that is pre-associated with the threat intelligence for the third feature (step D4).
[0107] Next, the third teacher data generating unit 12d associates the acquired label with the third feature amount to generate third teacher data (step D5).
[0108] In step D5, the third teacher data generating unit 12d stores the generated third teacher data in the feature amount management information stored in the management data 22a of the storage device 20.
[0109] Furthermore, in step D5, the third teacher data generation unit 12d deletes the third feature (the first feature with low similarity (low judgment accuracy)) corresponding to the data group containing threat intelligence information from the temporary feature management information stored in the management data 22a of the storage device 20.
[0110] Furthermore, if the data group corresponding to the third feature does not include threat intelligence contained in the intelligence management information (step D3: No), the third feature is stored in the feature temporary management information of the management data 22a of the storage device 20 (step D6).
[0111] Thereafter, the re-learning unit 13 re-learns the incident scenario determination model 21 using the first teacher data (including the second teacher data) and the third teacher data.
[0112] [Effects of the second embodiment] As described above, according to the second embodiment, re-learning is performed using the third training data generated using threat intelligence, so that an incident scenario can be derived even in the event of a cyber-attack that has not been predefined.
[0113] The processes of storing the data group, learning, determining, verifying, and relearning, which have been described in the second embodiment, can be instructed from the user's terminal device.
[0114] [program] The program in the second embodiment may be any program that causes a computer to execute steps A1 to A3, B1 to B5, D1 to D6, and C1 to C4 shown in Figures 14, 21, and 16. By installing and executing this program on a computer, the information processing device and information processing method in the first embodiment can be realized. In this case, the processor of the computer functions as a learning unit 11 (feature generation unit 11a, first teacher data generation unit 11b, model learning unit 11c), a determination unit 14 (feature generation unit 12a (11a), decision unit 12b, matching unit 12c, third teacher data generation unit 12d), and a relearning unit 13 (classification unit 13a, extraction unit 13b, second teacher data generation unit 13c, model learning unit 11c) and performs processing.
[0115] The program in embodiment 1 may be executed by a computer system constructed by a plurality of computers. In this case, for example, each computer may function as one of the learning unit 11 (feature amount generation unit 11a, first teacher data generation unit 11b, model learning unit 11c), the determination unit 14 (feature amount generation unit 12a (11a), decision unit 12b, matching unit 12c, third teacher data generation unit 12d), and the relearning unit 13 (classification unit 13a, extraction unit 13b, second teacher data generation unit 13c, model learning unit 11c).
[0116] [Physical configuration] A computer that realizes the information processing device by executing the program according to the first and second embodiments will now be described with reference to Fig. 22. Fig. 22 is a diagram illustrating an example of a computer that realizes the information processing device according to the first and second embodiments.
[0117] 22, the computer 110 includes a CPU (Central Processing Unit) 111, a main memory 112, a storage device 113, an input interface 114, a display controller 115, a data reader / writer 116, and a communication interface 117. These components are connected to each other via a bus 121 so as to be able to communicate data with each other. Note that the computer 110 may include a GPU or an FPGA in addition to or instead of the CPU 111.
[0118] The CPU 111 loads a program in the embodiment, which is composed of a group of codes and stored in the storage device 113, into the main memory 112 and executes each code in a predetermined order to perform various calculations. The main memory 112 is typically a volatile storage device such as a DRAM (Dynamic Random Access Memory).
[0119] The program in the embodiment is provided in a state stored in a computer-readable recording medium 120. The program in the embodiment may be distributed over the Internet connected via the communication interface 117.
[0120] Specific examples of the storage device 113 include a hard disk drive and a semiconductor storage device such as a flash memory. The input interface 114 mediates data transmission between the CPU 111 and input devices 118 such as a keyboard and a mouse. The display controller 115 is connected to a display device 119 and controls the display on the display device 119.
[0121] The data reader / writer 116 mediates data transmission between the CPU 111 and the recording medium 120, reads programs from the recording medium 120, and writes processing results from the computer 110 to the recording medium 120. The communication interface 117 mediates data transmission between the CPU 111 and other computers.
[0122] Specific examples of the recording medium 120 include general-purpose semiconductor storage devices such as CF (Compact Flash (registered trademark)) and SD (Secure Digital), magnetic recording media such as flexible disks, or optical recording media such as CD-ROMs (Compact Disk Read Only Memory).
[0123] The information processing device in the first and second embodiments can be realized not by a computer on which a program is installed but by hardware corresponding to each unit, for example, an electronic circuit. Furthermore, the information processing device may be partially realized by a program and the remaining unit by hardware. In the first and second embodiments, the computer is not limited to the computer shown in FIG. 22.
[0124] [Note] The following supplementary notes are further provided with respect to the above-described embodiments. Some or all of the above-described embodiments can be expressed by (Supplementary Note 1) to (Supplementary Note 12) described below, but are not limited to the following descriptions.
[0125] (Appendix 1) a feature generation unit that generates first features using a group of target data acquired from a victim system that has been subjected to a cyber-attack in an operation phase; a determination unit that inputs the first feature into an incident scenario determination model that outputs a label corresponding to an incident scenario when an input and a feature of an incident are similar, acquires a label corresponding to the first feature from the incident scenario determination model, and determines an incident scenario corresponding to the label based on the acquired label corresponding to the first feature; An information processing device having the above.
[0126] (Appendix 2) the feature generator generates second feature values using a set of past data previously acquired from the victim system in the learning phase; a first teacher data generation unit that generates first teacher data by associating the second feature with the label corresponding to a preset incident scenario; a model learning unit that uses the first teacher data to learn the incident scenario determination model, 2. The information processing device according to claim 1.
[0127] (Appendix 3) a classification unit that executes a clustering process using third feature quantities determined to be dissimilar to feature quantities of incidents among the first feature quantities input to the incident scenario determination model, and classifies the third feature quantities into clusters; an extraction unit that extracts, for each cluster, a fourth feature amount that represents the cluster; a second training data generation unit that compares the fourth feature amount with the second feature amount, and associates the label corresponding to the second feature amount that is most similar to the fourth feature amount with the fourth feature amount, thereby generating second training data; the model learning unit re-learns the incident scenario determination model using the first teacher data and the second teacher data; 3. The information processing device according to claim 2.
[0128] (Appendix 4) a matching unit that acquires a data group corresponding to the third feature amount and matches the data group to determine whether or not it contains predetermined threat intelligence; a third training data generation unit that generates third training data by associating the third feature with the label that has been previously associated with the threat intelligence when the data group includes threat intelligence, the model learning unit uses the first teacher data and the third teacher data to learn the incident scenario determination model; 4. The information processing device according to claim 3.
[0129] (Appendix 5) The information processing device In the operation phase, a first feature is generated using a set of target data obtained from a system that has been victimized by a cyber attack, inputting the first feature into an incident scenario determination model that outputs a label corresponding to an incident scenario when an input and a feature of an incident are similar, and acquiring a label corresponding to the first feature from the incident scenario determination model; determining an incident scenario corresponding to the label based on the acquired label corresponding to the first feature; Information processing methods.
[0130] (Appendix 6) In a learning phase, a second feature is generated using a set of past data previously acquired from the victim system; generating first training data by associating the second feature with the label corresponding to a preset incident scenario; training the incident scenario determination model using the first training data; 1. The information processing method described in Appendix 5.
[0131] (Appendix 7) performing a clustering process using third feature quantities determined to be dissimilar to the feature quantities of the incidents among the first feature quantities input to the incident scenario determination model, and classifying the third feature quantities into clusters; extracting a fourth feature amount representing each cluster; comparing the fourth feature amount with the second feature amount, and associating the label corresponding to the second feature amount that is most similar to the fourth feature amount with the fourth feature amount to generate second training data; re-learning the incident scenario determination model using the first teacher data and the second teacher data; 1. The information processing method described in Appendix 6.
[0132] (Appendix 8) acquiring a data group corresponding to the third feature amount, and comparing the data group to determine whether or not it contains predetermined threat intelligence; If the data group includes threat intelligence, the label that is pre-associated with the threat intelligence is associated with the third feature amount to generate third training data; training the incident scenario determination model using the first teacher data and the third teacher data; 7. The information processing method described in Appendix 7.
[0133] (Appendix 9) On the computer, In the operation phase, a first feature is generated using a set of target data obtained from a system that has been victimized by a cyber attack, inputting the first feature into an incident scenario determination model that outputs a label corresponding to an incident scenario when an input and a feature of an incident are similar, and acquiring a label corresponding to the first feature from the incident scenario determination model; determining an incident scenario corresponding to the label based on the acquired label corresponding to the first feature; program.
[0134] (Appendix 10) In a learning phase, a second feature is generated using a set of past data previously acquired from the victim system; generating first training data by associating the second feature with the label corresponding to a preset incident scenario; training the incident scenario determination model using the first training data; 10. The program described in Appendix 9.
[0135] (Appendix 11) performing a clustering process using third feature quantities determined to be dissimilar to the feature quantities of incidents among the first feature quantities input to the incident scenario determination model, and classifying the third feature quantities into clusters; extracting a fourth feature amount representing each cluster; comparing the fourth feature amount with the second feature amount, and associating the label corresponding to the second feature amount that is most similar to the fourth feature amount with the fourth feature amount to generate second training data; re-training the incident scenario determination model using the first training data and the second training data; 10. The program described in Appendix 10.
[0136] (Appendix 12) acquiring a data group corresponding to the third feature amount, and comparing the data group to determine whether or not it contains predetermined threat intelligence; If the data group includes threat intelligence, the label that is pre-associated with the threat intelligence is associated with the third feature amount to generate third training data; training the incident scenario determination model using the first teacher data and the third teacher data; 12. The program described in Appendix 11.
[0137] Although the present invention has been described above with reference to the embodiments, the present invention is not limited to the above-described embodiments. Various modifications that can be understood by those skilled in the art can be made to the configuration and details of the present invention within the scope of the present invention. [Industrial Applicability]
[0138] According to the above description, it is possible to derive an incident scenario even when a cyber attack that has not been predefined occurs, and this is useful in fields where the derivation of an incident scenario is required. [Explanation of symbols]
[0139] 10, 10a Information processing device 11 Learning Department 11a Feature generation unit 11b First teacher data generation unit 11c Model Learning Section 12, 14 Judgment section 12a Feature generation unit 12b Decision section 12c Matching section 12d Third training data generation unit 13 Re-learning section 13a Classification section 13b Extraction part 13c Second training data generation unit 20, 20a Storage device 21 Incident Scenario Judgment Model 22 Management Data 100, 100a systems 110 Computer 111 CPU 112 main memory 113 Storage device 114 Input Interface 115 Display Controller 116 Data Reader / Writer 117 Communication Interface 118 Input Devices 119 Display Device 120 Recording Media 121 Bus
Claims
1. a feature generation means for generating a first feature using a group of target data acquired from a victim system that has been subjected to a cyber-attack in an operation phase; a determination means for inputting the first feature into an incident scenario determination model that outputs a label corresponding to an incident scenario when an input and a feature of an incident are similar, and acquiring a label corresponding to the first feature from the incident scenario determination model, and determining an incident scenario corresponding to the label based on the acquired label corresponding to the first feature; An information processing device having the above.
2. the feature generating means generates second feature values using a group of past data previously acquired from the victim system in a learning phase; a first training data generation means for generating first training data by associating the second feature with the label corresponding to a preset incident scenario; a model learning means for learning the incident scenario determination model using the first training data, The information processing device according to claim 1 .
3. a classification means for executing a clustering process using third feature quantities determined to be dissimilar to feature quantities of incidents among the first feature quantities input to the incident scenario determination model, and classifying the third feature quantities into clusters; extraction means for extracting, for each cluster, a fourth feature amount representing the cluster; a second training data generating means for comparing the fourth feature amount with the second feature amount, and generating second training data by associating the label corresponding to the second feature amount that is most similar to the fourth feature amount with the fourth feature amount, the model learning means re-learns the incident scenario determination model using the first teacher data and the second teacher data; The information processing device according to claim 2 .
4. a matching means for acquiring a data group corresponding to the third feature amount and matching the data group to determine whether or not it contains predetermined threat intelligence; and a third training data generation means for generating third training data by associating the third feature with the label that has been previously associated with the threat intelligence when the data group includes threat intelligence, the model learning means uses the first teacher data and the third teacher data to learn the incident scenario determination model; The information processing device according to claim 3 .
5. The information processing device In the operation phase, a first feature is generated using a set of target data obtained from a system that has been victimized by a cyber attack, inputting the first feature into an incident scenario determination model that outputs a label corresponding to an incident scenario when an input and a feature of an incident are similar, and acquiring a label corresponding to the first feature from the incident scenario determination model; determining an incident scenario corresponding to the label based on the acquired label corresponding to the first feature; Information processing methods.
6. In a learning phase, a second feature is generated using a set of past data previously acquired from the victim system; generating first training data by associating the second feature with the label corresponding to a preset incident scenario; training the incident scenario determination model using the first training data; The information processing method according to claim 5 .
7. performing a clustering process using third feature quantities determined to be dissimilar to the feature quantities of the incidents among the first feature quantities input to the incident scenario determination model, and classifying the third feature quantities into clusters; extracting a fourth feature amount representing each cluster; comparing the fourth feature amount with the second feature amount, and associating the label corresponding to the second feature amount that is most similar to the fourth feature amount with the fourth feature amount to generate second training data; re-learning the incident scenario determination model using the first teacher data and the second teacher data; The information processing method according to claim 6.
8. acquiring a data group corresponding to the third feature amount, and comparing the data group to determine whether or not it contains predetermined threat intelligence; If the data group includes threat intelligence, the label that is pre-associated with the threat intelligence is associated with the third feature amount to generate third training data; training the incident scenario determination model using the first teacher data and the third teacher data; The information processing method according to claim 7.
9. On the computer, In the operation phase, a first feature is generated using a set of target data obtained from a system that has been victimized by a cyber attack, inputting the first feature into an incident scenario determination model that outputs a label corresponding to an incident scenario when an input and a feature of an incident are similar, and acquiring a label corresponding to the first feature from the incident scenario determination model; determining an incident scenario corresponding to the label based on the acquired label corresponding to the first feature; program.
10. In a learning phase, a second feature is generated using a set of past data previously acquired from the victim system; generating first training data by associating the second feature with the label corresponding to a preset incident scenario; training the incident scenario determination model using the first training data; The program according to claim 9.
11. performing a clustering process using third feature quantities determined to be dissimilar to the feature quantities of incidents among the first feature quantities input to the incident scenario determination model, and classifying the third feature quantities into clusters; extracting a fourth feature amount representing each cluster; comparing the fourth feature amount with the second feature amount, and associating the label corresponding to the second feature amount that is most similar to the fourth feature amount with the fourth feature amount to generate second training data; re-training the incident scenario determination model using the first training data and the second training data; The program according to claim 10.
12. acquiring a data group corresponding to the third feature amount, and comparing the data group to determine whether or not it contains predetermined threat intelligence; If the data group includes threat intelligence, the label that is pre-associated with the threat intelligence is associated with the third feature amount to generate third training data; training the incident scenario determination model using the first teacher data and the third teacher data; The program according to claim 11.
Citation Information
Patent Citations
Incident analysis device and analysis method thereof
JP2019050477A