Threat intelligence generation apparatus and threat intelligence generation method
The threat intelligence generation device integrates and analyzes information from multiple organizations to generate comprehensive threat intelligence by identifying common incidents and filtering sensitive data, improving the accuracy and completeness of threat prediction.
Patent Information
- Application Number
- JP2024054144
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-03-28
- Publication Date
- 2025-10-09
AI Technical Summary
Existing technologies struggle to integrate and analyze sensitive information from multiple organizations to generate effective threat intelligence due to lack of cooperation and appropriate methods for information sharing and analysis, leading to incomplete and inaccurate threat prediction.
A threat intelligence generation device that identifies victim users and devices, collects and compares incident-related information across organizations, extracts common points, and filters out non-sensitive information to generate and share integrated threat intelligence.
Prevents information leaks while enabling the integration and sharing of threat intelligence across organizations, enhancing the accuracy and completeness of threat intelligence generation.
Smart Images

Figure 2025152311000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to a threat intelligence generation device and a threat intelligence generation method. [Background technology]
[0002] In recent years, cyber attacks against various organizations, including government agencies, companies, research institutes, and schools, have become more frequent, and each organization is increasingly aware of the importance of cybersecurity and is therefore required to take measures. However, cyber attacks are becoming more sophisticated and complex, and in order to take measures, more advanced and continuous information gathering is required.
[0003] Information about cyber attacks includes the attacker's objectives, methods, and targets, and is collectively referred to as threat intelligence.
[0004] Currently, there are several challenges to generating and utilizing threat intelligence to deal with cyberattacks. Specifically, information sharing regarding cyberattacks is personal and unsystematic, resulting in a lack of cooperation between different organizations. Another challenge to information sharing is the existence of sensitive information. Much of the information held by organizations is highly confidential, making it difficult to share with other organizations. This is one of the factors that limits the generation of effective threat intelligence and the prediction of attack patterns.
[0005] Another issue is the lack of an established method for analyzing cyber-attack-related information with high accuracy and generating threat intelligence. The motives, objectives, and methods used by cyber attackers change daily, and responding to this requires immediate and accurate information collection and analysis, but there is a lack of appropriate methods and tools for this.
[0006] Regarding threat intelligence against cyber threats, for example, Patent Document 1 describes an information processing device having: "a registration unit that, when a first system receives information about a cyber attack from a first user terminal, stores the information in a storage device in a state accessible from a second user terminal that can access the first system, converts the data structure of the information into a state usable in a second system different from the first system, and stores the information in the storage device accessible from the second system, or stores the information in the second system; and an output unit that, when other information about a cyber attack is added to the second system, converts the other information received by the first system from the second system or the storage device into a state accessible from the second user terminal and outputs the converted information." [Prior art documents] [Patent documents]
[0007] [Patent Document 1] Japanese Patent Application Publication No. 2019-40533 Summary of the Invention [Problem to be solved by the invention]
[0008] According to the technology described in Patent Document 1, information can be collected from various information sources, aggregated, and accumulated to generate threat intelligence that can be accessed from other systems. In addition, the shared threat intelligence includes information indicating the access range, such as TLP (Traffic Light Protocol), making it possible to control the access range.
[0009] However, the technology described in Patent Document 1 cannot integrate information held by multiple organizations to generate new threat intelligence. Also, the technology controls shared sensitive information using TLP or the like, and while this method can control access to common information, it cannot integrate and analyze sensitive information held by each organization.
[0010] The present invention has been made in consideration of the above points, and aims to enable the generation and sharing of threat intelligence by integrating information obtained from multiple different organizations while preventing information leaks. [Means for solving the problem]
[0011] The present application includes a number of means for solving at least some of the above-mentioned problems, examples of which are as follows.
[0012] In order to solve the above-mentioned problems, one embodiment of the threat intelligence generation device of the present invention is a threat intelligence generation device that generates threat intelligence related to incidents caused by cyber attacks, and is equipped with one or more computing devices, one or more memory resources, and one or more storage devices, and is characterized in that the computing device identifies at least one of the victim users and victim devices of the incident that occurred in a first organization where the threat intelligence generation device is located, collects first incident-related information related to the identified victim users and at least one of the victim devices, collects second incident-related information related to at least one of the victim users and victim devices of an incident that occurred in a second organization different from the first organization and is the same as the incident that occurred in the first organization, compares the first incident-related information with the second incident-related information to extract common points, excludes information from the extracted common points that is unlikely to be the threat intelligence, and presents the common points that were not excluded. [Effects of the Invention]
[0013] According to the present invention, it is possible to prevent information leaks while integrating information obtained from multiple different organizations to generate and share threat intelligence.
[0014] Problems, configurations, and effects other than those described above will become apparent from the following description of the embodiments. [Brief explanation of the drawings]
[0015] [Figure 1] FIG. 1 is a diagram illustrating an example of the configuration of a threat intelligence generation support system according to one embodiment of the present invention. [Figure 2] FIG. 2 is a diagram illustrating an example of the configuration of a general computer. [Figure 3] FIG. 3 is a diagram illustrating an example of the data structure of the user data table. [Figure 4] FIG. 4 is a diagram illustrating an example of the data structure of the device data table. [Figure 5] FIG. 5 is a diagram illustrating an example of the data structure of the history data table. [Figure 6] FIG. 6 is a diagram illustrating an example of the data structure of the attribute list table. [Figure 7] FIG. 7 is a diagram illustrating an example of the data structure of the configuration information table. [Figure 8] FIG. 8 is a diagram illustrating an example of the data structure of the whitelist table. [Figure 9] FIG. 9 is a diagram illustrating an example of the data structure of the attack group profile table. [Figure 10] FIG. 10 is a flowchart illustrating an example of a threat intelligence generation process. [Figure 11] FIG. 11 is a diagram showing a display example of an intelligence generation operation screen as a UI (User Interface) screen. [Figure 12] FIG. 12 is a diagram showing a display example of a time-series event drawing screen as a UI screen. DETAILED DESCRIPTION OF THE INVENTION
[0016] An embodiment of the present invention will be described below with reference to the drawings. In all drawings illustrating an embodiment, identical components are generally designated by the same reference numerals, and repeated description thereof will be omitted. Furthermore, in the following embodiments, components (including element steps, etc.) are not necessarily essential unless otherwise specified, or when they are clearly considered essential in principle. Furthermore, when the terms "consisting of A," "composed of A," "having A," or "including A" are used, other elements are not excluded unless otherwise specified, or when it is clearly considered that only that element is included. Similarly, in the following embodiments, when referring to the shape, positional relationship, etc. of components, etc., these terms include those that are substantially similar or similar to the shape, etc., unless otherwise specified, or when they are clearly considered otherwise in principle.
[0017] <Configuration example of threat intelligence generation support system 100> FIG. 1 shows an example of the configuration of a threat intelligence generation support system 100 according to an embodiment of the present invention.
[0018] The threat intelligence generation support system 100 collects information related to cyberattacks from various organizations, such as government agencies, companies, research institutes, and schools, and generates and shares new threat intelligence about the cyberattacks based on commonalities among them. By sharing threat intelligence, each organization can identify the attacking group behind incidents caused by cyberattacks and respond appropriately to the incidents.
[0019] The threat intelligence generation support system 100 has a threat intelligence generation device 120 provided in an information using organization 101, and information providing devices 140 provided in each of multiple information providing organizations 102. The threat intelligence generation device 120 and the multiple information providing devices 140 are connected via a network (not shown) such as the Internet.
[0020] The threat intelligence generation device 120 of the information using organization 101 collects incident-related information about users and devices that have been affected by incidents caused by cyber attacks that have occurred within the information using organization 101, and also collects incident-related information about users and devices that have been affected by incidents that have occurred at the information providing organization 102 where the same incident as the incident in question has occurred, integrates this information, and generates threat intelligence about the incident in question.
[0021] The threat intelligence generation device 120 has the following functional blocks: an input unit 121, a victim user / device identification unit 122, an information collection unit 123, an information analysis unit 124, a filtering unit 125, and an output unit 126. The threat intelligence generation device 120 also has the following tables: a user data table 112, a device data table 113, a history data table 114, an attribute list table 115, a configuration information table 116, a whitelist table 117, and an attack group profile table 118.
[0022] The threat intelligence generation device 120 is realized by a general computer such as a personal computer or a server computer, for example.
[0023] 2 shows an example configuration of a general computer 150 that constitutes the threat intelligence generation device 120. The computer 150 has an arithmetic unit 151, a storage unit 152, an auxiliary storage unit 153, an input unit 154, an output unit 155, and a communication unit 156.
[0024] The arithmetic device 151 is made up of a processor such as a CPU (Central Processing Unit). The storage device 152 is made up of memory resources such as DRAM (Dynamic Random Access Memory). The auxiliary storage device 153 is made up of storage such as an HDD (Hard Disk Drive) or SSD (Solid State Drive). The input device 154 is made up of a keyboard, mouse, media drive, etc. The output device 155 is made up of a display, speakers, etc. The communication device 156 is made up of an Ethernet (trademark) card, Wi-Fi (trademark) adapter, etc.
[0025] The computer 150 serving as the threat intelligence generation device 120 realizes the functional blocks of an input unit 121, a victim user / device identification unit 122, an information collection unit 123, an information analysis unit 124, a filtering unit 125, and an output unit 126 by the calculation unit 151 executing a predetermined program stored in a memory device 152.
[0026] The program executed by the arithmetic unit 151 may be stored in advance in the storage unit 152, or may be downloaded from a predetermined server or the like via a removable medium (CD-ROM, flash memory, etc.) or a network such as the Internet, stored in the auxiliary storage unit 153, which is a non-transitory storage medium, and read out from the auxiliary storage unit 153 to the storage unit 152 when needed. For this reason, it is desirable that the computer 150 has an interface for reading data from removable media.
[0027] Furthermore, the threat intelligence generation device 120 may be realized by one physical or logical computer, or by two or more physical or logical computers, which may be distributed over a network.
[0028] Returning to FIG. 1, the input unit 121 accepts various operations and inputs from a security operator or the like. For example, the input unit 121 accepts incident designation information (e.g., a hash value of malware) that is input by a security operator or the like using a UI screen and that is used to designate an incident for which threat intelligence is to be generated. Note that the incident designation information may be manually input by a security operator or the like, or may be automated by some method.
[0029] The victim user / device identification unit 122 identifies users and devices that have been victimized by an incident that has occurred in the information using organization 101, as specified by the incident specification information.
[0030] The information collection unit 123 collects incident-related information (corresponding to the first incident-related information of the present invention) related to the victim user / device identified by the victim user / device identification unit 122. The information collection unit 123 also transmits an information use request including incident designation information to the information providing device 140 of each information providing organization 102.
[0031] The information analysis unit 124 acquires incident-related information (corresponding to the second incident-related information of the present invention) relating to victim user devices at each information providing organization 102, collected by the information providing device 140 of each information providing organization 102. The information analysis unit 124 also compares the incident-related information collected within the information using organization 101 with the incident-related information (corresponding to the second incident-related information of the present invention) relating to victim user devices acquired from each information providing organization 102, and extracts commonalities.
[0032] The filtering unit 125 excludes, from among the commonalities of the incident-related information extracted by the information analysis unit 124, information that is unlikely to be threat intelligence, and outputs to the output unit 126 information that is likely to be threat intelligence.
[0033] The output unit 126 generates an intelligence generation operation screen 1001 (FIG. 11) or a time-series event drawing screen 1101 (FIG. 12) as a UI screen in response to a predetermined operation by a security operator or the like, and displays them on the output device 155.
[0034] The user data table 112, the device data table 113, the history data table 114, the attribute list table 115, the configuration information table 116, the whitelist table 117, and the attack group profile table 118 are stored in the auxiliary storage device 153 of the computer 150.
[0035] The user data table 112 is a table that stores data on users such as employees who belong to the information using organization 101.
[0036] 3 shows an example of the data structure of the user data table 112. The user data table 112 has fields 201 to 204 for storing information indicating job type, job position, and organization in association with a user ID.
[0037] Field 201 stores a user ID, which is an identifier for uniquely identifying a user. Field 202 stores information representing the user's occupation. Field 203 stores information representing the user's job position. Field 204 stores information representing the organization to which the user belongs.
[0038] By recording the job type, job position, and industry in the user data table 112, if an attack group targets a specific job type, job position, or industry, it is possible to generate threat intelligence that indicates which job type, job position, or industry the incident is targeting by matching the job types, job positions, and industries of victim users in each organization. Note that if there is attribute information targeted by the attack group other than the job type, job position, and industry, this information may be added to the user data table 112.
[0039] Returning to Figure 1, the device data table 113 is a table that stores data relating to devices that may be subject to incident damage, such as computers used in the information using organization 101.
[0040] 4 shows an example of the data structure of the device data table 113. The device data table 113 has fields 301 to 302 for storing information indicating the type and OS (Operating System) in association with the device ID.
[0041] Field 301 stores a device ID, which is an identifier that uniquely identifies a device. Field 302 stores information that indicates the type of device. Field 303 stores information that indicates the OS of the device. In addition to the model and OS, if there is attribute information of the device targeted by the attack group, such as the OS version or model lot, this information may be added to the device data table 113.
[0042] Returning to Fig. 1, the history data table 114 is a table in which information relating to users belonging to the information using organization 101 and events occurring in devices owned by the information using organization 101 is stored in chronological order.
[0043] 5 shows an example of the data structure of the history data table 114. The history data table 114 has fields 401 to 407 for storing information representing a timestamp, a user ID, a device ID, a level of importance, a type, and a type value in association with an event ID.
[0044] Field 401 stores an event ID, which is an identifier that uniquely identifies the event that has occurred. Field 402 stores a timestamp that indicates the time when the event occurred to a user or device. Field 403 stores the user ID of the user who caused the event to occur or the user who uses the device on which the event occurred. Field 404 stores the device ID 301 of the device on which the event occurred. Note that if the event that has occurred is related only to the user and not to the device, field 404 may be left blank.
[0045] Information indicating the importance of an event is stored in field 405. For example, if a security appliance determines that an event occurred when a device accessed a website and issues an alert because the security appliance determines that the access is suspicious, the importance of the event may be increased.
[0046] Field 406 stores information indicating the type of event that has occurred. It is desirable to collect a variety of events, including those that at first glance do not seem to be related to user or device incidents. By comparing various pieces of information, commonalities among incidents that have occurred in each organization can be calculated. Field 407 stores the value of the type of event stored in field 406.
[0047] Events can be collected from application programs used by users, such as browsers, schedulers, mailers, etc. For example, email text matching can be performed using PSI (private set intersection) encryption so that the email text can be matched in an encrypted state.
[0048] Returning to Figure 1, the attribute list table 115 is a table that stores the types of attributes to be matched to generate threat intelligence, the matching method for each attribute, and so on.
[0049] 6 shows an example of the data structure of the attribute list table 115. The attribute list table 115 has fields 501 to 505 for storing attribute items, confidentiality (or sensitivity), matching methods, and time windows in association with attribute IDs.
[0050] Field 501 stores an attribute ID for uniquely identifying each attribute. Field 502 stores attribute items to be matched. Field 503 stores information indicating whether each attribute is confidential. Information on highly confidential attributes is matched in a PSI-encrypted state to prevent leaks to other organizations. Field 504 stores the attribute matching method. Possible matching methods include exact matches and partial matches. For example, topics may be extracted from the body of an email and exact or partial matches of the topics may be calculated. A keyword dictionary prepared in advance or natural language processing may be used to extract topics. Field 505 stores a time window (a window within which a match is determined). Even if attribute values are the same, if events with the attribute values occurred at different times, the two events are considered to be related to different incidents. For this reason, attributes are matched within the time window. Therefore, the time window stored in field 505 is used for processing, such as filtering by the filtering unit 125, to exclude events that did not occur within the time window.
[0051] Returning to Fig. 1, the configuration information table 116 is a table in which configuration information of the network devices and the like owned by the information using organization 101 is stored.
[0052] 7 shows an example of the data structure of the configuration information table 116. The configuration information table 116 has fields 601 to 605 for storing IP addresses, host names, categories, and device names in association with device IDs.
[0053] Field 601 stores a device ID for uniquely identifying a device that constitutes the IT (Information Technology) environment of each organization. Field 602 stores the IP (Internet Protocol) address of the device. Field 603 stores the host name of the device. Field 604 stores the category of the device. Field 605 stores the device name of the device. The device name is used to abstract the device identified by the IP address.
[0054] Returning to Figure 1, the whitelist table 117 is a table that stores information that has been determined in advance to have a low probability of becoming threat intelligence. The whitelist table 117 is used by the filtering unit 125.
[0055] 7 shows an example of the data structure of the whitelist table 117. The whitelist table 117 has fields 701 to 703 for storing items and values of the items in association with the information ID of information that has been determined in advance to have a low probability of becoming threat intelligence.
[0056] Field 701 stores an information ID for uniquely identifying information that has been determined in advance to have a low probability of becoming threat intelligence. Field 702 stores an item of data to be excluded. Field 703 stores a value of the data to be excluded.
[0057] Returning to Figure 1, the attack group profile table 118 is generated in advance for each attack group based on publicly known information, and stores the characteristics of each attack group.
[0058] 9 shows an example of the data structure of the attack group profile table 118. The attack group profile table 118 has fields 801 to 803 for storing items and item values in association with item IDs.
[0059] Field 801 stores an item ID for uniquely identifying an item that characterizes an attack group. Field 802 stores an item that characterizes an attack group. Field 803 stores a value for each item.
[0060] Returning to Figure 1, in response to an information use request sent from the threat intelligence generation device 120, if an incident damage corresponding to the incident designation information included in the information use request has occurred, the information providing device 140 of the information providing organization 102 provides the threat intelligence generation device 120 with incident-related information relating to each user and each device that has suffered the incident damage.
[0061] Like the threat intelligence generation device 120, the information providing device 140 is realized by a general computer 150 (Figure 2), and the functional blocks of the input unit 131, victim user / device identification unit 132, and information collection unit 133 are realized by the arithmetic unit 151 of the computer 150 executing a predetermined program stored in the memory device 152.
[0062] The input unit 131 receives an information utilization request from the threat intelligence generation device 120 and outputs incident specification information (for example, a malware hash value) included in the information utilization request to the victim user / device identification unit 122.
[0063] The victim user / device identification unit 132 identifies users and devices that have suffered incident damage in the information providing organization 102, as specified by the incident specification information.
[0064] The information collection unit 133 collects incident-related information about the victim user / device identified by the victim user / device identification unit 132 and transmits it to the threat intelligence generation device 120.
[0065] The information providing device 140 also has a user data table 112, a device data table 113, and a history data table 114. The data structure of each table is the same as that of the tables assigned the same reference numerals in the threat intelligence generation device 120, and therefore a description thereof will be omitted.
[0066] In addition, the input unit 121, victim user / device identification unit 122, information collection unit 123, user data table 112, device data table 113, and history data table 114 may be omitted from the threat intelligence generation device 120, and threat intelligence may be generated based on incident-related information regarding victim user / devices collected from multiple information providing organizations 102.
[0067] <About the threat intelligence generation process> FIG. 10 is a flowchart showing an example of a threat intelligence generation process by the threat intelligence generation support system 100.
[0068] The threat intelligence generation process is initiated, for example, when a security operator or the like belonging to the information using organization 101 inputs incident designation information (e.g., a malware hash value, etc.) to the intelligence generation operation screen 1001 (Figure 11) displayed by the output unit 126 of the threat intelligence generation device 120 to specify the incident for which threat intelligence is to be generated, and the input unit 121 accepts the input.
[0069] First, the victim user / device identification unit 122 of the threat intelligence generation device 120 identifies users and devices that have suffered incident damage in the information using organization 101, as specified by the incident specification information (step S101).
[0070] For example, if the incident designation information is a hash value of malware, the victim user / device identification unit 122 identifies the victim device by checking the log of each device, etc., to identify the device that has or executed the file with that hash value. In addition, the victim user is identified by identifying the user who is using the identified victim device.
[0071] Next, the information collection unit 123 collects incident-related information relating to victim users and victim devices within the information using organization 101 (step S102).
[0072] Here, the incident-related information collected by the information collection unit 123 includes information on users and devices themselves stored in the user data table 112 and the device data table 113, information on organizations to which users belong, and chronological information on users and devices stored in the history data table 114. Furthermore, a security operator may investigate an incident and, as a result of analyzing the infection route and malware obtained as a result, collect information on the services targeted by the attack and the stolen information. Furthermore, the incident-related information may be collected from outside the organization, such as the Information-technology Promotion Agency (IPA).
[0073] Next, the information collection unit 123 sends an information usage request including incident designation information to the information providing device 140 of each information providing organization 102 (step S103), and collects incident-related information regarding victim users and victim devices in each information providing organization 102 (step S104).
[0074] Next, the information analysis unit 124 of the threat intelligence generation device 120 compares the incident-related information regarding victim users and victim devices within the information utilization organization 101 collected in step S102 with the incident-related information regarding victim users and victim devices within the information providing organization 102 collected in step S104 (step S105).
[0075] The incident-related information is collated by referring to the attribute list table 115 and using a collation method that is predefined for each attribute item.
[0076] For example, if the occupation of the victim user of an incident within the information using organization 101 is a researcher, the matching method corresponding to the occupation in the attribute list table 115 (Figure 6) is an exact match, so a match is made to determine whether the occupation of the victim user of an incident within the information providing organization 102 is a researcher.
[0077] Furthermore, when comparing incident-related information for victim devices, the configuration information table 116 (Figure 7) for each organization is referenced as necessary, and the information is abstracted before being compared. For example, if the victim device of the incident is connected to IP address (192.0.2.1), the connection to IP address (192.0.2.1) is converted to a connection to the default gateway before being compared. This makes it possible to abstract and compare local IP addresses that differ depending on the organization.
[0078] Next, the filtering unit 125 refers to the whitelist table 117 (Figure 8) and, from among the common points obtained as a result of the information analysis unit 124 matching the incident-related information of the information using organization 101 and the information providing organization 102, excludes those that are unlikely to be threat intelligence, and outputs those that are likely to be threat intelligence to the output unit 126 (step S106).
[0079] Possible filtering methods include referring to the whitelist table 117, or, for example, comparing users or device groups that have been affected by a common incident with users or device groups that have not been affected by the incident, and if there is no significant difference, excluding them because they are not highly correlated with the presence or absence of the incident.
[0080] Next, the output unit 126 displays the input from the filtering unit 125 on the intelligence generation operation screen 1001 (FIG. 11) as a UI screen (step S107).
[0081] <Intelligence Generation Operation Screen 1001> 11 shows an example of the display of an intelligence generation operation screen 1001. The intelligence generation operation screen 1001 is provided with a search box 1002, a matching result display field 1003, an attribution result display field 1004, and a risk score display field 1005.
[0082] The search box 1002 is used by a security operator or the like belonging to the information using organization 101 to input incident specification information that specifies an incident for which threat intelligence is to be generated.
[0083] The matching result display field 1003 displays a graph showing the degree of commonality in the attributes of the incident-related information of the information using organization 101 and the information providing organization 102 in descending order, expressed as a percentage.
[0084] In the example displayed in Figure 11, the same incident occurred in eight organizations (eight infections), 100% of the organizations where the incident occurred belonged to the electric power industry, and 90% of the victimized users were researchers. This indicates that there is a high probability that the incident in question was an attack targeting researchers in the electric power industry. However, if many of the information user organizations 101 and information provider organizations 102 belong to the same industry, the degree of commonality between the industries will be calculated as a high commonality. Normalization can be performed to avoid this problem.
[0085] In this embodiment, the number of infected organizations is displayed as the number of incidents, but the number of victimized users or victimized devices may also be displayed.
[0086] The attribution result display field 1004 compares the threat intelligence generated based on the matching results with the attack group profile table 118, and displays the attack group responsible for the incident in order of likelihood along with the probability score. In the display example of Figure 11, it is displayed that the probability score indicating the likelihood that the incident was an attack by attack group A is 90, and the probability score indicating the likelihood that the incident was an attack by attack group B is 80.
[0087] In the risk score display column 1005, users who are judged not to be currently victims of an incident based on the results of the matching but who are close to the target of an attack and therefore have a high probability of becoming victims of an incident in the future, or who have already been attacked but have not yet detected the attack, are displayed in descending order of risk together with their risk scores. In the display example of Figure 11, it is displayed that users A and B are at high risk of becoming victims of an incident.
[0088] <Display example of the time series event drawing screen 1101> FIG. 12 shows an example of a time-series event drawing screen 1101 displayed as a UI screen by the output unit 126. As shown in FIG.
[0089] The time-series event drawing screen 1101 is displayed in response to a predetermined operation by a security operator, etc. The time-series event drawing screen 1101 displays a directed graph in which common events obtained as a result of matching victim users and victim devices, and uncommon events that are highly likely to be related to the incident and have a high degree of suspiciousness, are expressed as nodes.
[0090] The display example in Figure 12 shows the time series events of two devices A and B that were damaged when a common event, "Malware XXX executed," occurred, and shows that before the damage occurred, common events (such as "connection to YYYY" and "launch of process X") and uncommon events (such as "connection to XXXX") occurred. Common events may be the result of a common attack that caused the incident. Uncommon events may be the cause of the same incident, but may be slight changes to the attack method, etc., and security operators and others can use this directed graph to search for threat intelligence.
[0091] The present invention is not limited to the above-described embodiments, and various modifications are possible. For example, the above-described embodiments have been described in detail to clearly explain the present invention, and the present invention is not necessarily limited to those having all of the described configurations. Furthermore, it is possible to replace part of the configuration of one embodiment with or add to the configuration of another embodiment.
[0092] Furthermore, some or all of the aforementioned configurations, functions, processing units, processing means, etc. may be implemented in hardware, for example, by designing them as integrated circuits. Furthermore, the aforementioned configurations, functions, etc. may be implemented in software by a processor interpreting and executing a program that implements each function. Information such as programs, tables, and files that implement each function may be stored in memory, a storage device such as a hard disk or SSD, or a storage medium such as an IC card, SD card, or DVD. Furthermore, the control lines and information lines shown are those considered necessary for explanation, and do not necessarily represent all control lines and information lines in the product. In reality, it can be assumed that almost all components are interconnected. [Explanation of symbols]
[0093] 100···Threat intelligence generation support system, 101···Information user organization, 102···Information providing organization, 112···User data table, 113···Device data table, 114···History data table, 115···Attribute list table, 116···Configuration information table, 117···Whitelist table, 118···Attack group profile table, 120···Threat intelligence generation device, 121···Input unit, 122···Victim user / device identification unit, 1 23···Information gathering unit, 124···Information analysis unit, 125···Filtering unit, 126···Output unit, 131···Input unit, 132···Victim user / device identification unit, 133···Information gathering unit, 140···Information providing device, 150···Computer, 151···Calculation unit, 152···Storage device, 153···Auxiliary storage device, 154···Input device, 155···Output device, 156···Communication device, 1001···Intelligence generation operation screen, 1101···Time series event drawing screen
Claims
1. A threat intelligence generation device that generates threat intelligence related to incidents caused by cyber attacks, one or more computing devices, one or more memory resources, and one or more storage devices; The computing device Identifying at least one of a victim user and a victim device of the incident that occurred in a first organization where the threat intelligence generation device is installed; collecting first incident-related information relating to at least one of the identified victim user and the identified victim device; collecting second incident-related information relating to at least one of a victim user and a victim device of an incident that occurred in a second organization different from the first organization and is the same as the incident that occurred in the first organization; comparing the first incident-related information with the second incident-related information to extract commonalities; Among the extracted commonalities, information that is unlikely to be the threat intelligence is excluded; A threat intelligence generation device that presents the common points that were not excluded.
2. 2. The threat intelligence generating device of claim 1, A threat intelligence generation device characterized in that, when comparing the first incident-related information with the second incident-related information, the computing device compares highly sensitive information in an encrypted state.
3. 2. The threat intelligence generating device of claim 1, The threat intelligence generation device is characterized in that, when comparing the first incident-related information with the second incident-related information, the calculation device abstracts local information that differs for each organization and then compares the information.
4. 2. The threat intelligence generating device of claim 1, The threat intelligence generation device is characterized in that the calculation device matches the first incident-related information with the second incident-related information within a predetermined time window.
5. 2. The threat intelligence generating device of claim 1, The computing device is a threat intelligence generation device characterized in that it displays a time series event drawing screen that chronologically shows events that are common to at least one of the victim users and the victim devices of the same incident that occurred in the first organization and the second organization, and events that are not common but are highly suspicious.
6. A threat intelligence generation method for a threat intelligence generation device that generates threat intelligence related to incidents caused by cyber attacks, comprising: one or more computing devices, one or more memory resources, and one or more storage devices; The threat intelligence generation method includes: The computing device identifies at least one of a victim user and a victim device of the incident that occurred in the first organization where the threat intelligence generating device is installed; The computing device collects first incident-related information relating to at least one of the identified victim user and the victim device; The computing device collects second incident-related information relating to at least one of a victim user and a victim device of an incident that occurs in a second organization different from the first organization and is the same as the incident that occurred in the first organization; The calculation device compares the first incident-related information with the second incident-related information to extract commonalities; The computing device excludes information that is unlikely to be the threat intelligence from the extracted common points; and a step of presenting the commonalities that were not excluded.
Citation Information
Patent Citations
Cyber attack information processing program, cyber attack information processing method and information processing device
JP2019040533A