Threat intelligence generation apparatus and threat intelligence generation method
Patent Information
- Application Number
- JP2024054144
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-03-28
- Publication Date
- 2026-08-27
AI Technical Summary
【0013】 本発明によれば、情報漏洩を防止しつつ、異なる複数の組織から得た情報を統合して脅威インテリジェンスを生成、共有することが可能となる。
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a threat intelligence generation device and a threat intelligence generation method.
Background Art
[0002] In recent years, cyberattacks against various organizations such as government agencies, companies, research institutions, and schools have become active. Each organization recognizes the importance of cybersecurity and the need to take countermeasures. However, cyberattacks are sophisticated and complex, and more advanced and continuous information collection is required to take countermeasures.
[0003] Information on cyberattacks includes the attacker's purpose, method, attack target, etc., which are collectively referred to as threat intelligence.
[0004] Currently, there are several issues regarding the generation and utilization of threat intelligence for dealing with cyberattacks. Specifically, information sharing regarding cyberattacks is personal and not systematized, and there is a lack of cooperation between different organizations. And as an issue of information sharing, the existence of confidential information is cited. The information held by organizations includes a lot of highly confidential information, which is difficult to share with other organizations, and this is one of the reasons that restricts the effective generation of threat intelligence and the prediction of attack patterns.
[0005] Furthermore, there is also an issue that a method for accurately analyzing information related to cyberattacks and generating threat intelligence has not been established. The motives, purposes, and methods used by cyberattackers change daily, and in order to cope with this, immediate and accurate information collection and analysis are required, but appropriate methods and tools for this are lacking.
[0006] Regarding threat intelligence against cyber threats, for example, Patent Document 1 describes an information processing device characterized by having "a registration unit which, when the first system receives information relating to a cyberattack from a first user terminal, stores the information in a storage device in a state that can be accessed by a second user terminal that can access the first system, and converts the data structure of the information into a state that can be used by a second system different from the first system, and stores it in the storage device accessible from the second system, or stores it in the second system, and when other information relating to a cyberattack is added to the second system, the first system converts the other information received from the second system or the storage device into a state that can be accessed by the second user terminal and outputs it." [Prior art documents] [Patent Documents]
[0007] [Patent Document 1] Japanese Patent Publication No. 2019-40533 [Overview of the project] [Problems that the invention aims to solve]
[0008] According to the technology described in Patent Document 1, it is possible to collect, aggregate, and store information from various sources to generate threat intelligence that can be accessed from other systems. Furthermore, the shared threat intelligence includes information indicating the scope of access, such as TLP (Traffic Light Protocol), and the scope of access can be controlled.
[0009] However, the technology described in Patent Document 1 cannot integrate information held by multiple organizations to generate new threat intelligence. Furthermore, while it is possible to control access to shared sensitive information using methods such as TLP, it is not possible to integrate and analyze the sensitive information held by each organization.
[0010] This invention has been made in view of the above-mentioned points, and aims to enable the generation and sharing of threat intelligence by integrating information obtained from multiple different organizations while preventing information leakage. [Means for solving the problem]
[0011] This application includes several means to solve at least some of the aforementioned problems, and some examples are as follows.
[0012] To solve the aforementioned problems, a threat intelligence generating device according to one aspect of the present invention is a threat intelligence generating device that generates threat intelligence related to an incident caused by a cyberattack, comprising one or more computing devices, one or more memory resources, and one or more storage devices, wherein the computing devices identify at least one of the affected users and affected equipment of the incident that occurred in a first organization where the threat intelligence generating device is installed, collect first incident-related information relating to at least one of the identified affected users and affected equipment, and collect second incident-related information relating to at least one of the affected users and affected equipment of the same incident that occurred in the first organization, which occurred in a second organization different from the first organization. The local information that differs for each organization between the first incident-related information and the second incident-related information is abstracted, and the abstracted First incident-related information and The abstracted The method is characterized by comparing the information with the second incident-related information to extract commonalities, excluding information from the extracted commonalities that is unlikely to be threat intelligence, and presenting the commonalities that were not excluded. [Effects of the Invention]
[0013] According to the present invention, it is possible to generate and share threat intelligence by integrating information obtained from multiple different organizations while preventing information leakage.
[0014] Other issues, configurations, and effects not mentioned above will be clarified by the following description of the embodiments.
Brief Description of Drawings
[0015] [Figure 1] FIG. 1 is a diagram showing a configuration example of a threat intelligence generation support system according to an embodiment of the present invention. [Figure 2] FIG. 2 is a diagram showing a configuration example of a general computer. [Figure 3] FIG. 3 is a diagram showing an example of the data structure of a user data table. [Figure 4] FIG. 4 is a diagram showing an example of the data structure of a device data table. [Figure 5] FIG. 5 is a diagram showing an example of the data structure of a history data table. [Figure 6] FIG. 6 is a diagram showing an example of the data structure of an attribute list table. [Figure 7] FIG. 7 is a diagram showing an example of the data structure of a configuration information table. [Figure 8] FIG. 8 is a diagram showing an example of the data structure of a whitelist table. [Figure 9] FIG. 9 is a diagram showing an example of the data structure of an attack group profile table. [Figure 10] FIG. 10 is a flowchart showing an example of threat intelligence generation processing. [Figure 11] FIG. 11 is a diagram showing a display example of an intelligence generation operation screen as a UI (User Interface) screen. [Figure 12] FIG. 12 is a diagram showing a display example of a time-series event drawing screen as a UI screen.
Embodiments for Carrying Out the Invention
[0016] Hereinafter, an embodiment of the present invention will be described based on the drawings. In all the drawings for describing an embodiment, the same members are generally denoted by the same reference numerals, and repeated descriptions thereof are omitted. Further, in the following embodiments, the components (including element steps, etc.) are not necessarily essential unless specifically stated or considered to be clearly essential in principle. Also, when it is said that "consisting of A", "comprising A", "having A", or "including A", other elements are not excluded unless it is specifically stated that only that element is involved. Similarly, in the following embodiments, when referring to the shape, positional relationship, etc. of components, etc., those substantially approximating or similar to the shape, etc. are included unless specifically stated or considered not to be so in principle.
[0017] <Configuration example of threat intelligence generation support system 100> FIG. 1 shows a configuration example of a threat intelligence generation support system 100 according to an embodiment of the present invention.
[0018] The threat intelligence generation support system 100 collects information related to cyberattacks from various organizations such as government agencies, companies, research institutions, schools, etc., generates new threat intelligence regarding the cyberattacks from their commonalities, and shares it. By sharing threat intelligence, each organization can identify the attack groups behind incidents caused by cyberattacks and take appropriate measures against the incidents.
[0019] The threat intelligence generation support system 100 includes a threat intelligence generation device 120 provided in an information utilization organization 101 and information providing devices 140 provided in a plurality of information providing organizations 102, respectively. The threat intelligence generation device 120 and the plurality of information providing devices 140 are connected via a network (not shown) represented by the Internet.
[0020] The threat intelligence generating device 120 of the information utilization organization 101 collects incident-related information concerning users and equipment affected by an incident resulting from a cyberattack that occurred within the information utilization organization 101, and also collects incident-related information concerning users and equipment affected by an incident that occurred in the information providing organization 102, where the same incident occurred. This information is then integrated to generate threat intelligence related to the incident.
[0021] The threat intelligence generator 120 has the following functional blocks: an input unit 121, a victim user / device identification unit 122, an information collection unit 123, an information analysis unit 124, a filtering unit 125, and an output unit 126. The threat intelligence generator 120 also has the following tables: a user data table 112, a device data table 113, a history data table 114, an attribute list table 115, a configuration information table 116, a whitelist table 117, and an attack group profile table 118.
[0022] The threat intelligence generator 120 is implemented using a general-purpose computer, such as a personal computer or a server computer.
[0023] Figure 2 shows an example configuration of a typical computer 150 that constitutes the threat intelligence generation device 120. The computer 150 has an arithmetic unit 151, a storage device 152, an auxiliary storage device 153, an input device 154, an output device 155, and a communication device 156.
[0024] The arithmetic unit 151 consists of a processor such as a CPU (Central Processing Unit). The storage device 152 consists of memory resources such as DRAM (Dynamic Random Access Memory). The auxiliary storage device 153 consists of storage such as an HDD (Hard Disk Drive) or SSD (Solid State Drive). The input device 154 consists of a keyboard, mouse, media drive, etc. The output device 155 consists of a display, speaker, etc. The communication device 156 consists of an Ethernet® card or Wi-Fi® adapter, etc.
[0025] The computer 150, acting as a threat intelligence generation device 120, implements the following functional blocks by having its arithmetic unit 151 execute a predetermined program stored in its storage device 152: the input unit 121, the victim user / device identification unit 122, the information collection unit 123, the information analysis unit 124, the filtering unit 125, and the output unit 126.
[0026] The program executed by the arithmetic unit 151 may be stored in the storage device 152 in advance, or it may be downloaded from a predetermined server via removable media (CD-ROM, flash memory, etc.) or a network such as the Internet, stored in the auxiliary storage device 153, which is a non-temporary storage medium, and read from the auxiliary storage device 153 to the storage device 152 when needed. For this reason, it is desirable that the computer 150 has an interface for reading data from removable media.
[0027] Furthermore, the threat intelligence generator 120 may be implemented using one physical or logical computer, or using two or more physical or logical computers. The two or more physical or logical computers may be distributed across a network.
[0028] Return to Figure 1. The input unit 121 accepts various operations and inputs from security operators, etc. For example, the input unit 121 accepts incident specification information (e.g., malware hash value) that security operators, etc. input using a UI screen to specify the incident for which they want to generate threat intelligence. Note that incident specification information can be entered manually by security operators, etc., or it may be automated by some method.
[0029] The affected user / device identification unit 122 identifies the users and devices affected by the incident that occurred in the information utilization organization 101, as specified by the incident designation information.
[0030] The information collection unit 123 collects incident-related information (corresponding to the first incident-related information of this invention) concerning the affected user and equipment identified by the affected user and equipment identification unit 122. The information collection unit 123 also transmits an information utilization request, including incident designation information, to the information provision device 140 of each information provision organization 102.
[0031] The information analysis unit 124 acquires incident-related information (corresponding to the second incident-related information of this invention) concerning affected users and equipment in each information-providing organization 102, which is collected by the information-providing device 140 of each information-providing organization 102. The information analysis unit 124 also compares the incident-related information collected within the information-utilizing organization 101 with the incident-related information (corresponding to the second incident-related information of this invention) obtained from each information-providing organization 102 to extract commonalities.
[0032] The filtering unit 125 excludes commonalities in incident-related information extracted by the information analysis unit 124 that have a low probability of being threat intelligence, and outputs those that have a high probability of being threat intelligence to the output unit 126.
[0033] The output unit 126 generates an intelligence generation operation screen 1001 (Figure 11) and a time-series event drawing screen 1101 (Figure 12) as UI screens in response to a predetermined operation from a security operator or the like, and displays them on the output device 155.
[0034] The user data table 112, the device data table 113, the history data table 114, the attribute list table 115, the configuration information table 116, the whitelist table 117, and the attack group profile table 118 are stored in the auxiliary storage device 153 of the computer 150.
[0035] User data table 112 is a table that stores data about users such as employees belonging to information utilization organization 101.
[0036] Figure 3 shows an example of the data structure of the user data table 112. The user data table 112 associates the user ID with the job title, job position, and Industry It has fields 201 to 204 for storing information representing the function.
[0037] Field 201 stores the User ID, which is an identifier that uniquely identifies the user. Field 202 stores information representing the user's occupation. Field 203 stores information representing the user's job title. Field 204 stores information representing the user's organization to which the user belongs. Industry Information representing this is stored.
[0038] By recording job titles, positions, and industries in the user data table 112, when an attack group targets a specific job title, position, or industry, it becomes possible to generate threat intelligence indicating which job title, position, or industry the incident is targeting by cross-referencing it with the job titles, positions, and industries of affected users in each organization. In addition to job title, position, and industry, any other attribute information targeted by the attack group may also be added to the user data table 112.
[0039] Return to Figure 1. The equipment data table 113 is a table that stores data on equipment such as computers used in the information utilization organization 101 that may be susceptible to incident damage.
[0040] Figure 4 shows an example of the data structure of the device data table 113. The device data table 113 has fields 301~ for storing information representing the type and OS (Operating System) associated with the device ID. 303 It has.
[0041] Field 301 stores the device ID, which is an identifier that uniquely identifies the device. Field 302 stores information representing the type of device. Field 303 stores information representing the operating system of the device. In addition to the model and OS, if there is any attribute information of the device targeted by the attack group, such as the OS version or model lot number, this may be added to the device data table 113.
[0042] Return to Figure 1. The history data table 114 is a table that stores information about users belonging to the information utilization organization 101 and events that occurred on equipment owned by the information utilization organization 101 in chronological order.
[0043] Figure 5 shows an example of the data structure of the history data table 114. The history data table 114 has fields 401 to 407 for storing information representing the timestamp, user ID, device ID, severity, type, and type value, associated with the event ID.
[0044] Field 401 stores the event ID, which is an identifier that uniquely identifies the event that occurred. Field 402 stores a timestamp representing the time the event occurred for the user or device. Field 403 stores the user ID of the user who caused the event, or the user using the device where the event occurred. Field 404 stores the user ID of the device where the event occurred. Device IDThis information is stored here. Note that if the event that occurred is related only to the user and not to the device, field 404 may be left blank.
[0045] Field 405 stores information indicating the importance of the event. For example, if a security appliance detects an event where a device accesses a website as suspicious and raises an alert, the importance of that event might be increased.
[0046] Field 406 stores information representing the type of event that occurred. It is desirable to collect a variety of events, including those seemingly unrelated to user or equipment incidents. By cross-referencing this diverse information, commonalities in incidents occurring within each organization can be calculated. Field 407 contains information about the events stored in Field 406. kinds The value is stored there.
[0047] The events can be collected from application programs used by the user, such as browsers, schedulers, and mail clients. For example, to match email bodies, PSI (private set intersection) encryption can be used so that the email bodies can be matched while encrypted.
[0048] Returning to Figure 1, the attribute list table 115 is a table that stores the types of attributes to be matched for generating threat intelligence, the matching method for each attribute, and so on.
[0049] Figure 6 shows an example of the data structure of the attribute list table 115. The attribute list table 115 has fields 501 to 505 for storing attribute items, confidentiality (or sensitivity), matching method, and time window, associated with the attribute ID.
[0050] Field 501 stores an attribute ID to uniquely identify each attribute. Field 502 stores the attribute items to be matched. Field 503 stores information indicating whether each attribute is confidential or not. Information on highly confidential attributes is matched in a PSI encrypted state to prevent leakage to other organizations. Field 504 stores the attribute matching method. Possible matching methods include exact match, partial match, or methods such as extracting topics from the body of an email and calculating exact or partial matches of those topics. Topic extraction may use a pre-prepared keyword dictionary or natural language processing. Field 505 stores the time window used to determine a match during matching. Even if the attribute values are the same, if the date and time the events for those attribute values occurred are different, the two events are considered to be related to different incidents. Therefore, attributes are matched within the time window. The time window stored in field 505 is then used by the filtering unit 125 to exclude events that did not occur within that time window.
[0051] Return to Figure 1. The configuration information table 116 is a table that stores configuration information of network equipment and other devices owned by the information utilization organization 101.
[0052] Figure 7 shows an example of the data structure of the configuration information table 116. The configuration information table 116 has fields 601 to 605 for storing the IP address, hostname, category, and device name, which are associated with the device ID.
[0053] Field 601 stores the device ID, which uniquely identifies the equipment that makes up each organization's IT (Information Technology) environment. Field 602 stores the IP (Internet Protocol) address of the device. Field 603 stores the hostname of the device. Field 604 stores the category of the device. Field 605 stores the device name of the device. The device name is used to abstract the device that is identified by its IP address.
[0054] Returning to Figure 1, the whitelist table 117 is a table that stores information that has been predetermined to have a low probability of becoming threat intelligence. The whitelist table 117 is used in the filtering unit 125.
[0055] Figure 8 This shows an example of the data structure of the whitelist table 117. The whitelist table 117 has fields 701 to 703 for storing items and their values, associated with information IDs of information that has been predetermined to have a low probability of becoming threat intelligence.
[0056] Field 701 stores an information ID that uniquely identifies information that has been predetermined to have a low probability of being considered threat intelligence. Field 702 stores the items of data to be excluded. Field 703 stores the values of data to be excluded.
[0057] Returning to Figure 1, the attack group profile table 118 is pre-generated for each attack group based on publicly available information and stores the characteristics of each attack group.
[0058] Figure 9 shows an example of the data structure of the attack group profile table 118. The attack group profile table 118 has fields 801 to 803 for storing items and their values, associated with item IDs.
[0059] Field 801 stores an item ID to uniquely identify the item that characterizes the attack group. Field 802 stores the item that characterizes the attack group. Field 803 stores the value for each item.
[0060] Returning to Figure 1, the information provision device 140 of the information provision organization 102, in response to an information utilization request transmitted from the threat intelligence generation device 120, provides the threat intelligence generation device 120 with incident-related information related to each user and each device affected by the incident if an incident corresponding to the incident designation information included in the information utilization request has occurred.
[0061] The information provision device 140, like the threat intelligence generation device 120, is implemented by a general-purpose computer 150 (Figure 2). The computing unit 151 of the computer 150 executes a predetermined program stored in the storage device 152 to realize the respective functional blocks: the input unit 131, the victim user / device identification unit 132, and the information collection unit 133.
[0062] The input unit 131 receives an information utilization request from the threat intelligence generation device 120, and the incident designation information (e.g., malware hash value, etc.) included in the information utilization request is processed by the victim user / device identification unit. 132 Output to [this location].
[0063] The affected user / device identification unit 132 identifies the users and devices affected by the incident at the information providing organization 102, as specified by the incident designation information.
[0064] The information gathering unit 133 collects incident-related information concerning the affected user and equipment identified by the affected user and equipment identification unit 132 and transmits it to the threat intelligence generation device 120.
[0065] Furthermore, the information providing device 140 has a user data table 112, an equipment data table 113, and a history data table 114. The data structure of each table is the same as that of the tables assigned the same codes in the threat intelligence generating device 120, so a detailed explanation is omitted.
[0066] Alternatively, the threat intelligence generation device 120 may omit the input unit 121, the victim user / device identification unit 122, the information collection unit 123, the user data table 112, the device data table 113, and the history data table 114, and generate threat intelligence based on incident-related information about victim users and devices collected from multiple information-providing organizations 102.
[0067] <About the Threat Intelligence Generation Process> Figure 10 is a flowchart showing an example of the threat intelligence generation process by the threat intelligence generation support system 100.
[0068] The threat intelligence generation process is initiated, for example, when a security operator belonging to the information utilization organization 101 inputs incident specification information (e.g., malware hash value) to specify the incident for which threat intelligence should be generated, to the intelligence generation operation screen 1001 (Figure 11) displayed by the output unit 126 of the threat intelligence generation device 120, and the input unit 121 accepts the input.
[0069] First, the victim user / device identification unit 122 of the threat intelligence generation device 120 identifies the users and devices affected by the incident in the information utilization organization 101, as specified by the incident designation information (step S101).
[0070] For example, if the incident designation information is the hash value of malware, the victim user / device identification unit 122 identifies the victim device by checking the logs of each device to identify the device that possesses or executed the file with that hash value. Furthermore, it identifies the victim user by identifying the user using the identified victim device.
[0071] Next, the information gathering unit 123 collects incident-related information regarding affected users and affected equipment within the information utilization organization 101 (step S102).
[0072] Here, the incident-related information collected by the information gathering unit 123 includes information about users and devices themselves stored in the user data table 112 and the device data table 113, information about the organization to which the user belongs, and chronological information about users and devices stored in the history data table 114. In addition, security operators may investigate the incident and, as a result of analyzing the infection route and malware obtained, collect information such as the services targeted by the attack and the information stolen. Furthermore, such incident-related information may be collected from external sources such as the IPA (Information-technology Promotion Agency).
[0073] Next, the information collection unit 123 transmits an information utilization request, including incident designation information, to the information provision device 140 of each information provision organization 102 (step S103), and collects incident-related information regarding affected users and affected equipment at each information provision organization 102 (step S104).
[0074] Next, the information analysis unit 124 of the threat intelligence generation device 120 matches the incident-related information regarding affected users and equipment within the information utilization organization 101 collected in step S102 with the incident-related information regarding affected users and equipment within the information providing organization 102 collected in step S104 (step S105).
[0075] The method for matching incident-related information is to refer to attribute list table 115 and use the predefined matching method for each attribute item.
[0076] For example, if the occupation of the user affected by an incident within information utilization organization 101 is research, the matching method corresponding to the occupation in attribute list table 115 (Figure 6) is exact match, so it matches whether or not the occupation of the user affected by the incident within information provision organization 102 is research.
[0077] Furthermore, when matching incident-related information of damaged equipment, the configuration information table 116 (Figure 7) of each organization is referred to as needed, and the information is abstracted before matching. For example, if the damaged equipment in the incident is connected to the IP address (192.0.2.1), the connection to the IP address (192.0.2.1) is converted to a connection to the default gateway before matching. This makes it possible to abstract and match local IP addresses that differ from organization to organization.
[0078] Next, the filtering unit 125 refers to the whitelist table 117 (Figure 8) and, from the commonalities obtained as a result of matching incident-related information from the information utilization organization 101 and the information providing organization 102 by the information analysis unit 124, excludes those with a low probability of being threat intelligence and outputs those with a high probability of being threat intelligence to the output unit 126 (step S106).
[0079] Filtering methods include referring to the whitelist table 117, or, for example, comparing users and devices affected by a common incident with users and devices not affected by the same incident. If there is no significant difference, these can be excluded because they are considered to have little correlation with the presence or absence of the incident.
[0080] Next, the output unit 126 displays the input from the filtering unit 125 on the intelligence generation operation screen 1001 (Figure 11), which serves as a UI screen (step S107).
[0081] <About the Intelligence Generation Operation Screen 1001> Figure 11 shows an example of the display of the intelligence generation operation screen 1001. The intelligence generation operation screen 1001 is provided with a search window 1002, a matching result display field 1003, an attribution result display field 1004, and a risk score display field 1005.
[0082] The search box 1002 is for security operators and others belonging to the information utilization organization 101 to input incident specification information that specifies the incident for which they want to generate threat intelligence.
[0083] The matching results display area 1003 displays a graph showing the degree of commonality between the attributes of incident-related information of the information utilization organization 101 and the information providing organization 102, in descending order of similarity, as a percentage.
[0084] In the example shown in Figure 11, the same incident occurred in eight organizations (eight infections), 100% of the affected organizations belong to the power industry, and 90% of the affected users are in research positions. Therefore, it is highly probable that this incident was an attack targeting researchers in the power industry. However, if many of the information-using organizations 101 and information-providing organizations 102 belong to the same industry, the degree of commonality within that industry tends to be calculated as high. To avoid this problem, normalization can be performed.
[0085] In this embodiment, the number of infections is displayed as the number of organizations where an incident occurred, but it may also be possible to display the number of affected users or the number of affected devices.
[0086] The attribution results display area 1004 compares the threat intelligence generated based on the matching results with the attack group profile table 118, and displays which attack group caused the incident, along with their probability scores, in descending order of likelihood. In the example display in Figure 11, the probability score for the incident, representing the likelihood that the attack came from attack group A, is 90, and the probability score for the attack, representing the likelihood that the attack came from attack group B, is 80.
[0087] The risk score display section 1005 shows users who, based on the matching results, have not currently been affected by an incident but are likely to be affected in the future due to their proximity to attack targets, or who have already been attacked but have not detected the attack, along with their risk scores, in descending order of risk. In the example shown in Figure 11, users A and B are displayed as having a high risk of being affected by an incident.
[0088] <Example of display on time-series event plotting screen 1101> Figure 12 shows an example of the display of the time-series event plotting screen 1101, which is displayed as a UI screen by the output unit 126.
[0089] The time-series event plotting screen 1101 is displayed in response to a predetermined operation by a security operator or the like. The time-series event plotting screen 1101 displays a directed graph in which common events obtained as a result of matching affected users and affected devices, and events that are not common but have a high probability of being related to the incident and are highly suspicious, are represented as nodes.
[0090] In the example shown in Figure 12, the time-series events of two devices A and B that were affected by a common event, "Executing malware XXX," are displayed. It shows that prior to the incident, both common events ("Connecting to YYYY," "Starting process X," etc.) and non-common events ("Connecting to XXXX," etc.) occurred. The common event may be the same attack that caused the incident. The non-common event may be the same cause of the incident, but with slightly different attack methods, etc. Security operators can use this directed graph to explore threat intelligence.
[0091] The present invention is not limited to the embodiments described above, and various modifications are possible. For example, the embodiments described above are described in detail to make the present invention easier to understand, and are not necessarily limited to those having all the configurations described. Furthermore, it is possible to replace or add to the configurations of one embodiment with those of another embodiment.
[0092] Furthermore, each of the aforementioned configurations, functions, processing units, and processing means may be implemented in hardware, either partially or entirely, by designing them as integrated circuits, for example. Alternatively, each of the aforementioned configurations and functions may be implemented in software by a processor interpreting and executing programs that realize each function. Information such as programs, tables, and files that realize each function can be stored in memory, recording devices such as hard disks and SSDs, or recording media such as IC cards, SD cards, and DVDs. Also, control lines and information lines are shown only if deemed necessary for explanation, and not all control lines and information lines are necessarily shown in the actual product. In practice, it can be assumed that almost all configurations are interconnected. [Explanation of Symbols]
[0093] 100...Threat intelligence generation support system, 101...Information utilization organization, 102...Information provision organization, 112...User data table, 113...Device data table, 114...History data table, 115...Attribute list table, 116...Configuration information table, 117...Whitelist table, 118...Attack group profile table, 120...Threat intelligence generation device, 121...Input unit, 122...Victim user / device identification unit, 1 23... Information Collection Unit, 124... Information Analysis Unit, 125... Filtering Unit, 126... Output Unit, 131... Input Unit, 132... Victim User / Equipment Identification Unit, 133... Information Collection Unit, 140... Information Provisioning Device, 150... Computer, 151... Arithmetic Unit, 152... Storage Device, 153... Auxiliary Storage Device, 154... Input Device, 155... Output Device, 156... Communication Device, 1001... Intelligence Generation Operation Screen, 1101... Time-Series Event Drawing Screen
Claims
1. A threat intelligence generator that generates threat intelligence related to incidents caused by cyberattacks, It comprises one or more arithmetic units, one or more memory resources, and one or more storage devices. The aforementioned computing device is Identify at least one of the affected users and affected equipment of the incident that occurred in the first organization where the threat intelligence generating device is installed. Collect first incident-related information relating to at least one of the identified affected user and the affected equipment, Collect second incident-related information concerning at least one of the affected users and affected equipment of an incident that occurred in a second organization different from the first organization, which is the same incident as the one that occurred in the first organization. The local information that differs for each organization between the first incident-related information and the second incident-related information is abstracted, The abstracted first incident-related information and the abstracted second incident-related information are compared to extract commonalities. Of the extracted commonalities, information with a low probability of being threat intelligence is excluded. A threat intelligence generating device characterized by presenting the aforementioned commonalities that were not excluded.
2. A threat intelligence generating device according to claim 1, The aforementioned computing device is a threat intelligence generating device characterized in that, when matching the first incident-related information and the second incident-related information, it matches highly sensitive information in an encrypted state.
3. A threat intelligence generating device according to Claim 1, The aforementioned calculation device is a threat intelligence generation device characterized by matching the first incident-related information and the second incident-related information within a predetermined time window.
4. A threat intelligence generating device according to Claim 1, The threat intelligence generating device is characterized in that the computing device displays a time-series event drawing screen that shows, in chronological order, events common to at least one of the affected users and affected devices of the same incident that occurred in the first organization and the second organization, and events that are not common but are highly suspicious.
5. A method for generating threat intelligence by a threat intelligence generating device that generates threat intelligence related to an incident caused by a cyberattack, It has one or more arithmetic units, one or more memory resources, and one or more storage devices. The aforementioned threat intelligence generation method is: The computing device includes the step of identifying at least one of the affected user and the affected equipment of the incident that occurred in the first organization where the threat intelligence generation device is installed, The calculation device collects first incident-related information relating to at least one of the identified affected user and the affected equipment, The steps include: the computing device collecting second incident-related information relating to at least one of the affected users and affected equipment of an incident occurring in a second organization different from the first organization, which is the same incident as the incident that occurred in the first organization; The local information that differs for each organization between the first incident-related information and the second incident-related information is abstracted, The arithmetic unit performs the steps of matching the abstracted first incident-related information and the abstracted second incident-related information to extract commonalities, The calculation device performs the following steps: excluding information from the extracted commonalities that is unlikely to be threat intelligence; A method for generating threat intelligence, characterized by comprising the step of presenting the commonalities that were not excluded.
Citation Information
Patent Citations
Cyber attack information processing program, cyber attack information processing method and information processing device
JP2019040533A