relay device

The relay device enhances training email credibility by mimicking mass emails' content and timing, addressing the inadequacies of existing systems in training users to handle malicious attacks in mass email scenarios.

JP2026061872APending Publication Date: 2026-04-09SAXA
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-09-30
Publication Date
2026-04-09

AI Technical Summary

Technical Problem

Existing technologies fail to generate highly credible training emails that mimic mass emails, leading to a decrease in the quality of training for users' ability to handle malicious attack emails, particularly when mass emails are sent to multiple recipients.

Method used

A relay device that monitors and controls data communication to detect mass emails, generating training emails that mimic the content and timing of actual mass emails, and sends them to users at predicted new timings, reflecting the regularity of the mass email transmission.

Benefits of technology

Enables accurate assessment of users' ability to handle malicious attack emails that resemble mass emails by sending highly credible training emails at appropriate times, thereby improving security awareness and response accuracy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026061872000001_ABST
    Figure 2026061872000001_ABST
Patent Text Reader

Abstract

This device provides a relay system that accurately assesses users' ability to deal with malicious attack emails disguised as mass emails. [Solution] The relay device 10 includes a relay circuit 13 that relays user terminals 16 connected to it via LAN to the communication network, and a control circuit 15 that monitors and controls data communication between the user terminals 16 and the communication network via the relay circuit 13. The control circuit 15 includes a mail monitoring unit 15A that detects mass emails addressed to multiple users, including the training target user, from among the received mails that the user terminal 16 receives from the mail server 50 on the communication network, and a training control unit 15B that generates training email content addressed to the training target user that mimics the mass email based on the content of the mass email detected periodically by the mail monitoring unit 15A, and instructs the training device 51 on the communication network to send a training email using the training email content at a new sending timing predicted from the regularity regarding the sending timing of the mass email.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a security countermeasure technology for training a user to correctly handle attack emails based on training emails that mimic malicious attack emails.

Background Art

[0002] In recent years, the damage caused by malicious malware that uses emails as an infection route has been increasing rapidly. For example, according to "Emotet," which infects simply by clicking on an attached file in a targeted attack email or a URL (Uniform Resource Locator) described in an attack email, not only the email data registered on the user terminal but also important personal information including authentication information such as IDs and passwords is said to be leaked. Therefore, if such malware infection occurs, new attack emails are generated based on the leaked email data and the infection spreads to other users, access to the internal network is made based on the leaked authentication information and confidential information is stolen, or it leads to extremely large damage such as being infected with a malicious program typified by "Ransomware" that demands a ransom. Therefore, it is important to correctly handle attack emails, and users are required to acquire correct handling methods on a daily basis.

[0003] Conventionally, as a technology for grasping the user's correct handling ability for such attack emails, Patent Document 1 proposes a training device that trains correct handling of attack emails to generate training emails that mimic malicious attack emails based on a preset template, transmits them to a user to be trained via a mail server, and detects that the user has received the training emails on the user terminal and opened the attached files attached to the training emails. Thereby, the user's correct handling ability for attack emails can be grasped, and it can be reflected in efforts to enhance the user's security awareness and to improve the overall security literacy of the organization to which the user belongs.

Prior Art Documents

[0004] [Patent Document 1] Japanese Patent Publication No. 2013-149063 [Overview of the project] [Problems that the invention aims to solve]

[0005] How users respond to targeted attack emails largely depends on how those emails are sent. In particular, users tend to have a relatively high level of security awareness regarding attachments and URLs when emails are sent to them personally, but their security awareness decreases when they receive mass emails addressed to multiple users, including themselves, and they tend to click on them carelessly.

[0006] Mass email distribution is not uncommon. For example, companies sometimes send out mass emails to all employees at specific times, such as the end of the year, the beginning and end of the fiscal year, before and after long holidays, or on company anniversaries, containing messages from the president or survey content. In addition, when it is necessary to warn users about attack emails, mass emails are sometimes sent to multiple users belonging to the same group to notify them of the dangers of attack emails.

[0007] These types of mass emails often include a URL to a website where users can easily view the details of the announcement. Attack emails use such URLs to activate macros that download and execute malware from a specific server.

[0008] However, since users can somewhat anticipate receiving mass emails like the ones mentioned above, their security awareness regarding URLs included in such emails tends to decrease. Therefore, it is important to understand users' ability to deal with mass emails.

[0009] According to the conventional technology described above, while it is possible to arbitrarily adjust the date, time, and number of training emails sent, there was a problem in that it was not possible to send training emails that mimicked the mass emails that were being sent to the target users at the same time. Furthermore, when training emails are generated based on pre-registered template data, as in the conventional technology described above, it is not possible to reflect the content of the mass emails that the target users have received, resulting in the inability to generate highly credible training emails and a decrease in the quality of the training itself.

[0010] This invention aims to solve these problems and provide a security measure that can accurately assess users' ability to deal with malicious attack emails that mimic mass emails. [Means for solving the problem]

[0011] To achieve this objective, the relay device according to the present invention comprises a relay circuit configured to relay user terminals connected to it via a LAN to a communication network, and a control circuit configured to monitor and control data communication between the user terminals and the communication network via the relay circuit. The control circuit comprises a mail monitoring unit configured to detect mass emails addressed to multiple users, including the training target user, from among the received emails received by the user terminal from a mail server on the communication network, and a training control unit configured to generate training email content addressed to the training target user, mimicking the mass emails, based on the mass email content of the mass emails periodically detected by the data monitoring unit, and to instruct a training device on the communication network to send a training email using the training email content at a new transmission timing predicted from the regularity of the transmission timing of the mass emails.

[0012] Furthermore, another relay device according to the present invention comprises a relay circuit configured to relay user terminals connected to it via a LAN to a communication network, and a control circuit configured to monitor and control data communication between the user terminals and the communication network via the relay circuit, wherein the control circuit comprises a mail monitoring unit configured to detect from among the received mails received by the user terminal from a mail server on the communication network a mass mail addressed to multiple users including the training target user, and a warning mail for disseminating a warning about malware, and a training control unit configured to generate training mail content addressed to the training target user, which mimics the warning mail detected by the data monitoring unit, and to instruct a training device on the communication network to send a training mail using the training mail content.

[0013] Furthermore, another relay device according to the present invention comprises a relay circuit configured to relay user terminals connected to it via a LAN to a communication network, and a control circuit configured to monitor and control data communication between the user terminals and the communication network via the relay circuit, wherein the control circuit comprises a site monitoring unit configured to monitor the provision of malware warning information at a predetermined specific site, and a training control unit configured to, in response to the detection of the provision of new warning information by the site monitoring unit, generate training email content addressed to the training target user, which mimics a warning email for disseminating the warning information, based on the content of the warning information, and instruct a training device on the communication network to send a training email using the training email content. [Effects of the Invention]

[0014] According to the present invention, it becomes possible to accurately grasp a user's ability to deal with malicious attack emails that mimic mass emails. [Brief explanation of the drawing]

[0015] [Figure 1]FIG. 1 is a block diagram showing the configuration of the relay device according to the first embodiment. [Figure 2] FIG. 2 is an explanatory diagram showing a setting example of the implementation content data according to the first embodiment. [Figure 3] FIG. 3 is a sequence diagram showing the operation of the relay device according to the first embodiment. [Figure 4] FIG. 4 is an explanatory diagram showing an example of the content of the notification email according to the first embodiment. [Figure 5] FIG. 5 is an explanatory diagram showing an example of the content of the training email according to the first embodiment. [Figure 6] FIG. 15 is a block diagram showing the configuration of the relay device according to the second embodiment. [Figure 7] FIG. 18 is an explanatory diagram showing a setting example of the implementation content data according to the second embodiment. [Figure 8] FIG. 21 is a sequence diagram showing the operation of the relay device according to the second embodiment. [Figure 9] FIG. 24 is an explanatory diagram showing an example of the content of the alert email according to the second embodiment. [Figure 10] FIG. 27 is an explanatory diagram showing an example of the content of the training email according to the second embodiment. [Figure 11] FIG. 30 is an explanatory diagram showing an evaluation form according to the second embodiment. [Figure 12] FIG. 33 is a block diagram showing the configuration of the relay device according to the third embodiment. [Figure 13] FIG. 36 is an explanatory diagram showing a setting example of the implementation content data according to the third embodiment. [Figure 14] FIG. 39 is an explanatory diagram showing an example of the alert information according to the third embodiment. [Figure 15] FIG. 42 is a sequence diagram showing the operation of the relay device according to the third embodiment. [Figure 16] FIG. 45 is an explanatory diagram showing an example of the content of the alert email according to the third embodiment. [Figure 17]Figure 17 is an explanatory diagram showing an example of training email content according to the third embodiment. [Modes for carrying out the invention]

[0016] Next, embodiments of the present invention will be described with reference to the drawings.

[0017] [First Embodiment] First, with reference to the block diagram in Figure 1, the relay device 10 according to the first embodiment of the present invention will be described.

[0018] This relay device 10 consists of relay devices such as a UTM (Unified Threat Management) device and a gateway, and is configured to relay user terminals 16 such as PCs and smartphones, which are connected to it via a LAN (Local Area Network), to a higher-level communication network NW such as the Internet.

[0019] [Principle of the present invention] How users respond to targeted attack emails largely depends on how those emails are sent. In particular, users tend to have a relatively high level of security awareness regarding attachments and URLs when emails are sent to them personally, but their security awareness decreases when they receive mass emails addressed to multiple users, including themselves, and they tend to click on them carelessly.

[0020] It is not uncommon to send mass emails. For example, companies sometimes send messages from the president or surveys to all employees simultaneously via mass email at specific times such as the end of the year, the beginning and end of the fiscal year, before and after long holidays, or on company anniversaries.

[0021] Furthermore, if it is necessary to warn users about attack emails, a mass email notifying multiple users belonging to the same group about the dangers of attack emails may be sent simultaneously.

[0022] Because users can anticipate receiving such mass emails, their security awareness regarding URLs included in these emails tends to decrease. Therefore, it is important to understand users' ability to deal with mass emails.

[0023] Here, the relay device 10 is configured to monitor and control data communication, including email exchanges, between the user terminal 16 connected to it via the LAN and the communication network NW, and can detect mass emails from among the received emails that the user terminal 16 receives from the mail server 50.

[0024] The present invention focuses on the configuration for monitoring and controlling emails that is originally provided in such a relay device 10, and is configured to detect mass emails from among the received emails that the target user terminal 16 receives from the mail server 50, and periodically send training emails that mimic the detected mass emails to the training target users at a new sending timing predicted from the regularity regarding the sending timing of the said mass emails.

[0025] This allows for the sending of training emails mimicking new mass emails to trainee users at the same time they receive them, and furthermore, it enables the generation of highly credible training emails that reflect the content of mass emails received by trainee users. Therefore, it becomes possible to accurately grasp users' ability to deal with malicious attack emails that mimic mass emails.

[0026] [Detailed configuration of the relay device] Next, with reference to the block diagram in Figure 1 mentioned above, the detailed configuration of the relay device 10 according to the first embodiment will be described.

[0027] The relay device 10 according to this embodiment includes, as its main circuit configuration, a network interface 11, a LAN interface 12, a relay circuit 13, a memory circuit 14, and a control circuit 15.

[0028] [Network I / F] The network interface 11 is connected to the communication network NW via the communication line L1 and is configured to perform data communication with the communication network NW based on instructions from the control circuit 15.

[0029] [LANI / F] LANI / F12 is connected to the LAN and is configured to communicate data with the LAN based on instructions from the control circuit 15.

[0030] [Relay Circuit] It is connected to the network interface 11 and LAN interface 12, and is configured to relay data communication between the network interface 11 and LAN interface 12 in response to instructions from the control circuit 15.

[0031] [Memory circuit] The memory circuit 14 consists of a storage device such as a semiconductor memory or a hard disk, and is configured to store processing data and program 14P used in the training email control processing executed by the control circuit 15.

[0032] The main processing data stored in the memory circuit 14 is the execution content data 14A.

[0033] [Implementation details data] Implementation content data 14A is data used to set the content of the training to be actually conducted using training emails, and is pre-set in the memory circuit 14 by the training administrator. Note that the data set in implementation content data 14A is not limited to the data described below, and other data used to create training emails, such as personal information such as the affiliation of the training target users, may also be set in implementation content data 14A.

[0034] In the example settings shown in Figure 2, the username of the user to be trained is set to "Saxa Taro," and the email address of the user to be trained is set to "saxa.taro@saxa.jp." As a result, training is conducted on a user named "Saxa Taro," the content of a mass email addressed to "saxa.taro@saxa.jp" is retrieved, and a training email mimicking a mass email is generated based on that content, with "saxa.taro@saxa.jp" set as the recipient.

[0035] [program] Program 14P is a program that, in cooperation with the CPU of the control circuit 15, realizes various processing units for executing training email control processing in the control circuit 15. This program 14P is read from an external device or recording medium (neither of which are shown) and stored in the memory circuit 14 in advance.

[0036] [control circuit] The control circuit 15 has a CPU and its peripheral circuits, and is configured to execute training email control processing by having the CPU and the program 14P of the memory circuit 14 cooperate to realize various processing units.

[0037] The main processing units implemented in the control circuit 15 are the email monitoring unit 15A and the training control unit 15B.

[0038] [Email Monitoring Department] The email monitoring unit 15A monitors data communication between the user terminal 16 and the communication network NW via the relay circuit 13, and is configured to detect the mass emails received by each user terminal 16 from the mail server 50 based on the implementation data 14A in the storage circuit 14, and record them in the storage circuit 14 as a mass email reception history.

[0039] To identify mass emails to be detected, for example, if a predetermined number of email addresses, including the email addresses of the training users, are set as the recipient addresses of the received email, it can be identified as a mass email. Alternatively, if a predetermined number of users receive a mass email with the same message ID, that mass email may be identified as a target for detection.

[0040] [Training Control Unit] The training control unit 15B is configured to refer to the broadcast email reception history recorded in the memory circuit 14, and periodically generate training email content addressed to the target user, mimicking the broadcast email, based on the content of the broadcast email that has been detected. It then instructs the training device 51 on the communication network NW to send a training email using the training email content at a new sending timing predicted from the regularity regarding the sending timing of the broadcast email.

[0041] Regarding new sending timings, you can check the sending timings of mass emails included in the mass email reception history that have the same sender email address, subject, and other specific items. Identify regularities (periodicities) such as the beginning of the month, the end of the month, specific days within the month, the beginning of the year, the end of the year, the beginning of the fiscal year, the end of the fiscal year, before and after long holidays, and anniversaries. Select the mass emails that are detected regularly and predict the next new sending timing based on these regularities.

[0042] [Operation of the first embodiment] Next, the operation of the relay device 10 according to the first embodiment will be described with reference to the sequence diagram in Figure 3. In the following description, the case in which the contents shown in Figure 2 above are pre-set in the implementation data 14A of the memory circuit 14 will be explained as an example.

[0043] First, in the control circuit 15 of the relay device 10, the training control unit 15B sets the implementation content data 14A in response to instructions from the user terminal 16 used by the training administrator, which are received via LANI / F12 (step 100), and the email monitoring unit 15A starts monitoring the broadcast emails received by the training target users based on the implementation content data 14A.

[0044] After monitoring begins, if a mail reception request is sent from the target user terminal 16 to the mail server 50 (step 101), the control circuit 15 relays and forwards the request to the mail server 50 on the communication network NW via LANI / F12, relay circuit 13, and network I / F11.

[0045] In response, when the mail server 50 sends back a mail reception response addressed to the training target user (step 102), the mail monitoring unit 15A takes this mail reception response from the relay circuit 13 to detect the broadcast mail received by the target user terminal 16 (step 103), and records the reception status of the broadcast mail, including the content of the broadcast mail, in the storage circuit 14 (step 104).

[0046] The training control unit 15B relays the email reception response received by the email monitoring unit 15A to the target user terminal 16 connected to the LAN via the relay circuit 13 and LANI / F 12 (step 105).

[0047] Subsequently, in response to a training start instruction from the user terminal 16 used by the training administrator (step 110), the training control unit 15B refers to the broadcast email reception history recorded in the memory circuit 14 and generates training email content addressed to the training target user, mimicking the broadcast email that was periodically detected (step 111). Next, the training control unit 15B determines a new transmission timing predicted from the regularity regarding the transmission timing of the broadcast email (step 112).

[0048] The mass emails used for training may be those specified in the training start instructions, those randomly selected from the mass email reception history, or those with the most recent sending time.

[0049] Comparing the mass email content shown in Figure 4 with the training email content shown in Figure 5, the "Date" column in the training email content, which indicates the sending date and time, is set to "2024 / 08 / 19 09:00," which is approximately one month after the most recent date and time the mass email was sent, "2024 / 07 / 20 09:00." In addition, a training URL similar to that of an attack email has been added to the body of the mass email content, stating, "Please note that the settlement method has changed, so please check here." Other items such as the subject and sender email address are set to the same values ​​in the training email content as in the mass email content.

[0050] Subsequently, the training control unit 15B instructs the training device 51 on the communication network NW via the network I / F 11 to send a training email using the contents of the training email so that the training email is sent at a new transmission timing (step 113).

[0051] The training device 51 generates a training email addressed to the email address of the training target user based on the training email content included in the training email transmission instruction from the relay device 10, and sends it to the mail server 50 at the training email transmission date and time (step 114).

[0052] Subsequently, if a mail reception request is sent from the target user terminal 16 to the mail server 50 (step 120), the control circuit 15 relays and forwards the request to the mail server 50 on the communication network NW via LANI / F12, relay circuit 13, and network I / F11.

[0053] In response, if the mail server 50 returns an incoming mail (step 121), the control circuit 15 relays and forwards it to the target user terminal 16 via the network interface 11, relay circuit 13, and LAN interface 12.

[0054] As a result, the training email is relayed to the target user terminal 16 and viewed by the training user. Therefore, if the monitored user's response to the training email is inappropriate, a notification that malware has infected the training device 51 on the communication network NW is sent, similar to known technologies, and this is collected as training results. At this time, a training email mimicking a mass email that the training user has received in the past is sent back to the training user at a time that matches the timing of that mass email. In addition, a highly credible training email reflecting the content of the mass email that the training user has received is sent.

[0055] [Effects of the First Embodiment] Thus, in this embodiment, the relay device 10 pre-records the history of broadcast emails received by the target user terminal 16 of the training target user from the mail server 50, refers to the broadcast email reception history when training is performed, and periodically generates training email content that mimics the broadcast email and is addressed to the training target user based on the content of the broadcast email detected, and instructs the training device 51 on the communication network NW to send a training email using the training email content at a new sending timing predicted from the regularity regarding the sending timing of the broadcast email.

[0056] This allows for the sending of training emails mimicking new mass emails to trainee users at the same time they receive them. Furthermore, it enables the generation and sending of highly credible training emails that reflect the content of the mass emails the trainee users actually receive. Therefore, it becomes possible to accurately assess users' ability to deal with malicious attack emails that mimic mass emails.

[0057] In this embodiment, the example described is the case where training emails are sent from the training device 51 on the communication network NW. However, the system is not limited to this, and the relay device 10 may generate the training emails and send them to the mail server 50. Specifically, the training control unit 15B may be configured to generate training emails that mimic the content of the broadcast emails detected periodically, addressed to the training target users, and send them to the mail server 50 at a new sending timing predicted from the regularity of the sending timing of the broadcast emails.

[0058] This allows the relay device 10 alone to accurately grasp the user's ability to respond to mass emails, and simplifies the required configuration.

[0059] [Second Embodiment] Next, with reference to the block diagram in Figure 6, a relay device 20 according to a second embodiment of the present invention will be described.

[0060] This relay device 20 consists of relay devices such as a UTM (Unified Threat Management) device and a gateway, and is configured to relay user terminals 26 such as PCs and smartphones, which are connected to it via a LAN (Local Area Network), to a higher-level communication network NW such as the Internet.

[0061] [Principle of the present invention] How users respond to targeted attack emails largely depends on how those emails are sent. In particular, users tend to have a relatively high level of security awareness regarding attachments and URLs when emails are sent to them personally, but their security awareness decreases when they receive mass emails addressed to multiple users, including themselves, and they tend to click on them carelessly.

[0062] One example of such mass emails is the alert email, which is sent to raise awareness about attack emails. Because these alert emails are usually sent by internal security management departments or external security organizations, recipients tend to have a lowered level of security awareness. As a result, many attack emails mimic these alert emails. Therefore, it is important to understand users' ability to deal with attack emails that mimic alert emails.

[0063] This embodiment aims to provide a security measure that can accurately grasp a user's ability to deal with malicious attack emails that mimic such warning emails. It is configured to detect, from among the incoming emails received by the target user terminal 26 of the training user from the mail server 50 on the communication network NW, a mass email addressed to multiple users including the training user, and a warning email intended to inform users about attack emails, and to send a training email that mimics that warning email to the training user.

[0064] [Detailed configuration of the relay device] Next, with reference to the block diagram in Figure 6, the detailed configuration of the relay device 20 according to the second embodiment will be described.

[0065] The relay device 20 according to this embodiment includes, as its main circuit configuration, a network interface 21, a LAN interface 22, a relay circuit 23, a memory circuit 24, and a control circuit 25.

[0066] [Network I / F] The network interface 21 is connected to the communication network NW via the communication line L1 and is configured to perform data communication with the communication network NW based on instructions from the control circuit 25.

[0067] [LANI / F] LANI / F22 is connected to the LAN and is configured to communicate data with the LAN based on instructions from the control circuit 25.

[0068] [Relay Circuit] It is connected to the network interface 21 and LAN interface 22, and is configured to relay data communication between the network interface 21 and LAN interface 22 in response to instructions from the control circuit 25.

[0069] [Memory circuit] The memory circuit 24 consists of a storage device such as a semiconductor memory or a hard disk, and is configured to store processing data and program 24P used in the training email control processing executed by the control circuit 25.

[0070] The main processing data stored in the memory circuit 24 is the execution content data 24A.

[0071] [Implementation details data] The training content data 24A is data used to set the content of the training that will actually be conducted using training emails, and is pre-set in the memory circuit 24 by the training administrator. Note that the data set in the training content data 24A is not limited to the data described below, and other data used to create training emails, such as personal information such as the affiliation of the training target users, may also be set in the training content data 24A.

[0072] In the example settings shown in Figure 7, the username of the user being trained is set to "Saxa Taro," and the email address of the user being trained is set to "saxa.taro@saxa.jp." The sending timing is set to "24 hours after the detection of the warning email."

[0073] This will train a user named "Saxa Taro," retrieve the content of a warning email sent to the email address "saxa.taro@saxa.jp," generate a training email mimicking the warning email based on that content, and send the training email to "saxa.taro@saxa.jp" 24 hours after the warning email is detected.

[0074] [program] Program 24P is a program that, in cooperation with the CPU of the control circuit 25, realizes various processing units for executing training email control processing in the control circuit 25. This program 24P is read from an external device or recording medium (neither of which are shown) and stored in the memory circuit 24 in advance.

[0075] [control circuit] The control circuit 25 has a CPU and its peripheral circuits, and is configured to execute training email control processing by having the CPU and the program 24P of the memory circuit 24 cooperate to realize various processing units.

[0076] The main processing units implemented in the control circuit 25 are the email monitoring unit 25A and the training control unit 25B.

[0077] [Email Monitoring Department] The email monitoring unit 25A monitors data communication between the user terminal 26 and the communication network NW via the relay circuit 23, and is configured to detect, based on the implementation data 24A of the memory circuit 24, the mass email received by each user terminal 26 from the email server 50, and which is a warning email intended to inform the public about attack emails.

[0078] To identify mass emails to be detected, for example, if the recipient address of an incoming email includes a predetermined number of email addresses, including the email addresses of the training target users, it can be identified as a mass email. Alternatively, if an incoming email with the same message ID is received by a predetermined number of users, it can be identified as a mass email to be detected. Furthermore, warning emails can be detected by checking whether keywords such as "malware" or "Emotet" are included in the email body.

[0079] [Training Control Unit] The training control unit 25B is configured to generate training email content that mimics the content of the warning email detected by the email monitoring unit 25A, and is addressed to the training target user, and to instruct the training device 51 on the communication network NW to send the training email using the training email content.

[0080] Furthermore, when the training control unit 25B instructs the training device 51 to send a training email, it is configured to determine and instruct the date and time of sending the training email based on the transmission timing set in the implementation data 24A of the memory circuit 24. In this case, for example, according to the example in Figure 7 mentioned above, the date and time of sending the training email is determined to be 24 hours after the date and time when the warning email was detected.

[0081] [Operation of the second embodiment] Next, the operation of the relay device 20 according to the second embodiment will be described with reference to the sequence diagram in Figure 8. In the following description, the case in which the contents shown in Figure 2 above are pre-set in the implementation data 24A of the memory circuit 24 will be explained as an example.

[0082] First, in the control circuit 25 of the relay device 20, the training control unit 25B sets the implementation content data 24A in response to instructions from the user terminal 26 used by the training administrator, which are received via LANI / F22 (step 200), and the email monitoring unit 25A starts monitoring the warning emails received by the training target users based on the implementation content data 24A.

[0083] After monitoring begins, if a mail reception request is sent from the target user terminal 26 to the mail server 50 (step 201), the control circuit 25 relays and forwards the request to the mail server 50 on the communication network NW via LANI / F22, relay circuit 23, and network I / F21.

[0084] In response, if the mail server 50 sends back an email reception response addressed to the training target user (step 202), the mail monitoring unit 25A temporarily receives this email reception response from the relay circuit 23 and detects the alert email received by the target user terminal 26 (step 203).

[0085] The training control unit 25B obtains the content of the warning email from the warning email detected by the email monitoring unit 25A (step 204), and relays the email reception response to the target user terminal 26 connected to the LAN via the relay circuit 23 and LANI / F22 (step 205).

[0086] Next, the training control unit 25B determines the date and time to send the training email based on the transmission timing set in the implementation data 24A (step 210). In this case, the training control unit 25B determines the date and time to send the training email to be 24 hours after the time the warning email was detected, as the date and time to send the training email in the example of Figure 7 described above.

[0087] Next, the training control unit 25B generates training email content that mimics a warning email based on the acquired warning email content (step 211).

[0088] Comparing the content of the warning email shown in Figure 9 with the content of the training email shown in Figure 10, the "Date" column in the training email, which indicates the sending date and time, is set to "2024 / 07 / 21 09:00," which is 24 hours after the date and time the warning email was sent, "2024 / 07 / 20 09:00." In addition, a training URL similar to that of an attack email has been added to the body of the mass email, stating, "For more details on Emotet infection, please click here." Other items such as the subject and sender's email address are set to the same values ​​in the training email as in the mass email.

[0089] Subsequently, the training control unit 25B instructs the training device 51 on the communication network NW to send a training email using the contents of the training email via the network I / F 21 (step 212), and the email monitoring unit 25A terminates email monitoring (step 213).

[0090] Subsequently, if a mail reception request is sent from the target user terminal 26 to the mail server 50 (step 220), the control circuit 25 relays and forwards the request to the mail server 50 on the communication network NW via LANI / F22, relay circuit 23, and network I / F21.

[0091] In response, if the mail server 50 returns an incoming mail (step 221), the control circuit 25 relays and forwards it to the target user terminal 26 via the network interface 21, relay circuit 23, and LAN interface 22.

[0092] As a result, the training email is relayed to the target user terminal 26 and viewed by the training user. Therefore, if the monitored user's response to the training email is inappropriate, a notification that malware infection has occurred is sent to the training device 51 on the communication network NW, similar to known technologies, and this is collected as training results. At this time, a training email mimicking the warning email is sent back to the training user at the same time that the training user receives the warning email. In addition, a highly credible training email reflecting the content of the warning email received by the training user is sent.

[0093] In this embodiment, we have described an example where a training email is sent one day (24 hours) after the detection of a warning email, but the system is not limited to this. As time passes after the warning email is made public, users' ability to deal with attack emails tends to decrease. Therefore, by sending training emails at different timings, it is possible to grasp the changes in the ability of the trained users to deal with attacks and accurately evaluate their ability to deal with attacks.

[0094] The evaluation table in Figure 11 shows an example where training emails are sent at both "within one week" and "one month or more" after the warning email, and the ability of the trained users to respond is evaluated based on the training results. The training control unit 25B of the training device 51 or relay device 20 may use this evaluation table to evaluate, based on the training results, the relationship between awareness of attack emails, the time elapsed since the warning, and whether future warnings are necessary.

[0095] For example, if appropriate action is taken (marked "○") in both the training emails sent "within one week" and "more than one month," it indicates a "high" level of awareness of attack emails, that action is "always possible" regardless of the time elapsed since the initial warning, and that further warnings are "unnecessary or the status quo can be maintained."

[0096] Furthermore, if a training email sent "within one week" resulted in an appropriate response ("○"), but a training email sent "one month or more" resulted in an inappropriate response ("×"), then the awareness of attack emails is considered "medium," the warning is only "appropriate for immediate action," and future warnings are "necessary on a regular basis."

[0097] Furthermore, if an inappropriate response ("×") was made to a training email sent "within one week," but an appropriate response ("〇") was made to a training email sent "one month or more later," then awareness of attack emails is "medium," and regardless of the time elapsed since the warning, the response is "unstable," and future warnings should be evaluated as "need to consider whether response education is necessary."

[0098] Furthermore, if an inappropriate response ("×") is marked in both the training emails sent "within one week" and "after one month," it indicates a "low" level of awareness of attack emails, meaning that "response is always impossible" regardless of the time elapsed since the initial warning. In such cases, future warnings will be evaluated as "requiring response training."

[0099] [Effects of the second embodiment] Thus, in this embodiment, the relay device 20 is configured to detect, from among the received emails that the target user terminal 26 of the training target user receives from the mail server 50 on the communication network NW, a mass email addressed to multiple users including the training target user, and a warning email intended to inform users about attack emails. The relay device 20 then generates training email content addressed to the training target user that mimics the warning email, and instructs the training device 51 on the communication network NW to send a training email using the training email content.

[0100] This allows for the sending of training emails to trainee users that mimic real warning emails, and furthermore, enables the generation and sending of highly credible training emails that reflect actual warning information. Therefore, it becomes possible to accurately assess users' ability to deal with malicious attack emails that mimic warning emails.

[0101] In this embodiment, the example described is the case where a training email is sent from a training device 51 on the communication network NW. However, the invention is not limited to this, and the training email may be generated in the relay device 20 and sent to the mail server 50. Specifically, the training control unit 25B may be configured to generate a training email that mimics the content of the detected warning email, addressed to the training target user, and send it to the mail server 50.

[0102] This allows the relay device 20 alone to accurately grasp the user's ability to respond to mass emails, and simplifies the required configuration.

[0103] [Third Embodiment] Next, with reference to the block diagram in Figure 12, a relay device 30 according to a third embodiment of the present invention will be described.

[0104] This relay device 30 consists of relay devices such as a UTM (Unified Threat Management) device and a gateway, and is configured to relay user terminals 36 such as PCs and smartphones, which are connected to it via a LAN (Local Area Network), to a higher-level communication network NW such as the Internet.

[0105] [Principle of the present invention] How users respond to targeted attack emails largely depends on how those emails are sent. In particular, users tend to have a relatively high level of security awareness regarding attachments and URLs when emails are sent to them personally, but their security awareness decreases when they receive mass emails addressed to multiple users, including themselves, and they tend to click on them carelessly.

[0106] One example of such mass emails is the alert email, which is sent to raise awareness about attack emails. Because these alert emails are usually sent by internal security management departments or external security organizations, recipients tend to have a lowered level of security awareness. As a result, many attack emails mimic these alert emails. Therefore, it is important to understand users' ability to deal with attack emails that mimic alert emails.

[0107] This embodiment aims to provide a security measure that can accurately grasp a user's ability to deal with malicious attack emails that mimic such warning emails. It monitors the provision of malware warning information at a specific site 52 on a pre-designated communication network NW, and in response to the detection of new warning information, generates training email content that mimics a warning email to notify training target users of the malware warning based on the content of the warning information, and sends training emails using the training email content to training target users.

[0108] [Detailed configuration of the relay device] Next, with reference to the block diagram in Figure 12, the detailed configuration of the relay device 30 according to this embodiment will be described.

[0109] The relay device 30 according to this embodiment includes, as its main circuit configuration, a network interface 31, a LAN interface 32, a relay circuit 33, a memory circuit 34, and a control circuit 35.

[0110] [Network I / F] The network interface 31 is connected to the communication network NW via the communication line L1 and is configured to perform data communication with the communication network NW based on instructions from the control circuit 35.

[0111] [LANI / F] LANI / F32 is connected to the LAN and is configured to communicate data with the LAN based on instructions from the control circuit 35.

[0112] [Relay Circuit] It is connected to the network interface 31 and LAN interface 32, and is configured to relay data communication between the network interface 31 and LAN interface 32 in response to instructions from the control circuit 35.

[0113] [Memory circuit] The memory circuit 34 consists of a storage device such as a semiconductor memory or a hard disk, and is configured to store processing data and program 34P used in the training email control processing executed by the control circuit 35.

[0114] The main processing data stored in the memory circuit 34 is the execution content data 34A.

[0115] [Implementation details data] The implementation content data 34A is data used to set the content of the training that will actually be conducted using training emails, and is pre-set in the memory circuit 34 by the training administrator. Note that the data set in the implementation content data 34A is not limited to the data described below, and other data used to create training emails, such as personal information such as the affiliation of the training target users, may also be set in the implementation content data 34A.

[0116] In the example settings shown in Figure 13, the username of the user being trained is set to "Saxa Taro," and the email address of the user being trained is set to "saxa.taro@saxa.jp."

[0117] As a result, training will be conducted targeting a user named "Saxa Taro," and a training email mimicking a warning email will be sent to the email address "saxa.taro@saxa.jp".

[0118] [program] Program 34P is a program that, in cooperation with the CPU of the control circuit 35, realizes various processing units for executing training email control processing in the control circuit 35. This program 34P is read from an external device or recording medium (neither of which are shown) and stored in the memory circuit 34 in advance.

[0119] [control circuit] The control circuit 35 has a CPU and its peripheral circuits, and is configured to execute training email control processing by having the CPU and the program 34P of the memory circuit 34 cooperate to realize various processing units.

[0120] The main processing units implemented in the control circuit 35 are the site monitoring unit 35A and the training control unit 35B.

[0121] [Site Monitoring Department] The site monitoring unit 35A is configured to sequentially access specific sites 52 on the communication network NW via the network I / F 31 based on URLs pre-registered in the memory circuit 34, to monitor for the provision of malware-related warning information, and to acquire such warning information in response to the detection of new warning information.

[0122] The specific sites 52 to be monitored are, for example, sites operated by external security organizations, which provide warning information about malware and attack emails, as shown in Figure 14. For warning information, detection can be done by checking whether keywords such as "malware" or "Emotet" are included in the provided information.

[0123] [Training Control Unit] The training control unit 35B is configured to generate warning email content indicating a warning email to disseminate the warning information detected and acquired by the site monitoring unit 35A, and to instruct the training device 51 on the communication network NW to send a warning email using the warning email content in a broadcast email format, addressed to the email addresses of each user other than the training target user, which are pre-registered in the storage circuit 34.

[0124] Furthermore, the training control unit 35B is configured to generate training email content that mimics the aforementioned warning email and is addressed to the training target user, and to instruct the training device 51 on the communication network NW to send the training email using the training email content.

[0125] [Operation of the third embodiment] Next, the operation of the relay device 30 according to the third embodiment will be described with reference to the sequence diagram in Figure 15. In the following description, the case in which the contents shown in Figure 13 above are pre-set in the implementation data 34A of the memory circuit 34 will be described as an example. Furthermore, the case in which, among the user terminals 36, the target user terminal 36 of the training target user is user terminal A, and the user terminals 36 other than the target user terminal 36 are user terminal B which is the recipient of the warning email will be described as an example.

[0126] First, in the control circuit 35 of the relay device 30, the training control unit 35B sets the implementation content data 34A in response to instructions from the user terminal 36 used by the training administrator, which are received via LANI / F32 (step 300), and the site monitoring unit 35A accesses a specific site 52 on the communication network NW via the network I / F31 and starts monitoring for the provision of warning information regarding malware (step 301).

[0127] If the provision of new warning information is detected at this point (step 302), the site monitoring unit 35A acquires the warning information (step 303).

[0128] The training control unit 35B generates an alert email content indicating an alert email based on the alert information detected by the site monitoring unit 35A (step 304), and instructs the training device 51 on the communication network NW via the network I / F 31 to send an alert email using the alert email content in a broadcast email format, addressed to the email addresses of each user other than the training target user, which are pre-registered in the memory circuit 34 (step 305). As a result, the training device 51 sends an alert email to the mail server 50 (step 306).

[0129] Furthermore, the training control unit 35B generates training email content that mimics the warning email based on the content of the warning email (step 310), and instructs the training device 51 on the communication network NW via the network I / F 31 to send a training email to the target user using the training email content (step 311). As a result, the training device 51 sends a warning email to the mail server 50 (step 312).

[0130] The warning email content shown in Figure 16 has a subject line and email body created based on the warning information shown in Figure 14. For email addresses, just like with a typical mass email, you can set the email addresses in the "To" and "CC" fields of the warning email content.

[0131] The training email content shown in Figure 17 differs from the warning email content in Figure 16 in that the email body includes a training URL that mimics an attack email, stating, "For more details on Emotet infection, please click here." Additionally, the "To" field is set to the training target user's email address, "saxa.taro@saxa.jp". Other items, such as the subject and email body, are set to the same values ​​as in the warning email.

[0132] Subsequently, if a mail reception request is sent from user terminal B to mail server 50 (step 320), the control circuit 35 relays and forwards the request to mail server 50 on the communication network NW via LANI / F32, relay circuit 33, and network I / F31.

[0133] In response, the mail server 50 sends back an incoming email containing a warning email via email reception response (step 321), and the control circuit 35 relays and forwards it to user terminal B via the network interface 31, relay circuit 33, and LAN interface 32.

[0134] Furthermore, when a mail reception request is sent from the target user terminal A to the mail server 50 (step 330), the control circuit 35 relays and forwards the request to the mail server 50 on the communication network NW via LANI / F32, relay circuit 33, and network I / F31.

[0135] In response, the mail server 50 returns the received mail, including the training mail, via a mail reception response (step 331), and the control circuit 35 relays and forwards it to the target user terminal 36 via the network interface 31, relay circuit 33, and LAN interface 32.

[0136] As a result, the training email is relayed to the target user terminal 36 and viewed by the training user. Therefore, if the monitored user's response to the training email is inappropriate, a notification that malware infection has occurred is sent to the training device 51 on the communication network NW, similar to known technologies, and this is collected as training results. At this time, a training email mimicking the warning email is sent back to the training user in conjunction with the timing of new warning information being provided at the specific site 52. In addition, a highly credible training email that reflects the content of the actual warning information is sent.

[0137] Furthermore, in this embodiment, when new warning information is provided on a specific site 52, a warning email is sent to each user other than the pre-registered training target users. This ensures that the latest warning information is disseminated to each user. Note that this embodiment can also be implemented without sending warning emails.

[0138] [Effects of the third embodiment] As described above, in this embodiment, the relay device 30 monitors the provision of malware alert information at a specific site 52 on a pre-designated communication network NW, and upon detection of the provision of new alert information, generates training email content that mimics an alert email to notify the target user of the malware alert based on the content of the alert information, and instructs the training device 51 on the communication network NW to send a training email using the training email content.

[0139] This allows for the sending of training emails mimicking warning emails to trainee users at the same time that new warning information is provided on a specific site 52. Furthermore, it enables the generation and sending of highly credible training emails that reflect actual warning information. Therefore, it becomes possible to accurately assess users' ability to deal with malicious attack emails that mimic warning emails.

[0140] In this embodiment, the example of sending training emails from the training device 51 on the communication network NW was described, but the invention is not limited to this, and the training emails may be generated in the relay device 30 and sent to the mail server 50. Specifically, the training control unit 35B may be configured to generate a training email that mimics the warning email, addressed to the training target user, based on the warning information detected by the site monitoring unit 35A, and send it to the mail server 50.

[0141] This allows the relay device 30 alone to accurately grasp the user's ability to respond to mass emails, and simplifies the required configuration.

[0142] [Expansion of the embodiment] Although the present invention has been described above with reference to embodiments, the present invention is not limited to the above embodiments. Various modifications to the configuration and details of the present invention can be made within the scope of the present invention as can be understood by those skilled in the art. Furthermore, each embodiment can be arbitrarily combined and implemented without contradiction. [Explanation of symbols]

[0143] 10…Relay device, 11…Network interface, 12…LAN interface, 13…Relay circuit, 14…Memory circuit, 14A…Implementation data, 14P…Program, 15…Control circuit, 15A…Email monitoring unit, 15B…Training control unit, 16…User terminal, 16…Target user terminal, 20…Relay device, 21…Network interface, 22…LAN interface, 23…Relay circuit, 24…Memory circuit, 24A…Implementation data, 24P…Program, 25…Control circuit, 25A…Email monitoring unit, 25B… Training control unit, 26...User terminal, 26...Target user terminal, 30...Relay device, 31...Network I / F, 32...LAN I / F, 33...Relay circuit, 34...Memory circuit, 34A...Implementation content data, 34P...Program, 35...Control circuit, 35A...Site monitoring unit, 35B...Training control unit, 36,B...User terminal, 36,A...Target user terminal, 50...Mail server, 51...Training device, 52...Specific site, LAN...Local network, L1...Communication line, NW...Communication network.

Claims

1. A relay circuit configured to relay user terminals connected to it via LAN to a communication network, The system includes a control circuit configured to monitor and control data communication between the user terminal and the communication network via the relay circuit, The aforementioned control circuit is A mail monitoring unit configured to detect mass emails addressed to multiple users, including the training target user, from among the received emails received by the user terminal from the mail server on the communication network, A training control unit is configured to generate training email content that mimics the mass email content detected periodically by the email monitoring unit and is addressed to the target user, and to instruct the training device on the communication network to send the training email using the training email content at a new sending timing predicted from the regularity of the sending timing of the mass email. A relay device characterized by being equipped with the following features.

2. A relay circuit configured to relay user terminals connected to it via LAN to a communication network, The system includes a control circuit configured to monitor and control data communication between the user terminal and the communication network via the relay circuit, The aforementioned control circuit is A mail monitoring unit is configured to detect, from among the incoming mail received by the user terminal from the mail server on the communication network, a mass mail addressed to multiple users including the training target user, and a warning mail intended to disseminate information about malware. A training control unit is configured to generate training email content that mimics the warning email detected by the email monitoring unit and is addressed to the training target user, and to instruct the training device on the communication network to send the training email using the training email content. A relay device characterized by being equipped with the following features.

3. A relay circuit configured to relay user terminals connected to it via LAN to a communication network, The system includes a control circuit configured to monitor and control data communication between the user terminal and the communication network via the relay circuit, The aforementioned control circuit is A site monitoring unit configured to monitor the provision of malware warning information on pre-designated specific sites, A training control unit is configured to, upon detection of new alert information by the site monitoring unit, generate training email content that mimics an alert email intended to disseminate the alert information, addressed to the training target user, based on the content of the alert information, and to instruct the training device on the communication network to send the training email using the training email content. A relay device characterized by being equipped with the following features.

Citation Information

Patent Citations

  • Target type mail attack simulation system and target type mail attack simulation program

    JP2013149063A