relay device

The relay device addresses the issue of inaccurate training by generating credible training emails based on actual attack content, enhancing users' ability to handle deceptive emails.

JP2026061874APending Publication Date: 2026-04-09SAXA
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-09-30
Publication Date
2026-04-09

AI Technical Summary

Technical Problem

Conventional training devices fail to generate highly credible training emails that mimic actual attack emails, leading to inaccurate assessment of users' ability to handle such emails, especially those with deceptive content.

Method used

A relay device that monitors and controls data communication, detects malicious attack emails, and generates training emails mimicking the actual attack emails' content to accurately assess users' response capabilities.

Benefits of technology

Enables accurate evaluation of users' ability to handle actual attack emails by sending highly credible training emails that reflect real email content, thereby improving security awareness and response skills.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026061874000001_ABST
    Figure 2026061874000001_ABST
Patent Text Reader

Abstract

This device provides a relay system that accurately assesses a user's ability to deal with attack emails under desired email reception conditions. [Solution] The relay device 10 includes a relay circuit 13 that relays user terminals 20 connected to it via LAN to the communication network, and a control circuit 15 that monitors and controls data communication between the user terminals 20 and the communication network via the relay circuit 13. The control circuit 15 includes a mail monitoring unit 15A that monitors incoming mail received by the user terminals 20 from a mail server on the communication network and detects malicious attack mail containing malware, and a training control unit 15B that, in response to the detection of attack mail by the mail monitoring unit 15A, acquires the content of the attack mail, selects the recipient user of the attack mail as a training target user, generates training mail content that mimics the attack mail and is addressed to the training target user based on the obtained attack mail content, and instructs a training device on the communication network to send a training mail using the training mail content.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a security countermeasure technology for training a user to correctly handle attack emails based on training emails that mimic malicious attack emails.

Background Art

[0002] In recent years, the damage caused by malicious malware that uses emails as an infection route has been increasing rapidly. For example, according to "Emotet", which infects just by clicking on and opening an attached file in a targeted attack email, it is said that not only the email data registered on the user terminal but also important personal information including authentication information such as IDs and passwords will be leaked. Therefore, if such malware infection occurs, new attack emails will be generated based on the leaked email data and the infection will spread to other users, access to the internal network will be made based on the leaked authentication information and confidential information will be stolen, or the user will be infected with a malicious program typified by "Ransomware" that demands a ransom, leading to extremely large damage. Therefore, it is important to correctly handle attack emails, and users are required to learn how to correctly handle them on a daily basis.

[0003] Conventionally, as a technique for grasping the user's correct handling ability for such attack emails, Patent Document 1 proposes a training device for training correct handling of attack emails, which generates training emails that mimic malicious attack emails based on a preset template, transmits them to a user to be trained via a mail server, and detects that the user has received the training emails on the user terminal and opened the attached files attached to the training emails. Thereby, the user's correct handling ability for attack emails can be grasped, and it can be reflected in efforts to raise the user's security awareness and in improving the security literacy of the entire organization to which the user belongs.

Prior Art Documents

Patent Documents

[0004] [Patent Document 1] Japanese Patent Publication No. 2013-149063 [Overview of the project] [Problems that the invention aims to solve]

[0005] A user's response to an attack email varies depending on the perceived credibility of the email's content. In particular, targeted attack emails aimed at specific companies or organizations often contain deceptive language disguised as legitimate requests, such as quotes, product inquiries, or media interview requests. In such cases, even highly cautious users are likely to be tricked into opening attachments containing malware. Therefore, it is crucial to assess users' response capabilities through training emails using highly credible content.

[0006] According to the conventional technology described above, when training emails are generated based on pre-registered template data, the content of emails received by the trainee users cannot be reflected. As a result, it was not possible to generate highly credible training emails, and there was a problem in that it was not possible to accurately grasp the users' ability to deal with attack emails.

[0007] This invention aims to solve these problems and provide security measures that can accurately grasp a user's ability to deal with actual attack emails. [Means for solving the problem]

[0008] To achieve this objective, the relay device according to the present invention comprises a relay circuit configured to relay user terminals connected to it via a LAN to a communication network, and a control circuit configured to monitor and control data communication between the user terminals and the communication network via the relay circuit, wherein the control circuit comprises a mail monitoring unit configured to monitor incoming mail received by the user terminals from a mail server on the communication network and to detect malicious attack mail containing malware, and a training control unit configured to acquire the content of the attack mail in response to the detection of the attack mail by the mail monitoring unit, select the recipient user of the attack mail as a training target user, generate training mail content that mimics the attack mail and is addressed to the training target user based on the obtained attack mail content, and instruct a training device on the communication network to send a training mail using the training mail content.

[0009] Furthermore, another relay device according to the present invention comprises a relay circuit configured to relay user terminals connected to it via a LAN to a communication network, and a control circuit configured to monitor and control data communication between the user terminals and the communication network via the relay circuit, wherein the control circuit comprises a mail monitoring unit configured to monitor incoming mail received by the user terminals from a mail server on the communication network and to detect malicious attack mail containing malware, and a training control unit configured to acquire the contents of the attack mail in response to the detection of the attack mail by the mail monitoring unit, select the recipient user of the attack mail as a training target user, generate a training mail addressed to the training target user that mimics the attack mail based on the obtained attack mail contents, and send it to the mail server. [Effects of the Invention]

[0010] According to the present invention, it becomes possible to accurately grasp a user's ability to deal with actual attack emails. [Brief explanation of the drawing]

[0011] [Figure 1] Figure 1 is a block diagram showing the configuration of a relay device according to the first embodiment. [Figure 2] Figure 2 is an explanatory diagram showing an example of setting up implementation details data. [Figure 3] Figure 3 is a sequence diagram showing the operation of the relay device according to the first embodiment. [Figure 4] Figure 4 is an explanatory diagram showing an example of the content of an attack email. [Figure 5] Figure 5 is an explanatory diagram showing an example of training email content. [Figure 6] Figure 6 is a sequence diagram showing the operation of the relay device according to the second embodiment. [Modes for carrying out the invention]

[0012] Next, embodiments of the present invention will be described with reference to the drawings.

[0013] [First Embodiment] First, with reference to the block diagram in Figure 1, the relay device 10 according to the first embodiment of the present invention will be described.

[0014] This relay device 10 consists of relay devices such as a UTM (Unified Threat Management) device and a gateway, and is configured to relay user terminals 20 such as PCs and smartphones, which are connected to it via a LAN (Local Area Network), to a higher-level communication network NW such as the Internet.

[0015] [Principle of the present invention] The actions taken by users against attack emails vary depending on the credibility of the email content of those attack emails. In particular, in actual targeted attack emails aimed at specific companies or organizations, the email content uses deceptive phrases that seem highly credible, such as estimates regarding requests, inquiries about products, or applications for interviews from the media. In such cases, even users with strong vigilance are likely to be deceived by the clever tactics and accidentally open attached files containing malware. Therefore, it is important to grasp the response ability of users through training emails with highly credible email content.

[0016] Here, the relay device 10 is originally configured to monitor and control data communication including email exchanges between user terminals 20 connected subordinate via a LAN and the communication network NW. The user terminal 20 can obtain the received email content of emails received from the email server 30 by the relay device 10, and can detect actual attack emails containing malware based on the received email content, like a general UTM device.

[0017] Therefore, when creating training emails, it is not easy to generate highly credible email content like actual attack emails, but the email content of actual attack emails can be easily obtained.

[0018] Focusing on the configuration related to email monitoring and control originally provided in such a relay device 10 and the fact that the email content of actual attack emails includes highly credible content, the present invention monitors the email exchanges between the user terminal 20 and the email server 30. When the received email received by the user terminal 20 from the email server 30 is an attack email, it acquires the attack email content of the attack email, selects the destination user of the attack email as the training target user, and generates a training email based on the obtained attack email content.

[0019] As a result, it is possible to grasp the user's response ability with the training mail generated based on the highly reliable mail content of the actual attack mail. Therefore, it becomes possible to accurately grasp the user's coping ability with respect to the actual attack mail.

[0020] [Detailed Configuration of Relay Device] Next, referring to the block diagram of FIG. 1 described above, the detailed configuration of the relay device 10 according to the present embodiment will be described.

[0021] The relay device 10 according to the present embodiment includes, as main circuit configurations, a network I / F 11, a LAN I / F 12, a relay circuit 13, a memory circuit 14, and a control circuit 15.

[0022] [Network I / F] The network I / F 11 is connected to the communication network NW via the communication line L, and is configured to perform data communication with the communication network NW based on an instruction from the control circuit 15.

[0023] [LAN I / F] The LAN I / F 12 is connected to the LAN, and is configured to perform data communication with the LAN based on an instruction from the control circuit 15.

[0024] [Relay Circuit] It is connected to the network I / F 11 and the LAN I / F 12, and is configured to relay and connect the data communication between the network I / F 11 and the LAN I / F 12 in response to an instruction from the control circuit 15.

[0025] [Memory Circuit] The memory circuit 14 is generally composed of a storage device such as a semiconductor memory or a hard disk, and is configured to store processing data and a program 14P used in the training mail control process executed by the control circuit 15.

[0026] The main processing data stored in the memory circuit 14 includes implementation content data 14A.

[0027] [Implementation details data] Implementation content data 14A is data used to set the content of the training to be actually conducted using training emails, and is pre-set in the memory circuit 14 by the training administrator. Note that the data set in implementation content data 14A is not limited to the data described below, and other data used to create training emails, such as personal information such as the affiliation of the training target users, may also be set in implementation content data 14A.

[0028] In the example configuration shown in Figure 2, the username of the user to be trained is set to "Saxa Taro," and the email address of the user to be trained is set to "saxa.taro@saxa.jp." As a result, training is conducted on the user named "Saxa Taro," and the content of an incoming email addressed to "saxa.taro@saxa.jp" is retrieved. Based on that email content, a training email mimicking a resent email is generated, and "saxa.taro@saxa.jp" is set as the recipient email address. In addition, in the example configuration shown in Figure 2, the timing for sending the training email is set to "When an attack email is detected," meaning that the training email will be sent immediately when it is detected that any user has received an attack email.

[0029] [program] Program 14P is a program that, in cooperation with the CPU of the control circuit 15, realizes various processing units for executing training email control processing in the control circuit 15. This program 14P is read from an external device or recording medium (neither of which are shown) and stored in the memory circuit 14 in advance.

[0030] [control circuit] The control circuit 15 has a CPU and its peripheral circuits, and is configured to execute training email control processing by having the CPU and the program 14P of the memory circuit 14 cooperate to realize various processing units.

[0031] The main processing units implemented in the control circuit 15 are the email monitoring unit 15A and the training control unit 15B.

[0032] [Email Monitoring Department] The email monitoring unit 15A monitors data communication between the user terminal 20 and the communication network NW via the relay circuit 13, and is configured to monitor received emails from the email server 30 to any user terminal 20 based on the implementation data 14A of the memory circuit 14, and to detect malicious attack emails containing malware. Specifically, for example, received emails can be detected from the email reception response sent back from the email server 30 in response to an email reception request sent from any user terminal 20. For the detection of malicious attack emails containing malware, well-known techniques used in general UTM devices can be used. Note that the target for detecting attack emails may be all user terminals 20 connected to the LAN, or only pre-specified user terminals 20 may be targeted for detection.

[0033] [Training Control Unit] The training control unit 15B is configured to, when the email monitoring unit 15A detects an attack email received by any user terminal 20, acquire the content of the received attack email, generate training email content that mimics the attack email based on the obtained attack email content, and instruct the training device 31 on the communication network NW to send a training email using that training email content.

[0034] Furthermore, when the training control unit 15B instructs the training device 31 to send a training email, it is configured to instruct the date and time of sending the training email based on the transmission timing set in the implementation data 14A of the memory circuit 14. In this case, for example, as shown in the example in Figure 2 above, it is instructed to send immediately in response to the instruction from the relay device 10.

[0035] [Operation of the first embodiment] Next, the operation of the relay device 10 according to the first embodiment will be described with reference to the sequence diagram in Figure 3. In the following description, the case in which the contents shown in Figure 2 above are pre-set in the implementation data 14A of the memory circuit 14 will be explained as an example. Among the user terminals 20, user terminal A corresponds to the target user terminal 20 of the training target user, and user terminal B is the user terminal 20 of the user to whom the attack email is sent. Furthermore, the attack email will be detected targeting all user terminals.

[0036] First, in the control circuit 15 of the relay device 10, the training control unit 15B sets the implementation content data 14A in response to instructions from the user terminal 20 used by the training administrator, which are received via LANI / F12 (step 100), and the email monitoring unit 15A starts monitoring received emails received by all user terminals 20 connected to the LAN based on the implementation content data 14A (step 101).

[0037] After monitoring begins, if a mail reception request is sent from user terminal B to mail server 30 (step 102), the control circuit 15 relays and forwards the request to mail server 30 on the communication network NW via LANI / F12, relay circuit 13, and network I / F11.

[0038] In response, when the mail server 30 sends back a mail reception response addressed to the training target user (step 103), the mail monitoring unit 15A takes this mail reception response from the relay circuit 13 and inspects the received mail received by the user terminal B.

[0039] If the received email is detected as a malicious attack email containing malware (step 104), the training control unit 15B obtains the content of the attack email from the attack email detected by the email monitoring unit 15A (step 105), and relays the received email response to the user terminal B that requested the email and is connected to the LAN, via the relay circuit 13 and LANI / F 12 (step 106). If the received email in step 104 is not an attack email, the process proceeds to step 106 as described above, and the received email response is relayed to the user terminal B that requested the email (step 106).

[0040] Next, the training control unit 15B generates training email content that mimics an attack email based on the acquired attack email content (step 110).

[0041] Comparing the attack email content shown in Figure 4 with the training email content shown in Figure 5, the "To" field, which indicates the recipient's email address, has been replaced from "shirokane.saxa.jiro@saxa.jp" in Figure 4 to the training target user's email address "saxa.taro@saxa.jp" in Figure 5. Additionally, the attachment has been replaced from the malicious attachment containing malware in Figure 4 to the training attachment in Figure 5. In this case, the attachment filename from Figure 4 is used as the attachment filename in Figure 5. Note that in Figure 5, the "From" field indicating the sender's email address, the "Subject" field indicating the subject, the "Message-Id" indicating the email identifier, and the email body are the same as in Figure 4.

[0042] After this, the training control unit 15B determines the date and time to send the training email based on the transmission timing set in the implementation content data 14A (step 111), instructs the training device 31 on the communication network NW to send a training email using the contents of the training email via the network I / F 11 (step 112), and the email monitoring unit 15A terminates email monitoring (step 113).

[0043] In this case, the training control unit 15B determines that the training email should be sent immediately, since the transmission timing is set to "when an attack email is detected" in the example shown in Figure 2. The content of the training email instructed to the training device 31 is not limited to the configuration shown in Figure 5; it may also be instructed using a list showing the contents of each column.

[0044] The training device 31 generates a training email addressed to the email address of the training target user based on the training email content included in the training email transmission instruction from the relay device 10, and sends it to the mail server 30 at the training email transmission date and time (step 114).

[0045] Subsequently, if a mail reception request is sent from the target user terminal A to the mail server 30 (step 120), the control circuit 15 relays and forwards the request to the mail server 30 on the communication network NW via LANI / F12, relay circuit 13, and network I / F11.

[0046] In response, if the mail server 30 returns an incoming mail (step 121), the control circuit 15 relays and forwards it to the target user terminal A via the network interface 11, relay circuit 13, and LAN interface 12.

[0047] As a result, the training email is relayed to target user terminal A and viewed by the training user. Therefore, if the monitored user's response to the training email is inappropriate, the malware in the attached file is activated, similar to known techniques, and a notification of malware infection is sent to the training device 31 on the communication network NW, which is then collected as training results. At this time, a training email mimicking an attack email is sent back to the trained user at the same time the monitored user receives the email. In addition, a highly credible training email reflecting the content of an actual attack email received by any user is sent.

[0048] [Effects of the First Embodiment] Thus, in this embodiment, the relay device 10 monitors incoming emails received by any user terminal 20 from the mail server 30, and in response to the detection of the receipt of a malicious attack email containing malware, it acquires the content of the attack email, generates training email content that mimics the attack email and is addressed to the training target user based on the obtained attack email content, and instructs the training device 31 on the communication network NW to send a training email using the training email content.

[0049] This allows the system to send a training email to a trainee user that mimics an actual attack email received by any user, timed to coincide with the trainee user's email reception. Furthermore, it can send a highly credible training email that accurately reflects the content of a real attack email. Therefore, it becomes possible to accurately assess a user's ability to deal with actual attack emails.

[0050] [Second Embodiment] Next, a relay device 10 according to a second embodiment of the present invention will be described. In the first embodiment described above, the case in which the transmission of training emails and the collection of training results are performed by an existing training device 31 on a communication network NW was described as an example. In this embodiment, the case in which the configuration of the training device 31 is implemented in the control circuit 15 of the relay device 10 will be described as an example.

[0051] The configuration of the relay device 10 according to this embodiment is almost the same as the block diagram shown in Figure 1 above, but some of the configurations of the training control unit 15B of the control circuit 15 are different.

[0052] [Training Control Unit] The training control unit 15B is configured to, when the email monitoring unit 15A detects an attack email received by any user terminal 20, acquire the content of the attack email, generate a training email that mimics the attack email based on the obtained content, and send the training email to the email server 30 on the communication network NW.

[0053] In this case, the training control unit 15B is configured to determine the date and time to send the training email based on the transmission timing set in the implementation data 14A of the memory circuit 14, and to send the training email to the mail server 30 according to that date and time. For example, according to the example in Figure 2 above, it is instructed to send immediately upon detection of an attack email.

[0054] Furthermore, the training control unit 15B is configured to collect training results related to the target user terminal 20 and store them in the memory circuit 14 if it is notified that malware attached to a training email has been activated and the target user terminal 20 has been infected with malware.

[0055] [Operation of the second embodiment] Next, with reference to the sequence diagram in Figure 6, the operation of the relay device 10 according to the second embodiment will be described. In the following description, the case in which the contents shown in Figure 2 above are pre-set in the implementation data 14A of the memory circuit 14, and a training email addressed to the training target user is sent from the relay device 10 will be described as an example. Steps 100 to 106 in Figure 3 are the same in this embodiment as well, and a detailed explanation will be omitted here.

[0056] The training control unit 15B generates a training email that mimics the attack email based on the content of the attack email obtained in step 105 of Figure 3 (step 200). In this case, the content of the training email is the same as the example in Figure 5.

[0057] After this, the training control unit 15B determines the date and time to send the training email based on the transmission timing set in the implementation data 14A (step 201), sends the training email to the mail server 30 on the communication network NW via the network I / F 11 (step 202), and the mail monitoring unit 15A terminates mail monitoring (step 203).

[0058] In this case, the training control unit 15B determines that the training email will be sent immediately, since the transmission timing is set to "when an attack email is detected" in the example shown in Figure 2 above.

[0059] Subsequently, if a mail reception request is sent from the target user terminal A to the mail server 30 (step 120), the control circuit 15 relays and forwards the request to the mail server 30 on the communication network NW via LANI / F12, relay circuit 13, and network I / F11.

[0060] In response, if the mail server 30 returns an incoming mail (step 121), the control circuit 15 relays and forwards it to the target user terminal A via the network interface 11, relay circuit 13, and LAN interface 12.

[0061] As a result, the training email is relayed to target user terminal A and viewed by the training user. Therefore, if the monitored user's response to the training email is inappropriate, the malware in the attached file is activated, similar to known techniques, and the relay device 10 is notified of the malware infection, which is then collected as training results. At this time, a training email mimicking the attack email is sent to the training user at the same time that any user receives an attack email. In addition, a highly credible training email reflecting the content of an actual attack email received by the training user is sent.

[0062] [Effects of the second embodiment] Thus, in this embodiment, the relay device 10 is configured to, upon detecting the receipt of an attack email by any user terminal 20, acquire the content of the attack email, generate a training email that mimics the attack email and is addressed to a target user based on the acquired attack email content, and send it to the mail server 30.

[0063] Therefore, the relay device 10 alone can accurately grasp the user's ability to deal with actual attack emails, and the required configuration can be simplified.

[0064] [Expansion of the embodiment] Although the present invention has been described above with reference to embodiments, the present invention is not limited to the above embodiments. Various modifications to the configuration and details of the present invention can be made within the scope of the present invention as can be understood by those skilled in the art. Furthermore, each embodiment can be arbitrarily combined and implemented without contradiction.

[0065] Furthermore, in the embodiments described above, the example given was the transmission of a training email generated from the content of an attack email to a target user terminal 20 of a training target user connected under the relay device 10 that detected the attack email. However, the invention is not limited to this. For example, the training email generated from the content of an attack email may be transmitted to a target user terminal 20 of a training target user connected under a relay device 10 different from the one that detected the attack email.

[0066] Furthermore, in the embodiments described above, the training target users were explained as being pre-configured in the implementation data 14A of the memory circuit 14, but this is not the only example. For example, the email monitoring unit 15A may detect multiple destination email addresses set collectively from each user's received emails and record them in the memory circuit 14. When an attack email is detected, the training target users may be identified based on the destination email address of the attack email and the email addresses that are set collectively most frequently. [Explanation of Symbols]

[0067] 10...Relay device, 11...Network interface, 12...LAN interface, 13...Relay circuit, 14...Memory circuit, 14A...Implementation data, 14P...Program, 15...Control circuit, 15A...Email monitoring unit, 15B...Training control unit, 20...User terminal, 20...Target user terminal, 30...Email server, 31...Training device, LAN...Local network, L...Communication line, NW...Communication network.

Claims

1. A relay circuit configured to relay user terminals connected to it via LAN to a communication network, The system includes a control circuit configured to monitor and control data communication between the user terminal and the communication network via the relay circuit, The aforementioned control circuit is A mail monitoring unit configured to monitor incoming mail received by the user terminal from a mail server on the communication network and to detect malicious attack mail containing malware, A training control unit is configured to, upon detection of an attack email by the email monitoring unit, acquire the content of the attack email, select the recipient user of the attack email as a training target user, generate training email content that mimics the attack email and is addressed to the training target user based on the obtained attack email content, and instruct a training device on the communication network to send a training email using the training email content. A relay device characterized by being equipped with the following features.

2. A relay circuit configured to relay user terminals connected to it via LAN to a communication network, The system includes a control circuit configured to monitor and control data communication between the user terminal and the communication network via the relay circuit, The aforementioned control circuit is A mail monitoring unit configured to monitor incoming mail received by the user terminal from a mail server on the communication network and to detect malicious attack mail containing malware, A training control unit is configured to, upon detection of an attack email by the email monitoring unit, acquire the content of the attack email, select the recipient user of the attack email as a training target user, generate a training email that mimics the attack email and is addressed to the training target user based on the obtained attack email content, and send it to the email server. A relay device characterized by being equipped with the following features.

Citation Information

Patent Citations

  • Target type mail attack simulation system and target type mail attack simulation program

    JP2013149063A