Threat intelligence management device, threat intelligence management method, and program

The system enhances threat intelligence sharing by generating cohesive intelligence from user-submitted data, providing incentives, and recommending relevant information, addressing the fragmentation and motivation issues in existing systems.

JP2026088864APending Publication Date: 2026-05-29HITACHI LTD

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
HITACHI LTD
Filing Date
2024-11-19
Publication Date
2026-05-29

AI Technical Summary

Technical Problem

Current threat intelligence sharing systems often share information as isolated points rather than a cohesive whole, making it difficult to utilize effectively, and the motivation for posting threat intelligence depends on individual user incentives.

Method used

A threat information management system that receives, processes, and generates threat intelligence by calculating relationships between threat information, provides incentives for users, and scores and recommends information based on relevance and user preferences.

Benefits of technology

Improves the usability of threat intelligence by identifying relevant information, encouraging user contributions, and forming a collective defense ecosystem through incentives and tailored recommendations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026088864000001_ABST
    Figure 2026088864000001_ABST
Patent Text Reader

Abstract

The present invention provides a threat information management device, a threat information management method, and a program that can generate threat intelligence from threat information and improve its usability compared to a case without the configuration of the present invention. [Solution] A threat information management device comprising a threat information receiving unit program 108 that receives threat information posted by users, a correlation calculation program 109 that generates threat intelligence based on the correlation between threat information, and an incentive calculation program 110 that calculates an incentive for the user who posted the threat information.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a threat information management apparatus, a threat information management method, and a program. In particular, the present invention relates to a threat information management apparatus, a threat information management method, and a program for generating threat intelligence from threat information.

Background Art

[0002] Information such as malware information used in cyberattacks and malicious URL (Uniform Resource Locator) information is also called threat information. By using threat information, it is possible to detect malware and block access to malicious URLs. On the other hand, since the threat information obtained by individual organizations is limited, sharing and using it for collective defense is effective as a countermeasure against attackers who are becoming more sophisticated or organized.

[0003] Patent Document 1 describes a cyberattack information processing program. This cyberattack information processing program causes a computer to execute a storage process and an output process. The storage process stores information in a storage device in a state accessible from a second user terminal accessible to the first system when the first system receives information related to a cyberattack from the first user terminal. Further, the storage process converts the data structure of the information into a state usable in a second system different from the first system and stores it in a storage device accessible from the second system or stores it in the second system. The output process converts other information related to a cyberattack received by the first system from the second system or the storage device into a state accessible from the second user terminal and outputs it when other information related to a cyberattack is added to the second system.

[0004] Patent Document 2 describes an information sharing system in which multiple information management systems are connected to communicate via a network. In this information sharing system, the information management system includes a data processing unit that receives information managed by another party from an information processing device related to another party, calculates the level of trust in that other party, and calculates the level of credibility of the information based on the received information and the calculated level of trust; a response processing setting unit that determines the content of the response processing for the content indicated by the information based on the calculated level of trust; and a trust level update unit that changes the level of trust based on the content of the response processing.

[0005] Non-patent document 1 discloses MISP (Malware Information Sharing Platform) and a threat sharing project, which are reliable platforms capable of collecting and sharing threat information such as vulnerabilities and financial indicators used in fraud cases, as well as key breach indicators for targeted attacks. [Prior art documents] [Patent Documents]

[0006] [Patent Document 1] Japanese Patent Publication No. 2019-040533 [Patent Document 2] Japanese Patent Publication No. 2023-010181 [Non-patent literature]

[0007] [Non-Patent Document 1] Cynthia Wagner, Alexandre Dulaunoy, Gerard Wagener, and Andras Iklody: MISP: The Design and Implementation of a Collaborative Threat Intelligence Sharing Platform, In Proceedings of the 2016 ACM on Workshop on Information Sharing and Collaborative Security (WISCS '16), pp. 49-56 (2016). https: / / doi.org / 10.1145 / 2994539.2994542 [Overview of the project] [Problems that the invention aims to solve]

[0008] On the other hand, current threat intelligence sharing often involves sharing information as isolated points rather than as a cohesive whole (such as threat intelligence, which will be discussed later), making it difficult to utilize effectively. The present invention aims to provide a threat information management device, a threat information management method, and a program that can generate threat intelligence from threat information and improve its usability compared to a system without the configuration of the present invention. [Means for solving the problem]

[0009] To solve the above problems, the present invention provides a threat information management device comprising: a threat information receiving unit that receives threat information posted by users; a relationship calculation unit that generates threat intelligence based on the relationships between threat information; and an incentive calculation unit that calculates an incentive for the user who posted the threat information.

[0010] Here, for example, the relevance calculation unit extracts and groups relevance from the similarity of threat information posted by users, and generates threat intelligence. In this case, it is possible to generate common threat intelligence for the grouped threat information with high relevance. Furthermore, for example, the relevance calculation unit extracts and groups relevance from at least one of the similarities of user-defined tag information, surface information, and posting date. In this case, grouping can be performed using a more appropriate metric. Furthermore, for example, the incentive calculation unit can award users a score as an incentive. In this case, it can encourage users to submit threat information. Furthermore, for example, the incentive calculation unit assigns a score to the user based on at least one of the number of useful threat pieces of information that led to the construction of threat intelligence, and the nature of those threat pieces of information. In this case, a more reliable score can be calculated. Furthermore, it includes a screen rendering unit that creates display information, for example, about threat intelligence. In this case, threat information can be shared among users. Furthermore, for example, the displayed information could include information showing the users who posted threat information. In this case, it would encourage users to post threat information. Furthermore, the system may further include a threat information scoring unit that scores at least one of threat information and threat intelligence. In this case, the degree of threat posed by the threat information and threat intelligence can be evaluated. Furthermore, for example, the threat information score calculation unit calculates a score based on the number of times the user accesses at least one of the threat information and threat intelligence. This allows for assigning a higher score to threat information with a higher threat level. Furthermore, the system includes, for example, a prevalence calculation unit that estimates the prevalence of at least one of threat information and threat intelligence. In this case, the user can know the degree of prevalence of the threat information and threat intelligence. Furthermore, the system may include a threat information recommendation unit that recommends at least one of threat information and threat intelligence based on the user's preferences. In this case, threat information and threat intelligence that the user is interested in can be presented.

[0011] Furthermore, the present invention is a threat information management method in which a processor executes a program stored in memory to receive threat information submitted by users, generates threat intelligence based on the relationships between the threat information, and calculates an incentive for the user who submitted the threat information.

[0012] Furthermore, the present invention is a program for a computer that enables the following functions: receiving threat information submitted by users, generating threat intelligence based on the relationships between threat information, and calculating incentives for users who submit threat information. [Effects of the Invention]

[0013] According to the present invention, it is possible to provide a threat information management device, a threat information management method, and a program that can generate threat intelligence from threat information and improve its usability compared to a case without the configuration of the present invention. [Brief explanation of the drawing]

[0014] [Figure 1] This figure shows an example configuration of a cyber threat information sharing system according to the first embodiment. [Figure 2] This figure shows an example of a list of threat information. [Figure 3] This figure shows an example of a list of threat intelligence. [Figure 4] This figure shows an example of a user list. [Figure 5] This flowchart illustrates an example of the threat information receiving process performed by the cyber threat information sharing system of the first embodiment. [Figure 6]It is a flowchart for explaining an example of relevance calculation processing executed by the cyber threat information sharing system according to the first embodiment. [Figure 7] It is a flowchart for explaining an example of incentive calculation processing executed by the cyber threat information sharing system according to the first embodiment. [Figure 8] It is a flowchart for explaining an example of screen drawing processing executed by the cyber threat information sharing system according to the first embodiment. [Figure 9] It is an example of a cyber threat information sharing system drawing screen generated by a program constituting the cyber threat information sharing system according to the first embodiment. [Figure 10] It is a diagram showing a configuration example of the cyber threat information sharing system according to the second embodiment of the present invention. [Figure 11] It is a flowchart for explaining an example of access analysis processing executed by the access analysis program. [Figure 12] It is a flowchart for explaining an example of threat information score calculation processing executed by the threat information score calculation program. [Figure 13] It is a flowchart for explaining an example of popularity calculation processing executed by the popularity calculation program. [Figure 14] It is a flowchart for explaining an example of threat information recommendation processing executed by the threat information recommendation program.

Modes for Carrying Out the Invention

[0015] Hereinafter, embodiments of the present invention will be described with reference to the drawings. However, the present invention is not to be construed as being limited to the description of the embodiments shown below. Those skilled in the art will easily understand that the specific configuration can be changed without departing from the spirit or gist of the present invention. In the configuration of the invention described below, the same or similar configurations or functions are denoted by the same reference numerals, and duplicate descriptions are omitted. The designations "First," "Second," "Third," etc., used in this specification are for the purpose of identifying constituent elements and do not necessarily limit their number or order. The positions, sizes, shapes, and ranges of each component shown in the drawings, etc., may not represent the actual positions, sizes, shapes, and ranges, etc., in order to facilitate understanding of the invention. Therefore, the present invention is not limited to the positions, sizes, shapes, and ranges, etc., disclosed in the drawings, etc.

[0016] [First Embodiment] <Explanation of the Cyber ​​Threat Information Sharing System> The first embodiment describes the processing of a cyber threat intelligence sharing system in which the usability of threat information is improved by finding the relevance of threat information submitted by users and generating threat intelligence, and the formation of an ecosystem is supported by providing appropriate incentives to users who submit threat information. "Threat information" is a general term for information and data related to threats such as cyberattacks and hacking. "Threat intelligence" is derived from threat information by organizing and analyzing information on the attacker's intentions, capabilities, equipment, etc., and transforming it into usable knowledge. By utilizing threat intelligence, it becomes possible to defend against and detect sophisticated cyberattacks that were overlooked by conventional security measures. "Incentives" are rewards paid according to results.

[0017] Figure 1 shows an example configuration of a cyber threat information sharing system according to the first embodiment. The illustrated cyber threat information sharing system 101 is an example of a threat information management device and is connected to user terminals A, B, ..., X (115a~115c) operated by users, external user terminals A, B, ..., X (116a~116c) operated by external users, and the internet 118 via networks 117a~117b. Note that there may be any number of user terminals 115a~115c and external user terminals 116a~116c. Similarly, there may be any number of networks 117a~117b.

[0018] The cyber threat information sharing system 101 is a computer comprising a CPU (Central Processing Unit) 103, main memory 104 for storing data necessary for the CPU 103 to perform processing, storage device 105 such as a hard disk or flash memory with a large capacity to store a large amount of data, IF (interfaces) 102a to 102b for communicating with other devices, input / output devices 106 for input / output such as a keyboard and display, and communication channels 107 connecting these devices. The communication channel 107 is, for example, an information transmission medium such as a bus or cable.

[0019] The CPU 103 receives threat information by executing a threat information receiving program 108 stored in the main memory 104. The threat information receiving program 108 functions as a threat information receiving unit that receives threat information submitted by users. Furthermore, the CPU 103 calculates the relationships between threat information by executing the relationship calculation program 109. The relationship calculation program 109 functions as a relationship calculation unit that generates threat intelligence based on the relationships between threat information. Furthermore, the CPU 103 calculates the incentive to be given to the user who posted the threat information by executing the incentive calculation program 110. The incentive calculation program 110 functions as an incentive calculation unit that calculates the incentive for the user who posted the threat information. The CPU 103 then executes the screen rendering program 111 to display various results on a screen. The screen rendering program 111 functions as a screen rendering unit that creates display information to be shown regarding threat intelligence.

[0020] The storage device 105 stores a list of threat information 112 for managing threat information submitted by users, a list of threat intelligence 113 for managing constructed threat intelligence, and a list of users 114 for managing users. Each of the above programs and data may be stored in the main memory 104 or storage device 105 in advance, or they may be installed (loaded) from the input / output device 106 or from other devices via IF102a~102b when needed.

[0021] User terminals A, B, ..., X (115a~115c) and external user terminals A, B, ..., X (116a~116c) are also computer devices equipped with a CPU, main memory, storage device, etc. Networks 117a to 117b are, for example, LANs (Local Area Networks). This is a network. The communication lines used in networks 117a to 117b may be wired or wireless, or a combination of both may be used. In addition, relay devices such as gateway devices and routers may be used to connect multiple networks and communication lines. Note that the configuration of the cyber threat information sharing system described in Figure 1 is just one example and is not limited to this.

[0022] <Explanation of the data structure used in the cyber threat intelligence sharing system> Next, we will explain the data structure used in the cyber threat intelligence sharing system. Figure 2 shows an example of a list of threat information 112. As shown in Figure 2, the threat information list 112 is composed of, for example, a threat information ID 201, a registration date and time 202, a type 203, a content 204, a tag 205, and a user ID 206. Threat information ID 201 is a field that stores identification information for uniquely identifying threat information. In the first embodiment, a number is stored as the identification information in Threat information ID 201. The registration date and time 202 represents the date and time when the threat information was registered in the system. For example, the threat information corresponding to the entry with threat information ID 201 "0" was registered at 00:00:00 on January 1, 2024. The data format of the time stored in registration date and time 202 is not particularly limited. For example, any data format that allows time to be identified, such as Unixtime, may be used.

[0023] Type 203 is a field that stores the type of threat information. For example, an entry with Threat Information ID 201 of "0" indicates that the type of threat information is "malware". Content 204 is a field that stores threat information. For example, an entry with threat information ID 201 of "0" indicates that the threat information corresponding to that entry is "malwareA". Tag 205 is a field that stores information related to threat intelligence as a tag. For example, the tag corresponding to an entry with threat intelligence ID 201 "0" represents "Threat Group B". Note that multiple tags may be stored. Tag 205 can be assigned by the user. User ID 206 is a field that stores the ID 401 of the user who registered the threat information. For example, an entry with Threat Information ID 201 "0" indicates that the ID of the user who registered the threat information is "0". Note that the list of threat information explained in Figure 2 is just one example and is not limited to this.

[0024] Figure 3 shows an example of a list of 113 threat intelligence items. As shown in Figure 3, the threat intelligence list 113 is composed of, for example, a threat intelligence list ID 301, a registration date and time 302, a name 303, a related threat information ID 304, and a tag 305. The Threat Intelligence List ID 301 is a field that stores identification information for uniquely identifying threat intelligence. In the first embodiment, a number is stored as the identification information in the Threat Intelligence List ID 301. The registration date and time 302 represents the date and time when the threat intelligence was registered in the system. For example, a threat intelligence corresponding to an entry with threat intelligence list ID 301 of "0" was registered at 00:00:00 on January 17, 2024. Any data format that allows for time identification, such as Unixtime, can be used for the time stored in registration date and time 302.

[0025] Name 303 is a field that stores the name of the threat intelligence. For example, the name of the threat intelligence corresponding to the entry with Threat Intelligence List ID 301 "0" is "Threat Group B". The related threat information ID 304 is a field that stores the threat information ID 201 of the threat information that makes up the threat intelligence. For example, the threat information ID 201 of the threat information that makes up the threat intelligence corresponding to the entry where the threat intelligence list ID 301 is "0" is "0", "3", and "4". Tag 305 is a field that stores information related to threat intelligence as tags. For example, the tags corresponding to an entry with threat intelligence list ID 301 of "0" represent "malwareA", "threat group B", and "prevalent from 2024 / 01 / 01 to 01 / 15". Note that the list of threat intelligence explained in Figure 3 is just one example and is not limited to it.

[0026] Figure 4 shows an example of a user list 114. As shown in Figure 4, the user list 114 is composed of, for example, user ID 401, registration date and time 402, username 403, and score 404. User ID 401 is a field that stores identification information to uniquely identify a user. In the first embodiment, a number is stored as the identification information in User ID 401. The registration date and time 402 represents the date and time when the user was registered with the system. For example, the user corresponding to the entry with user ID 401 "0" was registered at 00:00:00 on January 1, 2024. In this embodiment, the data format of the time stored in the registration date and time 402 is not particularly limited. For example, any data format that can identify the time, such as Unixtime, may be used.

[0027] Username403 is a field that stores the name of the user. For example, the name of the user corresponding to the entry where User ID401 is "0" is "User A". Score 404 is a field that stores the incentives awarded to a user as a score. For example, the entry corresponding to user ID 401 with "0" indicates that the user's score is "21". Note that the user list shown in Figure 4 is just one example and is not limited to this.

[0028] <Explanation of how the Cyber ​​Threat Intelligence Sharing System works> Next, we will describe the processes performed by the cyber threat information sharing system 101. Figure 5 is a flowchart illustrating an example of the threat information reception process performed by the cyber threat information sharing system 101 of the first embodiment. The threat intelligence receiving program 108, executed by the CPU 103, starts the process described below upon receiving an execution instruction. The threat intelligence receiving program 108 receives threat information to be registered from the user (step 501). Next, the threat information receiving program 108 saves the threat information obtained in step 501 to the threat information list 112 and terminates the process (step 502). Note that the method for processing threat information received, as explained in Figure 5, is merely an example and is not limited thereto. Furthermore, threat information may be obtained and recorded from sources other than the threat information receiving program 108. For example, it may be obtained from a threat information sharing service.

[0029] Figure 6 is a flowchart illustrating an example of the relevance calculation process performed by the cyber threat information sharing system 101 of the first embodiment. When the relationship calculation program 109, executed by the CPU 103, receives an execution instruction, it starts the process described below. The relevance calculation program 109 calculates relevance and extracts threat information from the threat information list 112 within a certain period as candidates for building threat intelligence (step 601). Next, the relevance calculation program 109 creates clusters using the tag information for the threat information extracted in step 601 (step 602). Specifically, it creates clusters of items with matching tag information to create one or more sets of threat information. Next, the relevance calculation program 109 updates the clusters of threat information built in step 602 using the surface information of the threat information (step 603). Specifically, it takes advantage of the fact that URLs and filenames with similar strings and naming conventions may be exploited in the same attack campaign. If threat information with matching surface information is separated into different clusters, it merges the clusters, or if threat information with different surface information exists within the same cluster, it splits the clusters.

[0030] Next, the relevance calculation program 109 considers the threat information set contained in the cluster constructed up to step 603 as threat intelligence, and extracts representative tags from the cluster to use as the threat intelligence headings (step 604). For example, if an attack group name exists in the tag information, the program extracts the attack group name, or it extracts the tag with the highest number of occurrences within the cluster. Next, the relevance calculation program 109 saves the threat intelligence constructed up to step 604 to the threat intelligence list 113 and terminates the process (step 605).

[0031] The relationship calculation method described in Figure 6 is just one example and is not limited thereto. For example, other information, such as the proximity of the posting dates, may be used to construct the cluster. In this example, we used a combination of tag information (step 602) and surface information (step 603), but you can also calculate the relationships using only one of them, or by combining them with other methods. In this case, the relevance calculation program 109 can also be said to extract relevance from the similarity of threat information posted by users, group it through clustering, and generate threat intelligence. This makes it possible to generate common threat intelligence for grouped threat information with high relevance. Specifically, the relevance calculation program 109 extracts relevance from at least one of the similarities of user-set tag information, surface information, and posting time, and groups them. This makes it possible to group using a more appropriate metric.

[0032] Figure 7 is a flowchart illustrating an example of the incentive calculation process performed by the cyber threat information sharing system 101 of the first embodiment. When the incentive calculation program 110, executed by the CPU 103, receives an execution instruction, it starts the process described below. The incentive calculation program 110 extracts threat intelligence for which incentives have not yet been calculated from the threat intelligence list 113 (step 701). Next, the incentive calculation program 110 calculates an incentive for each threat intelligence extracted in step 701, based on the user's contribution to building the threat intelligence (step 702). For example, the incentive calculation program 110 scores the number of threat information entries submitted by the user as an incentive. Next, the incentive calculation program 110 updates the user-specific score 404 stored in the user list 114 based on the incentive calculated in step 702, and then terminates the process (step 703).

[0033] The incentive calculation method described in Figure 7 is just one example and is not limited thereto. For example, methods could be used to provide higher incentives to users who submit information about threat groups requiring more advanced knowledge than simple file names or communication destinations, thus rewarding those who make more significant contributions in the context of cybersecurity. Additionally, users who contribute to the creation of a cluster, such as users who post threat intelligence with a large number of links within the cluster, may be given significant incentives. In this case, the incentive calculation program 110 assigns a score to the user as an incentive. This can encourage users to submit threat information. It can also be said that the incentive calculation program 110 assigns a score to the user based on at least one of the number of useful threat pieces of information that led to the construction of threat intelligence, and the nature of the threat pieces of information. This allows for the calculation of a more reliable score.

[0034] The cyber threat information sharing system 101 performs screen rendering processing to display various information to the user. Figure 8 is a flowchart illustrating an example of the screen rendering process performed by the cyber threat information sharing system 101 of the first embodiment. When the screen rendering program 111, executed by the CPU 103, receives an execution instruction, it starts the process described below. The screen rendering program 111 obtains information related to the threat intelligence to be rendered from the threat intelligence list 113 (step 801). Here, it is assumed that a list containing entries consisting of threat intelligence list ID 301 is obtained. The screen rendering program 111 renders information about the threat intelligence to be rendered on the screen and then terminates processing (step 802). Note that the screen rendering method described in Figure 8 is just one example and is not limited to it.

[0035] Figure 9 is an example of a cyber threat information sharing system display screen generated by a program that constitutes the cyber threat information sharing system 101 of the first embodiment. The screen in Figure 9 includes the Threat Intelligence Overview 901 and the Threat Intelligence Configuration 902. Threat Intelligence Summary 901 contains basic information about the threat intelligence being described. For example, it includes the threat intelligence list ID, registration date and time, name, related threat information ID, and tags. Threat intelligence configuration 902 depicts the threat information that constitutes the threat intelligence being described, as well as the user who posted that threat information. This allows users to share threat information with each other. Here, the user who posted the threat information is depicted by displaying "You". As described above, by providing an overview of threat intelligence and displaying the threat information and users that comprise it, it is expected that the utilization of threat intelligence and the submission of threat information by users will be encouraged. In this example, the depiction screen was illustrated based on the execution results of each program according to the first embodiment, but this is merely an example and is not limited to this. For example, any information related to threat intelligence or user incentives related to threat intelligence may be depicted in any format. While sharing and aggregating threat intelligence is an effective countermeasure against increasingly sophisticated and coordinated attackers, existing technologies for sharing threat intelligence still have drawbacks, such as the information being scattered and the fact that posting threat intelligence depends on the motivation of the poster.

[0036] According to the first embodiment, the cyber threat information sharing system 101 identifies the relevance of threat information submitted by users and elevates it into threat intelligence, while also providing appropriate incentives to users who submit threat information. This is expected to improve the usability of threat information as threat intelligence, encourage users to submit threat information, and support the formation of an ecosystem for collective defense through the sharing and aggregation of threat information.

[0037] [Second Embodiment] The second embodiment describes the processing of a cyber threat intelligence sharing system that includes more advanced functions such as threat intelligence scoring, prevalence estimation, and recommendations tailored to user preferences. The second embodiment will now be described, focusing on the differences from the first embodiment.

[0038] Figure 10 shows an example configuration of a cyber threat information sharing system 101 according to a second embodiment of the present invention. The configuration of the cyber threat information sharing system 101 in the second embodiment differs in that, in addition to the main memory 104 of the first embodiment, it includes an access analysis program 1011, a threat information score calculation program 1012, a prevalence calculation program 1013, and a threat information recommendation program 1014; otherwise, it is the same. Note that the configuration of the cyber threat information sharing system according to the second embodiment, as described in Figure 10, is merely an example and is not limited thereto. The following describes the operation of the access analysis program 1011, the threat intelligence score calculation program 1012, the prevalence calculation program 1013, and the threat intelligence recommendation program 1014.

[0039] Figure 11 is a flowchart illustrating an example of the access analysis process performed by the access analysis program 1011. When the access analysis program 1011, executed by the CPU 103, receives an execution command, it starts the process described below. The access analysis program 1011 detects access to threat information (step 1101). Here, it is assumed that there is a page that displays entries consisting of threat information IDs, and that access to this page is detected when a user accesses it. Specifically, it is assumed that a button or similar is displayed on the user's terminal device to enter information on the page displaying threat information, and the user accesses the page when they click this button with a mouse or similar device. Next, the access analysis program 1011 records the access information for the threat information and terminates the process (step 1102). For example, it has a field for the number of accesses for each threat information, and each time an access is detected, it increments the access count and records the date and time of the access. Note that the access analysis processing method described in Figure 11 is just one example and is not limited thereto. Furthermore, access analysis processing may be performed not only on threat information but also on other information such as threat intelligence.

[0040] Figure 12 is a flowchart illustrating an example of the threat intelligence score calculation process performed by the threat intelligence score calculation program 1012. The threat intelligence score calculation program 1012, executed by the CPU 103, starts the process described below upon receiving an execution command. The threat intelligence score calculation program 1012 extracts the threat intelligence to be scored (step 1201). Here, it is assumed that a list containing entries consisting of threat intelligence IDs is obtained. Next, the threat information score calculation program 1012 calculates a score based on the number of accesses to the threat information (step 1202). Specifically, threat information that is of high user interest and frequently accessed is considered to have a high threat level, and the number of accesses made over a certain period is used as the score for that threat information. Next, the threat information score calculation program 1012 saves the score calculated in step 1202 in association with the threat information, and terminates the process (step 1203). The method for calculating threat intelligence scores, as explained in Figure 12, is merely an example and is not limited thereto. Other scoring methods may be implemented, such as calculating scores based on user votes, or assigning higher scores to threat intelligence containing information that is more important in the context of cybersecurity, such as threat group names. Furthermore, the threat intelligence score calculation process may be performed not only on threat intelligence but also on other types of information, such as threat intelligence. In this case, the threat information score calculation program 1012 functions as a threat information score calculation unit that scores at least one of the threat information and threat intelligence. This allows for an evaluation of the degree of threat posed by the threat information and threat intelligence. The threat information score calculation program 1012 also calculates a score based on the number of times the user accesses at least one of the threat information and threat intelligence. This allows for assigning a higher score to threat information with a higher threat level.

[0041] Figure 13 is a flowchart illustrating an example of the epidemic severity calculation process performed by the epidemic severity calculation program 1013. When the epidemic severity calculation program 1013, which is executed by the CPU 103, receives an execution instruction, it starts the process described below. The prevalence calculation program 1013 extracts threat information to be used for prevalence calculation (step 1301). Here, it is assumed that a list containing entries consisting of threat information IDs is obtained. Next, the prevalence calculation program 1013 calculates the prevalence based on the number of posts about the threat information (step 1302). Specifically, threat information with many overlapping user posts is considered to have a high prevalence, and the number of posts over a certain period is used as the prevalence level for that threat information. Next, the prevalence calculation program 1013 updates the prevalence level based on the number of accesses to the threat information (step 1303). Specifically, threat information that is of high user interest and receives many accesses is considered to have a high prevalence level, and the number of accesses over a certain period is used to update the prevalence level of that threat information. Next, the epidemic severity calculation program 1013 saves the epidemic severity calculated in the process up to step 1303, linked to the threat information, and terminates the process (step 1304). The method for calculating the epidemic severity described in Figure 13 is just one example and is not limited thereto. Furthermore, the prevalence calculation process may be performed not only on threat information but also on other information such as threat intelligence. In this case, the prevalence calculation program 1013 functions as a prevalence calculation unit that estimates the prevalence of at least one of the threat information and threat intelligence. This allows the user to know the degree of prevalence of the threat information and threat intelligence.

[0042] Figure 14 is a flowchart illustrating an example of the threat intelligence recommendation process performed by the threat intelligence recommendation program 1014. The threat intelligence recommendation program 1014, executed by the CPU 103, begins the process described below upon receiving an execution command. The threat intelligence recommendation program 1014 extracts posting information from users to whom recommendations should be made (step 1401). Here, a list is obtained that includes entries consisting of threat intelligence IDs associated with the user ID of the user in question. Next, the threat intelligence recommendation program 1014 extracts trends from the target user's posted information (step 1402). Specifically, it extracts information on tags that are frequently included in the threat intelligence registered by the user. Next, the threat intelligence recommendation program 1014 extracts and presents threat information similar to the trends related to user posts extracted in step 1402, and then terminates processing (step 1403). The threat information recommendation process described in Figure 14 is merely an example and is not limited to it. Other methods may be employed, such as having users manually register tags of interest in advance and then recommending threat information tailored to the user's preferences based on that information. Furthermore, threat intelligence recommendation processing may be performed not only on threat intelligence but also on other types of information, such as threat intelligence. In this case, the threat information recommendation program 1014 functions as a threat information recommendation unit that recommends at least one of threat information and threat intelligence according to the user's preferences. This allows the program to present threat information and threat intelligence that the user is interested in.

[0043] According to the second embodiment, the cyber threat information sharing system 101 provides more advanced functions in addition to those of the first embodiment, such as threat information scoring, prevalence estimation, and recommendations tailored to user preferences. Furthermore, the cyber threat information sharing system 101 is not limited to the one shown in the second embodiment. For example, it is not necessary to have all of the access analysis program 1011, the threat information score calculation program 1012, the prevalence calculation program 1013, and the threat information recommendation program 1014; it may consist of any one of them, any combination thereof, or a combination with other functions.

[0044] <Summary of effects> As mentioned earlier, it is desirable that threat information be shared not as isolated points of information, but as a continuous stream of information, like threat intelligence. In addition, in order to form an ecosystem that achieves collective defense by sharing threat information, it is desirable that some kind of incentive be provided to those who provide the information. Conventional technologies exist for sharing cyber threat intelligence across different systems. However, these technologies focus on conversion to absorb differences in the format of threat information resulting from different systems, and on information sharing as a result. The transformation of threat information into threat intelligence or the promotion of information sharing are outside their scope. Other conventional technologies include information management systems, information management methods, and information sharing systems that can increase the likelihood of effective processing based on information obtained from others. This technology scores the reliability of information obtained from others during the process of utilizing that information, and thus could be applied to extract highly useful information from threat intelligence and implement effective collective defense. However, since it only deals with individual threat intelligence, its scope is different. Furthermore, other conventional technologies provide platforms for managing and sharing threat intelligence. However, because the primary scope of this technology is platform provision, there is a possibility that information may become scattered. In addition, there is a challenge in that the posting of threat intelligence depends on the inherent motivation of the poster. As mentioned above, while conventional technologies exist for sharing threat intelligence, problems remain such as the information being scattered and the fact that posting threat intelligence depends on the motivation inherent in the poster. According to this embodiment, the usability of threat information submitted by users is improved by elevating it into threat intelligence, and the formation of an ecosystem is supported by providing appropriate incentives to users who submit threat information.

[0045] <Threat intelligence management method and program description> The processing performed by the cyber threat information sharing system 101 is realized through the cooperation of software and hardware resources. Specifically, a processor such as the CPU 103 provided in the cyber threat information sharing system 101 loads programs that realize each function of the cyber threat information sharing system 101 into memory such as the main memory 104 and executes them to realize each of these functions. Therefore, the processing performed by the cyber threat information sharing system 101 described above can be understood as a threat information management method in which the processor executes a program stored in memory to receive threat information posted by users, generates threat intelligence based on the relationships between the threat information, and calculates an incentive for the user who posted the threat information. This makes it possible to provide a threat information management method that can generate threat intelligence from threat information and improve its usability compared to a case without the configuration of the present invention. Furthermore, the program running on the cyber threat information sharing system 101 can be understood as a program that enables a computer to perform the following functions: receiving threat information posted by users, generating threat intelligence based on the relationships between threat information, and calculating incentives for users who posted threat information. This makes it possible to realize a function on a computer that can generate threat intelligence from threat information and improve its usability, compared to a case without the configuration of the present invention.

[0046] It should be noted that the present invention is not limited to the embodiments described above, and various modifications are included. For example, the embodiments described above are explained in detail to make the present invention easier to understand, and are not necessarily limited to those having all the configurations described. Furthermore, it is possible to replace parts of the configuration of one embodiment with the configuration of another embodiment, and it is also possible to add configurations from other embodiments to the configuration of one embodiment. In addition, it is possible to add, delete, or replace parts of the configuration of each embodiment with other configurations. Furthermore, each of the above configurations, functions, processing units, and processing means may be implemented in hardware, either partially or entirely, by designing them as integrated circuits, for example. Alternatively, each of the above configurations and functions may be implemented in software by having the processor interpret and execute programs that implement each function. Information such as programs, tables, and files that implement each function can be stored in memory, a recording device such as a hard disk or SSD (Solid State Drive), or a recording medium such as an IC card, SD card, or DVD. Furthermore, the control lines and information lines shown are those deemed necessary for explanatory purposes, and not all control lines and information lines are necessarily shown in the actual product. In reality, it is safe to assume that almost all components are interconnected. [Explanation of symbols]

[0047] 101…Cyber ​​Threat Information Sharing System, 102a~102b…IF, 103…CPU, 104…Main Memory, 105…Storage Device, 106…Input / Output Device, 107…Communication Channel, 108…Threat Information Receiving Program, 109…Relevance Calculation Program, 110…Incentive Calculation Program, 111…Screen Drawing Program, 1011…Access Analysis Program, 1012…Threat Information Score Calculation Program, 1013…Population Calculation Program, 1014…Threat Information Recommendation Program

Claims

1. A threat intelligence receiving unit that receives threat information submitted by users, A relationship calculation unit that generates threat intelligence based on the relationships between the aforementioned threat information, An incentive calculation unit that calculates an incentive for the user who posted the aforementioned threat information, A threat intelligence management device equipped with the following features.

2. The threat information management device according to claim 1, wherein the correlation calculation unit extracts and groups correlations from the similarity of the threat information posted by users, and generates the threat intelligence.

3. The threat information management device according to claim 2, wherein the relation calculation unit extracts and groups the relation from at least one of the similarities of user-defined tag information, surface information, and posting time as the similarity.

4. The threat information management device according to claim 1, wherein the incentive calculation unit provides the user with a score as the incentive.

5. The threat information management device according to claim 4, wherein the incentive calculation unit assigns the user a score according to at least one of the number of useful threat pieces of information that led to the construction of the threat intelligence and the nature of the threat pieces of information.

6. The threat information management device according to claim 1, further comprising a screen rendering unit that creates display information to be displayed regarding the aforementioned threat intelligence.

7. The threat information management device according to claim 6, wherein the display information includes information that displays the user who posted the threat information.

8. The threat information management device according to claim 1, further comprising a threat information score calculation unit that scores at least one of the threat information and the threat intelligence.

9. The threat information management device according to claim 8, wherein the threat information score calculation unit calculates a score based on the number of accesses to at least one of the user's threat information and the threat intelligence.

10. The threat information management device according to claim 1, further comprising a prevalence calculation unit for estimating the prevalence of at least one of the threat information and the threat intelligence.

11. The threat information management device according to claim 1, further comprising a threat information recommendation unit that recommends at least one of the threat information and the threat intelligence according to the user's preferences.

12. The processor executes the program stored in memory, We receive threat information submitted by users, Based on the relationships between the aforementioned threat information, threat intelligence is generated. To calculate an incentive for the user who posted the aforementioned threat information. Threat intelligence management methods.

13. On the computer, Features for receiving threat information submitted by users, A function to generate threat intelligence based on the relationships between the aforementioned threat information, A function to calculate incentives for users who post the aforementioned threat information, A program to achieve this.