Information management system, information management method, and information sharing system

The information management system addresses inefficiencies in information sharing by calculating provider reliability and information credibility, enabling effective countermeasures and adaptive sharing strategies.

JP7685896B2Active Publication Date: 2025-05-30HITACHI LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2021114135
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-07-09
Publication Date
2025-05-30
Estimated Expiration
2041-07-09

AI Technical Summary

Technical Problem

Existing information sharing systems face challenges in effectively utilizing shared information due to variations in judgment among multiple organizations, leading to inefficiencies in countermeasure implementation.

Method used

An information management system that calculates the reliability of information providers and the credibility of shared information, determining response processing based on credibility, and updating reliability based on response outcomes.

Benefits of technology

Enhances the possibility of performing effective processing based on shared information by providing a mechanism for objective feedback and adaptive information sharing strategies.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007685896000002
    Figure 0007685896000002
  • Figure 0007685896000003
    Figure 0007685896000003
  • Figure 0007685896000004
    Figure 0007685896000004
Patent Text Reader

Abstract

To provide an information management system, an information management method and an information sharing system that can enhance a possibility that effective processing is performed based upon information obtained from another person.SOLUTION: In an information sharing system to which a plurality of information management systems are connected communicably through a network comprises, an information management system 10 comprises: a data processing part 121 which receives information managed by another person from an information processing device related to the other person, calculates reliability on the other person, and calculates reliability on the information based upon the received information and the calculated reliability; a corresponding processing setting part 124 which determines contents of corresponding processing for contents indicated by that the information based upon the calculated reliability; and a reliability update part 122 which changes the reliability based upon the contents of the corresponding processing.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an information management system, an information management method, and an information sharing system.

Background Art

[0002] It is considered that more beneficial effects can be obtained by sharing information among multiple organizations and performing various processes based on this shared information. For example, protecting a network and a system from a cyber attack that occurs suddenly is an essential requirement for security operations. However, it is difficult for a single organization to defend against sophisticated and large-scale cyber attacks on its own. As one of the countermeasures against cyber attacks, it is considered to share information related to cyber attacks among multiple organizations and take preventive measures against cyber attacks based on this shared information.

[0003] For example, information sharing efforts are being made by the Cyber Security Council of the Cabinet Cyber Security Center and ISAC (Information Sharing and Analysis Center), which is an information sharing organization in various industries ). However, there are issues in order to smoothly promote information sharing. For example, the information provider may not want the fact that it has been attacked by a cyber attack to be known. In addition, information sharing may be inhibited due to the inclusion of sensitive information in the shared information, the inability to find the merits of information sharing, and the like.

[0004] As a technology related to information sharing between organizations, there is Japanese Patent Application Laid-Open No. 2019-191657 (Patent Document 1). Patent Document 1 describes that "the reported security threat information can be evaluated, and the evaluation result can be linked to the reward of the threat information reporter (provider), and the reward can be paid according to the value thereof. As a result, it can lead to an improvement in the motivation of the provider to share security threat information, and contribute to the sharing of early secure information and the prevention of incidents."

Prior Art Documents

Patent Document

[0005]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0006] Patent Document 1 discloses promoting information sharing by evaluating reported information and linking the evaluation results to the rewards of information reporters (providers). However, since the evaluation of information reporters is not considered, it may not be possible to obtain the expected results (such as being unable to take effective measures against the obtained information).

[0007] Therefore, an object of the present invention is to provide an information management system, an information management method, and an information sharing system capable of enhancing the possibility of performing effective processing based on information obtained from others.

Means for Solving the Problems

[0008] One aspect of the present invention for solving the above problems has a processor and a memory, receives information managed by another person from an information processing device related to the other person, calculates a reliability for the other person, and calculates a credibility for the information based on the received information and the calculated reliability, a response processing setting unit that determines the content of the response processing for the content indicated by the information based on the calculated credibility, and a reliability update unit that changes the reliability based on the content of the response processing, an information management system. shall be provided with

[0009] One aspect of the present invention for solving the above problems is that an information processing apparatus receives information managed by another person from an information processing apparatus related to the other person, calculates a reliability with respect to the other person, and calculates a credibility with respect to the information based on the received information and the calculated reliability; a correspondence processing setting process for determining the content of the correspondence processing with respect to the content indicated by the information based on the calculated credibility; and a reliability update process for changing the reliability based on the content of the correspondence processing. An information management method is provided to execute the processes.

[0010] Another aspect of the present invention for solving the above problems is an information sharing system configured to include a plurality of information management systems each having a processor and a memory, receiving information managed by another person from an information processing apparatus related to the other person, calculating a reliability with respect to the other person, calculating a credibility with respect to the information based on the received information and the calculated reliability, a correspondence processing setting unit for determining the content of the correspondence processing with respect to the content indicated by the information based on the calculated credibility, and a reliability update unit for changing the reliability based on the content of the correspondence processing.

Advantages of the Invention

[0011] According to the present invention, it is possible to increase the possibility of performing effective processing based on information obtained from others. Problems, configurations, and effects other than those described above will be clarified by the description of the following embodiments.

Brief Description of the Drawings

[0012]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Figure 12

Figure 13

Figure 14

Mode for Carrying Out the Invention

[0013] Hereinafter, embodiments of the present invention will be described in detail with reference to the drawings. In this embodiment, the same components are basically given the same reference numerals, and repeated explanations are omitted. Note that this embodiment is merely an example for realizing the present invention and does not limit the technical scope of the present invention.

[0014] In the following examples, taking threat information as an example of the information managed by the system, the threat information is evaluated based on the reliability of the information provider or information providing organization, and the setting content for the security appliance is controlled as the process according to the content indicated by the threat information. [Example 1] FIG. 1 is a diagram showing an example of the configuration of an information sharing system 1 according to Example 1. This information sharing system 1 includes a plurality of information management systems 10 respectively managed by a plurality of organizations (in this embodiment, Organization A, Organization B, and Organization C). Each consists of a plurality of information management systems 10 managed by each.

[0015] The information management system 10 is an information processing system that manages information (hereinafter referred to as threat information) regarding unauthorized cyberattacks (e.g., unauthorized modification or deletion of data, or addition of unauthorized data) against various devices of the organization that manages the information management system 10.

[0016] The information sharing system 1 collects and integrates threat information provided from each information management system 10 managed by others (other organizations or people, etc., hereinafter referred to as other organizations) to perform security operations. Then, the information sharing system 1 provides information for coping with threats to each information management system 10 that has provided the threat information, according to the accuracy of the threat information. With such a mechanism, each organization can receive more useful countermeasure information as it provides more useful threat information. In addition, when there is only one other organization, the information sharing system 1 evaluates the threat information provided from its information management system 10 based on the reliability (accuracy here), and provides information for coping with threats to the information management system 10.

[0017] Specifically, the information management system 10 includes each information processing device such as a receiving device 101 that receives threat information, etc., a transmitting device 102 that transmits threat information, etc., and a security appliance 103 (security monitoring server) that performs defense, etc., regarding threat information. These are communicably connected via a network 104. Also, the information management systems 10 are communicably connected via a network 105. Note that the receiving device 101 and the transmitting device 102 may be different information processing devices, or may be configured as an integrated information processing device (information sharing management device).

[0018] Note that the networks 104 and 105 are, for example, a wired LAN (Local Area Network), a wireless LAN, the Internet, or a dedicated line, etc.

[0019] Next, FIG. 2 is a diagram illustrating an example of the configuration of the receiving device 101, the transmitting device 102, and the security appliance 103. First, the receiving device 101 includes, as hardware, a communication IF 111 (communication interface), a processing device 112, a main memory 113, a storage device 114, and a communication path 115 connecting these.

[0020] The communication IF 111 may be a network interface card (NIC), a wireless communication module, a Universal Serial Interface (USB) module, or a serial The processing device 112 is a CPU (Central Processing Unit). ), MPU (Micro Processing Unit), or GPU (Graphics Processing Unit), etc. The main memory 113 is a semiconductor memory device such as a ROM (Read Only Memory) or a RAM (Random Access Memory). The memory device 114 is a magnetic memory device or a semiconductor memory device such as a hard disk drive, a flash memory, or a solid state drive (SSD). The communication path 115 is an information transmission medium such as a bus or a cable.

[0021] The receiving device 101 includes functional units (programs) of a data processing unit 121, a reliability updating unit 122, an access control list updating unit 123, a response processing setting unit 124, and a display unit 125.

[0022] The data processing unit 121 is a program that processes or integrates data obtained from a plurality of transmitting devices 102 of other organizations, and creates or updates an integrated table 131, which will be described later.

[0023] The reliability update unit 122 is a program that creates or updates a reliability table 133 described later using the determination result obtained as a result of operating the security appliance 103 and an integration table 131 described later.

[0024] The access control list update unit 123 is a program that creates or updates an access control list table 162 described later using a reliability table 133 described later.

[0025] The correspondence processing setting unit 124 is a program that sets the security appliance using an integration table 131 described later.

[0026] The display unit 125 is a program that performs screen display and input processing for the screen described later.

[0027] Also, the receiving device 101 stores the data of each of the integration table 131, the determination result table 132, and the reliability table 133.

[0028] The integration table 131 stores information obtained by integrating threat information (specifically, a threat information table 163 described later) acquired from another information management system 10.

[0029] The determination result table 132 stores information regarding whether the threat indicated by each threat information in the integration table 131 is actually a threat (whether the threat information is actually information indicating the presence of fraud. Hereinafter, referred to as a true positive).

[0030] The reliability table 133 stores information regarding the reliability (hereinafter, referred to as reliability) of the own organization with respect to other organizations. Details of the integration table 131, the determination result table 132, and the reliability table 133 will be described later.

[0031] Note that, although details will be described later, the reliability of a self-organizing system with respect to other organizations is a parameter whose value increases when the information provided from the other organization to the self-organizing system is beneficial, and whose value decreases when the information is incorrect. The reliability is used when determining the range of information provided from the self-organizing system to other organizations. That is, the self-organizing system provides more information to other organizations with high reliability in a simpler manner, and provides less information to other organizations with low reliability in a more complex manner using processing such as encryption and anonymization. Also, the reliability is used to set the processing content performed by the security appliance 103. That is, when the reliability of the threat information provided from other organizations is high, the information management system 10 trusts the other organization and performs a high-security level setting such as communication interruption and data deletion for the threat information. On the other hand, when the reliability of the threat information provided from other organizations is low, the information management system 10 does not trust the other organization (assuming that the other organization has many false detections) and performs a low-security level setting according to the reliability, for example, setting the execution of threat detection.

[0032] The above functions of the receiving device 101 are realized by the hardware of the receiving device 101 or by the processing device 112 reading and executing a program stored in the main memory 113 or the storage device 114. Also, part or all of the above programs and data can be stored in the main memory 113 or the storage device 114 from, for example, another device having a non-temporary storage device via the network 104 or from a readable non-temporary recording medium.

[0033] Next, the transmitting device 102 is the receiving device 101 for communicating with The communication IF 141, the processing device 142, the main memory 143, the storage device 144, and the communication path 145 connecting these are provided as hardware, respectively. Also, the transmitting device 102 includes an input / output IF 146. The input / output IF 146 is connected to an input / output device 147 for performing input / output such as a keyboard and a display, and mediates the input / output of data with the input / output device 147.

[0034] The transmitting device 102 includes each functional unit (program) of the access control unit 151 and the display unit 152. When the access control unit 151 receives a data acquisition request from the receiving device 101 of another information management system 10, it performs processing according to the policy indicated by the access control list table 162 described later.

[0035] The display unit 152 is a program that performs screen display and processing of input to the screen, etc., which will be described later.

[0036] The transmitting device 102 also stores each data of the density table 161, the access control list table 162, and the threat information table 163.

[0037] (Density table) FIG. 3 is a diagram showing an example of the density table 161. The density table 161 has each data item of the record ID 301, the data name 302 in which the name of the held data managed or held by the self-organization is set, and the density 303 in which the density of the data related to the data name 302 is set. Note that the density 303 may be set manually by the administrator, or may be automatically set based on the content of the held data, for example, increasing the density when the held data includes personal information. The density table 161 is used in the process of generating and updating the access control list table 162 described later.

[0038] (Access control list table) FIG. 4 is a diagram showing an example of the access control list table 162. The access control list table 162 stores the information providing method 1623 when the self-organization provides each held data 1622 related to the threat information of the self-organization to each other organization 1621. This information providing method 1623 is information on the content and scope of providing threat information.

[0039] For example, as shown in the figure, when the self-organization provides "malware data" related to threats to "Organization B", it shares malware specimens which are raw data (unprocessed data) (raw data sharing 1623a). When the self-organization provides "malware data" related to threats to "Organization C", it processes the raw data by hashing, encrypting, anonymizing, etc., and shares the processed data ( hash sharing 1623b). On the other hand, when providing the "suspicious connection destination list" to "Organization C", self-organizing "Organization A" provides only the common data between the threat information such as the suspicious connection destination list received from "Organization C" and the suspicious connection destination list held by "Organization A" (sharing only the common part 1623c).

[0040] Also, "sharing only the determination result" in the information providing method 1623 means that after performing a predetermined process using the data held by the self-organization, only the result of that process is provided to other organizations (sharing only the determination result 1623d). In the example of the figure, the self-organization creates a web access trend model based on its own "web access log", and performs a process of calculating the degree of deviation between the obtained trend of the access log and the "web access log" presented by another organization "Organization B ". The self-organization provides only the degree of deviation to "Organization B ".

[0041] Note that the access control list table 162 may be set by the administrator while referring to the content of the confidentiality table 161, or the content may be automatically set. In that case, for example, a security level is set in advance for each piece of information that can be set in the information providing method 1623 (for example, the security level is increased in the order of raw data sharing, sharing only the common part, encrypted sharing, sharing only the determination result, non-sharing).

[0042] (Threat Information Table) FIG. 5 is a diagram showing an example of the threat information table 163. The threat information table 163 stores threat information detected by an organization (information management system 10) and information regarding the degree of confidence (hereinafter referred to as confidence level) of the organization as to whether the threat information actually indicates the fact of a threat (cyber attack).

[0043] The threat information table 163 has data items for each of a record ID 501, a threat trace 502 in which threat information detected by the information management system 10 is set, and a confidence level 503 in which a confidence level for the threat information is set.

[0044] In this embodiment, in the threat trace 502, data that makes one suspect that a cyber attack has been performed or the location where the data exists is set. For example, an IoC (Indicator of Compromise) or the like is set in the threat trace 502. Specifically, in the threat trace 502, a suspicious connection destination domain, IP address, URL (Uniform Resource Locator), registry changed by an attack, name of a process used, e-mail information, and the like are included. Note that other information may be set in the threat trace 502 as long as it is information indicating the basis of the threat. Also, the user may set the value of the confidence level in the confidence level 503, or it may be automatically set.

[0045] The above functions of the transmission device 102 are realized by the hardware of the transmission device 102 or by the processing device 142 reading and executing a program stored in the main memory 143 or the storage device 144. Also, part or all of the above programs and data can be stored in the main memory 143 or the storage device 144 from, for example, another device having a non-transitory storage device via the network 104 or from a readable non-transitory recording medium.

[0046] Note that the receiving device 101 and the transmitting device 102 described here may be different information processing devices or may be integrally configured.

[0047] Next, the security appliance 103 performs response processing against cyberattacks. For example, the security appliance 103 blocks communication that is not defined and dangerous communication, such as FW (Fire Wall), IPS (Intrusion Prevent System), and EDR (Endpoint Detection and Response), and stops suspicious processes. Also, the security appliance 103 detects communication that is not defined and dangerous communication, as well as suspicious processes, such as IDS (Intrusion Detection System) and SIEM (Security Information Event Management).

[0048] The security appliance 103 performs response processing against threats based on an integration table 131, a reliability table 133, or a predetermined threshold value, which will be described later. For example, the security appliance 103 blocks or detects connections to a specific domain, or stops or detects a specific process. Then, the security appliance 103 stores those results. These results are used for creating and updating a determination result table 132, which will be described later. Next, the processing performed in the information sharing system 1 will be described.

[0049] <Overview of Processing> FIG. 6 is a sequence diagram for explaining the overview of threat information sharing processing performed in the information sharing system 1. The threat information sharing processing is started, for example, at a timing designated by the user or at a predetermined timing (for example, a predetermined time interval, a predetermined time).

[0050] First, the receiving device 101 of each organization requests provision of threat information from the transmitting device 102 of each other organization (S901:S902~S904).

[0051] That is, the receiving device 101 of each organization transmits a data acquisition request for threat information to the transmitting device 102 of each other organization (S902).

[0052] The data acquisition request includes, for example, specifications regarding the content of the data to be acquired and / or the method of providing the data. When the specification is for the content of the data, it is, for example, the specification of a list of suspicious destinations. When the specification is for the method of providing the data, it is, for example, "share only common parts". In this case, the data acquisition request may include information (e.g., a destination list) for specifying the common parts.

[0053] When the access control unit 151 of the transmitting device 102 of each organization receives a data acquisition request, it refers to the access control list table 162 and determines the disclosure content of the data indicated by the received data acquisition request (S903). Specifically, the access control unit 151 searches the access control list table 162 for threat information specified by the data content and the data providing method indicated by the received data acquisition request.

[0054] When disclosing data, each transmitting device 102 acquires the data (threat information and its confidence level) of the disclosure content determined in S903 from the threat information table 163, and transmits the acquired data to the receiving device 101 of the source of the data acquisition request by the method indicated by the access control list table 162 (S904).

[0055] Thereafter, the data processing unit 121 of the receiving device 101 of each organization creates or updates the integrated table 131 by integrating the data of each organization received in S904 (S905).

[0056] (Integrated Table) FIG. 7 is a diagram showing an example of the data content of the integrated table 131. The integrated table 131 is a table obtained by combining information from the threat information tables 163 received from a plurality of other organizations.

[0057] The integrated table 131 stores trace information 1312, which indicates whether each organization has a trace of each threat information 1311, and the confidence level 1313 for that threat information. Regarding the trace information 1312 indicating whether there is threat information, for example, 1 is set when there is threat information, and 0 is set when there is no threat information.

[0058] In the example of the figure, it shows the case where the transmitting device 102 of "Organization B" transmits threat information of "aaa.com", "bbb.com", and "ccc.com" to the receiving device 101 of the self-organization "Organization A", and the transmitting device 102 of "Organization C" transmits threat information of "bbb.com", "ccc.com", and "ddd.com".

[0059] Subsequently, as shown in FIG. 6, the corresponding processing setting unit 124 of the receiving device 101 of each organization refers to the integrated table 131 generated in S905 and executes a security appliance setting process for generating the settings of the security appliance (S906). The details of the security appliance setting process S906 will be described later.

[0060] Then, the corresponding processing setting unit 124 of the receiving device 101 of each organization sends instruction information on the settings of the security appliance to the security appliance 103 (S907).

[0061] The security appliance 103 that has received the instruction information performs corresponding processing (such as monitoring) for the threat information according to the conditions indicated by the instruction information (S908).

[0062] As an example of monitoring, for instance, the security appliance 103 detects a suspicious destination domain "aaa.com". If the security appliance 103 fails to detect a connection to "aaa.com" from an external device for a predetermined period, it memorizes that there is actually no threat and uses this as the determination result. On the other hand, when the security appliance 103 detects a connection to "aaa.com" from an external device, it memorizes that this connection is a suspicious connection (actually a threat) and uses this as the determination result. At this time, the security appliance 103 determines whether the connection to "aaa.com" is actually a threat related to a cyber-attack or a normal process (i.e., a false detection). Note that the security appliance 103 may obtain the determination result by using, as comparison data with the above external connection, malicious data to be detected and benign data not to be detected, which are prepared in advance, instead of the result of actual security operations.

[0063] The security appliance 103 transmits the determination result obtained from the monitoring of S908 to the receiving device 101 that is the transmission source of the instruction information (S909). Then, the receiving device 101 records the received determination result in the determination result table 132.

[0064] (Determination Result Table) FIG. 8 is a diagram showing an example of the determination result table 132. The determination result table 132 has each data item of a record ID 701, a threat trace 702 where threat information is set, and a true positive 703 where true positive information indicating whether the threat indicated by the threat information is actually a threat (illegal information processing such as a cyber-attack) is set.

[0065] The threat traces 702 store the threat information recorded in the integration table 131 that has been detected by the security appliance 103. Also, for true positives 703, true positive information is set based on the detection results of the security appliance 103. That is, "1" is set when the detection result is actually a threat, and "0" is set when the detection result is not actually a threat.

[0066] Subsequently, as shown in FIG. 6, the reliability update unit 122 of the receiving device 101 of each organization performs a reliability table update process (S910) for creating or updating the reliability table 133 based on the determination result acquired from the security appliance 103. In this reliability table update process S910, the reliability update unit 122 creates or updates the reliability table 133 based on the determination result table 132 generated in S909. The details of the reliability table update process S910 will be described later.

[0067] (Reliability Table) FIG. 9 is a diagram showing an example of the reliability table 133. The reliability table 133 has data items for each record: an ID 801, an organization name 802 where information on the organization for which reliability is to be determined is set, a correctness score 803 that sets information regarding the degree of accuracy of the threat information provided by the organization related to the organization name 802 (hereinafter referred to as the correctness score), and a reliability 804 that sets the reliability of the own organization with respect to the other organization related to the organization name 802. In the reliability 804, a value obtained by normalizing the correctness score 803 is set. Note that when the value of the correctness score is less than 0, 0 may be set in the data item of the correctness score 803.

[0068] Also, as shown in FIG. 6, the access control list update unit 123 of the receiving device 101 of each organization updates the access control list table 162 of the transmitting device 102 of the respective organization based on the density table 161 and the reliability table 133 (S911).

[0069] For example, the access control list update unit 123 displays the contents of the device density table 162 and the reliability table 133, and accepts corrections to the access control list table 162 from the user.

[0070] Also, the access control list update unit 123 may automatically correct the access control list table 162. For example, the access control list update unit 123 multiplies the reliability for each other organization by the device density of its own organization (the device density stored in the device density table 161) for each other organization to calculate an index value indicating the scope or level of content (such as device density) of information sharing. The access control list update unit 123 compares this index value with the security values associated with each piece of information (e.g., raw data sharing, sharing only common parts, encrypted sharing, sharing only judgment results, non-sharing) that can be set in the information providing method 1623 to identify the content of the information providing method 1623 having the security value corresponding to the index value.

[0071] Note that the calculation method described here is just an example, and the access control list update unit 123 can update the access control list table 162 having appropriate scope and content of information providing information based on the device density indicated by the device density table 161 and the reliability indicated by the reliability table 133. The threat information sharing process ends here.

[0072] <Security Appliance Setting Process> FIG. 10 is a flowchart for explaining the details of the security appliance setting process S906.

[0073] The correspondence processing setting unit 124 repeats S1002 to S1005 for each piece of threat information set in the integrated table 131.

[0074] That is, first, the correspondence processing setting unit 124 selects one piece of threat information stored in the integrated table 131 (specifically, selects one record from the integrated table 131), and acquires the confidence level of each organization and the reliability for each organization with respect to the selected threat information (hereinafter referred to as the selected threat information). Based on the acquired confidence level of each organization and the reliability for each organization, the correspondence processing setting unit 124 calculates a threat level (reliability with respect to the threat information, hereinafter also referred to as the credibility), which is a parameter indicating the magnitude of the threat indicated by the selected threat information (S1002). In the present embodiment, the correspondence processing setting unit 124 calculates the threat level (credibility) using the following weighted average formula.

Equation

[0075] Here, E i is the trace information of organization i (1 if there is a trace, 0 if there is no trace), C is the confidence level of organization i, and T i is the reliability with respect to organization i. i is the reliability with respect to organization i.

[0076] In the examples of FIGS. 7 and 9, the threat level with respect to the selected threat information "aaa.com" is 0.72, and the threat level with respect to the selected threat information "bbb.com" is 0.42.

[0077] Here, the threat level (credibility) is calculated by a weighted average with the reliability T as the weight, but other methods may also be used.

[0078] The correspondence processing setting unit 124 determines whether the threat level calculated in S1002 exceeds a predetermined threshold (S1003). If the threat level is equal to or lower than the threshold (S1003: No), the correspondence processing setting unit 124 executes the process of S1005. On the other hand, if the threat level exceeds the threshold (S1003: Yes), the correspondence processing setting unit 124 executes the process of S1004.

[0079] In S1004, the response processing setting unit 124 adds settings for the security appliance 103 to prevent access to the location indicated by the selected threat information. At this time, the response processing setting unit 124 may confirm with the user whether to add this setting.

[0080] For example, when the selected threat information is "suspicious connection destination domain", the response processing setting unit 124 generates setting information to block access to the connection destination domain. Also, when the selected threat information is "suspicious file name", the response processing setting unit 124 generates setting information to delete the file. After that, the process of S1005 is performed.

[0081] In S1005, the response processing setting unit 124 makes settings for the security appliance 103 to detect access to the location indicated by the selected threat information.

[0082] The response processing setting unit 124 repeats the above processing for all the threat information set in the integrated table 131 (S1006).

[0083] In the above example, the response processing setting unit 124 explained the prevention and detection response processing for the threat information (S1004, S1005), but other arbitrary response processing (notification, log output, etc.) may be performed.

[0084] <Reliability update process> FIG. 11 is a flowchart for explaining an example of the reliability update process S910.

[0085] The reliability update unit 122 selects one piece of threat information for which the reliability has not been calculated from the threat information recorded in the determination result table 132 (S1101).

[0086] Also, the reliability update unit 122 selects one of the organizations recorded in the integrated table 132 (S1102).

[0087] The reliability update unit 122 determines whether the organization selected in S1102 (hereinafter referred to as the selected organization) may have been subject to the threat indicated by the threat information selected in S1101 (hereinafter referred to as the selected threat information) (S1103). Specifically, the reliability update unit 122 checks whether the value of the trace information 1312 of the data item related to the selected organization in the record related to the selected threat information in the integrated table 131 is 1 or 0.

[0088] If the selected organization is unlikely to have been subject to the threat indicated by the selected threat information (S1103: Yes), the reliability update unit 122 executes the process of S1107. If the selected organization may have been subject to the threat indicated by the selected threat information (S1103: No), the reliability update unit 122 executes the process of S1104.

[0089] In S1104, the reliability update unit 122 checks whether the selected organization has actually been subject to the threat indicated by the selected threat information as an illegal information process. Specifically, the reliability update unit 122 checks whether the true positive 703 of the record related to the selected threat information is 1 or 0.

[0090] If the selected organization has actually been subject to the threat indicated by the selected threat information as an illegal information process (S1104: Yes), the reliability update unit 122 executes the process of S1105. If the selected organization has not actually been subject to the threat indicated by the selected threat information as an illegal information process (S1104: No), the reliability update unit 122 executes the process of S1106.

[0091] In S1105, the reliability update unit 122 calculates or updates the error score of the selected organization regarding the selected threat information. Specifically, the reliability update unit 122 trace information 131 2 calculates the product of the confidence level of the selected organization and the confidence level of the selected organization, and adds the value to the current error score of the selected organization. Note that the reliability update unit 122 may further multiply the severity of the threat indicated by the selected threat information by the above product. After that, the process of S1107 is performed.

[0092] In S1106, the reliability update unit 122 calculates or updates the error score of the selected organization regarding the selected threat information. Specifically, the reliability update unit 122 calculates the product of the information 131 of the record related to the selected threat information in the integrated table 131 and the confidence level of the selected organization, and subtracts that value from the current error score of the selected organization. Then, the process of S1107 is performed. trace information 131 2 After that, the process of S1107 is performed.

[0093] The reliability update unit 122 repeats the processes from S1102 to S1106 for all organizations regarding the selected threat information (S1107).

[0094] Also, the reliability update unit 122 repeats the processes from S1101 to S1107 for all threat information (S1108).

[0095] The reliability update unit 122 calculates the reliability of each other organization by dividing the error score of each other organization calculated by the processes from S1101 to S1108 by the total value of the error scores of all organizations. The reliability update unit 122 updates the reliability table 133 by setting the calculated reliability value to the reliability 804 of the record related to each organization in the reliability table 133 (S1109).

[0096] Here, a specific example of calculating the reliability is shown based on the examples in FIGS. 8 and 9. First, "aaa.com" is selected as the selected threat information in S1101. Next, "Organization B" is selected as the selected organization in S1102. From the integrated table 131, since "Organization B" has no trace of the threat of "aaa.com" (S1103: No), S1104 is executed. The determination result table 132 is referred to, and since the true positive 703 for "aaa.com" is 1 (S1104: Yes), the product of the trace information and the reliability in the integrated table 131, that is, the result of "1×1.0", is added to the existing value of the correct / error score 803 of the record related to "Organization B" in the reliability table 133. Next, "Organization C" is selected in S1102. From the integrated table 131, since "Organization C" has no trace of the threat of "aaa.com" (S1103: Yes), the correct / error score is not updated. Thereafter, "bbb.com", "ccc.com", and "ddd.com" are sequentially selected in S1101, and 0.5 and 0.3 are added to the correct / error scores of "Organization B ", respectively. As a result, as shown in FIG. 9, the correct / error score of "Organization B" becomes 1.8. On the other hand, for the correct / error score of "Organization C", 0.5 and 0.8 are added respectively, and 1.0 is subtracted. As a result, as shown in FIG. 9, the correct / error score of "Organization C" becomes 0.3. Assuming that the total of the correct / error scores other than "Organization B" and "Organization C" is 0.4, the total value of the correct / error scores of all organizations becomes 2.5. Therefore, the reliability of Organization B is 0.72 by dividing 1.8 by 2.5. Also, the reliability of Organization C is 0.12 by dividing 0.3 by 2.5.

[0097] Next, the screen displayed by the information management system 10 will be described. Note that each of the screens described below may be displayed by any device of the information management system 10. <Shared Status Information Display Screen>

[0098] FIG. 12 is a diagram showing an example of a shared status information display screen 1201 that displays data on the content and range that the self-organization can send to other organizations (disclosable data) and data on the content and range that the self-organization can receive from other organizations (acquirable data).

[0099] The shared status information display screen 1201 has a displayable data display column 1202 and an acquirable data display column 1203.

[0100] In the displayable data display column 1202, the content of the access control list table 162 of the self-organization is displayed. In the acquirable data display column 1203, based on the content of the access control list table 162 acquired from other organizations, the data disclosure status to the self-organization is displayed.

[0101] With the shared status information display screen 1201, users of each organization can easily confirm the scope of information sharing with other organizations regarding threat information.

[0102] <Shared Status Details Information Display Screen> FIG. 13 is a diagram showing an example of a shared status details information display screen 1301 that displays details of displayable data and acquirable data.

[0103] The shared status details information display screen 1301 includes an organization selection column 1302 that accepts a user's selection of an organization, a data selection column 1303 that selects data to be displayed, an analysis display column 1304, and a shared history display column 1305.

[0104] The organization selection column 1302 is a selection column for the user to select an organization from the organizations displayed in the displayable data display column 1202 and the acquirable data display column 1203 of the shared status information display screen 1201. Note that the organization selection column 1302 may be a selection column for selecting an organization in a pull-down manner.

[0105] The data selection column 1303 is a selection column for the user to select threat information from each threat information. Note that the data selection column 1303 may be a selection column for selecting threat information in a pull-down manner or a selection column that displays a list of threat information.

[0106] In the analysis display column 1304, analysis results regarding access to threat information specified by the organization selection column 1302 and the data selection column 1303 are presented. For example, in the analysis display column 1304, for the threat information selected in the data selection column 1303, the daily transition (history) of the number of times other organizations selected in the organization selection column 1302 accessed the self-organization (sent and received data acquisition requests) is displayed. Note that instead of the number of times other organizations accessed the self-organization, the number of times the self-organization actually provided information to other organizations or the data volume may be displayed.

[0107] In the shared history display column 1305, the transition (history) of the sharing scope or shared content (non-shared, raw data sharing, encrypted sharing, sharing only judgment results, etc.) of the threat information specified by the data selection column 1303 with other organizations is displayed.

[0108] Note that on the shared status detailed information display screen 1301, information other than the information described above may be displayed and, for example, information on the reliability of other organizations with respect to the self-organization may be displayed.

[0109] Through the shared status detailed information display screen 1301 as described above, users of each organization can know the details of the information sharing status with other organizations.

[0110] [Example 2] FIG. 14 is a diagram for explaining an example of the configuration of the information sharing system 2 according to Example 2. This information sharing system 2, unlike Example 1, has a shared management device 1402 having the same configuration as the receiving device 101 and the transmitting device 102 of each information management system 10 in Example 1. The shared management device 1402 comprehensively performs processes corresponding to the processes performed by the receiving device 101 and the transmitting device 102 of each information management system 10 in Example 1.

[0111] In addition, each information management system 10 in this information sharing system 2 includes a participant terminal 1401. The participant terminal 1401 realizes functions that the receiving device 101 and the transmitting device 102 do not have. That is, the participant terminal 1401 executes programs and stores data that are not transferred to the shared management device 1402. With the above configuration, the same effects as those of the information sharing system 1 in the first embodiment can be obtained.

[0112] As described above, the information management system 10 of the present embodiment receives threat information detected by that information management system 10 from another information management system 10, calculates a reliability level for the other party, calculates a credibility level of the threat information based on the threat information and the reliability level, determines a response process (threat prevention measures, detection) for the threat indicated by the threat information based on the calculated credibility level, and changes the reliability level based on the result.

[0113] That is, the information management system 10 can calculate the credibility level of the threat information and take countermeasures against the threat based on the reliability level for another organization (another party) that has provided the threat information. Then, the reliability level for the other organization is changed based on the result. That is, the information management system 10 can provide feedback to the other organization according to the result of the response process performed on the threat information provided by the other party.

[0114] In this way, according to the information management system 10 of the present embodiment, the possibility of performing effective processing based on information obtained from others can be increased.

[0115] Note that in the present embodiment, since it is configured as the information sharing system 1 including a plurality of information management systems 10, independent organizations can cooperate to counter threats.

[0116] That is, the information management system 10 of the present embodiment has a mechanism for integrating information collected from a plurality of organizations. Thereby, it is possible to solve the conventional problem that judgments on the information of a plurality of organizations vary and each piece of information cannot be effectively utilized. For example, regarding a certain threat, there are organizations that provide information indicating that a certain website is a suspicious website, and there are also organizations that provide information indicating that it is a normal website. In such a case, it is possible to solve the problem that judgments vary and effective countermeasures against the threat cannot be taken.

[0117] In addition, when the information management system 10 of the present embodiment receives a threat information transmission request from the information management system 10 of another party (another organization), based on the reliability with respect to the other organization, it determines the content or scope of the threat information to be transmitted in response to the transmission request, and transmits the threat information to the other organization.

[0118] In this way, by changing the scope and content of the threat information according to the reliability with respect to other organizations, it is possible to provide only appropriate threat information to other organizations. For example, for a trustworthy other organization that has provided useful threat information, more threat information can be provided.

[0119] In addition, when the information management system 10 of the present embodiment receives a threat information transmission request from the information management system 10 of another party (another organization), based on the density of threat information managed by the own organization, by changing the scope and content of the threat information, it is possible to flexibly provide threat information according to the situation of the own organization to the other organization.

[0120] In addition, when the threat indicated by the threat information provided by another party (another organization) is actually an illegal information process (when the information indicates the existence of illegality), the reliability with respect to the other organization is increased, and when the threat indicated by the threat information is not actually an illegal information process, the reliability with respect to the other organization is decreased. Thereby, it is possible to give objective and fair feedback to other organizations.

[0121] In addition, when the threat indicated by the threat information provided by another party (another organization) is actually an illegal information process, the information management system 10 of the present embodiment increases the reliability according to the confidence level of the other organization, and when it is not actually an illegal information process, the reliability is decreased according to the confidence level. In this way, by changing the degree of increase or decrease in reliability according to the subjective judgment of the other organization, effective feedback can be given to the other organization.

[0122] In addition, the information management system 10 of the present embodiment provides threat information to other organizations in forms such as "raw data sharing", "encrypted data sharing", "sharing only judgment results", or "sharing only common parts" according to the reliability with respect to other organizations. By doing so, appropriate threat information corresponding to the nature of the threat information can be provided to other organizations.

[0123] In addition, the information management system 10 of the present embodiment displays information on the content or scope of threat information that can be transmitted to other organizations (available data), or information on the content or scope of threat information that can be received from other organizations (acquirable data), so that users of each organization can know the shareable range of threat information.

[0124] In addition, the information management system 10 of the present embodiment displays the access history with other information management systems 10 regarding threat information, or the history of the shared content or scope of threat information thereby, so that the user can know the details of the sharing of threat information.

[0125] The present invention is not limited to the above-described embodiments, and can be implemented using any components without departing from the gist thereof. The embodiments and modifications described above are merely examples, and the present invention is not limited to these contents as long as the features of the invention are not impaired. In addition, although various embodiments and modifications have been described above, the present invention is not limited to these contents. Other aspects conceivable within the scope of the technical idea of the present invention are also included in the scope of the present invention.

[0126] For example, the configuration of each functional unit described in this embodiment is an example. For example, part of the functions of a certain functional unit may be provided in other functional units, or a certain functional unit may be divided into a plurality of functional units. A plurality of functional units may be integrated into one functional unit. One or more functional units within one device may be distributed among a plurality of devices and processed in cooperation.

[0127] Also, in this embodiment, it is assumed that the information managed by the information management system 10 is threat information, but it may be other types of information such as important information of a business shared among organizations. In this case, the true positive information may not be information indicating the actual existence of fraud as in this embodiment, but may be information indicating that the information is appropriate or important, for example.

[0128] Or, the information managed by the information management system 10 may be information in other fields such as environmental information. For example, it may be information detected by sensors owned by other organizations. Sensor information obtained from one or more organizations may be evaluated based on reliability, and if it is information obtained from a plurality of organizations, they may be integrated to determine a response process.

Description of Reference Numerals

[0129] 1 Information sharing system, 10 Information management system, 121 Data processing unit, 122 Reliability update unit, 124 Security appliance setting unit

Claims

1. It has a processor and a memory, receives information managed by the other party from an information processing device related to the other party, calculates a reliability with respect to the other party, and calculates a credibility with respect to the information based on the received information and the calculated reliability; a data processing unit, a response processing setting unit that determines the content of the response processing for the content indicated by the information based on the calculated credibility; a reliability update unit that changes the reliability based on the content of the response processing; An information management system comprising:

2. When receiving a transmission request for the information from the information processing device related to the other party, based on the reliability with respect to the other party, determines the content or scope of the information to be transmitted in response to the transmission request, and transmits information with the determined content or scope to the information processing device related to the other party, further comprising an access control unit, The information management system according to claim 1.

3. When receiving a transmission request for the information from the information processing device related to the other party, the access control unit determines the content or scope of the information to be transmitted in response to the transmission request based on the reliability with respect to the information processing device related to the other party and the confidentiality of the information. The information management system according to claim 2.

4. The response processing setting unit performs a process of determining whether the information is information indicating the existence of fraud as the response processing for the information. When it is determined that the information is information indicating the existence of fraud, the reliability update unit increases the reliability, and when it is determined that the information is not information indicating the existence of fraud, the reliability update unit decreases the reliability. The information management system according to claim 1.

5. When it is determined that the information is information indicating the existence of fraud, the reliability update unit increases the reliability according to a certainty factor, which is a parameter indicating the degree to which the other party is convinced that the information is actually fraudulent information, and when it is determined that the information is not information indicating the existence of fraud, the reliability update unit decreases the reliability according to the certainty factor. The information management system according to claim 4.

6. When the access control unit receives a transmission request for the information from the information processing apparatus related to the other party, based on the reliability with respect to the other party, as the content or range of the information to be transmitted in response to the transmission request, whether to transmit the information to the information processing apparatus related to the other party without processing the information, whether to process the information and transmit it to the information processing apparatus related to the other party, whether to transmit the result of a predetermined process executed based on the information to the information processing apparatus related to the other party, or whether to transmit information within the range of information that the information processing apparatus related to the other party has transmitted in the past to the information processing apparatus related to the other party, determines at least one of them. The information management system according to claim 2.

7. The information management system according to claim 2, further comprising a display unit that displays at least one of information on the content or range of the information that can be transmitted to the information processing apparatus related to the other party when the transmission request is received, or information on the content or range of the information that can be received from the information processing apparatus related to the other party when a transmission request is transmitted to the information processing apparatus related to the other party.

8. The display unit The information management system according to claim 7, wherein the display unit displays at least one of the history of transmission and reception of the transmission request or the history of the content or range of the information transmitted and received in response to the transmission request determined by the transmission and reception of the transmission request.

9. An information processing apparatus receives information managed by the other party from an information processing apparatus related to the other party, calculates the reliability with respect to the other party, and performs data processing to calculate the credibility of the information based on the received information and the calculated reliability; a correspondence processing setting process for determining the content of the correspondence process for the content indicated by the information based on the calculated credibility; a reliability update process for changing the reliability based on the content of the correspondence process; An information management method for executing the above.

10. having a processor and a memory, receives information managed by the other party from an information processing apparatus related to the other party, calculates the reliability with respect to the other party, and has a data processing unit that calculates the credibility of the information based on the received information and the calculated reliability; a correspondence processing setting unit that determines the content of the correspondence process for the content indicated by the information based on the calculated credibility; a reliability update unit that changes the reliability based on the content of the correspondence process; An information sharing system configured to include a plurality of information management systems each including the above.

Citation Information

Patent Citations

  • Terminal, security system, terminal program, and security information management method

    JP2009110334A

  • Threat information sharing system between a plurality of organizations and method

    JP2019191657A

  • Illegal communication control apparatus and method

    WO2017068714A1

  • Computer system and method for sharing information

    WO2021024532A1