Zero-day URL attack defense service providing apparatus for email security infrastructure and its operation method
The zero-day URL attack prevention service apparatus and method address the inadequacies in existing email security systems by inspecting and converting zero-day URLs into security URLs, ensuring secure connections and preventing malicious attacks, thus ensuring safe information exchange.
Patent Information
- Application Number
- JP2023532749
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2020-12-29
- Publication Date
- 2025-06-09
- Estimated Expiration
- 2040-12-29
AI Technical Summary
Existing email security systems are inadequate in detecting and blocking zero-day URL attacks, which pose significant security threats through URLs included in emails, especially when reputation information is lacking.
A zero-day URL attack prevention service apparatus and method that inspects URLs within emails, converts zero-day URLs into security URLs, and periodically diagnoses whether these URLs are malicious, ensuring secure connections only after thorough security checks.
This solution effectively prevents zero-day URL attacks by providing a security zone for users until normal URL data is accumulated, ensuring secure connections and blocking malicious purposes, thus guaranteeing safe information exchange and processing between users.
Smart Images

Figure 0007689675000001 
Figure 0007689675000002 
Figure 0007689675000003
Abstract
Description
[Technical field]
[0001] The present invention relates to an apparatus and an operating method for providing a zero-day URL attack defense service based on email security, and more particularly, to an apparatus and an operating method for providing a zero-day URL attack defense service based on email security, capable of detecting and blocking zero-day attacks that pose security threats through URLs included in emails. [Background technology]
[0002] In today's society, with the development of computers and information and communication technology around the world, dependence on cyber is increasing in all areas of social life, and this trend is accelerating. In recent years, 5G mobile communications, which features ultra-high speed, ultra-low latency, and multiple simultaneous connections, has become commonplace, and new services based on this have emerged, making cyber security even more important.
[0003] Technological fields such as the Internet of Things (IoT), cloud systems, big data, and artificial intelligence (AI) are combining with information and communication technology to provide new service environments. Systems that provide such services can be used in real life by connecting to PCs or mobile terminal devices via the Internet or wireless networks.
[0004] As information and communication technology, which is connected to various terminal devices or communication devices, becomes more and more closely integrated into real life, malicious cybersecurity threats are increasing day by day. Cybersecurity threats, which are becoming more sophisticated and advanced, can cause damage by causing abnormal operation of the information and communication terminal devices of organizations, institutions, and individuals, or by leading individuals to make mistakes by forging or altering management information, thereby stealing and damaging information. In addition, information illegally stolen through cybersecurity threats can be used to commit financial fraud and other economic and social crimes.
[0005] To intercept and respond to cyber security threats, an information protection system that protects and manages systematized information and communication technologies can be utilized. The information protection system can be constructed according to the type of information and communication technology system or the characteristics of the technology to be able to respond to various cyber threats and can be applied step by step.
[0006] The email system utilized in information and communication technology can provide an email service including the text content so that messages can be exchanged using the communication line between users through computer terminals. At this time, an email can attach an electronic file containing the content to be shared, or a connection link (URL; Uniform Resource Locator) to a website can be described in the text or inserted into the attached file.
[0007] In this way, an executable electronic file containing malicious code can be attached through the email system with malicious intent, or a URL that can be linked to a specific website can be inserted. As a result, the recipient of the email may execute the malicious code, or by connecting to a fake or forged website through the inserted URL, unintended information processing may be carried out by the user, and information can be stolen.
[0008] To address email security threats that can induce economic and social damage and may be linked to various crimes, a "System for Controlling and Blocking Emails with Malicious Codes" is disclosed, such as Korean Registered Patent No. 10-1595379. In the said registered patent, if an email sent from an external server or a terminal passes through a firewall and a spam blocking device with built-in spam blocking software, the target system has a function to receive the email, and the target system checks whether there is an attached file in the email. If there is no attached file, the email is transferred from the target system to the mail server. If there is an attached file, in addition to the types of attached files most frequently used for the user's business purposes (documents, compressed files, images), the email is blocked to prevent infection by malicious codes in advance, and when the type of the attached file is an image, since the image cannot be converted and thus cannot be infected by malicious codes, the email is transferred from the target system to the mail server. When the type of the attached file is a document, the document is converted to an unmodifiable PDF format, and in case a URL with a malicious code reflected inside the document is clicked by the email recipient, the method of blocking in advance the case where the user terminal is infected by the malicious code is adopted, and a function to transfer a notification email by selecting one or more from email, messenger, mobile, and KakaoTalk from the target system to the user terminal is provided. When the type of the attached file is a compressed file, the compression is released in advance, the file type is analyzed, in the case of an image, it is processed by the said method, in the case of a document, it is converted to PDF and processed by the said method, in the case of an executable file, a malicious code infection inspection and treatment are carried out using Virtual BOX equipped with various malicious code treatment solutions, and a function to transfer a notification email including the result by selecting one or more from email, messenger, mobile, and KakaoTalk from the target system to the mail server for notification processing is provided, and attached files other than executable files that require malicious code inspection from the target system are VirtualA target system having a function of transmitting to a BOX to process inspection and treatment of malicious code and transmitting the result back to the target system for further processing; a Virtual BOX that receives an executable file from the target system, configures a virtual environment in a separate system, is equipped with various malicious code treatment solutions to process inspection and treatment of malicious code hidden in the executable file, transmits the result back to the target system again, and performs a process of restoring to the environment before inspection; a mail server that receives an email (including a notification email) from the target system and has a function of transmitting the email (including a notification email) to a user terminal; and a user terminal that has a function of allowing or rejecting the original email by the user's confirmation when receiving a notification email from the target system and a function of checking the received email after logging in; are described for a system for controlling and blocking emails with attached malicious code.
[0009] Such a system for controlling and blocking emails with attached malicious code can configure a virtual environment to perform inspection and treatment on emails containing attached files in which hacking code (or malicious code) can be executed. However, the above content is only limited to the inspection of malicious code that can be included in the attached file. Also, when there is suspicion that the attached file contains malicious code, the method of converting it into PDF form and transmitting it to the recipient has a limitation in that it cannot prevent security risks when the recipient directly clicks on the URL included in the PDF or enters it into a web browser. Also, the above content has limitations in dealing with malicious URLs that can be included in the text content of the email other than the attached file.
Summary of the Invention
Problems to be Solved by the Invention
[0010] The present invention has been made to solve the above-described conventional problems, extracts and inspects a URL that can be included in the body content of received emails processed in an email system, an attached file, etc., and in particular, when it is a zero-day URL without reputation information, provides a security zone to the user until data that can be guaranteed as a normal URL is accumulated, and when a request to connect to the URL is made, first passes through, and allows the connection when security is guaranteed through a security inspection of the URL. An object of the present invention is to provide a zero-day URL attack prevention service providing apparatus for an email security infrastructure and an operation method thereof.
Means for Solving the Problems
[0011] The method according to an embodiment of the present invention for solving the above problems is an operation method of a zero-day URL attack prevention service providing apparatus for an email security infrastructure, and includes a collection stage of collecting email information transmitted and received between one or more user terminals, and according to a preset security threat architecture, when the email information includes a URL (Uniform Resource Locator), inspecting the URL by an email security process, and a security threat inspection stage of storing and managing URL inspection information based on the inspection result; and a zero-day URL conversion stage of converting the zero-day URL into a preset security URL when it is determined based on the URL inspection information that the URL is a zero-day URL potentially having a zero-day attack risk; and a zero-day URL diagnosis stage of periodically diagnosing whether the zero-day URL is a malicious URL.
[0012] Also, an apparatus according to an embodiment of the present invention for solving the above problems includes a collection unit that collects mail information transmitted and received between one or more user terminals, and according to a pre-set security threat architecture, when the mail information includes a URL (Uniform Resource Locator), the URL is inspected by a mail security process, and a security threat inspection unit that stores and manages URL inspection information based on the inspection result. Based on the URL inspection information, when it is determined that the URL is a zero-day URL with a potentially existing zero-day attack risk, a zero-day URL conversion unit that converts the zero-day URL into a pre-set security URL, and periodically, a zero-day URL diagnosis unit that diagnoses whether the zero-day URL is a malicious URL, and is a zero-day URL attack prevention service providing apparatus including the above components.
[0013] On the other hand, a method according to an embodiment of the present invention for solving the above problems can be embodied in a program for executing the method, or a recording medium on which the program is recorded and can be read by a computer.
Effect of the Invention
[0014] According to an embodiment of the present invention, it is possible to perform a security check on the content of the body of a received email or a URL that can be included in an attached file, etc., and provide information from which security threats have been removed to the recipient (user). In particular, when a zero-day URL that is not analyzed as a normal URL or a malicious URL is detected, when the recipient (user) requests a connection to the URL by converting the zero-day URL into a security URL, it is possible to process a primary connection to a URL for which security is ensured. At the same time, the connection of the recipient (user) can be permitted only when a security check of the actually described zero-day URL is performed and it is determined to be a safe URL. In addition, by tracking and inspecting additional URLs linked and derived from the zero-day URL, it is possible to block malicious purposes such as distributing malicious URLs through many link stages. In this way, by using insufficient evaluation information for a new URL to generate a zero-day malicious URL, malicious purposes such as user information theft, system attacks, and propagation of malicious code can be blocked in advance to prevent damage to the user in advance. Thereby, it is possible to provide an email service that guarantees safe information exchange and processing between users.
Brief Description of the Drawings
[0015]
Figure 1
Figure 2
Figure 3
Figure 4
Figures 5a-5b
Figure 6
Figures 7a-7c
DETAILED DESCRIPTION OF THE INVENTION
[0016] The following content merely exemplifies the principles of the present invention. Therefore, those skilled in the art can, although not explicitly described or illustrated in this specification, embody the principles of the present invention and invent various apparatuses and methods included in the concept and scope of the present invention. Also, all conditional terms and examples listed in this specification are, in principle, clearly intended only for the purpose of understanding the concept of the present invention and should not be understood as being limited to the specifically listed examples and conditions.
[0017] Also, it should be understood that not only the principles, aspects, and examples of the present invention, but also all detailed descriptions listing specific examples are intended to include structural and functional equivalents of such matters. Also, these equivalents include not only currently known equivalents but also equivalents developed in the future, that is, all elements invented to perform the same function regardless of structure.
[0018] Therefore, for example, the block diagrams in this specification must be understood as showing a conceptual view of an exemplary circuit embodying the principles of the present invention. Similarly, all flowcharts, state transition diagrams, pseudocode, etc. can be substantially represented on a computer-readable medium and are to be understood as showing various processes that can be performed by a computer or processor, whether or not a computer or processor is explicitly illustrated.
[0019] Also, the clear use of terms presented as a processor, control, or similar concepts should not be construed as exclusively referring to hardware with the ability to execute software, and should be understood to implicitly include, without limitation, the hardware of a digital signal processor (DSP), ROM (Read Only Memory) for storing software, RAM, and non-volatile memory. Other hardware of well-known tolerance can also be included.
[0020] The above-described objects and features should become clearer through the following detailed description related to the accompanying drawings, by which those of ordinary skill in the technical field to which the present invention pertains can easily implement the technical idea of the present invention. Also, in implementing the present invention, if it is determined that a specific description of the known technology related to the present invention may unnecessarily obscure the gist of the present invention, the detailed description thereof will be omitted.
[0021] The terms used in this application are only used to describe specific embodiments and are not intended to limit the present invention. A single expression includes multiple expressions unless the context clearly indicates a different meaning. In this application, terms such as "including" or "having" are intended to specify the existence of features, numbers, steps, operations, components, parts, or combinations thereof described in the specification, and should not be understood to preclude the existence or addition possibility of one or more other features, numbers, steps, operations, components, parts, or combinations thereof in advance.
[0022] Hereinafter, with reference to the accompanying drawings, preferred embodiments of the present invention will be described in more detail. In describing the present invention, for the sake of easy overall understanding, the same reference numerals are given to the same components in the drawings, and repeated descriptions of the same components are omitted.
[0023] As used herein, the term "mail" can be used generically to refer to terms such as Electronic mail, Web mail, e-mail, and electronic mail items that a user exchanges through a computer communication network using a terminal device and a client program or website installed thereon.
[0024] FIG. 1 is a conceptual diagram showing an overall system according to an embodiment of the present invention.
[0025] Referring to FIG. 1, a system according to an embodiment of the present invention includes a service providing device 100, a user terminal 200, a mail server 300, and a URL service device 400.
[0026] More specifically, the service providing device 100, the user terminal 200, the mail server 300, and the URL service device 400 can be connected through one or more of wired and wireless connections through a connection to a public network to transmit and receive data. The public network is a communication network constructed and managed by a country or a major telecommunications carrier, and generally includes a telephone network, a data network, a CATV network, and a mobile communication network, etc., and provides a connection service so that an unspecified number of ordinary people can connect to other communication networks and the Internet. In the present invention, the public network is referred to as a network for convenience.
[0027] Also, the service providing device 100, the user terminal 200, the mail server 300, and the URL service device 400 can each include a respective communication module for communicating using a protocol corresponding to each communication network.
[0028] The service providing apparatus 100 can be connected to each user terminal 200 and a mail server 300 through a wired / wireless network for providing a mail security service, and devices or terminals connected to each network can communicate with each other through a preset network channel. Also, when the user terminal 200 makes a connection request to use a URL included in the text content or attachment file of a received mail, it can be connected to a URL service apparatus 400 that is connected through the wired / wireless network to provide a service.
[0029] Here, each of the networks can be implemented by all types of wired / wireless networks such as a Local Area Network (LAN), a Wide Area Network (WAN), a Value Added Network (VAN), a Personal Area Network (PAN), a Mobile radio communication network, or a satellite communication network.
[0030] The service providing apparatus 100 described in this specification can provide a mail security service that can detect and block attacks that cause the execution of an unintended program through mail, unauthorized information leakage, a decrease in the data processing ability of a mail-related system, phishing fraud, and the like.
[0031] The user terminal 200 described in the foregoing specification includes, for example, a PC (personal computer), a laptop computer, a mobile phone, a tablet PC, a PDA (Personal Digital Assistants), a PMP (Portable Multimedia Player), etc. However, the present invention is not limited thereto, and it can be a device capable of connecting to the service providing apparatus 100 and a mail server 300, etc. via a public network or a private network, etc.
[0032] In addition to this, each device may be a variety of devices capable of inputting and outputting information through application driving or web browsing. In particular, usually, the user terminal 200 can be connected to the service providing apparatus 100 through an individual security network.
[0033] The mail server 300 may be a system that relays and stores the content of an e-mail so that a user can send an e-mail created through the user terminal 200, or the other party can receive an e-mail created through the user terminal 200. The mail server 300 can perform mutual communication by utilizing a preset protocol according to the purpose of use such as the processing of receiving and sending e-mails.
[0034] Generally, when receiving an e-mail, POP3 (Post Office Protocol 3) or IMAP (Internet Message Access Protocol) can be used for the protocol. Also, when sending an e-mail, SMTP (Simple Mail Transfer Protocol) can be used for the protocol. In this way, the mail server 300 can be configured and operated by a server system for e-mail sending and receiving processing. Also, the mail server 300 can be subdivided into a mail receiving server and a mail sending server to provide respective functions.
[0035] Figure 2 is a block diagram for explaining a zero-day attack defense service providing apparatus of a mail security infrastructure according to an embodiment of the present invention.
[0036] Referring to Figure 2, a service providing apparatus 100 according to an embodiment of the present invention may include a control unit 110, a collection unit 120, a security threat inspection unit 130, a zero-day URL conversion unit 140, a mail processing unit 150, a zero-day URL diagnosis unit 160, a URL classification information management unit 170, a security URL connection unit 180, and a communication unit 190. Further, the mail processing unit 150 may include a zero-day mail processing unit 151. Also, the zero-day URL diagnosis unit 160 may include a URL tracking module 161 and a URL chain diagnosis module 162.
[0037] The control unit 110 may be implemented by one or more processors for generally controlling the operations of each component of the service providing apparatus 100.
[0038] The collection unit 120 can collect mail information transmitted and received between one or more user terminals 200. The mail information may include information in an email header, the subject of the email, the content of the email body, the number of receptions during a certain period, and the like.
[0039] Specifically, the email header information may include the IP address of the mail sending server, the host name information of the mail sending server, the domain information of the sender's email, the sender's email address, the IP address of the mail receiving server, the host name information of the mail receiving server, the domain information of the recipient's email, the recipient's email address, the mail protocol information, the mail reception time information, the mail sending time information, and the like.
[0040] Also, the email header may include network path information necessary in the process of sending and receiving the mail, protocol information used between mail service systems for the mail exchange, and the like.
[0041] Furthermore, the email information can include the extension of the attached file, the hash information of the attached file, the attached file name, the text content of the attached file, a URL (Uniform Resource Locator), etc. The attached file can include additional information in addition to the text content of the email that the sender intends to convey to the recipient, or additional content for requesting a reply of information. The URL can be included in the text content of the email and can be confirmed from the information included in the content of the attached file.
[0042] The content can provide text, images, videos, etc. The recipient can execute the application corresponding to the file attached to the email to view the content. Also, the recipient can download the file attached to the email to a local storage device for storage and management. At this time, the URL in the content can be included as text information. Thereby, when the user terminal 200 requests a connection to the URL, the service provided by the URL service device 400 can be confirmed. The URL can be called by a script executed on a web page or the like. Also, the URL can be called by an event generated by the user terminal 200 on a web page or the like.
[0043] The extension of the attached file can classify the format and type of the file. The extension of the attached file can generally be classified by a character string indicating the attributes of the file and the application that generated the file. For example, a text file can be classified by an extension such as [file name].txt, an MS Word file by [file name].doc (docx), a Hangul file by [file name].hwp, etc. Also, an image file can have its extension classified like gif, jpg, png, tif, etc.
[0044] Furthermore, executable files, which are computer files that perform operations as instructed according to encoded instructions, can be classified as [file name].com, [file name].exe, [file name].bat, [file name].dll, [file name].sys, [file name].scr, etc.
[0045] The hash information of the attached file can verify the authenticity and alteration of the information and ensure the integrity of the information. The hash information or hash value can be mapped to a bit string of a fixed length for any data of any length through a hash function.
[0046] As a result, the hash information output through the hash function for the initially generated attached file will have a unique value. The output hash information or hash value has a one-way property that cannot extract the data input into the function conversely. Also, the hash function provides an output equal to the hash information or hash value output for one given input data, and other input data can ensure computationally impossible collision avoidance. Thus, when the data of the attached file is modified or added, the output value of the hash function is returned as different.
[0047] In this way, the unique hash information of the attached file can confirm whether the file has been modified or forged by comparing the hash information or hash value for the files exchanged through email. Also, since the hash information is fixed to a unique value, it enables pre - defensive measures against virus infection by utilizing reputation information, which is a database of past history data for files generated with malicious intent. Furthermore, the hash function can be used in technologies and versions that can ensure one - wayness and collision avoidance.
[0048] For example, the hash information can be utilized as search information regarding the presence or absence of malicious code in a file through the website of a virus total or the website of malware. Further, the website can provide evaluation and analysis information regarding the normality or abnormality of URL information. Through the website that provides the hash information analysis of the file, information such as the file provider and the hash value of the file can be provided. Also, since the search results for the hash information of the file can cross-check the reputation information determined by a global company that provides a number of IT information security solutions, it can be determined as more reliable information.
[0049] When the email information contains a URL (Uniform Resource Locator), the security threat inspection unit 130 can inspect the URL through the email security process and save and manage the URL inspection information based on the inspection result according to a preset security threat architecture. The security threat architecture can be classified into security threats of spam emails, security threats of malicious code, security threats of social technology, security threats of internal information leakage, and the like. According to the security threat architecture, the type, level, process, priority, and processing procedure of the security threat can be set.
[0050] The email security process corresponding to the security threat architecture can include a spam email security process, a security process for malicious code, a security process for phishing emails, a security process for email forwarding, and the like. In particular, the inspection of whether the email information contains a URL or not can be included in the security process for malicious code in the email security process.
[0051] The security threat inspection unit 130 can inspect the URLs detected in the email information through the security process of malicious code in the email security process. The security threat inspection unit 130 can detect URL information that can be included in the text content of the email and attached files through text-based extraction methods, image-based extraction methods, etc. Also, in the case of an attached file in web format, it can be inspected whether a URL is detected in the source code. Thus, the security threat inspection unit 130 can obtain inspection results by mapping the extracted URLs to the blacklist or whitelist it manages itself. Or, the security threat inspection unit 130 can match the extracted URLs in conjunction with the reputation analysis URL information that is analyzed and shared by domestic and foreign cyber security-related institutions, enterprises, portal companies, etc.
[0052] For example, when the URL detected by the security threat inspection unit 130 is confirmed to be "www.*fake-url*.com", the detected URL can be primarily matched with the reputation analysis URL information. Thus, the security threat inspection unit 130 can cross-check the information evaluated for the URL, and thereby obtain inspection information on whether it is a trusted (normal) URL or a malicious URL.
[0053] Also, the security threat inspection unit 130 performs stage-by-stage matching processing of the email security process corresponding to the email information according to a pre-set security threat architecture, inspects the email information by the matched email security process, and can save and manage the email security inspection information based on the inspection results.
[0054] The email security process can determine different email security processes corresponding to received emails or sent emails according to the security threat architecture. In addition, the inspection procedure or inspection level of the email security process is determined according to the preset security level and architecture.
[0055] The email security process can be explained by the virtual space concept in a fluid resource allocation method where, when email information for reception or transmission is sent from the user terminal 200, an independently sorted process is allocated to resources and immediately executed in the inspection area allocated from the email information. In the method of allocating resources to the virtual space, the email security process can immediately process the work in the inspection area allocated from the sequentially incoming email information when it is processed.
[0056] In contrast, an environment where a certain process with restricted processing in one resource, such as a virtual environment or a virtual machine, is allocated can have an idle time where other processes wait until the processing of a specific process is completed when processing the requested work. In this way, in the analysis method through the process, the fluid resources can have an advantage in processing speed and performance compared to the fixed-type resources.
[0057] The security threat inspection unit 130 can sort emails for the purpose of reception or transmission based on the email information collected by the collection unit 120. Then, the security threat inspection unit 130 can obtain email security inspection information for each email by sequentially matching or analyzing according to the set priority order with the email security process.
[0058] The spam email security threat can include types of emails that are unilaterally, massively, and indiscriminately distributed to an unspecified large number of recipients for purposes such as advertising and publicity between unrelated senders and recipients. Also, a large amount of spam emails can impose a load on the data processing capacity of the email system, which may cause a decrease in the processing capacity of the system. Additionally, there is a risk that spam emails may be unintentionally linked to the indiscriminate information contained in the text content, etc., and can be disguised as information for potential phishing fraud.
[0059] In order to detect and filter such spam emails, the security threat inspection unit 130 can include a spam email inspection unit (not shown). When the email security process is a spam email security process, the spam email inspection unit can match the email information including the information in the email header, the subject of the email, the text content of the email, the number of received emails during a certain period, etc. with a pre-set spam index step by step.
[0060] The spam email inspection unit can be used as an inspection item in the spam index through inspections of a certain pattern classified as spam for the email information including the information in the email header, the subject of the email, the text content of the email, etc. Thereby, the spam email inspection unit can match the spam index step by step to obtain, save, and manage spam email inspection information.
[0061] The spam index can have inspection items and level values obtained by inspections set step by step based on the items included in the email information. According to an embodiment of the present invention, the spam index can be configured to be subdivided and hierarchized into level 1, level 2, level 3, …, level [n].
[0062] The spam index level 1 can match the subject data of emails included in the email information based on big data and reputation information. As a result, the spam index level 1 can obtain the evaluated level value as the inspection information of the spam index level 1. The level value can be set as information that can be quantitatively measured. For example, when the inspection information of the spam index level 1 includes words such as "advertisement" or "publicity" in the subject of the email, which is the inspection item, and it matches the information defined as spam emails in the big data and reputation information, it can be evaluated as "1" among the level values divided into 0 and 1. Thus, "1" can be obtained as the inspection information of the spam index level 1.
[0063] Furthermore, the spam index level 2 can match the data included in the email information based on user-specified keywords. As a result, the spam index level 2 can obtain the evaluated level value as the inspection information of the spam index level 2. For example, when the inspection information of the spam index level 2 includes keywords such as "special price", "super special price", "sale", "sale", "out of stock", etc. in the body content of the email, which is the inspection item, and it matches the information defined as spam emails in the user-specified keywords, it can be evaluated as "1" among the level values divided into 0 and 1. Thus, "1" can be obtained as the inspection information of the spam index level 2.
[0064] In the next step, the spam index level 3 can match the data included in the mail information based on image analysis. As a result, the spam index level 3 can obtain the evaluated level value as the inspection information of the spam index level 3. For example, when the inspection information of the spam index level 3 includes, among the data extracted by analyzing the image included in the text content of the mail which is an inspection item, a phone number starting with "080", and it matches the information defined as spam mail in the image analysis, it can be evaluated as "1" among the level values sorted into 0 and 1. Thus, "1" can be obtained as the inspection information of the spam index level 3.
[0065] In this way, through the spam mail security process, the inspection information obtained in units of the spam index level can finally be totaled ("3") and saved and managed as spam mail inspection information. The spam mail inspection information totaled in this way can be included and managed in the mail security inspection information, and can be utilized as security threat discrimination information by the mail processing unit 150.
[0066] The security threat inspection unit 130 can further include a malicious code inspection unit (not shown). When the mail security process is a malicious code security process, the malicious code inspection unit can match the mail information further including the extension of the attached file, the hash information of the attached file, the attached file name, the text content of the attached file, URL (Uniform Resource Locator) information, etc. with a preset malicious code index step by step.
[0067] The malicious code inspection unit can use the extension of the attached file, the hash information of the attached file, the attached file name, etc., which can be confirmed by the attribute value of the attached file, together with the text content of the attached file and the URL (Uniform Resource Locator) information included in the text content as inspection items for the malicious code index. Accordingly, the malicious code inspection unit can match the malicious code index step by step according to items to obtain, save, and manage malicious code inspection information.
[0068] The inspection items based on the items included in the mail information and the level values obtained by the inspection can be set for the malicious code index step by step. According to an embodiment of the present invention, the malicious code index can be configured by being subdivided and staged into level 1, level 2, level 3, …, level [n].
[0069] The malicious code index level 1 can match the attached file name and the extension of the attached file included in the mail information based on big data and reputation information. Accordingly, the malicious code index level 1 can obtain the evaluated level value as the inspection information of the malicious code index level 1. For example, when the inspection information of the malicious code index level 1 is such that the attached file name, which is an inspection item, is "Trojan" and the extension of the attached file includes "exe", and it matches the information defined as malicious code in the big data and reputation information, it can be evaluated as "1" among the level values sorted into 0 and 1. Thus, "1" can be obtained as the inspection information of the malicious code index level 1.
[0070] Furthermore, the malicious code index level 2 can match the hash information of the email attachment file based on big data and reputation information. Thereby, the evaluated level value can be obtained as the inspection information of the malicious code index level 2. For example, when the hash information of the attachment file, which is an inspection item, is analyzed as "a1b2c3d4" in the malicious code index level 2, if it matches the information defined as malicious code in the reputation information, it can be evaluated as "1" among the level values sorted into 0 and 1. Thereby, "1" can be obtained as the inspection information of the malicious code index level 2.
[0071] In the next step, the malicious code index level 3 can match the URL (Uniform Resource Locator) information included in the attachment file or the body content of the email based on the URL reputation information. The level value evaluated thereby can be obtained as the inspection information of the malicious code index level 3. For example, if the URL information, which is an inspection item, is confirmed to be "www.malicious-code.com" in the malicious code index level 3, and it matches the information defined as a harmful site containing a malicious code file in the URL reputation information, it can be evaluated as "1" among the level values sorted into 0 and 1. Thereby, "1" can be obtained as the inspection information of the malicious code index level 3. And the malicious code inspection unit can respond to zero-day attacks that may leak from the URL reputation information. The malicious code inspection unit can change the IP address of the link to a URL without reputation information to the IP address of a specific system and provide the changed IP address to the user terminal 200. When the user terminal 200 attempts to connect to the URL, it can connect to the IP address of the specific system changed by the malicious code inspection unit. The specific system whose IP address has been changed in advance to the link to the URL can continue to inspect whether it contains malicious code up to the endpoint of the URL.
[0072] In this way, the inspection information obtained in units of malicious code index levels through the malicious code security process can ultimately be totaled ("3") and stored and managed as malicious code inspection information. The malicious code inspection information totaled in this way can be included in and managed in the mail security inspection information, and can be utilized as security threat discrimination information by the mail processing unit 150.
[0073] The security threat inspection unit 130 may further include a spoofed mail inspection unit (not shown). The spoofed mail inspection unit can match with a preset relationship analysis index step by step when the mail security process is a spoofed mail security process. The relationship analysis information can be obtained through mail information analysis including mail information and attribute information of mails confirmed as normal ones.
[0074] The spoofed mail inspection unit can use, as relationship analysis index inspection items, the domain of the received mail, the domain of the sent mail, the received mail address, the sent mail address, the routing of the mail, the text content information of the mail, etc., which can be extracted from the mail determined to be normal. Thereby, the spoofed mail inspection unit can match the relationship analysis index step by step by item, obtain spoofed mail inspection information, and store and manage it. Thereby, the spoofed mail inspection unit can detect similar domains and filter mails that can pose a security threat by tracking or verifying the mail sending route.
[0075] For the relationship analysis index, inspection items based on the relationship analysis information and level values obtained by inspection can be set step by step. According to an embodiment of the present invention, the relationship analysis index can be configured by being subdivided and staged into level 1, level 2, level 3,..., level [n].
[0076] The relationship analysis index level 1 can match the domain of the sender's email, the sender's email address, etc. based on the reputation information. As a result, the relationship analysis index level 1 can obtain the evaluated level value as the inspection information of the relationship analysis index level 1. For example, when the inspection information of the relationship analysis index level 1 is that the domain of the sent email, which is an inspection item, is "@fake.com" and the sender's email address contains "fake@", and it matches the information defined as malicious code in the reputation information, it can be evaluated as "1" among the level values sorted into 0 and 1.
[0077] Furthermore, the relationship analysis index level 2 can match the domain of the sender's email, the sender's email address, etc. based on the relationship analysis information. As a result, the relationship analysis index level 2 can obtain the evaluated level value as the inspection information of the relationship analysis index level 2. For example, when the inspection information of the relationship analysis index level 2 is that the domain of the sent email, which is an inspection item, is "@fake.com" and the sender's email address contains "fake@", and it does not match the information defined as the attribute information of a normal email in the relationship analysis information, it can be evaluated as "1" among the level values sorted into 0 and 1. As a result, "1" can be obtained as the inspection information of the relationship analysis index level 3.
[0078] In the next step, the relationship analysis index level 3 can match routing information of emails based on the relationship analysis information. As a result, the relationship analysis index level 3 can obtain the evaluated level value as the inspection information of the relationship analysis index level 3. For example, if it is confirmed that the routing information of the email, which is an inspection item, is "1.1.1.1", "2.2.2.2", or "3.3.3.3" in the inspection information of the relationship analysis index level 3, and the routing information, which is the email transmission path, does not match the information defined as the attribute information of normal emails in the relationship analysis information, it can be evaluated as "1" among the level values sorted into 0 and 1. As a result, "1" can be obtained as the inspection information of the relationship analysis index level 3.
[0079] In this way, the inspection information obtained in units of the relationship analysis index level through the fake email security process can finally be totaled to "3" and stored and managed as fake email inspection information. The fake email inspection information totaled in this way can be included in and managed by the email security inspection information, and can be utilized as security threat discrimination information by the email processing unit 150.
[0080] The security threat inspection unit 130 can include an email carry-out inspection unit (not shown) to address the security threat of internal information leakage. When the email security process is the security process of email carry-out, the email carry-out inspection unit can match the preset email carry-out management index with the email information step by step.
[0081] The email carry-out inspection unit can utilize the attribute information of the email information as an inspection item of the email carry-out management index. Also, the management index inspection item can utilize the assigned IP information of the internally managed user terminal 200.
[0082] The mail delivery management index can be set with inspection items and level values determined in advance step by step. According to an embodiment of the present invention, the mail delivery management index can be configured by being subdivided and staged into level 1, level 2, level 3, …, level [n].
[0083] For the outgoing mail environment inspection, the mail delivery management index can include an item for controlling so that only allowed IP addresses among the IP addresses assigned to the user terminal 200 can register mail information. Since unauthenticated user terminals are relatively likely to leak internal information and relatively likely to pose a security threat through mails, it is possible to manage a management index that can block this in advance.
[0084] In addition, the mail delivery inspection unit can classify the mail delivery management index into inspection items such as IP address information and the number of sending times, and utilize it as the mail delivery management index. Further, the mail delivery inspection unit can be further provided with a control unit such as an approval process as a mail sending environment inspection item, thereby reducing the threat of internal information leakage. As a result, the mail delivery inspection unit can save and manage the level value calculated by matching the inspection item through the mail delivery process as mail delivery inspection information.
[0085] When the zero-day URL conversion unit 140 determines that the URL is a zero-day URL with a potentially existing zero-day attack risk based on the URL inspection information obtained by the security threat inspection unit 130, the zero-day URL conversion unit 140 can convert the zero-day URL into a pre-set security URL. A zero-day attack can be carried out by taking advantage of security vulnerabilities or the unconstructed state of a security attack defense system before the existence of problems related to an ICT (Information and Communication Technology) system is announced or analyzed. At this time, through reputation analysis URL information, etc., it can be determined whether it is a normal URL or a malicious URL, or URLs that cannot be analyzed can be sorted into zero-day URLs. The zero-day URL can include the possibility of a zero-day attack depending on the intention of the generator. The zero-day URL can be disguised as a normal URL, and can also be derived from a URL that is linked to a URL determined to be a normal URL and contains a malicious URL. Thus, the zero-day URL can be exploited as a means of a zero-day attack.
[0086] The security threat inspection unit 130 analyzes the evaluation information of the extracted URL to determine whether it is a trusted (normal) URL or a malicious URL, but there are limitations in obtaining evaluation information for newly generated URLs. In addition, when the IP address mapped to the URL is not included in the blacklist or whitelist information, the security threat inspection unit 130 cannot provide discrimination information regarding the presence or absence of anomalies. As described above, when the extracted URL does not correspond to reputation analysis through internal and external management data and is determined to be unknown information, the zero-day URL conversion unit 140 can determine the extracted URL as a zero-day URL.
[0087] As a result, the zero-day URL conversion unit 140 can convert a URL determined to be a zero-day URL into a security URL, which is reliable URL information, and include it in the mail information. The zero-day URL conversion unit 140 deletes the URL determined to be a zero-day URL from the mail information, inserts the security URL into the deleted part and performs conversion, and can generate a URL conversion table so as to save and manage the conversion details of the deleted URL and the security URL. When a connection request from the user terminal 200 to the security URL applied to the received mail that the user terminal 200 can view occurs, the URL conversion table can be utilized as information enabling connection to the verified zero-day URL.
[0088] The mail processing unit 150 can process the mail status based on the URL inspection information analysis. The mail processing unit 150 can include a zero-day mail processing unit 151 that, for a mail containing the zero-day URL, replaces the zero-day URL with the security URL and processes it to a received state accessible by the user terminal.
[0089] The zero-day mail processing unit 151 processes the mail replaced with the security URL to a received state, whereby the user terminal 200 can recognize the URL described in the text content or attachment file of the mail as a security URL rather than the originally described zero-day URL.
[0090] Also, the mail processing unit 150 can process the mail status according to the security threat determination information obtained through the mail security inspection information and the mail information analysis.
[0091] The relationship analysis unit (not shown) can store and manage relationship analysis information obtained based on the mail information and the trust authentication log analysis. The trust authentication log can include record information such as the domain of the received mail, the domain of the sent mail, the received mail address, the sent mail address, the mail routing, and the content information of the mail body when the mail information is processed as normal mail according to the security threat discrimination information through the mail processing unit 150.
[0092] The mail processing unit 150 can perform the mail security process according to a preset priority order. When the security threat discrimination information through the mail security process is determined to be spam by the mail processing unit 150, it can determine whether to interrupt the subsequent mail security process and process the mail status. Accordingly, when a problem is found at the inspection stage first according to the priority order, the mail processing unit 150 can only perform the necessary processing at that stage, determine whether the inspection is completed, and end without performing the subsequent inspection stage. Thereby, the efficiency of the mail security service can be ensured, the complexity of the system can be reduced, and the processing efficiency can be improved.
[0093] The email security inspection information can utilize the information obtained by summarizing the spam email inspection information, malicious code inspection information, phishing email inspection information, and email transfer inspection information calculated by the security threat inspection unit 130. For example, when the security threat inspection unit 130 performs a process on the email information and the score calculated for the spam email inspection information is "3", the score calculated for the malicious code inspection information is "2", the phishing email inspection information is "1", and the score calculated for the email transfer inspection information is "0", the score obtained as the email security inspection information can be "7". At this time, as the criterion for the pre-set security threat discrimination information, when the comprehensive score is in the range of 0 to 3, it can be classified as a normal email, when it is in the range of 4 to 6, it can be classified as a gray email, and when it is in the range of 7 to 12, it can be classified as a nuisance email. Accordingly, an email with the email security inspection information of "7" can be determined as a nuisance email. And the result value of each inspection information item included in the email information inspection information can have an absolute priority specified by the item, or the priority can be determined by information with a weighted value.
[0094] The email processing unit 150 can include an email distribution processing unit (not shown) that processes emails determined to be normal emails according to the security threat discrimination information in a reception or transmission state that can be processed by the user terminal.
[0095] Also, the email processing unit 150 can further include an email discard processing unit (not shown) that processes emails determined to be nuisance emails according to the security threat discrimination information in a state where access to the user terminal is impossible.
[0096] Furthermore, the email processing unit 150 can further include an email harmlessization processing unit (not shown) that converts the gray email into non-executable file content and provides it so that the user terminal can selectively process the email state for emails determined to be gray emails according to the security threat discrimination information.
[0097] Generally, the gray mails can be sorted into spam mails or junk mails, and conversely, they can also be sorted into normal mails. In the present invention, the gray mails can be defined as a type of mail that is sorted when the security threat discrimination information is calculated as an intermediate value within a certain range where it cannot be determined whether it is normal or abnormal. The mail harmless processing unit can convert the gray mails including the suspected text content into image files and provide them in a mail state that can be confirmed by the user terminal 200. In addition, the mail harmless processing unit can remove or correct the suspected malicious code parts in the attached files and provide them to the user terminal 200.
[0098] The zero-day URL diagnosis unit 160 can periodically diagnose whether the zero-day URL is a malicious URL. The malicious URL can include security threats such as inducing input of personal information, downloading malicious code, executing malicious scripts, and web vulnerability attacks.
[0099] Since the zero-day URL has not been used before or has not been evaluated, the reliability of the service or content provided through the connection thereto is not guaranteed. In addition, the zero-day URL may be provided for malicious purposes by imitating a normal web page through forgery or alteration. Of course, a zero-day URL that provides normal services or content may occur. This is classified as a zero-day URL only because it is the first time the URL is provided.
[0100] However, since there is no information analyzed and evaluated on what purpose the zero-day URL is served and what content it provides, etc., the possibility of causing harm by making the user execute abnormal behaviors cannot be excluded. Therefore, the zero-day URL must be subject to a security check so that it can be immediately determined whether it is a malicious URL as soon as it is discovered.
[0101] The security inspection can go through a primary stage of extracting the IP address corresponding to the zero-day URL and rematching it with a blacklist. The blacklist can utilize database information that classifies and stores harmful IPs by itself. Additionally, it can utilize the harmful IP address reputation analysis information analyzed and shared by domestic and foreign cyber security-related institutions, enterprises, portal companies, etc.
[0102] Such blacklist matching inspection can first be utilized for the reputation analysis URL information correspondence inspection by the security threat inspection unit 130. However, the reputation analysis URL information and the reputation information for harmful IPs can be further implemented by the zero-day URL diagnosis unit 160 in order to utilize real-time updated analysis information.
[0103] The zero-day URL diagnosis unit 160 can, primarily, based on the inspection result, determine whether the IP mapped to the zero-day URL is a harmful IP and proceed with subsequent inspections.
[0104] When the zero-day URL is re-determined as a zero-day URL that cannot be sorted as normal or abnormal, the zero-day URL diagnosis unit 160 can inspect whether the services or content provided by connecting to the zero-day URL are normal.
[0105] The zero-day URL diagnosis unit 160 can conduct an action-based dynamic inspection by connecting to the zero-day URL. Thereby, the zero-day URL diagnosis unit 160 can gradually conduct inspections on whether the zero-day URL induces the input of personal information, downloads malicious code, induces malicious code download, executes malicious scripts, etc. Additionally, it can inspect matters where web vulnerability attacks can occur.
[0106] When a problem is discovered during the inspection stage according to the priority order, the zero-day URL diagnosis unit 160 can perform only the necessary processing at that stage, determine whether the inspection has been completed, and end without performing subsequent inspection stages. This can ensure the efficiency of the email security service, reduce the complexity of the system, and improve the processing efficiency.
[0107] According to an embodiment of the present invention, the zero-day URL diagnosis unit 160 can perform an inspection on whether it is a malicious URL as follows.
[0108] First, the zero-day URL diagnosis unit 160 can re-inspect the reputation analysis URL information in real time.
[0109] For example, when "www.*zerodayurl1*.com" identified as a zero-day URL is provided, the zero-day URL diagnosis unit 160 can primarily diagnose whether the "www.*zerodayurl1*.com" is a malicious URL. At this time, based on the IP address information "1.2.3.4" obtained by analyzing the IP address mapped to "www.*zerodayurl1*.com", it can also diagnose whether it is a harmful IP. The zero-day URL diagnosis unit 160 can confirm that the zero-day URL and the IP address mapped thereto still do not correspond to the reputation analysis information.
[0110] In the next stage, the zero-day URL diagnosis unit 160 can perform a dynamic inspection of the behavior base by directly connecting or connecting to the zero-day URL.
[0111] For example, the zero-day URL diagnosis unit 160 can directly connect or link to the zero-day URL "www.*zerodayurl1.com*" to check whether it is a fake or forged URL. The zero-day URL diagnosis unit 160 can confirm that a web page menu providing financial services is configured at "www.*zerodayurl1*.com", and through this, it can be confirmed that it is a URL that induces the input of personal information and financial-related information. The zero-day URL diagnosis unit 160 can inspect and determine whether it is a URL attempting to steal personal information or financial-related information through this. Through the inspection, if it is determined to be a malicious URL, the zero-day URL diagnosis unit 160 can sense that "www.*zerodayurl1*.com" is provided to be similar to the configuration of the web page of "www.*zerodayurl*.com" that provides normal financial services, and when it confirms an attempt to steal the personal information and financial information of the user who uses this, it can be evaluated as a malicious URL. The "www.*zerodayurl1*.com" determined to be a malicious URL can add the number 1 to zerodayurl, which is the two-level domain of the normal URL "www.*zerodayurl*.com", to make the user have an illusion of a normal URL and induce a connection. Also, when connecting or linking to "www.*zerodayurl1*.com", the zero-day URL diagnosis unit 160 can check whether a file containing malicious code is downloaded or induced to be downloaded. Furthermore, when connecting or linking to "www.*zerodayurl1*.com", the zero-day URL diagnosis unit 160 can check whether a malicious script is executed. At the same time, the zero-day URL diagnosis unit 160 can grasp the execution operation of the menu provided at "www.*zerodayurl1*.com" and check for abnormalities.
[0112] In addition, the zero-day URL diagnosis unit 160 can check whether an attack using web vulnerabilities or the like is being carried out and determine whether it is normal. The web vulnerabilities can be exploited as tools for malicious purposes such as cyberattacks, information theft, illegal privilege acquisition, and fraud through programming in the source code area. The web vulnerabilities can be caused by SQL injection, XPath injection, injection of malicious content, cross-site scripting (XSS), cross-site request forgery, automated attacks, file upload, cookie forgery, and the like.
[0113] The zero-day URL diagnosis unit 160 can include a URL tracking module 161 that, at regular intervals, tracks and manages one or more first derived URLs linked from the zero-day URL and the [n]th derived URL that is derived in a chained manner through this, to obtain URL chain information. The URL tracking module 161 can inspect services or content provided directly connected or linked to the zero-day URL and track URL information provided as additional links. By obtaining the URL chain information, the URL tracking module 161 can utilize the URL chain information so that URLs that have been identified as existing malicious URLs among the derived URLs linked and connected to the zero-day URL can be selected.
[0114] At this time, when the zero-day URL provides services on a web page, the zero-day URL can configure a menu on the web page. The zero-day URL can thereby perform further operations on the web page and can provide further links to move to the first derived URL. Such a first derived URL can be provided in one or more on the web page provided by the zero-day URL. The web page to which the first derived URL is linked and connected can provide a second derived URL that is a further link through a menu or the like. The second derived URL can be provided in one or more through one or more menus or the like. Thus, the zero-day URL can include the first derived URL through the service or content provided, and the first derived URL can also include the second derived URL. Also, the second derived URL can include the third, fourth, and the [n]th derived URLs in a chain.
[0115] Thereby, the URL tracking module 161 can obtain URL chain information that maps by comprehensively detecting the URL information detected from the zero-day URL to the [n]th derived URL.
[0116] Thereby, the zero-day URL diagnosis unit 160 can use the URL chain information that is chained like the zero-day URL, the first derived URL derived from the zero-day URL, the second derived URL derived from the first derived URL, etc. to inspect and determine whether it is a malicious URL. Such a zero-day URL diagnosis unit 160 can track and extract URL information for the target from the zero-day URL to the end point where the [n]th derived URL is not detected according to a certain time, minute, second interval, or a specific criterion that can be sorted periodically.
[0117] Further, the zero-day URL diagnosis unit 160 may further include a URL chain diagnosis module 162 that diagnoses whether a [n]th derived URL is a malicious URL at regular intervals based on the URL chain information, and stores and manages chain diagnosis information.
[0118] The URL chain diagnosis module 162 can continuously update the chain diagnosis information to maintain the latest information. Accordingly, the URL chain diagnosis module 162 may be provided to add a URL determined to be a malicious URL to a blacklist in conjunction with an external agency.
[0119] The URL classification information management unit 170 can store and manage information selected and determined from among normal URLs, malicious URLs, and zero-day URLs as URL classification information by analyzing the URL inspection information. The URL classification information management unit 170 can include abnormality determination information for zero-day URLs and the [n]th derived URLs in the URL classification information based on the chain diagnosis information. Accordingly, the URL classification information management unit 170 can maintain the update of the URL classification information and provide information that can quickly respond to security threats.
[0120] When the user terminal 200 that receives an email including the security URL requests a connection to the security URL, the security URL connection unit 180 can be provided to a security zone that is primarily redirected by the user terminal 200. The security URL connection unit 180 can process connections to the zero-day URL and the [n]th derived URL that are determined not to be malicious URLs based on the diagnosis information.
[0121] For example, the user terminal 200 can check a received email in which the zero-day URL "www.*zerodayurl123*.com" (mapped IP address: 1.1.1.1) described in the initial email content is replaced with the security URL "www.*security123*.com" (mapped IP address: 10.10.10.10). Also, when the user terminal 200 requests a connection, the user terminal 200 can apply security URL conversion information obtained by converting the IP address mapped to the zero-day URL "www.*zerodayurl123*.com" without change. The user terminal 200 can click on the "www.*security123*.com" described for additional confirmation of the email content or enter it into a web browser to attempt a connection. At this time, when the user terminal 200 clicks on the "www.*security123*.com" described in the email content to request a connection, the user terminal 200 can be redirected to first connect to the IP address 10.10.10.10 of the security URL connection unit 180. Thereafter, according to the malicious URL inspection information, it is possible to allow or block movement to the IP address 1.1.1.1 mapped to the "www.*zerodayurl123*.com". Information regarding this can be provided for the user terminal 200 to check via a notification window or the like.
[0122] The record management department (not shown) can save and manage the mail information processed according to the security threat discrimination information as record information. When the record management department processes it as normal mail according to the security threat discrimination information, the record management department may further include a relationship information management department (not shown) that saves and manages the record information including the domain of the received mail, the domain of the sent mail, the received mail address, the sent mail address, the mail routing, the text content information of the mail, etc. as a trust authentication log. The record management department can further include normal URL information in the trust authentication log based on the abnormality determination information for the URL included in the text content of the mail. Thereby, the trust authentication log can be utilized for the analysis of relationship information that can be trusted for the mail information of the recipient and the sender. Also, the information included in the trust authentication log can have its reliability guaranteed while data is continuously accumulated through mutual information exchange.
[0123] Also, when the record management department processes it as spam mail according to the security threat discrimination information, the record information including the domain of the received mail, the domain of the sent mail, the received mail address, the sent mail address, the mail routing, the text content information of the mail, etc. can be utilized as a spam mail determination index during the execution of the mail security process. Also, the record management department can further include malicious URL information as a spam mail determination index based on the abnormality determination information for the URL included in the text content of the mail.
[0124] Figure 3 is a flowchart for explaining the operation method of the zero-day attack defense service providing apparatus of the mail security infrastructure according to an embodiment of the present invention.
[0125] Referring to Figure 3, in the operation method of the zero-day attack defense service providing apparatus, in the collection stage S101, the mail information transmitted and received between one or more user terminals 200 can be collected.
[0126] In addition, it is determined whether a URL is collected in the mail information (S103).
[0127] In the security threat inspection stage S105, according to a preset security threat architecture, when the mail information includes a URL (Uniform Resource Locator), the URL can be inspected by a mail security process. The security threat inspection stage S105 can save and manage URL inspection information based on the inspection result.
[0128] The mail security process can determine different mail security processes corresponding to received mail or sent mail according to the security threat architecture. Also, the inspection procedure or inspection level of the mail security process can be determined according to a preset security level and architecture.
[0129] At the same time, it is determined whether it is determined to be a zero-day URL according to the inspection result (S107).
[0130] In the URL conversion stage S109, based on the URL inspection information, when the URL is determined to be a zero-day URL that does not correspond to the reputation analysis URL information, the zero-day URL can be converted into a preset security URL.
[0131] The zero-day URL diagnosis stage S111 can diagnose whether the zero-day URL is a malicious URL at regular intervals.
[0132] The zero-day URL diagnosis stage S111 can further include a URL tracking stage (not shown) that, at regular intervals, tracks and manages one or more first derived URLs linked from the zero-day URL and the [n]th derived URL that is derivatively chained through this to obtain URL chain information.
[0133] In addition, the zero-day URL diagnosis stage S111 may further include a URL chain diagnosis stage (not shown) that diagnoses whether the [n]th derived URL is a malicious URL at regular intervals based on the URL chain information, and stores and manages the chain diagnosis information.
[0134] The email processing stage S113 can process the email status through URL inspection information analysis. The email processing stage S113 may further include a zero-day email processing stage (not shown) that replaces the zero-day URL with the security URL for the email containing the zero-day URL and processes it to a receivable state accessible by the user terminal 200.
[0135] A URL classification information management stage (not shown) is further included, and information selected and discriminated from among normal URLs, malicious URLs, and zero-day URLs through the URL inspection information analysis can be stored and managed as URL classification information.
[0136] A security URL connection stage (not shown) is further included. When the user terminal 200 that receives the email containing the security URL requests a connection to the security URL, it is first redirected to the security device designated as the security URL by the user terminal 200, and the connection to the zero-day URL and the [n]th derived URL determined not to be a malicious URL based on the diagnosis information can be processed.
[0137] FIG. 4 is an exemplary diagram for explaining a received email to which URL conversion is applied through a zero-day attack prevention service providing apparatus of a mail security infrastructure according to an embodiment of the present invention.
[0138] Referring to FIG. 4, emails sent from the outside can be collected through the mail server. At this time, the service providing device 100 can confirm that the URL detected by performing the mail security process is from http: / / www.**zeroday-url**.com. The service providing device 100 can determine whether it is a zero-day URL through an inspection of the URL. Thus, if it is determined to be a zero-day URL, the service providing device 100 can convert the http: / / www.**zeroday-url**.com into a security URL. The security URL is converted into a pre-set http: / / www.**security-platform**.com and applied to the mail content, and then the mail can be sent to the recipient.
[0139] Thus, the recipient can confirm the mail content sent by the phishing email and the URL information included in the mail content from the security URL http: / / www.**security-platform**.com. If the zero-day URL is clicked through the user terminal 200, it can be linked to a web page that cannot be guaranteed as a normal URL, etc., thereby generating a security risk.
[0140] On the contrary, when the converted security URL is clicked through the user terminal 200, it can be connected to a web page provided by a security device guaranteed as a safe URL, etc. Thereafter, when the security device performs a security inspection of the actual URL http: / / www.**zeroday-url**.com in real time and determines that it is safe, it can allow the connection to the actual URL and connect the user terminal 200.
[0141] FIG. 5 is an exemplary diagram for comparatively explaining a URL connection path through a zero-day attack defense service providing apparatus of a mail security infrastructure according to an embodiment of the present invention.
[0142] Referring to FIG. 5a, it is an exemplary diagram for explaining URL information provision and a URL connection path according to an embodiment of the present invention. An outsider can send a mail including a zero-day URL "www.*zerodayurl*.com". The user terminal 3 can view the mail received via the mail server and the zero-day attack defense system. At this time, the "www.*zerodayurl*.com" is converted to "www.*securityurl*.com" and provided to the user terminal 3. The user terminal 3 can click on the URL included for additional confirmation of the mail content to request a connection. At this time, the URL "www.*securityurl*.com" clicked by the user terminal 3 is called and connected to the zero-day attack defense system mapped with this and the IP address. The zero-day attack defense OS system can provide information such as connection status to the user terminal 3 on a web page or the like. The information such as the connection status can help understanding with a message stating that although the original URL included in the mail content transmitted to the user terminal 3 was "www.*zerodayurl*.com", it was determined as a zero-day URL and inspection was carried out to prevent security risks.
[0143] At the same time, the zero-day attack prevention system can check whether the "www.*zerodayurl*.com" is a malicious URL. When the zero-day attack prevention system determines that the "www.*zerodayurl*.com" is a malicious URL, it can block the link thereto and cut off the connection of the user terminal 3. Conversely, when the zero-day attack prevention system determines that the "www.*zerodayurl*.com" is a normal URL without security threats, it can allow the link thereto and connect the user terminal 3 to the "www.*zerodayurl*.com".
[0144] Referring to FIG. 5b, it is an exemplary diagram for explaining the URL information provision and the URL connection path according to the prior art. An outsider can send an email containing the zero-day URL "www.*zerodayurl*.com". The user terminal 7 will receive the zero-day URL "www.*zerodayurl*.com" sent by the outsider without any security inspection or URL modification measures. Since the user terminal 7 does not pass through the zero-day attack prevention system, it cannot go through the security inspection to determine whether the information of the www.*zerodayurl*.com is a malicious URL or a normal URL. Therefore, when the user terminal 7 requests a connection to the URL, in the case of a malicious URL, it can be exposed defenselessly to attacks such as personal information theft, malicious code download, and malicious script execution.
[0145] FIG. 6 is a flowchart for explaining the inspection stage of a zero-day URL and a URL derived therefrom through the zero-day attack prevention service providing apparatus of the mail security infrastructure according to an embodiment of the present invention.
[0146] Referring to FIG. 6, when the primary URL identified as the zero-day URL provides services as a web page, the zero-day URL can constitute a menu on the web page, thereby enabling further operations on the web page. As a result, the zero-day URL can provide an additional link to move to a secondary URL. Such a secondary URL can provide a tertiary URL through the additional link, and tertiary, quaternary, [n]th-level URLs derived therefrom can be sequentially identified. Security inspections can be performed on such hierarchical URLs to determine whether they are abnormal URLs, and tracked up to the end point to determine whether malicious code is discovered.
[0147] FIG. 7 is an exemplary diagram for explaining an inspection method according to a mail security architecture according to an embodiment of the present invention.
[0148] Referring to FIG. 7, an architecture for providing mail security, whereby the type and level of security threats, processes, priorities, processing procedures, etc. can be set. The architecture of the mail security service is classified into top-level categories such as received mail, sent mail, internal mail, user education, etc., and a hierarchical and step-by-step structure and processing method can be applied as a lower structure for each category. The top-level category can be classified according to the attribute value included in the mail information or the classification of the system connected according to the purpose of using the mail of the user terminal 200.
[0149] Within each security threat type, one or more specific email security processes can be assigned, which can be sorted by level and executed step by step and sequentially. Specifically, security threat types can be sorted into security threat types such as SPAM, Malicious code Attachment, Malicious code (URL), and Social Engineering Attack. As a result, the inspection process of security threat types can be sequentially fulfilled. Also, within each of the above security threat types, it can be sorted into levels 1, 2, 3, … [n] and sequentially fulfilled. At this time, each level is assigned specific items and indexes to be inspected, and inspection results can be obtained.
[0150] Also, according to the architecture settings, the email security processes within each security threat type may be performed in a way that parallelly inspects the assigned inspection areas.
[0151] The received email, which is one of the top categories, is at a lower level where security threat types can be sorted. Specifically, the security threat types can be sorted into SPAM processing, malicious code processing, social technology processing, etc.
[0152] For the security threat inspection of received emails, level 1 (Lv.1) within the SPAM processing department can inspect whether it is a spam email based on the reputation base. Then, if there are no problems found in the spam email inspection of the reputation base, level 2 (Lv.2) can inspect whether it is a spam email by filtering based on user-specified keywords.
[0153] After the completion of the execution of Level 2, the next stage, Level 3 (Lv.3), can inspect whether it is spam through the content analysis of the image base. In this way, the mail security service architecture enables verification by level through a specific spam filtering process in the SPAM processing type, and upon completion of the verification, it proceeds to the next level. And after the mail security service architecture completes the inspection of whether the mail is spam by SPAM processing, it can proceed to the malicious code processing stage to determine whether malicious code is included in the mail.
[0154] The malicious code processing can determine whether it includes the reputation-based malicious code of Level 1 and can proceed to the next stage during normal verification. When Level n (Lv.n) is determined as an attached file that may contain malicious code, the malicious code processing stage can be terminated through the harmless processing of transforming the executable code contained in the attached file. When the malicious code processing inspection is completed, the inspection stage can proceed to the social technology processing inspection stage. The social technology processing inspection stage can process or request corresponding actions based on the inspection result information after executing the social technology attack mail inspection process of the metadata base of Level 1 (Lv.1) and the relationship analysis base of Level n (Lv.n).
[0155] The outgoing mail, which is one of the top categories, has lower levels where security threat types can be sorted. The category of the outgoing mail can also be sorted into the SPAM processing, malicious code processing, and social technology processing stages for inspection, similar to the security threat types of incoming mail.
[0156] In particular, the security threat inspection of outgoing emails can include the outgoing environment inspection stage. When one or more user terminals 200 connect to the system for the purpose of sending emails, the outgoing environment inspection stage can perform a Level 1 (Lv.1) stage of verifying whether the user terminal is an IP address-allowed user terminal by a pre-registered whitelist. The user terminal 200 authenticated through the verification of the Level 1 stage can be determined as a normal email and proceed to the next stage when it is within a certain standard number of times with respect to the number of email transmissions. Thereafter, at the Level n (Lv.n) stage, a process of pre-inspecting the content of the outgoing email to determine whether it is abnormal can be executed to verify whether it is a normal email.
[0157] The internal email, which is one of the top categories, has a lower layer where an internal email management stage capable of preventing the leakage of internal information can be performed. The internal email management stage can inspect whether it is an abnormal email through an approval process at Level 1 (Lv.1). The approval process can determine the risk of information leakage for emails containing internal information.
[0158] The approval process can be carried out in such a way that it is pre-reviewed against the content of emails that are sequentially approved by the email management system and sent externally. Subsequently, at the level 2 (Lv.2) stage, DLP (Data Loss Prevention) and DRM (Digital Rights Management) control processes can be carried out to check whether internal information has leaked. The DLP control process can detect and control acts of attempting to transmit information by accessing a system that violates the policy without permission such as approval. The DRM control process can detect and control attempts to decrypt an encrypted internal document or attach a decrypted file to an email without permission such as approval. Subsequently, the level n (Lv.n) stage is an authentication process stage of the user terminal 200 when attempting to send an email, and can provide a multi-stage authentication process such as a first stage and a second stage. Thereby, normal email processing can be ensured by blocking users who attempt to seize or steal accounts.
[0159] The user education, which is one of the top categories, can include a lower layer, namely, a simulated phishing stage and a feedback system stage. In the simulated phishing stage, information such as the identification value and the number of times of the user terminal 200 with a history of using emails containing security threats can be saved and managed. The security threats can use emails configured in a harmless manner for actual systems and content. Thereby, the feedback system can provide result values obtained by analyzing statistical values and threat levels calculated through simulated phishing.
[0160] The security threat inspection configured by category can be determined by architecture and security level. Thereby, the inspection order and inspection level can be determined, and the presence or absence of abnormalities can be confirmed by sequential inspections. Also, the priority order of the inspection order and inspection level can be set by architecture and security level. When problems are discovered based on the inspection results of the process carried out according to the priority order, it is possible to determine whether the inspection has ended after performing the necessary processing at that stage. When the problem is determined to be spam or an email containing malicious code, the email can be discarded so that it cannot be confirmed on the user terminal 200, or it can be resolved by processing such as returning. When processing the problems of the email through the inspection process at a specific stage in this way, the subsequent inspection stage can be ended without being performed.
[0161] The method according to the present invention described above is made into a program for execution on a computer and can be stored in a computer-readable recording medium. Examples of computer-readable recording media include ROM, RAM, CD-ROM, magnetic tape, floppy disk, optical data storage device, etc., and also include those embodied in a carrier wave (for example, in the form of transmission via the Internet).
[0162] The computer-readable recording medium is distributed in a computer system connected by a network, and in a distributed manner, the computer-readable code can be stored and executed. And the functional program, code, and code segments for embodying the method can be easily inferred by a programmer in the technical field to which the present invention belongs.
[0163] In addition, although the preferred embodiments of the present invention have been illustrated and described above, the present invention is not limited to the specific embodiments described above. It goes without saying that various modifications can be made by those having ordinary knowledge in the technical field to which the present invention pertains without departing from the gist of the present invention claimed in the claims. These modified implementations should not be individually understood from the technical idea or perspective of the present invention.
Claims
1. A service providing apparatus, comprising: a collecting unit that collects mail information transmitted and received between one or more user terminals; a security threat inspection unit that inspects link information for a specific web page in the mail information by a mail security process and stores and manages inspection information based on the inspection result, when the link information for the specific web page is included in the mail information according to a preset security threat architecture; a zero-day diagnosis unit that performs an inspection for malicious code on a web page linked by the link information, when it is determined based on the inspection information that the link information potentially has a zero-day attack risk, wherein it is determined whether the link information potentially has a zero-day attack risk based on whether the link information is registered in a database; the zero-day diagnosis unit: after inspecting whether the link information exists in the database, performs a dynamic inspection of an action base by connecting or accessing the web page through the link information; the dynamic inspection of the action base includes a plurality of inspections on whether the web page is forged, whether there is access to the source code area, whether a file is downloaded, and whether a script is executed. The service providing apparatus
2. The service providing apparatus according to claim 1, further comprising a zero-day mail processing unit that replaces the link information with a security URL for a mail including the link information and processes it to a reception state accessible by the user terminal.
3. The service providing apparatus according to claim 2, further comprising a URL classification information management unit that stores and manages information selected and determined from a normal URL, a malicious URL, and a zero-day URL as URL classification information.
4. The zero-day diagnosis unit: The service providing apparatus according to claim 3, including a URL tracking module that tracks and manages one or more first derived URLs linked through the link information and an [n]th derived URL derived chainwise through the first derived URLs at regular intervals to obtain URL chain information.
5. The zero-day diagnosis unit: The service providing apparatus according to claim 4, further comprising a URL chain diagnosis module that diagnoses whether a [n] -th derived URL is a malicious URL at regular intervals based on the URL chain information, and stores and manages chain diagnosis information.
6. When the user terminal that receives the mail including the security URL requests a connection to the security URL, it is primarily redirected by the user terminal, and the link information determined not to be a malicious URL based on the diagnosis information, and a security URL connection unit that processes the connection to the [n] -th derived URL. The service providing apparatus according to claim 5, further comprising:
7. A method of operating a service providing apparatus, comprising: A collection stage of collecting mail information transmitted and received between one or more user terminals; According to a preset security threat architecture, when the mail information includes link information for a link to a specific web page, the link information is inspected by a mail security process, and a security threat inspection stage of storing and managing inspection information based on the inspection result; A zero - day diagnosis stage of performing an inspection for malicious code on the web page linked by the link information when the link information is determined to potentially have a zero - day attack risk based on the inspection information. Whether the link information potentially has a zero - day attack risk is determined based on whether the link information is registered in a database. The zero - day diagnosis stage is as follows: After inspecting whether the link information exists in the database, a dynamic inspection of the behavior base is performed by connecting or accessing the web page through the link information. The dynamic inspection of the behavior base includes a plurality of inspections for the presence or absence of forgery of the web page, access to the source code area, download of files, and whether a script is being executed. A method of operating a service providing apparatus.
8. The method of operating a service providing apparatus according to claim 7, further comprising a zero - day mail processing stage of replacing the link information in the mail including the link information with a security URL and processing it to a reception state accessible by the user terminal.
9. The method for operating a service providing apparatus according to claim 8, further comprising a URL classification information management step of storing and managing, as URL classification information, information selected and determined from among normal URLs, malicious URLs, and zero-day URLs.
10. The zero-day diagnosis step further includes a URL tracking step of tracking and managing, at regular intervals, one or more first derived URLs linked from the link information and the [n]th derived URLs derived chainwise through these to obtain URL chain information, for the method for operating a service providing apparatus according to claim 9.
11. The zero-day diagnosis step further includes a URL chain diagnosis step of diagnosing, at regular intervals, whether the [n]th derived URL is a malicious URL based on the URL chain information, and storing and managing chain diagnosis information, for the method for operating a service providing apparatus according to claim 10.
12. When the user terminal that receives the email including the security URL requests a connection to the security URL, it is first redirected at the user terminal, and further includes a security URL connection step of processing the connection to the link information and the [n]th derived URL that are determined not to be malicious URLs based on the diagnosis information, for the method for operating a service providing apparatus according to claim 11.
Citation Information
Patent Citations
Electronic mail monitoring system, electronic mail monitoring program and electronic mail monitoring method
JP2005056048A
External link processing
JP2014516183A
Radar device and target detection method
JP2018185249A
Malicious message detection and processing
US9241009B1