Information Processing Apparatus, Information Processing Method, and Program

The information processing apparatus addresses the challenge of uniform responses to unauthorized access by analyzing statistical biases in member information and selecting tailored countermeasures for each account, thereby enhancing security and user satisfaction.

JP7695322B2Active Publication Date: 2025-06-18LOYALTY MARKETING
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
JP2023187999
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2023-11-01
Publication Date
2025-06-18
Estimated Expiration
2040-07-09

AI Technical Summary

Technical Problem

Existing systems uniformly respond to unauthorized access by stopping services and requesting password changes, which can lead to user dissatisfaction, cumbersome password management, and potential security decreases.

Method used

An information processing apparatus that acquires member information from victim accounts, analyzes the statistical bias of this information, and selects tailored countermeasures for each account based on the analysis results.

Benefits of technology

This approach allows for more appropriate and effective countermeasures against unauthorized access, reducing the need for uniform responses and enhancing overall security and user satisfaction.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007695322000004
    Figure 0007695322000004
  • Figure 0007695322000005
    Figure 0007695322000005
  • Figure 0007695322000006
    Figure 0007695322000006
Patent Text Reader

Abstract

To provide a technology for appropriately allowing selection of a counter measure against illegal access.SOLUTION: There is provided an information processing device including an information acquisition unit which acquires membership information of a victim member suffering from illegal access to the account among members of service managing accounts by password authentication, an analysis unit which analyzes a statistical bias in the membership information, and a counter measure selection unit which selects a counter measure against the illegal access for each of the accounts managed by the service on the basis of the result of the analysis.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of the present invention relate to an information processing apparatus, an information processing method, and a program.

Background Art

[0002] With the development of communication technology, online services such as Internet banking and online shopping have become widespread. Generally, each user can log in to a system and receive service provision by inputting account identification information, also called a user ID or the like, and an authentication password.

[0003] With the spread of such online services, there has been a problem of unauthorized use by a third party without the right to use services with an access control function based on a combination of a user ID and a password. Here, such acts in general are called "illegal access" or "illegal login". When illegal access occurs, there is a risk that personal information may be stolen or cash and points may be illegally used.

[0004] In order to detect such illegal access, so-called risk-based authentication is known (see, for example, Patent Document 1).

Prior Art Documents

Patent Documents

[0005]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0006] Generally, when unauthorized access is detected, measures such as stopping the service of the account targeted by the unauthorized access are taken. However, for other accounts under management, only uniform measures have been taken, such as stopping all services and sending a notice requesting a password change. Frequent service outages may cause dissatisfaction among users (hereinafter also referred to as "members"). In addition, frequent password changes are not only cumbersome for users, but also make password management difficult, encourage the reuse of passwords across multiple services, and may even lead to a decrease in security.

[0007] This invention was made in view of the above circumstances, and its object is to provide a technology that enables more appropriate selection of countermeasures against unauthorized access.

Means for Solving the Problem

[0008] In order to solve the above problems, in one aspect of this invention, an information processing apparatus is provided, which includes an information acquisition unit that acquires member information regarding victim members whose accounts have been illegally accessed among the members of a service that manages accounts by password authentication, an analysis unit that analyzes the statistical bias of the member information, and a countermeasure selection unit that selects countermeasures against the illegal access for each account managed by the service based on the result of the analysis.

Effect of the Invention

[0009] According to one aspect of this invention, countermeasures are selected for each account under management based on the statistical bias of the member information of victim members who have actually been illegally accessed among the service members. As a result, when unauthorized access occurs, instead of taking uniform measures for all accounts, more appropriate measures can be taken for each account based on the trend of unauthorized access.

[0010] That is, according to this invention, a technology that enables more appropriate selection of countermeasures against unauthorized access can be provided.

Brief Description of Drawings

[0011]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Figure 12

Figure 13

Figure 14

Figure 15

Figure 16

Figure 17

Figure 18

[0012] Hereinafter, embodiments of the present invention will be described with reference to the drawings. In the following, the same or similar elements as those already described are denoted by the same or similar reference numerals, and redundant descriptions are basically omitted. For example, when there are a plurality of identical or similar elements, a common reference numeral may be used to describe each element without distinction, or a branch number may be used in addition to the common reference numeral to describe each element separately.

[0013] [Outline of Embodiment] The information processing apparatus according to the embodiment of the present invention can exchange information with a service that manages a member's account by password authentication. When there is a member who has received an unauthorized access, the information processing apparatus collects member information regarding the member, analyzes the statistical bias based on the member information, and selects a countermeasure against the unauthorized access based on the analysis result.

[0014] Here, the member information collected by the information processing apparatus may include all information related to members who have been subject to unauthorized access. For example, the member information includes personal information of the member, information associated with the account, activity history related to services on the network, and the like. Personal information includes, for example, name, address, gender, age, phone number, email address, occupation, annual income, family composition, hobbies, and the like. Information associated with the account includes, for example, the creation date and time of the account, the elapsed time since the account creation date and time, information on the website through which the account was created, login history, password change history, and the like. The activity history related to services on the network includes, for example, the usage history of social networking services (SNS), the posting history on SNS, the browsing history of a specific website, the usage history of credit cards, the purchase history and payment information related to online shopping, the balance and transaction history of bank accounts and electronic money accounts, the balance and exchange history of point accounts, the performance of insurance subscriptions and securities transactions, and the activity history of any service.

[0015] Hereinafter, as an example, a point service is assumed as a service for managing a member's account by password authentication, and the information processing apparatus according to the embodiment will be described as collecting the above member information from a server that provides the point service. However, this is only an example, and it should be noted that the information processing apparatus according to the embodiment can perform similar processing based on member information collected from other various information collection sources. For example, the information processing apparatus can collect member information by requesting the input of member information from the member who has been subject to unauthorized access. The information processing apparatus can also collect information publicly disclosed by the member on SNS. Alternatively, the information processing apparatus can collect information related to deposits and purchase history from the servers of financial institutions and credit card companies with the permission of the member. The information processing apparatus may collect member information from a plurality of information collection sources, such as information A from server X and information B from server Y, integrate it, and use it for subsequent processing.

[0016] [One Embodiment] (1) Configuration (1-1) System FIG. 1 is a diagram showing an example of the overall configuration of a system 1 including an information processing apparatus 10 according to an embodiment of the present invention. The information processing apparatus 10 can communicate with a point management server 20, service A servers 50A, service B servers 50B,... (hereinafter also collectively referred to as "service providing servers 50"), and user terminals UT1,..., UTi (hereinafter also collectively referred to as "user terminals UT") used by users via a network NW such as the Internet.

[0017] The point management server 20 is an example of a source for collecting member information of the information processing apparatus 10 and is a server computer managed by an operator providing a point service. The point service is, for example, a service in which a user who has registered as a member (hereinafter also simply referred to as a "member") is given points according to the purchase amount when purchasing a product or service (hereinafter also referred to as "products, etc.") or according to the number of visits to a store, etc., under conditions determined by the company side, and the accumulated points can be exchanged for products, etc. or used as payment when purchasing products, etc. at the next or subsequent store visits. The point management server 20 manages point data such as the points granted, the points used, and the remaining points for each member. Further, here, the point management server 20 will be described as providing a common point service that is commonly used among a plurality of services, but the present invention is not limited thereto, and it may manage individual or unique points used at the store or company level.

[0018] The service-providing server 50 is a server of a business operator that provides a partnering service and subscribes to the point service provided by the point management server 20. The service-providing server 50 may be a server that provides Web services such as online shopping or Internet banking, or may be a server that manages sales at physical stores such as convenience stores or gas stations. For example, in the case of a server that provides an online shopping site, when a user purchases goods or the like through the site, the service-providing server 50 calculates the number of points to be granted according to the purchase amount, and notifies the point management server 20 of the calculated number of points to be granted together with the identification information of the user or their point account. Alternatively, when a user purchases goods or the like at a store under the management of the service-providing server 50, for example, a POS terminal installed at the store calculates points according to the purchase amount, and performs a point granting process on the point card presented by the user or a mobile terminal having its function. Then, the service-providing server 50 receives the point processing information together with the settlement information from the POS terminal, and also notifies the point management server 20.

[0019] The user terminal UT is any information processing terminal connectable to the network NW, such as a smartphone, tablet terminal, notebook or desktop personal computer used by the user. A member of the point service can use the user terminal UT to access their point account, check the balance, or perform point use / exchange processing, etc., directly from, for example, a website or a dedicated application program (hereinafter also referred to as an "application") provided by the point management server 20, or via a website or a dedicated application provided by the service-providing server 50.

[0020] Here, when each member accesses the point account, password authentication using a combination of ID and password is used. For example, each member accesses the website provided by the point management server 20 via the user terminal UT, and as a result of sending an authentication request including the ID and password related to the point account to an authentication server (not shown), the member can access the point account by successfully authenticating. Alternatively, each member first successfully authenticates using a combination of a first ID and a first password to access the website (e.g., an account for online shopping) provided by the service providing server 50, and then further successfully authenticates using a combination of a second ID and a second password for accessing the point account via the website, so that points can be used on the website provided by the service providing server 50. Alternatively, it is also possible for the point management server 20 and the service providing server 50 to utilize authentication cooperation for the convenience of the members. Here, authentication cooperation refers to a mechanism that enables a user to access multiple services through a single authentication process. When authentication cooperation is utilized, for example, a member can seamlessly access the point account managed by the point management server 20 by logging in to their account on the website provided by the service providing server 50. However, when authentication cooperation is used, there is a risk of multiple damages occurring between the linked services in the event of unauthorized access.

[0021] When an unauthorized access occurs to an account under its management, the information processing apparatus 10 performs a process of selecting an appropriate countermeasure for each account, and is configured by a server computer or a personal computer. The information processing apparatus 10 can operate in cooperation with the point management server 20. Hereinafter, although the information processing apparatus 10 is configured to operate in cooperation with the point management server 20 and manages the accounts of the point service provided by the point management server 20, the present invention is not limited thereto. Note that the above-described password authentication process may be executed by an authentication server (not shown), may be executed by the information processing apparatus 10, or may be executed by the point management server 20.

[0022] (1-2) Information Processing Apparatus (1-2-1) Functional Configuration FIG. 2 is a block diagram showing an example of the functional configuration of the information processing apparatus 10 according to an embodiment. The information processing apparatus 10 includes a victim data acquisition unit 11, an analysis unit 12, a countermeasure selection unit 13, a victim data storage unit 14, a grade information storage unit 15, and a countermeasure policy storage unit 16.

[0023] The victim data acquisition unit 11, as an information acquisition unit, acquires member information (hereinafter also referred to as "victim data") regarding a member who has received unauthorized access to an account among the members under the management of the point management server 20 from the point management server 20 or its database (not shown), and stores it in the victim data storage unit 14. Here, the terms "victim" or "victim member" are used simply to refer to the member of the account that has received unauthorized access, regardless of whether actual financial damage has occurred.

[0024] The analysis unit 12 reads out the victim data stored in the victim data storage unit 14 in a certain amount and analyzes the statistical bias of the victim data. In one embodiment, the analysis unit 12 tabulates the number of victim members for each type of item included in the victim data, and analyzes the above statistical bias by calculating a statistic based on the tabulation result. Here, the "statistic" refers to all values obtained by summarizing the target data (for example, victim data) using a statistical algorithm. Below, as an example of a statistic, the deviation value for each type of item calculated using the number of victim members of unauthorized access occurring during a certain period as the population will be used for explanation. A specific example of the calculation method will be described later. Note that the present invention is not limited to this, and for example, other statistics such as the average value, median value, maximum value, and minimum value may be used to calculate the bias of the victim data.

[0025] Based on the result of the analysis by the analysis unit 12, the countermeasure selection unit 13 selects a countermeasure against unauthorized access for each account of the members under the management of the point management server 20. The countermeasure selection unit 13 can output the selection result to an arbitrary output destination (for example, the point management server 20, the service providing server 50, the user terminal UT, etc.). The countermeasure selection unit 13 can also evaluate the effectiveness of the selected countermeasure (such as whether the unauthorized access has decreased as a result of the execution of the countermeasure) by analyzing the victim data in chronological order, and use it for subsequent countermeasure selection.

[0026] The victim data storage unit 14 stores the victim data acquired by the victim data acquisition unit 11.

[0027] The grade information storage unit 15 stores a correspondence table specifying the relationship between a statistic (a deviation value by type as an example) representing the statistical bias of the above victim data and the risk level of password authentication.

[0028] The countermeasure policy storage unit 16 stores a correspondence table specifying countermeasures according to the risk level of password authentication.

[0029] (1-2-2) Hardware Configuration FIG. 3 is a block diagram showing an example of the hardware configuration of the information processing apparatus 10. The information processing apparatus 10 includes a CPU (Central Processing Unit) 101, a RAM (Random Access Memory) 102, a ROM (Read Only Memory) 103, an auxiliary storage device 104, an input device 105, an output device 106, and a communication interface (I / F) 107.

[0030] The processing functions of the victim data acquisition unit 11, the analysis unit 12, and the countermeasure selection unit 13 of the information processing apparatus 10 described above are realized by the CPU 101 expanding a program stored in the ROM 103 or the auxiliary storage device 104 into the RAM 102 and executing this program. The CPU 101 is an example of a hardware processor that controls the overall operation of the information processing apparatus 10. The hardware processor is not limited to a general-purpose processor such as the CPU 101, and may be a dedicated processor such as an ASIC (Application Specific Integrated Circuit) or an FPGA (Field-Programmable Gate Array). Also, the CPU 101 may be a single CPU or the like, or may be a plurality of CPUs or the like.

[0031] The auxiliary storage device 104 includes a computer-readable storage medium that stores data non-volatilely, and can be, for example, an HDD (Hard Disk Drive) or an SDD (Solid State Drive). The auxiliary storage device 104 can function as a storage unit including the victim data storage unit 14, the grade information storage unit 15, and the countermeasure policy storage unit 16 described above.

[0032] The input device 105 includes, for example, a keyboard and a mouse. The output device 106 includes a display device. The input device 105 and the output device 106 may be an integrated touch panel type device that combines a display device such as a liquid crystal panel and an input device such as a touch pad.

[0033] The communication interface 107 is an interface for communicating with an external device. The communication interface 107 includes, for example, a LAN (Local Area Network) port, is connected to the network NW using, for example, a LAN cable, and transmits and receives data to and from an external device via the network NW. The communication interface 107 may include a wireless module such as a wireless LAN module or a Bluetooth (registered trademark) module.

[0034] Regarding the specific hardware configuration of the information processing apparatus 10, depending on the embodiment, components can be appropriately omitted, replaced, or added.

[0035] In a conventional system, when a malicious third-party attack (act) such as unauthorized access (unauthorized login) to an online service is detected, and when an ID and password are adopted as a primary protection method for protecting the user and their information, 1) There is no method for logically and objectively inferring and determining the attacker's intention and target from probability theory. 2) Therefore, there was a problem in that it was necessary to uniformly require self-defense by changing the password from the perspective of user protection.

[0036] Therefore, password changes are required even for users who were not originally the target of the attack from the attacker's perspective, (a) The passwords that the user has to remember increase (unnecessarily), or (b) The structure of the newly set password becomes complex and diverse, and it becomes impossible to understand which ID's password for which service was created with what structure, and it is easily assumed that the user himself / herself will not be able to use the service, or (c) In order to avoid the above two problems, by reusing the password, the possibility (separate or future risk) that the attacker can successfully impersonate and intrude into another service on another occasion is increased.

[0037] Therefore, a method that focuses on points such as the following is necessary. (1) Instead of widely requesting unnecessary password changes such as for all users uniformly, request changes only for the minimum necessary users, (2) By not arbitrarily changing the passwords of low-risk IDs, maintain security instead, (3) When changing passwords, provide advice (support) on a highly secure (strong) structure to reduce the creative burden and the risk of forgetting and confusion for each user, (4) Take multi-level countermeasures according to the intentions and targets of attackers and the risk (degree of danger) characteristics of the targeted persons (for example, at the highest level, stop the service for all users, and at the lowest level, issue a warning on the service site's top page (login screen), etc.), (5) Even if the attack methods and targets of the attackers change in response to our defense measures, grasp and follow this, (6) Aim to establish the most effective (high attack resistance strength) security for the "service and its users" as a whole.

[0038] When unauthorized access is detected, the information processing apparatus 10 according to the above embodiment analyzes the statistical bias of the member information of the victim members related to the account that received the unauthorized access, and based on the result of the analysis, selects an appropriate countermeasure for each account under management. As a result, instead of taking the same countermeasure for all accounts, an appropriate countermeasure based on the actual tendency of unauthorized access can be selected for each account, and more effective security can be established for the service and all its users.

[0039] (2) Operations Next, the operations of the information processing apparatus 10 configured as described above will be described. Hereinafter, the operations of the information processing apparatus 10 will be described by dividing them into a first stage, a second stage, and a third stage. However, as will be described later, these do not necessarily need to be executed in order on the same time axis, and may be executed simultaneously, in a different order, or in combination according to the situation of the damage, etc.

[0040] Further, in the following, it is described on the premise that unauthorized access to the account of a point service member is detected by some method in the point management server 20 and that fact is notified from the point management server 20 to the information processing apparatus 10. The detection of unauthorized access may be based on, for example, an alert being issued from a risk-based authentication system as described above, or a report of a login history or point consumption that the member himself / herself has no recollection of, or a notice of a cyber attack received from the service providing server 50, etc.

[0041] (2-1) First stage The first stage is an operation mainly assumed as "initial response" and takes countermeasures at the "point". FIG. 4 is a flowchart showing an example of the operation of such a first stage.

[0042] First, in step S101, the information processing apparatus 10 acquires, by the victim data acquisition unit 11, the member information (victim data) of the member related to the account that has received unauthorized access and stores it in the victim data storage unit 14. The victim data acquisition unit 11 may receive the victim data transmitted from the point management server 20 every time unauthorized access occurs, or may receive the victim data from the point management server 20 regularly (for example, every hour, every day). Alternatively, similarly, the victim data acquisition unit 11 may read the victim data from the database of the point management server 20 at an arbitrary timing.

[0043] FIG. 5 shows an example of the victim data stored in the victim data storage unit 14. As described above, here, as a mere embodiment, it is described on the assumption that the point management server 20 provides a common point service and the point management server 20 and the service providing server 50 use authentication cooperation. The victim data in FIG. 5 may include the occurrence time, member ID, registration route, registration email domain, number of points held, number of updates of the structured password (structure PASS), ID registration date, etc. related to the damage of unauthorized access.

[0044] The occurrence time includes information such as year, month, day (YYYY / MM / DD), hour, minute, and second (hh:mm:ss), and may be, for example, the time when an unauthorized login occurred or the time when a damage report was received from a member.

[0045] The member ID is identification information assigned to each member (account). Here, it is temporarily assigned a three-digit symbol, but it may be managed with any number of digits and any character string. Note that the member ID and the ID used for password authentication may be the same or different.

[0046] The registration route indicates which service the user passed through when registering as a member to use the common point service. For example, the user can register as a member via the website provided by the point management server 20, or can also register via the website provided by the service providing server 50. Alternatively, the user can request member registration from any server by asking a proxy such as a store clerk to input via an application form installed in a physical store or the like, or by inputting information by himself / herself via a terminal installed in the physical store. Knowledge of the registration route can help, for example, to infer from which route the registered information was leaked or at which level an attack occurred (for example, whether the lower-level store server was the target of the attack or the higher-level management server was the target of the attack, etc.).

[0047] The registered email domain is the domain information of the email address specified by the member as the contact information related to the common point service. Knowledge of the registered email domain can help to determine whether countermeasures are necessary at the server level that manages the domain.

[0048] The number of points held is the balance of points held by each member. Since points have economic value, if the account of a member with a high number of points held is subject to unauthorized access, it can cause significant damage not only to the individual member but also to the provider of the point service and its partner companies. Also, it is conceivable that members with a high number of points held are more likely to be targeted for unauthorized access. Therefore, the number of points held can be an indicator of potential economic damage.

[0049] The number of times of structured password (structured PASS) updates is a parameter related to a system (not shown) that manages passwords in a structured manner for the purpose of improving security (hereinafter also referred to as the "structured password management system"). The number of times of structured PASS updates refers to the number of times the password has been updated as a collaborative password between the member himself / herself and the system side by the system side specifying the addition or deletion of some character string to the password set by the member himself / herself. That is, when requesting a password change for a member for some reason, instead of leaving it to the member, the system side provides advice on a structure with high security (password strength). This reduces the burden on each member in devising a new password and improves the overall security level of the members.

[0050] Here, the fact that the number of times the structure PASS is updated is "0 times" means that the password of the member remains the password set by the member himself / herself. Even if the password is changed regularly, if it is not in cooperation with the above system, the update count will be recorded as "0 times". For example, if the password initially set by the member is "PASSWORD", and the system side specifies "add the 3-digit string '123' to the 'end'", and the member registers a new password "PASSWORD123" accordingly, the update count will be "1 time". Further, if the system side specifies (for example, after a certain period) "delete the 2-digit string from the 'beginning'", and the member registers a new password "SSWORD123" accordingly, the update count will be "2 times". On the other hand, if the member does not respond to the system's instructions and registers a password selected by himself / herself, the update count remains 0 or is reset to 0. Depending on whether the number of times the structure PASS is updated is "0 times" or "1 time or more", it is possible to determine whether the member has used the above system or not, and it can be useful for inferring, for example, the path of information leakage or the attack method (for example, whether it is a list attack or a brute-force attack). Alternatively, it is also conceivable to collect not only the latest number of times the structure PASS is updated but also its update history as time-series data. For example, if the number of updates remains "1 time" over a certain period, it is inferred that the effect of using the above system appears. On the other hand, in the case of "2 times or more", since it has been attacked many times, it is inferred that the member or its registration route has become an attack target. When "0 times" and "1 time" are repeated, the password is determined by oneself without following the system's instructions (resulting in "0 times"), and because of an attack, it is changed according to the system's instructions (resulting in "1 time"), and then what happened afterwards (for example, whether it became "2 times" or otherwise), by aggregating time-series data for each pattern, it is possible to select a countermeasure considering the effect of the above structured password management system.

[0051] When the structured password management system as described above is used, it is possible to simultaneously improve diversity and security by taking actions jointly performed by the system and the members while reducing the risk of entrusting password updates only to the members. Also, by considering the number of structured PASSes in the analysis of statistical bias, it is possible to select countermeasures that take into account the personality and behavior patterns of the members. However, the use of the structured password management system as described above is optional, and when the structured password management system is not used, the number of structured PASS updates may not be included in the victim data.

[0052] The ID registration date represents the date when the membership registration was done. It may include not only the year, month, and day but also information on hours, minutes, and seconds. Knowledge of the ID registration date can be useful for inferring the route of information leakage and the target of attacks.

[0053] As described above, the victim data shown in FIG. 5 is merely an example. The victim data may contain more information or less information. The victim data can include personal information and activity history information on the network other than those described above. Also, as described above, the information processing apparatus 10 can collect information about the victim from any information collection source.

[0054] Subsequently, in step S102, the analysis unit 12 reads the victim data from the victim data storage unit 14 and analyzes the statistical bias of the victim data. More specifically, the analysis unit 12 reads the victim data for a previously specified period or amount, aggregates the number of victim members for each type of item (for example, occurrence time, member ID, registration route, registration email domain, number of points held, number of structured PASS updates, ID registration date, etc.) included in the read victim data, and performs a process of calculating the statistical quantity.

[0055] FIGS. 6 to 10 show examples of the results of the analysis process by the analysis unit 21 focusing on different items of the victim data.

[0056] FIG. 6 shows, as a first example, an example of the result of an analysis process of statistical bias of victim data according to the type regarding the registration path. Here, as a statistic representing the statistical bias, a deviation value is calculated based on the number of victim members of each type. Here, six types of registration paths, services A to F, are specified in advance. The number of types is not limited to six types. Services A to F may include the common point service itself (for example, the service provided by the point management server 20) and its partner service (for example, the service provided by the service providing server 50).

[0057] First, the analysis unit 21 extracts, from the set of the read victim data, the victim data ( "total") related to the most recent four days (here, from October 28th to October 31st) as the first evaluation target group, and tabulates the number of victim members ( "number of cases") for each type. In FIG. 6, it is tabulated that service A has 186 cases, service B has 126 cases, service C has 51 cases, service D has 30 cases, service E has 10 cases, service F has 0 cases, and the total is 403 cases.

[0058] Next, the analysis unit 21 calculates the deviation value for each type by the following formula using the total 403 cases as the population.

Equation

Equation

Equation

[0059] In the example of FIG. 6, the analysis unit 21 calculated the average value μ1 and the standard deviation σ1 for the first group of evaluation targets ( "Total") as follows. μ1 = (186 + 126 + 51 + 30 + 10 + 0) / 6 ≒ 67.17 σ1 = [ { (186 - 67.17) 2 + (126 - 67.17) 2 + (51 - 67.17) 2 + (30 - 67.17) 2 + (10 - 67.17) 2 + (0 - 67.17) 2} / 6 ] ^ (1 / 2) ≒ 67.09

[0060] Subsequently, the analysis unit 21 calculates the deviation values of services A to F using the average value μ1 and the standard deviation σ1 calculated as described above. For example, in the first group of evaluation targets, the deviation value T 1A for service A, the deviation value T 1B for service B, the deviation value T 1C for service C, the deviation value T 1D for service D, the deviation value T 1E for service E, and the deviation value T 1F for service F are calculated as follows. In FIG. 6, the highest deviation value is highlighted for each group of evaluation targets. T 1A = { (186 - 67.17) / 67.09} × 10 + 50 ≒ 67.71 T 1B = { (126 - 67.17) / 67.09} × 10 + 50 ≒ 58.77 T 1C = { (51 - 67.17) / 67.09} × 10 + 50 ≒ 47.59 T 1D = { (30 - 67.17) / 67.09} × 10 + 50 ≒ 44.46 T 1E = { (10 - 67.17) / 67.09} × 10 + 50 ≒ 41.48 T 1F = { (0 - 67.17) / 67.09} × 10 + 50 ≒ 39.99

[0061] The analysis unit 21 also calculates the average value, standard deviation, and deviation value for each of the victim data for each day among the data for the most recent four days, using the total value of the number of victim members (number of cases) for each day as the population, in the same manner as above, for the second to fifth evaluation target groups respectively. For example, on October 28th, there were a total of 3 victim reports, the average value was "0.50", the standard deviation was "0.50", and the deviation values for services A to F were calculated as "60.00", "60.00", "60.00", "40.00", "40.00", "40.00" respectively. Similarly, on October 29th, there were a total of 100 victim reports, and the highest deviation value of "71.08" was obtained for service B. On October 30th and October 31st, service A had the highest deviation value.

[0062] Which aspect of the results obtained as above should be focused on can be specified in advance by the administrator of the information processing device 10 or the like. For example, one may focus on the registration path with the maximum deviation value for each day and take measures for the accounts related to that registration path every day. In this case, in FIG. 6, on October 28th, services A to C are focused on, on October 29th, service B is focused on, on October 30th, service A is focused on, and on October 31st, service A is focused on. Similarly, one may focus on the registration path with the maximum deviation value in the total for the four days and take measures. In the example of FIG. 6, service A is focused on and measures are taken. Also, one may make a judgment by combining the daily aggregation results and the total aggregation results. Such a judgment can be realized by setting in advance the aggregation period and the deviation value range (for example, whether there is a type that exceeds a deviation value of 60 in the aggregation for four days, whether there is a type that exceeds a deviation value of 70 in the daily aggregation, etc.).

[0063] FIG. 7 shows, as a second example, an example of the result of the analysis process of the statistical bias of the victim data according to the type regarding the registered email domain. In this example, for instance, when focusing on the total for four days, since the second row "bbb.ne.jp" shows the highest deviation value of "70.95", it can be set to determine that the risk of the accounts registering the "bbb.ne.jp" domain is high.

[0064] FIG. 8 is an example of the result of an analysis process of statistical bias of victim data according to type with respect to the number of points held, as a third example. For example, when focusing on the total for four days, the second row "10,001 to 30,000" shows the highest deviation value of "68.59". In this case, it may be set to determine that the risk of the account corresponding to the point balance of "10,001 to 30,000" is high, or it may also be considered to set it to determine that the economic damage is low because the deviation value of the type of "150,001 or more" of the point balance is low over four days.

[0065] FIG. 9 is an example of the result of an analysis process of statistical bias of victim data according to type with respect to the number of times of structure PASS update, as a fourth example. As described above, this item is an indicator of whether the cooperative password between the user and the system is being used. In this example, since the deviation value of "0 times" is significantly high, it can be determined that the security of the cooperative password is high (the security of passwords other than the cooperative password is low). If the deviation value of the column where the number of times of structure PASS update is "1 time" or more is high, leakage from the structured password management system itself is suspected.

[0066] FIG. 10 is an example of the result of an analysis process of statistical bias of victim data according to type with respect to the ID registration time, as a fifth example. When focusing on the total for four days, since the deviation value of "within 361 days to 720 days" is slightly higher than others, it may be considered to set it to determine that the risk of the accounts corresponding to the same registration time is high, or it may also be considered to set it to determine that the leakage risk is higher as the service usage period is longer.

[0067] Regarding FIGS. 6 to 10, examples of aggregating the total or daily for the most recent four days were given for explanation, but these are merely examples. For example, any other arbitrary period such as one week or one month may be set as the evaluation target period. As the evaluation target, victim data (data for the entire past period) related to all unauthorized accesses occurring under the management of the point management server 20 may be used. Alternatively, a statistic obtained from an arbitrary recent period and a statistic obtained from victim data for the entire past period may be used in combination.

[0068] In step S103, the countermeasure selection unit 13 focuses on any one of the items and selects a countermeasure. For example, when focusing on the result of FIG. 7, the countermeasure selection unit 13 selects a pre-specified countermeasure, such as "display a warning message at login", for all accounts registered with email addresses having the same domain as "bbb.ne.jp" with the highest deviation value. Which item to focus on may be determined by calculating and comparing the deviation values for a plurality of items (for example, the item including the type with the largest deviation value), or a pre-set priority (for example, in the order of registration path, registration domain, number of points held, number of structure PASS updates, ID registration time) may be used.

[0069] As described above, the countermeasure selection unit 13 can focus on any one of the items and select a countermeasure for the type with the highest deviation value among them. Alternatively, the countermeasure selection unit 13 can also determine the risk level of the type according to the deviation value and select a countermeasure according to the risk level. Hereinafter, as an example of such a method, a method in which the countermeasure selection unit 13 selects a countermeasure using a correspondence table will be described.

[0070] FIG. 11 shows an example of a correspondence table specifying the correspondence between the deviation value and the risk level that can be used by the countermeasure selection unit 13. According to FIG. 11, when the deviation value exceeds 70, it is defined as "grade 1" with the highest risk level, and when the deviation value is less than 45, it is defined as "grade 6" with the lowest risk level. Such a correspondence table can be arbitrarily set by the administrator of the information processing apparatus 10 or the like and can be stored in the grade information storage unit 15.

[0071] FIG. 12 shows an example of the risk level (grade) determined by the countermeasure selection unit 13 based on the correspondence table shown in FIG. 11. FIG. 12 focuses on the registered email domain as an item and shows an example different from FIG. 7. The analysis unit 12 calculated deviation values for six types of registered email domain types, respectively. Then, the countermeasure selection unit 13 determined the respective risk levels based on the above correspondence table. For example, for the registered email domain "abc.co.jp", since the deviation value is "64.00", it corresponds to "Grade 2" according to the correspondence table in FIG. 11. Thereafter, the countermeasure selection unit 13 also selects countermeasures according to the respective risk levels using the correspondence table.

[0072] FIG. 13 shows an example of a correspondence table that specifies the correspondence relationship between the risk level and the countermeasures to be taken, which can be used by the countermeasure selection unit 13. According to FIG. 13, for the highest risk level "Grade 1", "Account suspension" is selected for the target account. On the other hand, for the lowest risk level "Grade 6", a countermeasure of taking no particular action is selected. Such a correspondence table can be arbitrarily set by the administrator of the information processing apparatus 10 or the like and stored in the countermeasure policy storage unit 16.

[0073] Based on the correspondence table in FIG. 13, the countermeasure selection unit 13 selects "Grade 2 = Login suspension" for the account having the registered email domain "abc.co.jp" in the example of FIG. 12. Similarly, the countermeasure selection unit 13 selects "Grade 1 = Account suspension" for the account having "def.com", "Grade 3 = Point usage suspension" for the account having "ghi.ne.jp", "Grade 6 = No action" for the account having "jkl.co.jp", "Grade 5 = Site warning" for the account having "mno.ne.jp", and "Grade 4 = Email warning" for other accounts. Note that the correspondence tables in FIGS. 11 and 13 may be set and stored integrally.

[0074] The countermeasure selection unit 13 can output the results of the above selection to an arbitrary output destination. For example, the countermeasure selection unit 13 may send all the results of the above selection to the point management server 20, and the point management server 20 may be configured to actually execute the selected countermeasure. For example, in the example of FIG. 12, the point management server 20 that has received the selection result extracts an account having the registered mail domain "abc.co.jp" and executes the countermeasure of "login stop" for the account. The point management server 20 can also appropriately notify the service providing server 50 as necessary for executing the countermeasure. Alternatively, the countermeasure selection unit 13 may change the output destination of the selection result according to the selected countermeasure. For example, the countermeasure selection unit 13 may send the account information for which "login stop" is selected to the point management server 20, and send the account information for which "site warning" is selected to both the point management server 20 and the service providing server 50. When "mail warning" is selected, the countermeasure selection unit 13 may be configured to directly send a message to the user terminal UT. Alternatively, the information processing apparatus 10 may be configured to execute the countermeasure selected by the countermeasure selection unit 13.

[0075] In Fig. 12, the registered email domain was described. However, the countermeasure selection unit 13 can perform the same risk level determination and countermeasure selection as described above for items other than the registered email domain. However, for the item "structured PASS update count", the following determination may be made exceptionally. As described above, "update count = 0 times" means the password of a member who did not use the structured password management system. Therefore, when the deviation value of "0 times" is high, there is a high possibility that the cause of unauthorized access is information leakage from a partnering service that does not use the above system. Therefore, a message prompting attention to such a partnering service or an investigation of the presence or absence of attacks and damages is sent, and the countermeasure selection unit 13 can select the countermeasures specified in Fig. 13 for all accounts corresponding to "0 times". On the other hand, when any of the deviation values of "1 time or more" is high, it can also be treated as an abnormal situation because there is a risk of information leakage from the structured password management system. This corresponds to the situation shown as "grade 0" in Fig. 13. When "grade 0" occurs, the countermeasure selection unit 13 can select the countermeasure of stopping all services, not limited to specific accounts.

[0076] As described above, as the first step, based on the deviation value results for each item, countermeasures can be taken in terms of "points". The first step assumes a process for immediate response at the time of occurrence as "initial response". If convergence is not expected in the first step, it is possible to proceed to the second step. As an example, after executing the above countermeasures, if the deviation value of the item decreases, it can be regarded as convergence. For example, if the trend of the change in the deviation value is downward, it can be determined as convergence (or the stage of monitoring), and if it is horizontal or upward, it can be determined that additional countermeasures are required.

[0077] (2-2) Second step In the second step, the subjects of the combination of levels with high deviation values among the selected items are determined, and countermeasures are taken in terms of "surface". Fig. 14 is a flowchart showing an example of the operation in such a second step. For the same processing as in Fig. 4, the same reference numerals as in Fig. 4 are used, and detailed description is omitted.

[0078] First, in step S101, the information processing apparatus 10 acquires victim data by the victim data acquisition unit 11 and stores it in the victim data storage unit 14.

[0079] Next, in step S102, the analysis unit 12 reads the victim data from the victim data storage unit 14, aggregates it by item, and calculates the deviation value by type.

[0080] Then, in step S203, the countermeasure selection unit 13 performs a cross-tabulation on any plurality of items and selects a countermeasure.

[0081] FIG. 15 is a diagram showing an example of such a cross-tabulation. As described in the first stage, the number of victim members by type is aggregated for each item included in the victim data, and the deviation value is calculated. Then, any two (or three or more) items are selected. In the example of FIG. 15, the registration path and the registration email domain are selected as items, and a cross-tabulation is performed for each grade. The "number of target persons" in FIG. 15 is an example of the result of the cross-tabulation and represents the total value of the number of target persons in the same grade of each item. For example, for grade 1, the sum of the number of accounts (target persons) with the registration path being "Service X" and the number of accounts (target persons) with the email domain being "def.com" is calculated as "300,000". The number of target persons represents the range of the attack risk.

[0082] In the second stage, the countermeasure selection unit 13 may select a response for the above target "300,000" at grade 1, that is, a countermeasure of account suspension. Alternatively, the countermeasure selection unit 13 may calculate the deviation value again based on the number of target persons obtained above and select a countermeasure according to the deviation value after the cross-tabulation. Here, for the second stage as well, the countermeasure selection unit 13 can select a countermeasure based on the correspondence table in FIG. 13 as a countermeasure according to the grade of the risk level.

[0083] FIG. 16 is a diagram showing another example of a correspondence table of countermeasures to be taken for the degree of risk. In the correspondence table of FIG. 16, each grade is further subdivided so that the upper and lower levels of the countermeasure content can be selected. As an example, the upper and lower levels of the countermeasure content are selected according to the scale (scope of influence) of the number of target persons, and the upper and lower determination can be automatically determined by setting a threshold value. Alternatively, the correspondence table of FIG. 16 can be assumed to be used for evaluation at a stage when a certain number of days have passed since the occurrence of unauthorized access and a tendency of unauthorized access has become apparent to some extent. For example, when the deviation value transition of a certain monitoring cycle (e.g., average every 3 days) is horizontal, the countermeasures can be selected as they are, one level up when it rises, and one level down when it falls.

[0084] For example, regarding Grade 1, the standard countermeasure is "Account suspension of only the target account" of "1B", but when selecting a countermeasure one level up, "Suspension of all services" of "1A" is selected, and when selecting a countermeasure one level down, "Login suspension of only the target account" of "1C" is selected.

[0085] Similarly, regarding Grade 2, in a situation where the standard countermeasure "Login suspension" of "2B" is being implemented, for example, if the damage situation has not changed even after one week, "Account suspension" of "2A" is carried out, and if the damage situation has decreased after one week, it can be shifted to "Point usage suspension" of "2C". Alternatively, if the damage situation has further decreased, the countermeasure itself may be cancelled.

[0086] It is also possible to perform cross-grade adjustments using the correspondence table in Fig. 16. For example, if there are other options within each grade, the countermeasure selection unit 13 can increase or decrease within that range. If the conditions are met for further increasing or decreasing while implementing the countermeasure at the highest or lowest level of each grade, it is possible to select the upper or lower countermeasure of the same countermeasure in the upper or lower grades. For example, in the example of Fig. 16, if the damage from unauthorized access escalates while implementing the countermeasure for grade "2A", since there is no higher option within grade "2", it is upgraded to grade "1". Here, in this example, since the countermeasure for the ongoing grade "2A" and the countermeasure for grade "1B" are both the same, "Account suspension (only the target account)", the countermeasure selection unit 13 can select "1A", which is one level above grade "1B". Conversely, if the damage from unauthorized access is reduced when the countermeasure for grade "1C" is selected, it is possible to transition to grade "2C", which is one level below grade "2B", where the countermeasure is the same as that of grade "1C" (login suspension). Such cross-grade logic may be constructed, for example, by comparing the values of the object of interest, such as the total number of damage cases, the number of damage cases for the item, and the total number of target persons for the item, with a preset threshold. Note that not limited to the above example, it may simply be set to downgrade one level from "1C" and select the countermeasure for "2A", or conversely, upgrade from the countermeasure for "2A" and select the countermeasure for "1C". If the damage from unauthorized access escalates, ultimately, "All service suspension" for grade "0" will be selected.

[0087] Needless to say, cross-tabulation using combinations other than "registration path" and "email domain" is also possible. Which items to select for cross-tabulation may be specified in advance, for example, or the two items with the highest deviation values may be selected.

[0088] Regarding the second stage as well, the countermeasure selection unit 13 can output the selection result to an arbitrary output destination.

[0089] As described above, in the second stage, by using cross-tabulation from the deviation value results for each item, countermeasures can be taken in terms of "surface". In the second stage, in particular, as "continuous response", it is possible to evaluate which users have a high risk of being attacked as the number of days passes, and to upgrade or downgrade countermeasures according to the scale (scope of influence) of the number of target persons. As an example, if an item with a high deviation value occurs separately from the items handled as described above, it may be considered that the influence of the continuous response extends over a wide range, and the process may proceed to the third stage. Alternatively, as in the convergence judgment in the first stage, judgment may be made according to the transition of the change in the deviation value.

[0090] (2-3) Third stage In the third stage, for the cross-tabulation in the second stage, countermeasures in terms of "depth" are taken by further considering the total or average points held by the target users to determine the impact (degree of influence). FIG. 17 is a flowchart showing an example of the operation in such a third stage. For the same processing as in FIG. 4, the same reference numerals as in FIG. 4 are used, and detailed description is omitted.

[0091] First, in step S101, the information processing apparatus 10 acquires victim data by the victim data acquisition unit 11 and stores it in the victim data storage unit 14.

[0092] Next, in step S102, the analysis unit 12 reads the victim data from the victim data storage unit 14, tabulates it by item, and calculates the deviation value for each type.

[0093] Next, in step S303, the countermeasure selection unit 13 performs cross-tabulation for any plurality of items. This process is the same as the process described as step S203 in the second stage.

[0094] Next, in step S304, the countermeasure selection unit 13 further adds another index to determine the impact and selects a countermeasure.

[0095] FIG. 18 shows an example of such index addition. Here, after performing a cross-tabulation by email domain and registration route, the total number of points (total P) and the average number of points (average P) held by the target person are further calculated. The number of target persons represents the range of the risk of being attacked, the total number of points represents the business impact, and the average number of points represents the personal impact. Here, the countermeasure selection unit 13 is configured to select a countermeasure using the number of target persons for this business impact and personal impact as a criterion.

[0096] For example, grade 6 has a low risk, but since the total number of points and the average number of points are large, it is conceivable to raise the countermeasure by one level. For example, a threshold value regarding the number of points can be set, and when the threshold value is exceeded, the response within the grade can be raised by one level (similar to FIG. 16, from grade 6B to grade 6A). Similarly, grade 3 has a medium risk, but since the total number of points and the average number of points are small, it can be set to select a countermeasure such as lowering the response within the grade by one level. Regarding the determination of raising or lowering the countermeasure, it can also be automatically performed by the countermeasure selection unit 13 by setting a threshold value. For example, when there are two types of grade 1 (deviation value over 70) within a certain item, a threshold value corresponding to the number of those types can be set and the determination can be automatically made. As an example, the number of target persons can be divided by the number of types corresponding to grade 1, and a threshold value at that numerical value can be set, and thereby the determination of raising or lowering the countermeasure can be made. In the example of FIG. 18, regarding the items "registration route" and "email domain" selected for the cross-tabulation, there are three in grade 3, namely "service Y", "service W", and "ghi.ne.jp", so the number of target persons can be divided by 3, and the result can be determined with the threshold value to make the determination of raising or lowering.

[0097] In the above example, the focus was on the number of points held as the "indicator" to be added to the cross-tabulation, but other indicators may also be used. For example, the "number of times of Structure PASS updates" or "registration time" exemplified as items in FIGS. 9 and 10 may be used, or other information may be used. As an example, when purchase data contributing to the generation of points for each member is accumulated, the cumulative purchase amount may be used as an indicator. Or, when the member information includes purchase data for each service, purchase store, or each company brand, the purchase amount (sales amount) for each service, purchase store, or each company brand may be used as an indicator.

[0098] As described above, in the third step, by further considering the information on the points held in the result of the cross-tabulation, countermeasures can be taken in terms of "depth". In other words, in this example, when the number of target persons by attribute is taken on the horizontal axis and weights are assigned considering an arbitrary indicator (for example, as described above, point damage, personal information leakage, or a combination thereof) on the vertical axis, those with a larger vertical × horizontal area should be quickly judged as priority events and countermeasures should be taken. This allows for evaluating the details and making decisions including service suspension to prevent the spread of damage. The damage is not limited to economic damage, of course, but also includes leakage of personal information and logical damage caused by the leakage of personal information. That is, depending on what indicator is added to the cross-tabulation as "depth", countermeasures based on various perspectives can be selected.

[0099] Regarding the third step as well, the countermeasure selection unit 13 can output the selection result to an arbitrary output destination.

[0100] Although it has been described that the process proceeds to the second stage when convergence is not observed in the initial response as the first stage, depending on the scale of the damage, etc., it is also possible to carry out the first and second stages simultaneously. For example, for the processing in the first stage, it is carried out quickly in the initial response (treatment method), and for the processing in the second stage, while observing the tendency of unauthorized access after seeing the results of the first stage, corresponding measures are taken (countermeasure implementation). For the processing in the third stage, corresponding measures are taken by observing the impact (impact on management, for example, if the damage amount or the number of damaged members has increased significantly) from the results of the first and second stages. Thus, it is not necessarily limited to the progression of first the first stage, then the second stage, and finally the third stage. Depending on different judgment axes, the corresponding measures in the previous stage can also be considered simultaneously and implemented in parallel. In other words, the information processing apparatus 10 can execute each of the above-described processes in parallel according to the accumulation of victim data, that is, as the judgment materials are gathered.

[0101] (3) Effect As described in detail above, the information processing apparatus 10 according to an embodiment of the present invention includes a victim data acquisition unit 11 that acquires member information of victim members who have suffered unauthorized access to their accounts among the members of a service that manages accounts by password authentication, an analysis unit 12 that analyzes the statistical bias of the member information, and a countermeasure selection unit 13 that selects countermeasures against unauthorized access for each account managed by the service based on the results of the analysis. Thereby, instead of a uniform measure for all accounts under management, more appropriate measures can be selected for each account based on the actual tendency of unauthorized access, and more effective security can be established for the service and all its users.

[0102] (4) Other Embodiments Note that the present invention is not limited to the above-described embodiments. For example, in one example of the above-described embodiments, the information processing apparatus 10 has been mainly described as managing an account related to a common point service. However, even for the same points, it may manage accounts related to services that are not limited to a general, overall, but rather a limited range such as unique points. In this case, some of the information included in the victim data illustrated with respect to FIG. 5 may be omitted. Alternatively, the victim data may include other member information (for example, attribute information such as place of residence, gender, age, etc.). Similarly, it is possible to analyze the statistical bias in this case as well. For example, deviation values may be calculated for each prefecture or municipality registered as the address, and it may be determined whether there is a bias in the damage to the members in a specific place of residence. A cross-tabulation based on the gender and age of the victim members may be performed, and further a depth cross-tabulation may be performed according to the activity history related to the service on the network (such as the browsing history of a specific website or the posting frequency on SNS), so that it may be possible to take measures considering the purpose and target of unauthorized access. Note that if the victim data includes at least three types of information, the same processing as in the above first stage, second stage, and third stage can be executed.

[0103] Also, in the above-described embodiment, the information processing apparatus 10 has been described as operating in cooperation with the point management server 20. However, it is not limited to this. The information processing apparatus 10 can collect victim data from any apparatus that manages personal information and perform the same processing as described in the above-described embodiment based on the type of any item included in the victim data. For example, the information processing apparatus 10 can collect information from all organizations that manage personal information, such as financial institutions (banks, securities companies, insurance companies, etc.), credit card companies, physical stores or online shops, membership community services, information management services, other online services, transportation agencies, administrative agencies, medical institutions, educational institutions, etc. Also, the information processing apparatus 10 may accept an input of personal information from the victim himself / herself.

[0104] Each functional unit included in the information processing apparatus 10 may be distributed and arranged in a plurality of devices, and these devices may cooperate with each other to perform processing. Further, each functional unit may be realized by using a circuit. The circuit may be a dedicated circuit that realizes a specific function, or a general-purpose circuit such as a processor.

[0105] Furthermore, the flow of each process described above is not limited to the described procedure, and the order of some steps may be changed, or some steps may be executed in parallel. Also, the series of processes described above do not need to be executed continuously in time, and each step may be executed at an arbitrary timing.

[0106] The method described above can be stored as a program (software means) to be executed by a computer on a recording medium (storage medium) such as a magnetic disk (floppy (registered trademark) disk, hard disk, etc.), an optical disk (CD-ROM, DVD, MO, etc.), a semiconductor memory (ROM, RAM, flash memory, etc.), and can also be transmitted and distributed through a communication medium. Note that the program stored on the medium side includes a setting program for configuring software means (including not only the execution program but also tables and data structures) to be executed by a computer in the computer. The computer that realizes the above device reads the program recorded on the recording medium, and in some cases, constructs software means by the setting program, and executes the above-described processing by being controlled by this software means. Note that the recording medium referred to in this specification includes not only a storage medium such as a magnetic disk or a semiconductor memory provided inside a computer or in a device connected via a network for distribution purposes.

[0107] In addition, regarding the collection timing, collection method, analysis method, etc. of each data, various modifications can be made and implemented without departing from the gist of the present invention.

[0108] Note that the present invention is not limited to the above-described embodiments, and various modifications can be made without departing from the gist thereof at the implementation stage. Also, the respective embodiments may be implemented in appropriate combination, and in that case, the combined effects can be obtained. Furthermore, the above-described embodiments include various inventions, and various inventions can be extracted by combinations selected from a plurality of disclosed constituent elements. For example, even if some constituent elements are deleted from all the constituent elements shown in the embodiments, if the problem can be solved and the effects can be obtained, the configuration from which these constituent elements are deleted can be extracted as an invention.

Explanation of Signs

[0109] 1... System, 10... Information processing apparatus, 11... Victim data acquisition unit, 12... Analysis unit, 13... Countermeasure selection unit, 14... Victim data storage unit, 15... Grade information storage unit, 16... Countermeasure policy storage unit, 20... Point management server, 50... Service provision server.

Claims

1. Among the members of a service that manages accounts through password authentication, a member information acquisition unit that acquires and stores member information regarding victim members who have suffered unauthorized access to their accounts, An analysis unit that analyzes the statistical bias of the member information regarding the victim members for items related to the damage caused by unauthorized access by calculating the statistical quantity of the number of victim members for items related to the damage caused by unauthorized access included in the member information regarding the victim members, An information processing apparatus comprising:

2. The information processing apparatus according to claim 1, wherein the items related to the damage caused by unauthorized access included in the member information regarding the victim members are at least indicators for inferring the attack target, economic damage, information leakage path, or attack method.

3. Further comprising a countermeasure selection unit that determines the risk corresponding to the statistical bias of the member information regarding the victim members for items related to the damage caused by unauthorized access based on the correspondence relationship between the statistical quantity and the risk of the password authentication, and selects a countermeasure according to the risk, the information processing apparatus according to claim 1 or 2.

4. The analysis unit analyzes the statistical bias of the member information regarding the victim members for each of at least two items related to the damage caused by unauthorized access included in the member information regarding the victim members, The countermeasure selection unit selects the countermeasure by combining the risks corresponding to the statistical bias of the member information regarding the victim members for each of the at least two items related to the damage caused by unauthorized access, The information processing apparatus according to claim 3.

5. The countermeasure selection unit selects the countermeasure based on the economic value regarding the victim members, the information processing apparatus according to claim 3 or 4.

6. The countermeasure selection unit evaluates the effectiveness of the selected countermeasure by analyzing the member information regarding the victim member in chronological order, the information processing apparatus according to any one of claims 3 to 5.

7. An information processing method executed by an information processing apparatus, a process in which the information processing apparatus acquires and stores member information regarding a victim member whose account has been illegally accessed among members of a service that manages accounts by password authentication; a process in which the information processing apparatus analyzes the statistical bias of the member information regarding the victim member for items related to the damage caused by the illegal access by calculating a statistical quantity of the number of victim members for items related to the damage caused by the illegal access included in the member information regarding the victim member; An information processing method comprising the above.

8. A program that causes a computer to execute the processing by each part of the apparatus according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • Method and device for evaluating security and method and device for aiding preparation of security measure

    JP2001101135A

  • Data protection method and authentication method and program

    JP2005275775A

  • End-user risk management

    JP2008507757A

  • Automatic transaction system

    JP2009217771A

  • Management method, management device, and management program

    JP2015176375A