Unauthorized Detection System, Unauthorized Detection Method, and Unauthorized Detection Program

The fraud detection system uses real sensors to monitor and analyze user behavior and communication data for automated fraud detection, addressing false positives and ensuring continuous monitoring.

JP7700583B2Active Publication Date: 2025-07-01OKI ELECTRIC INDUSTRY CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2021137710
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-08-26
Publication Date
2025-07-01
Estimated Expiration
2041-08-26

AI Technical Summary

Technical Problem

Existing anomaly detection technologies for fraud detection suffer from high false detection rates and require manual verification, and user operation-based methods face issues with application malfunction or unauthorized user interference.

Method used

A fraud detection system that utilizes real sensors to monitor user behavior, collects communication data, and analyzes it to identify suspicious activities, providing user and terminal identification information for automated fraud detection.

Benefits of technology

Enables accurate and automated fraud detection by analyzing user communication behavior, reducing false positives and ensuring continuous monitoring of user activities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007700583000001
    Figure 0007700583000001
  • Figure 0007700583000002
    Figure 0007700583000002
  • Figure 0007700583000003
    Figure 0007700583000003
Patent Text Reader

Abstract

To make it possible, when a user's suspicious behavior or the like is detected using a real sensor, to collect and analyze the user's communication behavior and detect whether the user has committed fraud.SOLUTION: A fraudulence detection system according to the present invention includes: sensor abnormality detection means for monitoring a user's behavior using one or more sensors, and on detecting the user's suspicious behavior, reporting suspicious information including the user's user identification information and terminal identification information on a communication terminal used by the user; communication behavior information collection means for collecting communication behavior information based on the user identification information and the terminal identification information from communication history information on passing communication data; and fraudulence detection means for detecting whether the user has committed fraud based on the communication behavior information from the communication behavior collection means.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a fraud detection system, a fraud detection method, and a fraud detection program, and can be applied to, for example, a system for detecting fraudulent acts of computer operators.

Background Art

[0002] Conventionally, for example, for malware infection detection and cyber attack detection, there is an anomaly detection technique using communication traffic. For example, there is a technique described in Patent Document 1. In Patent Document 1, a probe device that monitors communication traffic measures the number of packets and throughput of passing packets, and further analyzes header information to extract TCP port numbers (source TCP port number, destination TCP port number), UDP port numbers (source UDP port number, destination UDP port number), etc., and holds feature information having feature items. Then, the probe device calculates the statistical range during normal times of the feature information, and when it becomes an outlier with respect to the statistical range during normal times, the probe device detects an event different from normal.

[0003] On the other hand, there is also an anomaly detection technique for detecting fraudulent operations of users who operate computers. For example, there is a technique described in Patent Document 2. The technique described in Patent Document 2 is for suppressing internal fraud in an organization. It logs the operations performed by an operator who operates a computer, obtains the difference between the operation features of specific items in the operation log and the operation features during a period when no fraudulent operation has occurred, and identifies a suspicion of fraud based on the result.

Prior Art Documents

Patent Documents

[0004]

Patent Document 1

Patent Document 2

Summary of the Invention

Problems to be Solved by the Invention

[0005] However, the anomaly detection technology using communication traffic detects an anomaly when an event different from normal is detected. However, there are many false detections. To confirm whether it is an anomaly that is really desired to be detected (i.e., an anomaly related to suspicion of fraud), information on communication traffic alone is insufficient, and measures such as contacting the user and asking the user to perform a virus search are necessary. Furthermore, automatic processing is also difficult.

[0006] In addition, the anomaly detection technology for user operations requires an application to be operated on a personal computer. There are problems such as when the application does not operate properly or when an unauthorized user changes the operation of the application or stops the startup.

[0007] Therefore, in view of the above-described problems, the present invention provides a fraud detection system, a fraud detection method, and a fraud detection program that can detect whether a user has committed fraud by collecting and analyzing the communication behavior of the user when detecting suspicious behavior of the user using a real sensor.

Means for Solving the Problems

[0008] To solve such problems, a fraud detection system according to a first aspect of the present invention monitors the behavior of a user using one or more sensors, and when detecting suspicion of the user, notifies suspicious information including the user identification information of the user and the terminal identification information of the communication terminal used by the user; communication behavior information collection means for collecting communication behavior information of the user based on the user identification information and the terminal identification information from the communication history information of the passing communication data; and fraud detection means for detecting whether the user has committed an illegal act based on the communication behavior information from the communication behavior information collection means. Exhibited by a communication terminal of the user Showing behavior It is characterized by comprising:

[0009] The illegal detection method according to the second aspect of the present invention is such that when the sensor abnormality detection means monitors the behavior of a user using one or more sensors and detects something suspicious about the user, it notifies suspicious information including the user identification information of the user and the terminal identification information of the communication terminal used by the user. The communication behavior information collection means, based on the user identification information and the terminal identification information, collects the communication behavior information of the user from the communication history information of the passing communication data. The illegal detection means detects whether the user has committed an illegal act based on the communication behavior information from the communication behavior information collection means. Exhibited by a communication terminal of the user Showing behavior communication behavior information of the user, and the illegal detection means detects whether the user has committed an illegal act based on the communication behavior information from the communication behavior information collection means.

[0010] The illegal detection program according to the third aspect of the present invention causes a computer to function as sensor abnormality detection means that monitors the behavior of a user using one or more sensors and, when detecting something suspicious about the user, notifies suspicious information including the user identification information of the user and the terminal identification information of the communication terminal used by the user; communication behavior information collection means that collects the communication behavior information of the user based on the user identification information and the terminal identification information from the communication history information of the passing communication data; and illegal detection means that detects whether the user has committed an illegal act based on the communication behavior information from the communication behavior information collection means. Exhibited by a communication terminal of the user Showing behavior communication behavior information, and functions as illegal detection means that detects whether the user has committed an illegal act based on the communication behavior information from the communication behavior information collection means.

Effect of the Invention

[0011] According to the present invention, when detecting something suspicious about a user's behavior using a real sensor, by collecting and analyzing the communication behavior performed by the user, it is possible to detect whether the user has committed fraud.

Brief Description of the Drawings

[0012]

Figure 1

Figure 2

Figure 3

Mode for Carrying Out the Invention

[0013] (A) Embodiment Hereinafter, embodiments of a fraud detection system, a fraud detection method, and a fraud detection program according to the present invention will be described with reference to the drawings.

[0014] (A-1) Configuration of the Embodiment FIG. 1 is an overall configuration diagram showing the overall configuration of a fraud detection system according to an embodiment.

[0015] In FIG. 1, a fraud detection system 10 according to an embodiment includes a fraud detection device 1, a sensor abnormality detection device 2, and a communication monitoring system 3.

[0016] This embodiment is an example in which the present invention is applied to a system that, in cooperation with a sensor abnormality detection system (device) using one or more sensors and a communication monitoring system (device) that monitors using information on communication traffic passing on a network, identifies the communication behavior of an operator when there is suspicion (suspicion) of fraud by the operator, and detects whether there has been a fraudulent act.

[0017] Further, this embodiment exemplifies a case of detecting fraudulent acts by a person within an organization that operates a computer system, but is not limited to fraudulent acts by insiders within the organization.

[0018] Various fraudulent acts can be considered. For example, fraudulent acts related to information leakage such as access to a specific file (file data), download, file transfer, recording, and removal of a storage medium can be cited. Also, for example, fraudulent acts related to unauthorized access through a network such as access to a specific server or a specific website, attack, and impersonation can be cited.

[0019] The illegal acts assumed in this embodiment are not limited to the above examples. In any case, when there is suspicion about the real behavior of the operator, this embodiment comprehensively determines and detects fraud by associating the communication behavior based on the communication history of the operator.

[0020] That is, when monitoring an insider within an organization and detecting an operator whose behavior or actions are different from normal, it is determined that there is suspicion of fraud. Taking this as a trigger, an example is given where the behavior of the operator is analyzed from the communication history of the operator using a computer (such as a communication terminal) to detect whether it is an illegal act.

[0021] [Sensor Abnormality Detection Device 2] The sensor abnormality detection device 2 includes one or more sensor units 21 and a sensor abnormality detection unit 22 that performs abnormality detection using the sensing data of the sensor unit 21.

[0022] The sensor abnormality detection device 2 monitors the behavior, actions, operations, emotions, states, etc. (hereinafter referred to as "behavior, etc.") of the operator using the sensor unit 21.

[0023] In addition, the sensor abnormality detection device 2 monitors the operator and the communication terminal (computer) as monitoring targets and manages the operator and the communication terminal as monitoring targets.

[0024] For example, regarding the operator, the sensor abnormality detection device 2 assigns user identification information that uniquely identifies the operator and manages each operator. The sensor abnormality detection device 2 may manage the operator by associating part or all of the name, face image, biometric authentication information, etc. with the user identification information for each operator. Further, the sensor abnormality detection device 2 may associate the sensing data of each sensor unit 21 with the user identification information to keep a log. Furthermore, the sensor abnormality detection device 2 performs statistical processing using the sensing data, and associates the numerical values obtained by the statistical processing with the user identification information to manage the statistical values for each operator. That is, the sensor abnormality detection device 2 evaluates the behavior of the operator, etc. with statistical numerical values using the sensor data of the sensor unit 21, and manages the evaluated numerical values for each operator.

[0025] Also for example, regarding the communication terminal, the sensor abnormality detection device 2 manages the communication terminal using terminal identification information such as an identification number or IP address that uniquely identifies the communication terminal and is assigned to the communication terminal.

[0026] The sensor abnormality detection device 2 monitors the behavior of the operator, etc. using the sensor unit 21, and detects that there is a suspicion of fraud by the operator based on the data of the sensor unit 21. When it detects that there is a suspicion of fraud, the sensor abnormality detection device 2 transmits fraud suspicion information (also called suspicious information) including the user identification information of the operator and the terminal identification information of the communication terminal operated by the operator to the fraud detection device 1.

[0027] Fraud suspicion information refers to information indicating that the sensor abnormality detection unit 22 using one or more sensor units 21 has determined that the behavior of the computer operator, etc. is different from the normal operation and there is a suspicion of fraud. The fraud suspicion information includes user information that identifies the person (operator) with a suspicion of fraud, the terminal identification information of the communication terminal operated by the operator, etc. Not limited to this, it may also include the time (date and time information) when the suspicion of fraud was detected.

[0028] In addition, when the illegal act by an operator suspected of fraud has ended, the sensor abnormality detection device 2 transmits fraud suspicion resolution information to the fraud detection device 1. As a result, it is possible to perform the analysis process by the fraud detection device 1 within the time period of the illegal act and omit unnecessary analysis processes. Note that the sensor abnormality detection device 2 may include the illegal act execution time in the fraud suspicion resolution information for the purpose of post hoc log analysis by the fraud detection device 1.

[0029] The fraud suspicion resolution information refers to information indicating that the act of an operator suspected of fraud has ended by monitoring the behavior of the operator suspected of fraud. The fraud suspicion resolution information includes the user identification information of the operator, the terminal identification information of the communication terminal operated by the operator, the time when the act suspected of fraud has been resolved, the time when the act suspected of fraud was committed, and the like.

[0030] The sensor unit 21 is a real sensor having sensors that can be used for an illegal operation by a user, and is connected to the sensor abnormality detection unit 22. The sensor unit 21 can be applied to, for example, a camera sensor (image sensor), a vital sensor (for example, a heartbeat sensor, a respiration sensor, a body temperature sensor, a humidity sensor for detecting sweating, etc.), a sound sensor, a vibration sensor, a line-of-sight sensor, an operation sensor for monitoring operations of a keyboard, a mouse, etc. within a PC (personal computer), and the like.

[0031] Note that the type of sensor is not particularly limited, and an illuminance sensor for detecting the illuminance in a room, a human presence sensor, a power sensor for detecting the on / off of the PC power supply, a thermal camera, or the like may be used. For example, since fraud may be committed in a dark room outside working hours, an illuminance sensor, a thermal sensor, a human presence sensor, or the like for detecting the brightness in the room may be used to detect a situation where fraud is suspected.

[0032] For example, as the camera sensor, a camera mounted on a PC, an externally attached camera to the PC, a surveillance camera installed indoors, or the like can be used. The line-of-sight sensor for monitoring the line of sight of the operator can be installed in advance in a room, around a desk, near the PC, etc., and can be used to capture a state of restlessness and a swimming-eye appearance.

[0033] For example, vital sensors, sound sensors, and vibration sensors can use contact or non-contact types. Those installed in advance may be used, or data obtained from applications installed in smartphones, wearable terminals, tablet terminals, etc., or applications linked to various sensors may also be used.

[0034] For another example, an operation sensor for monitoring PC operations is installed in the PC as application software.

[0035] Based on the sensing data of the sensor unit 21, the sensor abnormality detection unit 22 detects a suspicion of fraud, and when it detects a suspicion of fraud, it notifies the fraud detection escalation unit 11 of fraud suspicion information including user identification information and terminal identification information. Also, when the abnormality is resolved and the suspicion of fraud decreases, the sensor abnormality detection unit 22 notifies the fraud resolution detection unit 13 that notifies fraud resolution information.

[0036] The sensor abnormality detection unit 22 can apply various existing abnormality detection methods, and not only one type of method but also multiple types of methods can be implemented simultaneously in parallel. When applying multiple types of methods, the sensor abnormality detection unit 22 can acquire data from one type or multiple types of sensor units 21 according to the type of abnormality detection method.

[0037] For example, consider a case where the situation of a person's leaving / entering the seat is monitored for each operator using a camera image, and statistical values such as the seating time or leaving time, the seating time zone or leaving time zone, the number of times of leaving the seat, and the number of times of entering the seat are held for each operator, and when there is an outlier with respect to the statistical range, it is determined as an abnormality (that is, having committed fraud or being fidgety and unable to calm down as if trying to commit fraud). In that case, the sensor abnormality detection unit 22 can acquire images from a monitoring camera installed indoors or a camera sensor installed in a PC. That is, the sensor abnormality detection unit 22 can acquire data from one type of sensor unit (in this case, a camera sensor). Note that even if they are of the same type, it may be possible to acquire data from multiple sensor units 21.

[0038] For example, the sensor abnormality detection unit 22 performs statistical calculations for each operator using the measured values of the operator's heart rate and body temperature and the measurement time, and when the heart rate is very high and the body temperature is very high with respect to the statistical ranges of the heart rate and body temperature (normal heart rate and body temperature) (for example, when the difference between the outlier value and the value within the statistical range is equal to or greater than the threshold value), consider the case of applying a method for determining that it is abnormal (that is, in an extremely tense state different from the normal state). In that case, the sensor abnormality detection unit 22 can acquire data from two types of sensor units 21, namely a heart rate sensor and a body temperature sensor.

[0039] Furthermore, for example, the sensor abnormality detection unit 22 can apply a method for determining abnormality based on the result of estimating a person's emotion using emotion estimation technology. In that case, the sensor abnormality detection unit 22 can acquire data from a plurality of types of sensor units 21 such as a camera sensor, a heart rate sensor, a body temperature sensor, a humidity sensor, a sound sensor, and a vibration sensor.

[0040] For example, when an application as an operation sensor is installed on a PC, the application may be operated so that it does not operate correctly. The sensor abnormality detection unit 22 determines that it is normal if the PC is normally in an operable state with the power on and the application as the operation sensor is operating. However, when it detects that the application as the operation sensor that should originally operate is not operating, the sensor abnormality detection unit 22 can also apply a method for determining that it is abnormal.

[0041] In this way, various methods can be applied to the abnormality detection method of the sensor abnormality detection unit 22. Also, when applying a plurality of types of methods, in order to improve the abnormality detection accuracy of the operator, the sensor abnormality detection unit 22 may comprehensively judge the results of the plurality of types of methods and determine that there is suspicion of irregularity in the behavior of the operator or the like.

[0042] [Communication monitoring system 3] The communication monitoring system 3 includes a network (NW) data acquisition unit 31, an NW abnormality detection unit 32, and an NW behavior data collection unit 33.

[0043] The communication monitoring system 3 is installed at a location where communication packets of a communication terminal (computer) to be monitored can be captured. The communication monitoring system 3 collects packet data flowing through the network.

[0044] When the fraud detection device 1 receives from the sensor abnormality detection device 2 that there is a suspicion of fraud in the behavior of the operator, etc., the communication monitoring system 3 collects the communication history of the communication terminal operated by the operator. The communication monitoring system 3 obtains information including the user information of the operator and / or terminal identification information such as an IP address from the fraud detection device 1, and uses this information to collect information indicating the behavior of the operator. For example, the communication monitoring system 3 collects communication traffic information including the user information of the operator and / or the IP address and notifies the fraud detection device 1.

[0045] The NW data acquisition unit 31 captures passing packets, analyzes the header information of the packets, collects packet data such as the type of packet, the source or destination, and provides it to the NW abnormality detection unit 32 and the NW behavior data collection unit 33.

[0046] The NW abnormality detection unit 32 obtains packet data from the NW data acquisition unit 31 and stores these packet data in the database unit 321. The NW abnormality detection unit 32 obtains the user information of the operator and / or the terminal identification information of the communication terminal from the fraud detection escalation unit 11, and receives an instruction for abnormality detection using the communication traffic information flowing through the network. Also, the NW abnormality detection unit 32 may obtain information including the fraud execution period in order to know the time period during which fraud was committed.

[0047] The NW abnormality detection unit 32 uses the communication traffic as a trigger to perform abnormality detection based on an instruction from the fraud detection escalation unit 11, and notifies the fraud detection result to the fraud detection unit 12.

[0048] The NW anomaly detection unit 32 can widely apply various methods as long as they are anomaly detection methods using communication traffic. For example, the NW anomaly detection unit 32 refers to the communication traffic information held in the database unit 321, and measures, for example, the number of IP packets per predetermined time and the throughput (data transfer amount per unit time) using the instructed user information (information including user identification information) and / or terminal identification information as keys. Also, the NW data acquisition unit 31 analyzes the header information of the packet to create feature information including items such as IP address, TCP window size, TCP port number, source TCP port number, destination TCP port number, UDP port number, source UDP port number, destination UDP port number, TCP flag, TCP flag set, ICMP type code, and IP protocol. This feature information of specific items is created and held every predetermined time.

[0049] Then, statistical processing is performed including the past history of the feature information, and the statistical value of the feature information during the period when no fraud is considered to have occurred is set as the normal statistical range. Furthermore, if there is an outlier outside the normal statistical range, it is determined that an event different from the normal time (that is, an anomaly) has occurred, and the result is notified to the fraud detection unit 12.

[0050] The above-described NW anomaly detection method is an example. Therefore, it is not limited to the above example. Also, when an NW anomaly is detected, the NW anomaly detection unit 32 notifies the fraud detection unit 12 of information including the communication traffic information related to the anomaly.

[0051] The NW behavior data collection unit 33 collects information on the operations of communication terminals and user behaviors on the network according to an instruction from the fraud detection escalation unit 11, and notifies the result to the fraud detection unit 12.

[0052] For example, based on terminal identification information such as the IP address instructed by the illegal detection escalation unit 11, the NW behavior data collection unit 33 determines whether there is a communication history of the operator's communication terminal accessing a specific server (e.g., a file server, a mail server, etc.). If there is a communication history, it collects communication behaviors such as file information including file type, file size, etc., and whether the file was downloaded or transferred (uploaded).

[0053] [Illegal Detection Device 1] The illegal detection device 1 includes an illegal detection escalation unit 11, an illegal detection unit 12, an illegal resolution detection unit 13, and a result aggregation unit 14.

[0054] When the illegal detection device 1 receives illegal suspicion information from the sensor abnormality detection unit 22, it uses this as a trigger to send user information and / or terminal identification information to be monitored to the communication monitoring system 3, and collects information regarding the operations of communication terminals and the behaviors of users on the network. Then, the illegal detection device 1 analyzes the behaviors of operators suspected of illegal activities and creates the results. Also, the illegal detection device 1 is connected to the communication control device 4, and in order to prevent or warn against illegal acts, it notifies the communication control device 4 that an illegal act has occurred.

[0055] When the illegal detection escalation unit 11 receives illegal suspicion information from the sensor abnormality detection unit 22, it sends information including user information and / or terminal identification information to the NW behavior data collection unit 33 to start collecting NW behavior data. Also, the illegal detection escalation unit 11 is connected to the illegal resolution detection unit 13 and the illegal detection unit 12 to manage the illegal detection status.

[0056] The fraud detection unit 12 receives an instruction to start fraud detection from the fraud detection escalation unit 11, and acquires communication traffic information regarding NW anomalies from the NW anomaly detection unit 32. Also, the fraud detection unit 12 acquires information regarding the operations of communication terminals and user behavior on the network from the NW behavior data collection unit 33. Then, until the fraud elimination detection unit 13 notifies the end of the suspicion of fraud, the fraud detection unit 12 performs fraud detection based on information such as the operations of communication terminals and user behavior. Furthermore, the fraud detection unit 12 outputs the results of the fraud detection to the result aggregation unit 14.

[0057] After receiving an instruction to start fraud detection from the fraud detection escalation unit 11, the fraud elimination detection unit 13 manages the monitoring state until it receives fraud suspicion elimination information indicating the end of fraud detection from the sensor anomaly detection unit 22. When it receives the fraud suspicion elimination information, the fraud elimination detection unit 13 notifies the fraud detection unit 12 that the fraud detection has ended and terminates the fraud detection.

[0058] The result aggregation unit 14 receives the situation of the possibility of fraud detection analyzed by the fraud detection unit 12 and the result of aggregating information associated with the time of suspicion of fraud, and holds the result.

[0059] (A-2) Operations of the Embodiment Next, the processing operations of the fraud detection method in the fraud detection system 10 according to the embodiment will be described with reference to the drawings.

[0060] FIG. 2 is a sequence diagram showing the fraud detection process according to the embodiment.

[0061] When the sensor unit 21 starts operating at the location to be monitored by the fraud detection system 10, the sensing data by the sensor unit 21 is provided to the sensor anomaly detection unit 22.

[0062] The sensor unit 21 can be, for example, a camera sensor, a vital sensor, a sound sensor, a vibration sensor, a line-of-sight sensor, an operation sensor installed on a PC, or the like. The sensor abnormality detection unit 22 acquires sensing data from the corresponding sensor unit 21 according to the abnormality detection method, and monitors the states of the operator and the communication terminal to be monitored.

[0063] For example, the sensor abnormality detection unit 22 analyzes a camera image that captures the state of the operator's leaving / returning to the seat, and stores statistical information regarding normal leaving / returning to the seat without suspicion of fraud for each operator. Then, when the number of times or the time of a certain operator's leaving / returning to the seat is an outlier with respect to the statistical range, the sensor abnormality detection unit 22 determines that the state is different from normal. More specifically, for example, when it is detected that the number of times of leaving the seat has extremely increased compared to normal, the time of leaving the seat is longer than normal, or the operator is seated during the late-night time zone outside of working hours, the sensor abnormality detection unit 22 detects an abnormality.

[0064] Also, for example, when the sensor abnormality detection unit 22 uses data from the vital sensor and detects that the heart rate, respiration, body temperature, etc. have extremely increased compared to normal, it determines that there is an abnormality.

[0065] For example, the sensor abnormality detection unit 22 statistically processes values indicating characteristics such as the volume and pitch of the voice generated by the operator using a sound sensor and stores them for each operator, or statistically processes values indicating characteristics such as the time interval, operation time, and time zone of the habit of the operator moving the body (e.g., poverty shaking, timing of changing posture, etc.) using a vibration sensor and stores them for each operator. Then, when the sensor abnormality detection unit 22 detects that the voice is significantly louder or the body movement is abnormally large compared to normal, it determines that there is an abnormality.

[0066] Also, for example, when the sensor abnormality detection unit 22 detects that the eyes are prone to swimming using a line-of-sight sensor such as a web camera, or detects a difference from normal in the operation of the keyboard or mouse using an operation sensor, it detects an abnormality.

[0067] Note that not only one anomaly detection method but also a plurality of anomaly detection methods may be used to comprehensively detect a person suspected of fraud. Further, when using a plurality of anomaly detection methods, the determination may be made by weighting a plurality of results.

[0068] Examples of patterns suspected of fraud include, for example, when the number of seatings on a chair is large, the person is fidgety, the line of sight is likely to wander, the heartbeat suddenly increases, and vibrations such as poor man's shakes are detected; or, for example, when a computer is being operated without turning on the lights in an empty room; or, for example, when monitoring cannot be performed because the sensor itself has been stopped. However, the examples are not limited to these.

[0069] When the sensor anomaly detection unit 22 determines, based on the data from the sensor unit 21, that the behavior of the operator is different from normal and there is suspicion of fraud (S101), it notifies the fraud detection escalation unit 11 of fraud suspicion information including user information including user identification information and / or terminal identification information (such as the IP address of the communication terminal) (S102).

[0070] When the fraud detection escalation unit 11 receives the fraud suspicion information, in order to monitor fraud, it notifies the fraud detection unit 12, the fraud resolution detection unit 13, the NW anomaly detection unit 32, and the NW behavior data collection unit 33 of the start of fraud detection including the user information of the operator suspected of fraud and / or the terminal identification information of the communication terminal operated by the operator (S103).

[0071] When the NW anomaly detection unit 32 obtains information including the user information of the operator and / or terminal identification information such as the IP address of the communication terminal from the fraud detection escalation unit 11, it learns the steady state of the communication traffic information for each user and each IP address, and detects as anomalies cases where the data volume statistically shows a difference from normal or where communication occurs at an abnormal time (S104). When an anomaly is detected, the NW anomaly detection unit 32 notifies the fraud detection unit 12 of the result (S105).

[0072] For example, the database unit 321 stores the communication history of the packets captured by the NW data acquisition unit 31. The NW anomaly detection unit 32 extracts the communication history of communication traffic information for each user based on the user information of the operator and for each IP address of the communication terminal (computer) operated by the operator, and learns based on the communication destination (destination IP address, destination port number) of the communication terminal, communication type (protocol), communication data volume, communication time, time zone, etc., to derive the communication information during normal times (a period when there is no suspicion of fraud). The NW anomaly detection unit 32 uses the information learned from the communication history for each user information and each IP address, and when the communication performed by the operator on the communication terminal during this fraud implementation period has a significantly larger data volume compared to the learned communication history (for example, the difference value from the average data volume of the history is equal to or greater than the threshold value), or when communicating during the late-night time zone when it is not normally done, etc., it determines that it is abnormal compared to the learned communication history.

[0073] As in the example described above, when the NW anomaly detection unit 32 detects an NW anomaly, it notifies the fraud detection unit 12 to that effect. Further, the NW anomaly detection unit 32 may notify the fraud detection unit 12 of the communication traffic information of the operator for each user and each IP address performed on the communication terminal. Furthermore, the NW anomaly detection unit 32 may also notify the fraud detection unit 12 of the communication history derived during learning.

[0074] Next, the NW behavior data collection unit 33 classifies the data obtained from the NW data acquisition unit 31 for each IP address and each user, and collects information regarding NW behavior such as which service, which server was communicated with, what files were transmitted and received, where the email was sent, etc. (S106), and notifies the fraud detection unit 12 of the information regarding the NW behavior (S107).

[0075] That is, the NW behavior data collection unit 33 collects information indicating the behavior of the operator using the communication terminal based on the user information of the operator notified from the fraud detection escalation unit 11 and the IP address of the communication terminal operated by the operator.

[0076] The NW behavior data collection unit 33 analyzes the behavior from the communication history of traffic information including the IP address of the terminal used by the operator. In addition to the detection of communication anomalies that deviate from normal by the NW anomaly detection unit 32, the NW behavior data collection unit 33 collects NW behavior data in detail, and records "which servers and which services were accessed", "which types of files were accessed", "which types of confidential data were accessed", "what actions (e.g., email sending, USB attachment / detachment, etc.) were taken after the access", etc.

[0077] The information collected by the NW behavior data collection unit 33 is about where the person who was actually determined to have suspicious behavior in the sensor anomaly detection device 2 accessed and what they did, so it is possible to determine whether the person's behavior is really an illegal act or not.

[0078] An example of the NW behavior data by the NW behavior data collection unit 33 will be described with reference to FIG. 3.

[0079] For example, the accessed server is identified based on the destination address (destination IP address, server name, etc.), port number, protocol, etc. from the communication history of traffic information including the IP address of the communication terminal operated by the operator. When the server is a file server (e.g., a server with access authority in a corporate network), it is analyzed which file name files were accessed and viewed. At this time, the number of login attempts to the server, the number of failures during the attempts, the number of accesses to the file, the file size of the file, etc. are recorded. Further, after the file access, the NW behavior data collection unit 33 checks whether an email is being sent to the email server, and if there is a history of email sending, the NW behavior data collection unit 33 records the email server, the email destination, the file size of the attached file, etc. Also, if multiple emails are sent, the number of email sendings is also counted. Such actions are used to create a communication behavior according to the time series based on time.

[0080] For example, if the access destination of the operator's communication terminal is a web server, the NW behavior data collection unit 33 records which website was accessed, the number of login attempts from the communication terminal or IP address, the number of successful logins of a large number of users from the communication terminal or IP address, the type of transaction with the website, the transaction amount, whether the login information (ID, password) was changed after the transaction, and so on.

[0081] While the state suspected of being illegal continues, the sensor abnormality detection unit 22 continues to detect abnormalities using the sensor unit 21. When the state suspected of being illegal ends, the sensor abnormality detection unit 22 notifies the illegal suspicion resolution detection unit 13 of illegal suspicion resolution information indicating that the state suspected of being illegal has ended (S109). Note that the illegal suspicion resolution information includes, for example, the operator's user information and / or terminal identification information.

[0082] Upon receiving the illegal suspicion resolution information, the illegal resolution detection unit 13 notifies the illegal detection unit 12 that the suspicion of illegality has been resolved for the corresponding user information and / or terminal identification information (S110).

[0083] The illegal detection unit 12, which has been notified by the illegal resolution detection unit 13 that the suspicion of illegality has been resolved, notifies the NW abnormality detection unit 32 and the NW behavior data collection unit 33 to lift the escalation, and stops the NW abnormality detection and NW behavior data collection for the corresponding IP and username.

[0084] The illegal detection unit 12 receives information on a communication situation different from normal from the NW abnormality detection unit 32. Also, the illegal detection unit 12 receives communication behavior information including, for example, the accessed server or file information (file name, file size, etc.) on the network, the number of login attempts, and when sending an email, the email destination and the attached file information (file name, file size, etc.) from the NW behavior data collection unit 33. Then, the illegal detection unit 12 aggregates the communication history of the operator suspected of illegal behavior using the above-mentioned communication situation information and communication behavior information. And it comprehensively determines whether there has been an illegal act (S111).

[0085] For example, assume that from the communication status information from the NW abnormality detection unit 32, it is communication during the late-night time zone, which is different from normal, and from the communication behavior information from the NW behavior data collection unit 33, access has been made to a highly confidential file from a specific file server. Further, assume that from the communication behavior information from the NW behavior data collection unit 33, there is a history that after accessing the confidential file, an email with the file attached has been sent to an external email destination multiple times. Then, the fraud detection unit 12 determines that there is a high suspicion of fraud.

[0086] Also, the fraud detection unit 12 may perform fraud detection using the sensing data of the sensor unit 21 from the sensor abnormality detection device 2. For example, it may make a determination using information such as the operation sensor having inserted or removed a recording medium such as a USB memory into the PC, or having recorded a file on the recording medium.

[0087] The fraud detection unit 12 prepares a fraud determination list in advance with items for determining fraud, such as communication during the late-night time zone or on holidays that is significantly outside working hours, access to a file server with high access rights, access to a highly confidential file, and email sending after file access. If there is behavior corresponding to the items in the list, it may be determined as fraud. The items may be weighted.

[0088] Then, the result aggregation unit 14 obtains the determination result from the fraud detection unit 12 (S112), and aggregates the detection time of the sensor unit 21, the user information of the operator suspected of fraud, the terminal identification information, the detection time of the NW abnormality detection unit 32, the abnormal communication status information, the collection time of the NW behavior data collection unit 33, the communication behavior, and the determination result of the fraud detection unit 12 to create a result (S113). Note that the result created by the result aggregation unit 14 is stored in a file.

[0089] (A-3) Effects of the Embodiment As described above, according to this embodiment, an abnormal situation suspected of user fraud is detected by detecting an abnormality in the real world with a real sensor, and fraud detection is started. By detecting NW abnormalities and collecting NW behavior data, information on what the user was trying to do can be collected, and the effect of detecting whether fraud was actually committed can be expected.

[0090] In addition, even for information that remains suspicious of fraud, there is also an effect that it is possible to investigate the suspicion of a user who has been considering fraud over a long period of time based on the trend of the data accumulated in the result aggregation unit.

[0091] (B) Other embodiments Although various modified embodiments have been mentioned in the above-described embodiment, the present invention can also be applied to the following modified embodiments.

[0092] (B-1) In addition to the above-described embodiment, when the fraud detection unit 12 determines that there is a high possibility of fraud, a configuration for preventing information leakage or the like may be provided. For example, as illustrated in FIG. 1, a communication control device 4 connectable to the fraud detection unit 12 is provided, and this communication control device 4 may have some or all of the functions such as a mail delayed delivery unit, a mail delivery after approval unit, and a communication relay unit, or these functions may be controllable. That is, when trying to send a highly confidential file to a specific mail destination, the fraud detection unit 12 notifies the communication control device 4 of information identifying the mail, so that the communication control device 4 can stop the transmission of the designated mail and prevent information leakage and the like.

[0093] (B-2) In the above-described embodiment, an example was illustrated in which fraud suspicion information (suspicious information) is notified to the fraud detection escalation unit 11, and further notified to the NW abnormality detection unit 32 and the NW behavior data collection unit 33, and fraud detection processing is started. However, fraud suspicion information may be directly notified to the NW abnormality detection unit 32 and the NW behavior data collection unit 33 without passing through the fraud detection escalation unit 11, and fraud detection processing may be disclosed. The present invention can also be realized by such a configuration. Although the configuration described in the embodiment is desirable in consideration of system implementation, the same effect can be achieved with the above-described modification examples.

Description of Signs

[0094] 10…Illegality Detection System, 1…Illegality Detection Device, 11…Illegality Detection Escalation Unit, 12…Illegality Detection Unit, 13…Illegality Resolution Detection Unit, 14…Result Aggregation Unit, 2…Sensor Abnormality Detection Device, 21…Sensor Unit, 22…Sensor Abnormality Detection Unit, 23…Database, 3…Communication Monitoring System, 31…NW Data Acquisition Unit, 32…NW Abnormality Detection Unit, 321…Database, 33…NW Behavior Data Collection Unit, 331…Database, 4…Communication Control Device.

Claims

1. Sensor anomaly detection means that monitors the behavior of a user using one or more sensors, and when detecting suspicion of the user, notifies suspicious information including the user identification information of the user and the terminal identification information of the communication terminal used by the user; Communication behavior information collection means that collects communication behavior information indicating the behavior of the user who used the communication terminal based on the user identification information and the terminal identification information from the communication history information of the passing communication data; Illegality detection means that detects whether the user has committed an illegal act based on the communication behavior information from the communication behavior information collection means An illegal detection system characterized by comprising.

2. By referring to the communication history information of the passing communication data, using the communication information obtained by extracting the communication history for each user identification information and the communication history for each terminal identification information, statistical communication information for each user and each communication terminal is derived, and when the communication situation by the user is different from the statistical communication information, communication anomaly detection means for detecting it as an anomaly in the communication situation is provided, The communication behavior information collection means collects the communication behavior information of the user from among the communication information detected as abnormal by the communication anomaly detection means. The illegal detection system according to claim 1, characterized in that.

3. Result aggregation means for creating a comprehensive detection result using the detection result determined by the illegal detection means, the detection result by the sensor anomaly detection means, and the communication behavior information collected by the communication behavior information collection means is provided. The illegal detection system according to claim 1 or 2, characterized in that.

4. The illegal detection system according to claim 3, characterized in that when the sensor anomaly detection means detects the resolution of suspicion by the user, it notifies suspicion resolution information indicating that the suspicion has been resolved.

5. The illegal detection system according to any one of claims 1 to 4, characterized in that it comprises communication control means for blocking, causing communication failure, or delaying the communication information by the user detected as illegal by the illegal detection means.

6. When the sensor anomaly detection means monitors the behavior of a user using one or more sensors and detects suspicion of the user, it notifies suspicious information including the user identification information of the user and the terminal identification information of the communication terminal used by the user, The communication behavior information collection means collects communication behavior information indicating the behavior of the user who uses the communication terminal based on the user identification information and the terminal identification information from the communication history information of the passed communication data. The fraud detection means detects whether or not the user has committed a fraudulent act based on the communication behavior information from the communication behavior information collection means. A fraud detection method characterized by the above.

7. A computer Sensor abnormality detection means that monitors the behavior of a user using one or more sensors, and when detecting suspicion of the user, notifies suspicious information including the user identification information of the user and the terminal identification information of the communication terminal used by the user. Communication behavior information collection means that collects communication behavior information indicating the behavior of the user who uses the communication terminal based on the user identification information and the terminal identification information from the communication history information of the passed communication data. Fraud detection means that detects whether or not the user has committed a fraudulent act based on the communication behavior information from the communication behavior information collection means A fraud detection program characterized by causing the computer to function as described above.

Citation Information

Patent Citations

  • Communication monitoring system

    JP2006148686A

  • Attack determination device, and attack determination method and program

    JP2010152773A

  • Log monitoring method, log monitor, log monitoring system, and log monitoring program

    JP2016143320A

  • Illegality detection device, illegality detection method, and illegality detection program

    JP2019121215A