Communications processing device and communications processing program
The communication processing device verifies phishing sites by comparing user terminal personal information with legitimate data and using authentication failures, addressing the inefficiencies of conventional URL-based methods and reducing processing loads.
Patent Information
- Application Number
- JP2022023570
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-02-18
- Publication Date
- 2026-01-09
- Estimated Expiration
- 2042-02-18
AI Technical Summary
Conventional URL-based phishing site verification methods are ineffective against frequently changing phishing site URLs and impose a heavy processing load, making it difficult to identify new or altered phishing sites.
A communication processing device that verifies whether a destination site is a phishing site by comparing personal information sent from a user terminal with legitimate personal information stored in a memory unit and determining the site as phishing based on authentication failures from the destination site.
Enables easy and efficient phishing site verification through simple processing, reducing the burden on browsers and improving identification of new or altered phishing sites.
Smart Images

Figure 0007796314000001 
Figure 0007796314000002 
Figure 0007796314000003
Abstract
Description
[Technical Field]
[0001] The present invention relates to a communication processing technology for verifying whether a destination site is a phishing site that illegally extracts personal information. [Background technology]
[0002] In recent years, there have been many reports of so-called phishing scams, in which emails (hereafter referred to as "emails") are sent to users to notify them of password changes or purchase completions, leading them to phishing sites disguised as legitimate financial institutions or shopping sites, where they are tricked into entering personal information such as credit card information, IDs, passwords, addresses, and telephone numbers. Therefore, it is important to verify whether the URLs contained in emails are phishing site URLs and to prevent access to phishing sites before they occur.
[0003] Conventionally, a technique has been proposed for verifying whether a target URL that a user is accessing is a phishing site URL by comparing the target URL with a URL list in which URLs of known phishing sites are registered, and determining that the target URL is a phishing site URL if the target URL is included in the URL list (see, for example, Patent Document 1). [Prior art documents] [Patent documents]
[0004] [Patent Document 1] Patent Publication No. 2021-033421 Summary of the Invention [Problem to be solved by the invention]
[0005] However, in such conventional technology, the target URL is verified based on a URL list in which the URLs of known phishing sites are registered. Therefore, if the target URL is registered in the URL list as a phishing site, access to the target URL can be prevented in advance. However, the URLs of phishing sites are frequently changed to evade tracking. Therefore, there is a problem in that if the target URL is not registered in the URL list as a phishing site, access to the target URL cannot be prevented in advance.
[0006] For this reason, conventional technologies acquire web access logs containing the types and sizes of resources used in a browser to construct the web page of a phishing site, register the logs in a blacklist, and verify whether a target URL is a phishing site URL based on whether the web access log of the site of the target URL is included in the blacklist. However, such technologies not only impose a heavy processing load on the verification process, but also have the problem of making it difficult to identify new phishing sites with different web page configurations or phishing sites whose configurations have been changed.
[0007] The present invention is made to solve such problems, and aims to provide a communication processing technology that can easily verify whether or not any destination site is a phishing site through simple processing. [Means for solving the problem]
[0008] In order to achieve this objective, the communication processing device of the present invention comprises a memory unit configured to store verification information including legitimate personal information used to access a legitimate site from a user terminal, and a control unit configured to compare the personal information included in a communication message sent from the user terminal to an arbitrary destination site with the verification information, and if it is confirmed that the personal information is legitimate personal information, to verify whether the destination site is a phishing site based on the authentication result for the legitimate personal information returned from the destination site.
[0009] In one configuration example of the communication processing device according to the present invention, the control unit is configured to determine that the destination site is a phishing site when the authentication result indicates an authentication failure.
[0010] One example configuration of the above-mentioned communication processing device according to the present invention is configured such that the control unit extracts personal information from a communication message sent from the user terminal to any destination site and temporarily stores it as provisional data in the memory unit, and then, when an authentication result indicating successful authentication of the personal information is returned from the destination site, the provisional data is registered in the verification information as valid authentication information.
[0011] In order to achieve this objective, the communication processing program of the present invention causes a computer to execute the steps of: storing verification information including legitimate personal information used to access a legitimate site from a user terminal; and comparing the verification information with personal information included in a communication message sent from the user terminal to any destination site; and, if it is confirmed that the personal information is legitimate personal information, verifying whether the destination site is a phishing site based on the authentication result for the personal information returned from the destination site. [Effects of the Invention]
[0012] According to the present invention, it is possible to easily verify whether a destination site is a phishing site through simple processing. [Brief explanation of the drawings]
[0013] [Figure 1] FIG. 1 is a block diagram showing the configuration of a communication processing device. [Figure 2] FIG. 2 is an explanatory diagram illustrating an example of the configuration of verification information. [Figure 3] FIG. 3 is a sequence diagram showing the relay connection process. DETAILED DESCRIPTION OF THE INVENTION
[0014] Next, an embodiment of the present invention will be described with reference to the drawings. [Communications processing device] First, a communication processing device 10 according to this embodiment will be described with reference to Fig. 1. Fig. 1 is a block diagram showing the configuration of the communication processing device.
[0015] This communication processing device 10 is configured to relay and connect a user terminal 20, such as a PC or smartphone, connected to a subordinate local area network LAN (hereinafter referred to as LAN) to any site on the communication network NW, and to verify in advance whether the any site on the communication network NW to which the connection is made is a phishing site attempting to steal personal information.
[0016] Generally, legitimate sites authenticate whether the personal information notified from the user terminal 20 is legitimate by referencing legitimate personal information that has been registered in advance. On the other hand, phishing sites do not hold legitimate personal information like legitimate sites, and therefore cannot authenticate whether the personal information notified from the user terminal 20 is legitimate. For this reason, some phishing sites, after receiving personal information notified from the user terminal 20, always return an authentication failure regardless of whether the personal information is legitimate or fraudulent, and prompt the user to enter other personal information they have, thereby extracting more personal information.
[0017] Therefore, if a destination site is notified of legitimate personal information that can be authenticated at a legitimate site and the authentication result returned from the destination site indicates authentication failure, there is an extremely high possibility that the destination site is a phishing site. The present invention focuses on the characteristic behavior of phishing sites when such legitimate personal information is notified, and is configured to verify whether the destination site is a phishing site based on the authentication result returned from the destination site.
[0018] [Configuration of communication processing device] Next, the configuration of the communication processing device 10 according to the present embodiment will be described with reference to FIG. The communication processing device 10 is connected to a path that relays user terminals 20 connected to a subordinate LAN to a communication network NW such as the Internet. The communication processing device 10 may be configured separately from a network control device such as a UTM (Unified Threat Management) device or a gateway, or may be implemented within these network control devices.
[0019] As shown in FIG. 1, the communication processing device 10 includes a network side I / F 11, a LAN side I / F 12, a storage unit 13, and a control unit 14 as main circuit components.
[0020] [Network side I / F] The network side I / F 11 is configured to perform data communication with a communication network NW such as the Internet via a communication line L. In addition to a legitimate site 30, a phishing site 40 is connected to the communication network NW. [LAN side I / F] The LAN side I / F 12 is configured to perform data communication with the user terminal 20 via the LAN.
[0021] [Storage] The storage unit 13 is generally made up of a storage unit such as a semiconductor memory, and is configured to store various processing information and programs 13P used in the communication processing executed by the control unit .
[0022] The program 13P is a communication processing program that cooperates with the CPU of the control unit 14 to realize various processing units for executing mail processing in the control unit 14 and causes the computer to function as a communication processing device. The program 13P is stored in advance in the storage unit 13 from an external device or recording medium (neither of which is shown) connected to the communication processing device 10 via the communication line L or LAN.
[0023] [Verification information] Verification information 13A is one of the main pieces of processing information stored in storage unit 13. Verification information 13A is data including URL information indicating the legitimate site of user terminal 20 and legitimate personal information notified from user terminal 20 to the legitimate site. Fig. 2 is an explanatory diagram showing an example of the configuration of verification information. In the example of Fig. 2, for each ID that identifies a site, the URL information of the legitimate site and the legitimate personal information that is to be notified to the legitimate site are registered as a pair.
[0024] A blacklist 13B is one of the main processing information stored in the storage unit 13. The blacklist 13B is list data that indicates URL information of sites to which the user terminal 20 is prohibited from accessing, such as phishing sites.
[0025] [Control Unit] The control unit 14 has a CPU and its peripheral circuits, and is configured to realize various processing units that execute mail processing by causing the CPU and the program 13P in the storage unit 13 to work together.
[0026] The control unit 14 is configured to notify the designated destination site of personal information that is legitimate personal information, and to verify whether the destination site is a phishing site based on the authentication result regarding the personal information returned from the destination site.
[0027] Specifically, the control unit 14 is configured to extract personal information and URL information from a communication message (communication data) such as an access request sent from the user terminal 20 to any destination site on the communication network NW, temporarily store the information as provisional data in the memory unit 13, and then, when an authentication result indicating successful authentication of the personal information is returned from the destination site, register the provisional data as valid authentication information in the verification information 13A of the memory unit 13.
[0028] The control unit 14 is configured to extract personal information and URL information from a communication message sent from the user terminal 20 to any destination site on the communication network NW, and to verify that the personal information is legitimate personal information by referring to the verification information 13A in the storage unit 13. Furthermore, the control unit 14 is configured to determine that the destination site is a phishing site if it is verified that the personal information is legitimate personal information and the authentication result for the personal information returned from the destination site indicates authentication failure.
[0029] Furthermore, when the control unit 14 determines that the destination site is a phishing site, it may register the destination URL of the destination site in the blacklist 13B of the memory unit 13, and when the destination URL specified in the access request to the communication network NW sent from the user terminal 20 is included in the blacklist 13B, it may be configured to stop the relay process of the user terminal 20 that responded to the access request to the communication network NW.
[0030] In addition, if the control unit 14 determines that the destination site is a phishing site, it may notify the requesting user terminal 20 of a warning message indicating that the destination site specified in the access request is likely to be a phishing site.
[0031] [Operation of this embodiment] Next, the operation of the communication processing device 10 according to the present embodiment will be described with reference to Fig. 3. Fig. 3 is a sequence diagram showing a relay connection process. Here, a registration process for registering legitimate personal information and URL information included in an access request from the user terminal 20 in the verification information 13A, and a verification process for verifying whether the destination site is a phishing site based on the verification information 13A will be described.
[0032] [Registration process] 3, when an access request is sent from user terminal 20 (step 100), control unit 14 extracts personal information and URL information indicating the connection destination from the access request and temporarily stores them as temporary data in storage unit 13 (step 101). Next, control unit 14 transfers the access request from network side I / F 11 via communication line L to the connection destination site connected to communication network NW (step 102).
[0033] If the response to the access request from the destination site indicates successful authentication (step 103), the control unit 14 determines that the provisional data is legitimate personal information and registers it as verification information 13A in the memory unit 13 (step 104), thereby completing the series of processes.
[0034] In this case, if the number of times that the personal information is determined to be valid is less than a threshold value, the data may remain as provisional data, and only when the number of times that the personal information is determined to be valid reaches or exceeds a threshold value, the provisional data may be registered in verification information 13A in storage unit 13. Also, if the personal information is the same but the URL information is different, new URL information may be added to the provisional data one by one, and only when the URL information is different, the number of times that the personal information is determined to be valid may be incremented.
[0035] [Verification process] When legitimate personal information is registered in the verification information 13A of the storage unit 13 and an access request is sent from the user terminal 20 (step 110), the control unit 14 extracts the personal information from the access request and compares it with the verification information 13A of the storage unit 13 (step 111). Here, only if legitimate personal information matching the personal information is registered in the verification information 13A, is the personal information confirmed to be legitimate personal information (step 112).
[0036] Next, the control unit 14 transfers the access request from the network side I / F 11 to a destination site connected to the communication network NW via the communication line L (step 113). If the destination site is a phishing site, the legitimate personal information included in the access request will be stolen (step 114).
[0037] If an authentication failure is returned from the phishing site in order to exploit more personal information (step 115), control unit 14 determines that the destination site is a phishing site because the authentication failure was returned despite legitimate personal information being sent (step 116).In response to this, control unit 14 registers the URL information of this destination site (phishing site) in blacklist 13B of storage unit 13 (step 117).
[0038] From this point on, if the destination URL specified in a newly sent access request to the communication network NW from the user terminal 20 is included in the blacklist 13B, the control unit 14 will stop the relay process of the user terminal 20 in response to the access request to the communication network NW.
[0039] Furthermore, if the control unit 14 determines that the destination site is a phishing site, it notifies the requesting user terminal 20 via the LAN from the LAN-side I / F 12 and the LAN of a warning message indicating that the destination site specified in the access request is likely to be a phishing site (step 118), and terminates the series of processes. For example, if the personal information notified to the phishing site is related to a cashless payment card, the warning message may be used to urge the user to suspend use of the card.
[0040] In addition, if the control unit 14 determines that the destination site is a phishing site, it may be configured to notify the user terminal 20 requesting user confirmation as to whether the destination site of the access request is a phishing site, and to determine whether the destination site is a phishing site based on the user confirmation result returned from the user terminal 20.
[0041] Furthermore, the control unit 14 may be configured to register the destination URL of the destination site in the blacklist 13B of the memory unit 13 if it is determined that the destination site is a phishing site based on the user confirmation result returned from the user terminal 20.
[0042] Furthermore, in step 111, the control unit 14 may extract personal information and a destination URL from the access request, and even if legitimate personal information matching the personal information is registered in the verification information 13A, if the destination URL matches any of the URL information registered in the verification information 13A together with the legitimate personal information, the control unit 14 may terminate the verification process for the destination site. Note that, in order to verify whether a destination site is a phishing site, it is sufficient to confirm that the personal information notified to the destination site is legitimate personal information. Therefore, it is sufficient that at least legitimate personal information is registered in the verification information 13A.
[0043] [Advantages of this embodiment] In this way, in this embodiment, the control unit 14 of the communication processing device 10 is configured to compare personal information contained in a communication message sent from the user terminal 20 to any destination site with the verification information 13A in the memory unit 13, and if it is confirmed that the personal information is legitimate personal information, to verify whether the destination site is a phishing site based on the authentication result for the personal information returned from the destination site.
[0044] This makes it possible to easily verify whether a destination site is a phishing site through an extremely simple process of determining whether it is a phishing site based on the authentication results when accessing the destination site using legitimate personal information, without requiring a verification process that places a heavy processing burden on the browser, such as obtaining and comparing web access logs that include the types and sizes of resources used to construct the phishing site's web page.
[0045] [Extended embodiment] Although the present invention has been described above with reference to the embodiments, the present invention is not limited to the above embodiments. Various modifications that can be understood by those skilled in the art can be made to the configuration and details of the present invention within the scope of the present invention.
[0046] For example, the configuration of the memory unit 13 and the control unit 14 according to the present invention is not limited to the form in which they are implemented in the communication processing device 10 shown in FIG. 1 described above, but may also be implemented in a communication terminal device such as a personal computer or a smartphone, represented by a user terminal 20.
[0047] When implemented in user terminal 20, a portion of the memory unit of user terminal 20 can be configured to store verification information including legitimate personal information used to access a legitimate site from user terminal 20, and a portion of the control unit of user terminal 20 can be configured to compare the personal information included in a communication message sent from user terminal 20 to a destination site in response to user operation with the verification information in the memory unit, and if it is confirmed that the personal information is legitimate personal information, to verify whether the destination site is a phishing site based on the authentication result for the personal information returned from the destination site.
[0048] If the site is determined to be a phishing site, the URL information is notified to the communications processing device 10 and registered in the blacklist 13B of the storage unit 13. [Explanation of symbols]
[0049] 10...communication processing device, 11...network side I / F, 12...LAN side I / F, 13...memory unit, 13A...verification information, 13B...blacklist, 13P...program, 14...control unit, 20...user terminal, 30...legitimate site, 40...phishing site, L...communication line, LAN...local area network, NW...communication network.
Claims
1. a storage unit configured to store verification information including authentic personal information used for accessing a legitimate site from a user terminal; a control unit configured to compare personal information included in a communication message sent from the user terminal to any destination site with the verification information, and when it is confirmed that the personal information is the legitimate personal information, to verify whether the destination site is a phishing site based on an authentication result for the legitimate personal information returned from the destination site; A communication processing device comprising:
2. 2. The communication processing device according to claim 1, The communication processing device, wherein the control unit is configured to determine that the destination site is a phishing site when the authentication result indicates an authentication failure.
3. 2. The communication processing device according to claim 1, The control unit extracts personal information from a communication message sent from the user terminal to an arbitrary destination site and temporarily stores it in the memory unit as provisional data, and then, when an authentication result indicating successful authentication of the personal information is returned from the destination site, registers the provisional data in the verification information as valid authentication information.
4. On the computer, a step of storing verification information including valid personal information used to access a legitimate site from a user terminal; a step of comparing personal information included in a communication message sent from the user terminal to an arbitrary destination site with the verification information, and if the personal information is confirmed to be valid personal information, verifying whether the destination site is a phishing site based on an authentication result for the personal information returned from the destination site; A communication processing program that executes the above.
Citation Information
Patent Citations
Electronic mail system and transmission reception method for electronic mail by facsimile machine and telephone set
JP2001257712A
Authentication information fraud prevention system, program, and method
JP2006221242A
Phishing page detection method and system
JP2018504677A
Analyzer, detector, system and program
JP2021033421A