Anti-phishing system, anti-phishing device, anti-phishing program, and anti-phishing method
The system addresses the limitations of existing phishing detection by using seed domain collection and time-based analysis to identify and prevent phishing sites, enhancing detection accuracy and timeliness.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-10-17
- Publication Date
- 2026-04-02
AI Technical Summary
Existing phishing detection methods require pre-registration of legitimate and phishing site information in a database, which is insufficient for early prevention, and smishing is difficult to detect due to weak filtering capabilities in internet service providers and firewalls.
A system that collects seed domains associated with phishing sites, uses a database to store domain information including registration times, and compares the registration times of unknown domains with seed domains to determine potential malicious domains based on time differences and domain associations.
Enables early and reliable identification of phishing sites, improving detection rates and preventing phishing attacks by analyzing domain registration patterns.
Smart Images

Figure 0007839506000001 
Figure 0007839506000002 
Figure 0007839506000003
Abstract
Description
[Technical Field]
[0001] The present invention relates to a phishing prevention system, a phishing inspection device, a phishing prevention program, and a phishing prevention method. More specifically, it relates to a phishing prevention system, a phishing inspection device, a phishing prevention program, and a phishing prevention method that can identify phishing sites early and reliably based on domain information and prevent phishing from occurring. [Background technology]
[0002] With the widespread use of network-connected communication devices such as personal computers and smartphones, phishing attacks are becoming increasingly common worldwide. Phishing is a type of fraud in which emails impersonating well-known companies are sent to users' devices, and by clicking on a URL in the email body, users are lured to a malicious fake website (phishing site) that closely resembles a legitimate website, where personal information such as IDs and passwords is illegally stolen.
[0003] Phishing attacks, which were common in the wake of the rise of online banking, often involved scams impersonating financial institutions. However, in recent years, phishing sites impersonating other entities, such as major shopping sites or delivery companies, have become rampant. Furthermore, the methods used to lure users have expanded beyond email to include scams using short message services (SMS) via mobile phone numbers (phishing using SMS is specifically called "smishing"), making it increasingly difficult to detect phishing attacks.
[0004] Smishing, in particular, is more difficult to detect than email phishing because internet service providers, firewalls, or mail servers either lack filtering capabilities or have weak filtering capabilities, and it is becoming the mainstream form of phishing scams in recent years.
[0005] In Japan, phishing was reported for the first time in 2015. In particular, mobile devices with a high market share and a weak security operation system are likely to be targeted by hacker groups. As a countermeasure, major Japanese mobile carriers have announced that they will start detecting malware that causes phishing from 2022.
[0006] Regarding the above problems, for example, Patent Document 1 discloses a method for identifying a phishing site. Specifically, it is determined whether the domain name corresponding to the URL accessed by the user from the user terminal is registered in the database as the domain name of a legitimate website. If it is registered, no warning is given. If it is not registered, the similarity to the past display screen of the legitimate website is calculated. If the similarity to the past display screen is above a predetermined level, it is determined that there is a possibility of a phishing site and a warning is given.
Prior Art Documents
Patent Documents
[0007]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0008] However, according to the technology disclosed in Patent Document 1 described above, it is necessary to register the information of each of the legitimate website and the phishing site in the database in advance. However, it is often at a stage where the damage has expanded to a certain extent that the collection of this information becomes possible. Therefore, the technology disclosed in Patent Document 1 was insufficient for preventing phishing from the initial stage.
[0009] In this regard, as a result of intensive research by the inventor of the present application, paying attention to the fact that hacker groups engaged in phishing tend to register a large number of domains in a batch, considering the registration time difference between the domain of a known phishing site (seed domain) and newly registered malicious domains related to the seed domain, and the reception status of electronic information on the user terminal, it has been found that the probability (TPR) of being determined as a malicious domain and the false positive rate (FPR) of misdetecting a non-malicious domain as a malicious domain can be significantly improved among the population of domains extracted.
[0010] The present invention was created in view of the above points, and aims to provide a phishing prevention system, a phishing inspection device, a phishing prevention program, and a phishing prevention method that can identify a phishing site early and surely based on domain information and prevent phishing.
Means for Solving the Problem
[0011] To achieve the above object, the phishing prevention system of the present invention includes a user terminal capable of transmitting and receiving predetermined electronic information via a network line, a seed domain collection device that collects seed domains which are the domains of websites incorporating software that causes phishing by commands via the network line, a database that is a data group composed of a plurality of the seed domains collected by the seed domain collection device and is registered in association with predetermined domain information including the domain names of the seed domains, an extraction unit that extracts an inspection domain which is the domain of a URL included in the electronic information received by the user terminal, a determination unit that collates the inspection domain with the data group and determines whether the minimum value of the absolute value of the difference between the registration time of a selected seed domain arbitrarily selected from a seed domain aggregate which is an aggregate of the seed domains having a part of the domain information other than the domain name of the inspection domain in the data group and the registration time of the inspection domain is within a range of a predetermined threshold value, and a phishing inspection device.
[0012] Here, by providing a user terminal capable of sending and receiving predetermined electronic information via a network line, predetermined information, including the URL of a phishing site, can be extracted from the electronic information received by the user terminal. Then, based on the extracted predetermined information, an inspection is performed by the phishing inspection device described later, and the inspection results are output to the user terminal. If the electronic information received by the user terminal has the potential to cause phishing, the user can be warned accordingly.
[0013] Furthermore, by incorporating a seed domain collection device that collects seed domains, which are the domains of URLs of websites containing software that causes phishing via commands over a network connection, it is possible to collect any domain of a phishing site's URL and register it in the database described below.
[0014] Furthermore, by having a database in which a data set consisting of multiple species domains collected by a species domain collection device is registered in association with predetermined domain information including the domain names of the species domains, it is possible to utilize species domain information by creating a database of species domains that are transmitted and received via a network line.
[0015] Furthermore, by incorporating a phishing inspection device that extracts the inspection domain, which is the domain of the URL contained in the electronic information received by the user's terminal, and determines whether or not the inspection domain is a malicious domain under predetermined judgment conditions, it is possible to determine whether or not it is a seed domain, or a malicious domain registered in association with a seed domain, based on the domain information of the inspection domain contained in the URL. Then, by outputting the judgment result to the user's terminal, it is possible to prevent damage from phishing.
[0016] The phishing detection device then compares the detection domain with the data set of seed domains registered in the database. For example, if the domain name of the detection domain matches the domain name of a seed domain registered in the database, it determines that the detection domain is a seed domain and can immediately output the determination result to the user terminal.
[0017] On the other hand, if the domain names of the inspection domain and the seed domain do not match, it is determined whether the inspection domain is a malicious domain based on whether the minimum absolute value of the difference between the registration time of any selected seed domain chosen from a seed domain set (a collection of seed domains that share some of the domain information other than the domain name, such as the country of registration or the registrant) and the registration time of the inspection domain falls within a predetermined threshold range.
[0018] In other words, because hacker groups tend to register a large number of domains simultaneously, it can be inferred that domains registered without a time lag from a seed domain are malicious domains registered in relation to the seed domain. Furthermore, if the minimum absolute value of the difference between the registration time of a selected seed domain chosen from the seed domain set and the registration time of the domain being checked falls within a predetermined threshold, the domain being checked can be determined to be a malicious domain registered without a time lag from the selected seed domain. This allows for immediate determination that the domain is malicious, even if the domain name of the domain being checked does not match the domain name of the seed domain registered in the database.
[0019] Also, threshold t h Here, σ is defined as the standard deviation between the registration time of the inspection domain and the average registration time of the species domain set, and x is defined as the proportionality constant that defines the threshold, and t h When the relationship is expressed as =σ×x, it is possible to uniformly determine whether or not a domain being inspected is a malicious domain based on that relationship.
[0020] Furthermore, if the phishing inspection device has an output unit that outputs the determination result to the user terminal when the determination unit determines that the domain name of the inspection domain matches the domain name of at least one seed domain in the data group, then when it is determined that the domain name of the inspection domain matches the domain name of the seed domain, the device can immediately determine that the inspection domain is a malicious domain, output the determination result to the user terminal, and warn the user.
[0021] Furthermore, if, when it is determined that the domain name of the inspection domain does not match the domain name of the seed domain of the data set, a further determination is made based on a selected seed domain chosen from the seed domain set, and the determination result is output to the user terminal, then even if the domain name of the inspection domain and the domain name of the seed domain of the data set do not match, it is possible to determine whether the inspection domain is a malicious domain based on the selected seed domain, thereby increasing the detection rate of malicious domains.
[0022] Furthermore, the seed domain collection device has an infected terminal with built-in software that can execute commands via a network connection. When identifying a seed domain from domain information contained in the transmitted and received logs of the infected terminal and sending it to the database, the infected terminal can receive electronic information sent from the hacker group. By identifying the seed domain from the received electronic information and sending the identified seed domain to the database to constantly update the database, the detection rate of malicious domains in the judgment unit can be increased.
[0023] To achieve the above objective, the phishing inspection device of the present invention includes an extraction unit that extracts an inspection domain, which is the domain of a URL contained in electronic information received by a user terminal capable of sending and receiving predetermined electronic information via a network line, and a determination unit that compares the inspection domain with a data set consisting of multiple species domains, which are the domains of URLs of websites incorporating software that causes phishing via a command via a network line, and determines whether the minimum absolute value of the difference between the registration time of one selected species domain, which is a collection of species domains from the data set in which a part of the domain information of the inspection domain is common, and the registration time of the inspection domain is within a predetermined threshold range.
[0024] With the above configuration, it is possible to immediately determine whether the domain of a URL contained in the electronic information received by the user's terminal is a seed domain, or even if it is not a seed domain, whether it is a malicious domain, and output the result of this determination to the user's terminal, thereby preventing phishing attacks.
[0025] To achieve the above objective, the phishing prevention program of the present invention causes a computer to perform the following steps: extract a test domain, which is a domain to be inspected, from a URL contained in predetermined electronic information received by a user terminal via a network line; compare the test domain with a data set consisting of seed domains, which are the domains of URLs of websites that incorporate software that causes phishing; if the domain name of the test domain and the domain name of the seed domain in the data set do not match, extract one selected seed domain arbitrarily selected from a seed domain set, which is a collection of seed domains that have some of the domain information other than the domain name of the test domain in common; determine whether the minimum absolute value of the difference between the registration time of the selected seed domain and the registration time of the test domain is within a predetermined threshold range; and if the absolute value of the difference is within the threshold range, output the determination result to the user terminal.
[0026] Here, by including a step of extracting the inspection domain, which is the domain to be inspected, from the URL contained in predetermined electronic information received by the user terminal via a network line, the domain name contained in the URL can be extracted as the target for inspection.
[0027] Furthermore, by including a step to compare the inspection domain with a data set consisting of species domains, which are the domains of URLs of websites containing software that causes phishing, for example, the domain name of the inspection domain can be compared with the domain name of one of the species domains that make up the data set. If the respective domain names match, it can be immediately determined that the inspection domain is a species domain, and the determination result can be output to the user terminal.
[0028] Furthermore, if the domain name of the inspection domain does not match the domain name of the seed domain in the data set, the system includes a step to extract one arbitrarily selected seed domain from a seed domain set, which is a collection of seed domains that share some of the domain information other than the domain name of the inspection domain. This allows the system to define a seed domain set as a collection of seed domains that share domain information other than the domain name (e.g., country of registration or registrant), and to determine whether the inspection domain is a malicious domain based on an arbitrary selected seed domain from this seed domain set, thereby increasing the detection rate of malicious domains.
[0029] Furthermore, by including a step to determine whether the minimum absolute value of the difference between the registration time of the selected species domain and the registration time of the inspection domain falls within a predetermined threshold range, it is possible to presume that a domain registered without a time difference from the selected species domain is a malicious domain registered in relation to the selected species domain, and to determine whether the inspection domain is a malicious domain.
[0030] Furthermore, by including a step that outputs the determination result to the user's terminal when the minimum absolute value of the difference falls within a threshold range, it is possible to prevent phishing attacks by notifying the user that the received electronic information may contain malicious domains.
[0031] Furthermore, if the step of comparing a data set consisting of a test domain and a seed domain includes a step of outputting the determination result to the user terminal when it is determined that the domain name of the test domain matches the domain name of one of the seed domains included in the data set, then when it is determined that the domain name of the test domain matches the domain name of the seed domain, the test domain can be immediately determined to be a malicious domain, the determination result can be output to the user terminal, and a warning can be issued to the user.
[0032] To achieve the above objective, the phishing prevention method of the present invention comprises the steps of: extracting a test domain, which is a domain to be tested, from a URL contained in predetermined electronic information received by a user terminal via a network line; comparing the test domain with a data set consisting of seed domains, which are the domains of URLs of websites in which software that causes phishing is incorporated; extracting a selected seed domain arbitrarily selected from a seed domain set, which is a collection of seed domains in which some of the domain information other than the domain name of the test domain is common, if the domain name of the test domain and the domain name of the seed domain in the data set do not match; determining whether the minimum absolute value of the difference between the registration time of the selected seed domain set and the registration time of the test domain is within a predetermined threshold range; and outputting the determination result to the user terminal if the absolute value of the difference is within the threshold range.
[0033] By following the above steps, it is possible to immediately determine whether the domain of a URL contained in the electronic information received on the user's terminal is a seed domain, or even if it is not a seed domain, whether it is a malicious domain, and output the result of this determination to the user's terminal, thereby preventing phishing attacks. [Effects of the Invention]
[0034] The phishing prevention system, phishing inspection device, phishing prevention program, and phishing prevention method according to the present invention are capable of early and reliable identification of phishing sites based on domain information, thereby preventing phishing from occurring. [Brief explanation of the drawing]
[0035] [Figure 1] This is a schematic diagram of a phishing prevention system according to an embodiment of the present invention. [Figure 2] This graph shows the deviation between the inspection domain and the species domain for any given malware. [Figure 3] This graph shows the relationship between FNR and FPR for each SMS reception rate. [Figure 4] This diagram shows the registration flow for a species domain into the database. [Figure 5] This diagram shows the judgment flow in a phishing inspection device. [Figure 6] This figure shows the results of scanning an arbitrary piece of malware. [Modes for carrying out the invention]
[0036] Hereinafter, the phishing prevention system, phishing inspection device, phishing prevention program, and phishing prevention method according to embodiments of the present invention will be described in detail with reference to drawings and other materials to facilitate understanding of the present invention.
[0037] Figure 1 shows the overall configuration of a phishing prevention system 1 according to an embodiment of the present invention. The phishing prevention system 1 mainly consists of a user terminal 10, a phishing inspection device 20, a species domain collection device 30, and a database 40, and each of these components is in a state where it can communicate with each other via a network line 50.
[0038] [User terminal] The user terminal 10 includes a mobile device (smartphone, tablet, etc.) or personal computer owned by the user, and is capable of communicating with a server (not shown) via a network line 50, and of sending and receiving predetermined electronic information (email, short message) with other communication terminals.
[0039] [Species Domain Collection Device] The seed domain collection device 30 has the function of collecting seed domains, which are domains that can identify the URLs of websites that contain software that causes phishing, via commands sent through the network line 50. It consists of some bots 31 that make up a botnet (a network built by computers that perform malicious activities) under the control of a hacker group, and a control device 32 that collects electronic information of the bots 31.
[0040] Here, the domains collected by the seed domain collection device 30 are not particularly limited, but for example, any domain that identifies a URL, or a combination of multiple domains, can be collected.
[0041] Bot 31 has phishing software installed on it, is able to communicate with a management server 60 controlled by the hacker group, and functions as a source to send instructions from the hacker group to an unspecified number of communication terminals via Bot 31.
[0042] In this embodiment of the present invention, software that causes phishing is pre-installed on any mobile device to function as a bot 31, and the bot 31 is configured to communicate only with the management server 60 and the control device 32, with communication with other communication devices being restricted. When the bot 31 starts communicating with the management server 60, the control device 32 acquires the communication information exchanged between the bot 31 and the management server 60.
[0043] [Database] Database 40 is a storage device where multiple seed domains collected by the seed domain collection device 30 are registered. When the control device 32 identifies a domain name from a URL contained in the electronic information received by the bot 31, the identified domain is sent to database 40. When database 40 receives a domain, it refers to predetermined information corresponding to that domain (domain registration time, domain registrant, domain registration country, etc.) from an external domain name registry 70, associates this information with the domain name, and databases it as domain information, forming a set of data.
[0044] Since bot 31 is able to communicate with the management server 60, whenever it receives new electronic information from the management server 60, the control device 32 analyzes the received electronic information, and if a new domain is extracted as a result of the analysis, it sends the extracted domain to the database 40. Therefore, the data set registered in the database 40 is always updated to the latest state.
[0045] Generally, hacker groups tend to abandon a group of domains they registered in bulk after a certain period and acquire a new group of domains. Therefore, it may be advisable to automatically delete domain information registered in database 40 after a predetermined period has elapsed, freeing up storage space to ensure that the latest domain information can always be registered.
[0046] [Phishing Inspection Device] The phishing inspection device 20 is installed on the user terminal 10 and is capable of executing a program that determines whether the domain of a URL contained in electronic information received by the user terminal 10 is a malicious domain that causes phishing. It consists of an extraction unit 21, a determination unit 22, and an output unit 23.
[0047] Here, the phishing detection device 20 does not necessarily need to be installed on the user terminal 10. For example, an external phishing detection device 20 may be configured to communicate with the user terminal 10 wirelessly or via a wired connection.
[0048] The extraction unit 21 has the function of identifying and extracting domains from URLs contained in electronic information. The extracted domains (hereinafter referred to as "inspection domains") are determined by the determination unit 22 to be malicious or not. The determination result from the determination unit 22 is then output to the user terminal 10 from the output unit 23. Therefore, by checking the determination result through the user terminal 10, the user can immediately determine whether the received electronic information contains a URL with a malicious domain or not.
[0049] The above describes the main hardware configuration of the phishing prevention system 1. Next, the specific inspection method for the inspection domain in the determination unit 22 will be explained. In the determination unit 22, if the domain name of the inspection domain matches the domain name of at least one species domain among the data group registered in the database 40, the inspection domain is determined to be a malicious domain. Otherwise, the determination of whether or not the inspection domain is a malicious domain is made according to the following calculation formula.
[0050] First, when the user terminal 10 receives electronic information, the inspection domain d displayed in the URL included in the received electronic information is checked. i Extract and check domain d i The registration time (generation time) is t(d i ) is defined as follows. Then, the selected species domain d satisfies the following equation (1) jWhen the registration time t(d j ) exists, the inspection domain d i is determined to be a malicious domain. |t(d i ) - t(d j )| ≤ t h (1)
[0051] To obtain the threshold t h defined by the above formula (1), the false negative rate (FNR) and the false positive rate (FPR) are calculated respectively. First, a set G (seed domain aggregate) of domains registered collectively as arbitrary malware for any OS and a set G' of domains unrelated to arbitrary malware for any OS are defined respectively. Here, the seed domain aggregate is an aggregate of domains where the domain names of each domain are different, but all other domain information (registration country, registrant, etc.) is the same. Among the seed domains constituting this seed domain aggregate, the seed domain with the minimum registration time is defined as the selected seed domain d j as defined above.
[0052] Here, necessarily, each domain constituting the seed domain aggregate does not necessarily need to have all domain information other than the domain name match, and may be composed of domains where some domain information matches.
[0053] FNR and FPR are related to the following formulas (2) and (3) respectively. As described later, in this embodiment, the threshold t h when FNR and FPR match is used. FNR = P(|t(d i ) - t(d j )| > t h |d i , d j Y ∈ G) (2) FPR = P(|t(d i ) - t(d j )| ≤ t h |d i ∈ G', d j Y ∈ G) (3)
[0054] Next, as shown in equation (4), t(d i The deviation L between ) and t(G) i Define. L i =t(d i )-t(d j ) (4) Note that t(G) is the average registration time of the domains included in the species domain set, and can be expressed by equation (5). t(G)=Σ d∈G t(d) / |G| (5)
[0055] Figure 2 shows the deviation L measured for arbitrary malware. i The horizontal axis represents the registration time of the domain. Note that the standard deviation σ in Figure 2 is the value for any set of species domains, and in this embodiment it is 4.4 seconds. Here, L i The mean is 0, and the variance is σ. 2 The normal distribution N(0, σ) 2 Let's assume that it follows a compound Poisson process. In this case, the number of domains registered generally follows a compound Poisson process. And the number of domains d registered at time (0, t) k Assuming that the number Z(t) ∈G' also follows the same rule, we define it as shown in equation (6). Z(t) = Y1 + Y2 + ...Y N(t) (6)
[0056] Here, N(t) is a Poisson distribution of the batch generation rate λ, and "Y1 + Y2 + ..." are independent, identically distributed Poisson random variables with mean batch size μ. Therefore, the expected value of Z(t) can be expressed as E(Z(t)) = λμt. Note that λμ is both the domain registration rate and the arrival rate (arrival frequency) of electronic information including URLs at the user terminal 10.
[0057] The above deviation L i Based on the assumption of the number of domains Z(t), FNR and FPR can be expressed by equations (7) and (8) below, respectively. Note that x = t h It is / σ. FNR = 1 - erf(x / 2) (7) FPR = 1 - exp(-2λσx(1 - e)-μ )) (8)
[0058] FNR is a monotonically decreasing function, and FPR is a monotonically increasing function. When plotted on a graph, they are shown in Figure 3, and there is one intersection point. Note that the horizontal axis x is the threshold t. h This is a proportionality constant that defines the relationship. The intersection point represents the equal error rate (EER) where FNR and FPR coincide, and the threshold t is calculated from the value of x on the horizontal axis at that point. h =xσ can be determined. For example, unlike email, SMS messages are not received very frequently on the user's terminal 10. If we assume an SMS arrival rate of 1 message per day (λμ=1), then ER=0.05%, which means that malicious domains can be reliably detected.
[0059] Next, a phishing prevention program according to an embodiment of the present invention will be described. Figure 4 is a diagram showing the registration flow of species domains collected by the species domain collection device 30 into the database 40.
[0060] First, bot 31 and management server 60 communicate, and once the domain name is identified from the URL contained in the electronic information received from management server 60 (STEP 11), domain information including the country of registration, registrant, and registration time, along with the domain name, is registered in database 40 based on information from the domain name registry (STEP 12), and the value of σ, which is the standard deviation for each piece of malware, is updated (STEP 13). By repeating STEP 11 to STEP 13, the data in database 40 is always kept up-to-date.
[0061] Next, based on Figure 5, we will explain the judgment flow in the phishing inspection device 20 when electronic information is received by the user terminal 10.
[0062] First, when the user terminal 10 receives electronic information containing a URL (STEP 21), the inspection domain d is accessed from the URL contained in the electronic information. i Identify (STEP22). Then, the inspection domain d identified in STEP22. iCheck whether a species domain with the same domain name as the given domain name is registered in database 40 (STEP 23).
[0063] If "YES" is selected in STEP 23, that is, the inspection domain d i If a species domain with the same domain name as the domain name is registered in database 40, then the inspection domain d i The system identifies the domain as a malicious phishing site and outputs the result to the user terminal 10 (STEP 24).
[0064] On the other hand, if the answer is "NO" in STEP23, that is, the inspection domain d i If no species domain with the same domain name as the domain name is registered in database 40, then the inspection domain d is determined based on the formula (1) described above. i and any selected species domain d selected from the species domain collection j Calculate the minimum absolute value δ of the difference between the registration time and the current time (STEP 25).
[0065] The phishing detection device 20 then calculates the EER (intersection in Figure 3) and threshold t based on a preset standard deviation σ, the reception rate λ of electronic information on the user terminal 10, and the average batch size μ. h We perform the calculation, and δ≦t h Determine whether or not (STEP26). If the determination in STEP26 is "YES", then the inspection domain d i is selected species domain d j It is determined that the domain is malicious if it has been registered in connection with [the relevant information]. On the other hand, if the answer in STEP 26 is "NO", it is determined that the domain is not malicious. The result of this determination is then output from the output unit 23 to the user terminal 10 (STEP 27).
[0066] Figure 6 shows the results of a malware scan of a random malware (FakeSpy) using the malware scanning website (VirusTotal). Note that the first-level domain is always ".com". In Figure 6, "Arrival Date" is the date the electronic information was received on user terminal 10, and "Registration Date" is the date (including time information) each domain was registered. SLDs with the same registration date are included in the set of domains registered together. VirusTotal is a site that uses datasets and scanning engines from 94 security companies to output the number of companies that identified a domain as malicious. As shown in Figure 6, the detection results for the first few days after arrival are almost all 0 (not detected).
[0067] In contrast, the SLD corresponding to "0" in Figure 6 has a species domain (a domain with the same registration date and a test result greater than 0), so equation (1) above holds true, and there is a possibility of detecting a malicious domain. For example, when λ=0.1, from Figure 3, t h =xσ=5.7×4.4>25, and from Figure 2, -10 <L i The result is <15. Therefore, by applying the present invention, it is possible to detect malicious domains in the "0" cells in Figure 6, and thus potentially improve the detection results.
[0068] As described above, the phishing prevention system, phishing inspection device, phishing prevention program, and phishing prevention method to which the present invention is applied can identify the domain of a phishing site that causes phishing early and reliably, and prevent phishing before it occurs. [Explanation of symbols]
[0069] 1. Anti-phishing system 10. User terminals 20 Fishing Inspection Device 21 Extraction part 22 Judgment section 23 Output section 30-domain collection device 31 Bots 32 Control device 40 databases 50 network lines 60 Management Servers 70 Domain Name Registries
Claims
1. A user terminal capable of sending and receiving specified electronic information via a network line, A seed domain collection device that collects seed domains, which are the URL domains of websites containing software that causes phishing via commands transmitted over a network line, A data set consisting of multiple species domains collected by the species domain collection device, and a database in which the data set is registered in association with predetermined domain information including the domain names of the species domains, The phishing inspection device includes: an extraction unit that extracts an inspection domain, which is the domain of a URL contained in the electronic information received by the user terminal; and a determination unit that compares the inspection domain with the data group and determines whether the absolute value of the difference between the registration time of a selected species domain, which is the species domain in the data group that has some of the domain information other than the domain name of the inspection domain in common with the inspection domain and whose registration time is the shortest, and the registration time of the inspection domain, is within a predetermined threshold range. Anti-phishing system.
2. The fishing inspection device is The determination unit has an output unit that outputs the determination result to the user terminal when it is determined that the domain name of the inspection domain matches the domain name of at least one of the species domains in the data group. The anti-phishing system according to claim 1.
3. The output unit is If the determination unit determines that the domain name of the inspection domain and the domain name of the species domain in the data group do not match, the determination unit performs a determination based on the selected species domain and outputs the determination result to the user terminal. The phishing prevention system according to claim 2.
4. The species domain collection device has an infected terminal into which the software is incorporated and which is capable of executing commands via a network line, The domain type is identified from the domain information contained in the transmission and reception logs of the infected terminal and transmitted to the database. The anti-phishing system according to claim 1.
5. An extraction unit that extracts an inspection domain, which is the domain of a URL contained in electronic information received by a user terminal capable of sending and receiving predetermined electronic information via a network line, The system includes a determination unit that compares a data set consisting of multiple species domains, which are the domains of URLs of websites containing software that causes phishing via commands over a network line, with the inspection domain, and determines whether a portion of the domain information other than the domain name of the inspection domain is common to the selected species domain, and whether the absolute value of the difference between the registration time of the selected species domain (which has the shortest registration time) and the registration time of the inspection domain falls within a predetermined threshold range. Fishing inspection device.
6. A step of extracting a test domain, which is a domain to be inspected, from a URL contained in predetermined electronic information received by a user terminal via a network line, The steps include comparing the aforementioned inspection domain with a set of data consisting of species domains, which are the domains of URLs of websites that contain software that causes phishing; If the domain name of the inspection domain and the domain name of the species domain in the data group do not match, the step of extracting a selected species domain in which some of the domain information other than the domain name of the inspection domain is common and the species domain has the shortest registration time, The steps include determining whether the absolute value of the difference between the registration time of the selected domain and the registration time of the inspection domain falls within a predetermined threshold range, The computer is instructed to perform the following steps: if the absolute value of the difference is within the range of the threshold, output the determination result to the user terminal. Phishing prevention program.
7. The step of comparing the inspection domain with a data group consisting of the species domains, wherein if it is determined that the domain name of the inspection domain matches the domain name of at least one of the species domains in the data group, the determination result is output to the user terminal. The phishing prevention program according to claim 6.
8. A step of extracting a test domain, which is a domain to be inspected, from a URL contained in predetermined electronic information received by a user terminal via a network line, The process involves comparing the aforementioned inspection domain with a data set consisting of species domains, which are the domains of URLs of websites that contain software that causes phishing. If the domain name of the inspection domain and the domain name of the species domain in the data group do not match, a step is taken to extract a selected species domain which has some of the domain information other than the domain name of the inspection domain in common and whose registration time is the shortest. A step of determining whether the absolute value of the difference between the registration time of the selected species domain and the registration time of the inspection domain is within a predetermined threshold range, The process includes outputting the determination result to the user terminal if the absolute value of the difference is within the range of the threshold. Methods to prevent phishing.
Citation Information
Patent Citations
Method of removing chip in cutting and joining machine for scarf of veneer
JP1982053302A
Early detection of risky domains via registration profiling
US10911477B1