Phishing warning device, phishing warning method, and phishing warning program
The phishing warning device addresses the accuracy issues of existing methods by using data deviation analysis to automatically detect and warn users of heightened phishing risk, enhancing their awareness and reducing deception.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-12-05
- Publication Date
- 2026-04-13
AI Technical Summary
Existing phishing detection methods lack sufficient accuracy, and users are often deceived due to susceptibility factors like unfamiliar environments or busy situations, necessitating a more reliable method to automatically detect and warn users of potential phishing threats.
A phishing warning device that acquires data at predetermined times, calculates deviation from normal values, and displays warning messages when certain conditions are met, using location, workload, and other indicators to alert users of heightened phishing risk.
The device effectively detects unusual situations making users susceptible to phishing, reducing the risk of deception by automatically warning users and improving their judgment in such scenarios.
Smart Images

Figure 0007844320000001 
Figure 0007844320000002 
Figure 0007844320000003
Abstract
Description
Technical Field
[0001] The present invention relates to a warning device for suppressing phishing damage.
Background Art
[0002] Conventionally, damages due to phishing, in which information such as IDs, passwords, and credit card information is stolen from users by posing as a service provider on the Internet, have been reported. In Non-Patent Document 1, a risk factor analysis of phishing damage is performed, and it is shown that a large workload and urgent work are indirectly at risk of being deceived by an attack. In addition, in Non-Patent Document 2, a survey of papers on phishing attack detection methods using deep learning is performed, and detection methods for phishing mails or phishing sites are introduced.
Prior Art Documents
Non-Patent Documents
[0003]
Non-Patent Document 1
Non-Patent Document 2
Summary of the Invention
Problems to be Solved by the Invention
[0004] To prevent phishing attacks, various studies have been conducted, such as those related to phishing email detection, as shown in Non-Patent Document 2. However, the accuracy of these detection methods is not yet sufficient, so the final decision of whether an email is a phishing email rests with the recipient. However, even when the same user receives the same phishing email, there are conditions under which they are more susceptible to being deceived, such as being in an unfamiliar environment like a business trip or being out, or being in a busy situation as described in Non-Patent Document 1.
[0005] The present invention aims to provide a phishing warning device, a phishing warning method, and a phishing warning program that can automatically detect unusual situations that make users susceptible to phishing and warn them accordingly. [Means for solving the problem]
[0006] The phishing warning device according to the present invention includes: a data acquisition unit that acquires at least one piece of data at a predetermined timing, the normal value of which can be estimated, which may be a factor in reducing the user's attention; a deviation degree calculation unit that calculates the degree of deviation of the data acquired by the data acquisition unit from the normal value; and a warning display unit that, if at least one piece of data with a deviation degree of or greater than a predetermined value is acquired, displays a warning message indicating that there is a high possibility of being deceived by a phishing scam.
[0007] The data acquisition unit may acquire the data at a predetermined timing when the user checks their email.
[0008] The deviation calculation unit may learn the fluctuation pattern of the normal value and calculate the degree of deviation from that fluctuation pattern.
[0009] The aforementioned data may include location information or usage time.
[0010] The aforementioned data may include indicators relating to the user's workload.
[0011] The warning display unit may display the warning message if the deviation level remains above a predetermined level for a predetermined period of time or longer.
[0012] The phishing warning device may include a warning selection unit that selects a warning message according to the type of data in which the degree of deviation exceeds a predetermined level.
[0013] The warning selection unit may select the warning message and the display mode of the warning message according to the degree of deviation.
[0014] The phishing warning device may include a warning selection unit that selects a warning message and a display method for the warning message according to the number of data points in which the deviation degree exceeds a predetermined level.
[0015] The warning selection unit may select the warning message and the display method of the warning message by weighting according to the type of data in which the deviation is greater than or equal to a predetermined level.
[0016] The phishing warning method according to the present invention includes a data acquisition step in which a computer acquires at least one piece of data at a predetermined time from which a normal value can be estimated, which may be a factor in reducing the user's attention; a deviation degree calculation step in which the computer calculates the degree of deviation of the data acquired in the data acquisition step from the normal value; and a warning display step in which, if at least one piece of data with a deviation degree of or greater than a predetermined value is acquired, the computer displays a warning message indicating that there is a high possibility of being deceived by a phishing scam.
[0017] The phishing warning program according to the present invention is for causing a computer to function as the phishing warning device. [Effects of the Invention]
[0018] According to the present invention, it is possible to automatically detect a situation different from the normal situation that is vulnerable to phishing and warn the user.
Brief Description of the Drawings
[0019] [Figure 1] It is a diagram showing the functional configuration of the phishing warning device in the embodiment. [Figure 2] It is a diagram illustrating a method for determining deviation in the embodiment. [Figure 3] It is a diagram showing an example of display of a warning message in the embodiment. [Figure 4] It is a flowchart showing the procedure of the phishing warning method in the embodiment.
Mode for Carrying Out the Invention
[0020] Hereinafter, an example of an embodiment of the present invention will be described. The phishing warning device of the present embodiment displays a warning message for preventing damage by estimating whether the user is in a situation vulnerable to phishing fraud.
[0021] Here, as an example of the timing when it is easy to suffer phishing fraud damage, it is assumed that the user checks an email. For example, in order to correctly distinguish a phishing email when the user checks an email, a function for displaying a warning message according to the situation is implemented by a mail add-on or the like. Thereby, the terminal as a phishing warning device detects the position of the user, the time zone, and the situation of the user's busyness, and displays a warning when it is determined that the user is checking an email under a situation different from the normal (ordinary) situation. As a result, even if the user receives a phishing fraud email, it is possible to improve the attention and prompt a correct judgment.
[0022] FIG. 1 is a diagram showing the functional configuration of the phishing warning device 1 in the present embodiment. The phishing warning device 1 is an information processing device (computer) equipped with a control unit 10 and a storage unit 20, as well as various data input / output devices and communication devices, and is a terminal on which software (mailer) for the user to send and receive emails, and add-ons for realizing each of the functions of this embodiment are installed.
[0023] The control unit 10 controls the entire phishing warning device 1, and by appropriately reading and executing various programs stored in the memory unit 20, it operates as the respective functional units described later, thereby realizing the functions in this embodiment. The control unit 10 may be a CPU.
[0024] The storage unit 20 is a storage area for various programs and data necessary for the hardware group to function as a phishing warning device 1, and may be ROM, RAM, flash memory, or a hard disk drive (HDD). Specifically, the storage unit 20 stores various databases and the like, in addition to add-ons (phishing warning programs) that cause the control unit 10 to execute each of the functions of this embodiment.
[0025] The control unit 10 includes a data acquisition unit 11, a deviation degree calculation unit 12, a warning selection unit 13, and a warning display unit 14.
[0026] The data acquisition unit 11 acquires at least one piece of data at a predetermined time that allows for the estimation of the normal value of the phishing warning device 1, which could be a factor in reducing the user's attention. The predetermined timing is when the user checks the email, and more specifically, it may be set in advance as when the email is opened, when a link (URL) in the email body is clicked, or when an attachment is clicked. When the data acquisition unit 11 detects these events, it acquires the predetermined data.
[0027] The acquired data is input data used to estimate that the user is in a situation different from normal. Examples include data that is almost constant under normal circumstances, such as location information, and data that fluctuates even under normal circumstances, such as the number of new and unread emails. Here, as an example, we will illustrate the case where two types of data are obtained: Wi-Fi® connection destination information as location information, and the number of new and unread emails.
[0028] The deviation calculation unit 12 calculates the degree of deviation between the data acquired by the data acquisition unit 11 and the normal state. The degree of deviation may be a value indicating the presence or absence of deviation, or it may be a value corresponding to the difference from the normal value.
[0029] Specifically, for example, in the case of Wi-Fi connection information, the access point with the longest connection time among the Wi-Fi connection information over a certain period of time in the past is considered to represent the normal state, and all others are considered to deviate from the normal state. Furthermore, in the case of time-series data such as the number of unread new emails, the normal fluctuation pattern of the values can be learned in advance using an ARMA / ARIMA model, and if the acquired data deviates from this normal fluctuation pattern and exceeds a certain threshold, it is considered to have deviated from normal. Alternatively, regardless of fluctuation, it may be considered to have deviated from normal if it exceeds a certain fixed threshold.
[0030] Figure 2 illustrates the method for determining the deviation in this embodiment. For example, if a normal fluctuation pattern A is obtained by training a predetermined model, the deviation calculation unit 12 may determine that there is a deviation from the normal state if the input data at a certain point in time exceeds B, which is a predetermined value greater than A (estimated value). Alternatively, the deviation calculation unit 12 may determine that the input data deviates from normal conditions if it exceeds a fixed threshold C, regardless of normal fluctuations.
[0031] The warning selection unit 13 selects a warning message indicating a high probability of being deceived by a phishing scam if at least one data point is acquired in which the deviation degree calculated by the deviation degree calculation unit 12 exceeds a predetermined level.
[0032] The warning display unit 14 displays the warning message selected by the warning selection unit 13, for example, at a predetermined location on the mailer application screen, or as a pop-up.
[0033] Figure 3 shows an example of the display of a warning message in this embodiment. Warning messages are displayed, for example, in a pre-set location on the mail client screen. Here, we show an example where a portion of the menu bar is used as the display area, but this is not the only option.
[0034] The warning message could be a fixed message such as, "Unusual conditions have been detected when you normally check your email. You are generally more susceptible to scams. Please be careful." Furthermore, the warning selection unit 13 may select a warning message using individual rules depending on the type of data that deviates from normal conditions. For example, if a deviation from normal conditions is detected in the Wi-Fi connection information, a location-specific message such as "You are checking your email in an unusual location. This is a situation where you are generally more susceptible to fraud. Please be careful." may be used.
[0035] Furthermore, as a variation of the warning message, the warning selection unit 13 may select a warning message and a display method for the warning message according to the magnitude of the deviation or according to the number of data points whose deviation exceeds a predetermined level. The display method can be designed as appropriate, such as by color-coding the message in stages or changing the display size. In this case, the warning selection unit 13 may select warning messages and the display modes of warning messages in stages based on a comprehensive evaluation that weights data according to the type of data whose deviation exceeds a predetermined level, that is, data related to situations that are more likely to deceive.
[0036] [Variations of input data] Up to this point, we have explained how to obtain Wi-Fi connection information as location information and the number of new and unread emails, but the input data is not limited to these, and may consist of three or more types of data. For example, it may be designed with the following data (1) to (6).
[0037] (1) Location information (GPS, wireless base stations, etc.) The location where the terminal is normally used can be set using, for example, a known clustering method. The deviation calculation unit 12 detects a deviation from the normal location if it is more than N kilometers (for example, 1 km) away from this normal location.
[0038] (2) CPU load of the terminal The deviation calculation unit 12 detects a deviation from normal conditions when the CPU load exceeds a threshold or exceeds a certain fixed threshold compared to the estimated value (fluctuation pattern) under normal conditions.
[0039] (3) Number of applications running on the device The deviation calculation unit 12 detects the deviation from normal conditions, similar to (2), based on the number of applications running on the terminal or the number of applications launched recently (for example, within the last hour).
[0040] (4) Operating hours The usage frequency for each day of the week, or for weekdays and holidays separately, can be used as normal data for each hour. For example, if the normal data shows that the terminal is activated 80% of the time between 8:00 and 9:00 on weekdays, and 1% between 23:00 and 24:00, the deviation calculation unit 12 will detect a deviation from normal data if the terminal is activated during time periods below N%.
[0041] (5) Planned number By learning the fluctuation patterns of the number of appointments registered in the user's schedule linked to the mail client, or in schedules managed by another application, or by performing statistical processing on a daily basis (for example, an average of N appointments on Mondays, etc.), an estimate of the normal state can be obtained. The deviation calculation unit 12 detects a deviation from normal conditions if the number of scheduled events exceeds a threshold or exceeds a certain multiple compared to this estimated value.
[0042] (6) Remaining time until the next appointment The system stores the statistical values (mean, variance, median, etc.) of the remaining time until the next appointment at the time the email is checked as the normal value. The deviation calculation unit 12 detects deviations from normal if the acquired remaining time is shorter than a predetermined amount than the normal average, or if the standard score is below a predetermined amount, etc.
[0043] Furthermore, since the degree of deviation may increase instantaneously, for example, in the case of CPU load, the warning display unit 14 may only display a warning message if the period of time for which a deviation is determined to be present exceeds a predetermined time.
[0044] Figure 4 is a flowchart showing the procedure for the phishing warning method in this embodiment. It should be assumed that normal-time information corresponding to the input data is pre-stored.
[0045] In step S1, the control unit 10 detects a predetermined event that the user should be aware of as a phishing attempt when checking an incoming email.
[0046] In step S2, the data acquisition unit 11 acquires multiple input data related to the user's attention.
[0047] In step S3, the deviation calculation unit 12 calculates the degree of deviation from the normal state for each of the input data acquired in step S2.
[0048] In step S4, the control unit 10 determines whether there is input data that deviates from the normal state. If the determination is YES, the process moves to step S5. If the determination is NO, the user is determined to be in a normal state and the process ends. The control unit 10 may update the stored normal information based on input data that is determined not to deviate from the normal state.
[0049] In step S5, the warning selection unit 13 selects a warning message to alert the user that there is a high possibility of being deceived by a phishing scam, based on the number and type of input data that deviates from normal conditions.
[0050] In step S6, the warning display unit 14 displays the warning message selected in step S5 at a predetermined position.
[0051] According to this embodiment, the phishing warning device 1 acquires at least one piece of data at a predetermined time, which may be a factor in reducing the user's attention span and whose normal value can be estimated. The phishing warning device 1 calculates the degree of deviation of this data from the normal value, and if there is data with a deviation of a predetermined level or higher, it determines that the user's attention span may be reduced and presents a warning message indicating that there is a high possibility of being deceived by a phishing scam. Therefore, the phishing warning device 1 can automatically detect situations that are different from normal and where users are likely to make mistakes in judgment, and warn the user that they are in a situation where they are susceptible to being deceived by phishing. As a result, damage caused by phishing is suppressed.
[0052] Specifically, by calculating the degree of deviation from normal behavior at a predetermined time when a user checks their email, it is possible to alert the user to the received email and suppress damage caused by phishing emails.
[0053] The phishing warning device 1 learns the fluctuation patterns of values under normal conditions and calculates the degree of deviation from these fluctuation patterns, thereby appropriately detecting situations that differ from normal conditions and make users more susceptible to phishing, even when dealing with fluctuating data.
[0054] The phishing warning device 1 can determine if the location or time of use is different from normal and appropriately alert the user. Furthermore, the phishing warning device 1 can use indicators related to the user's workload, i.e., busyness, such as the number of new and unread emails, CPU load, number of running applications, number of scheduled tasks, and time until the next scheduled task, to determine if the user is in a busy state that deviates from normal conditions and appropriately alert the user.
[0055] The phishing warning device 1, when dealing with highly volatile data, prevents the excessive issuance of warnings and appropriately alerts the user by only issuing a warning if the deviation from normal conditions exceeds a predetermined level for a predetermined period of time.
[0056] The phishing warning device 1 can alert users with a warning message appropriate to their situation by selecting a warning message and a display method for the warning message according to the type of data, the magnitude of the deviation, the number of data points that have deviated, etc. Furthermore, the phishing warning device 1 can weight data according to its type, giving more importance to data that is more closely related to the user's attention span, and thus warning users of situations where they are more likely to be deceived.
[0057] Furthermore, this will help reduce damage caused by, for example, phishing emails, thereby contributing to Goal 9 of the United Nations-led Sustainable Development Goals (SDGs): "Build resilient infrastructure, promote sustainable industrialization and foster innovation."
[0058] Although embodiments of the present invention have been described above, the present invention is not limited to the embodiments described above. Furthermore, the effects described in the embodiments described above are merely a list of the most preferred effects resulting from the present invention, and the effects of the present invention are not limited to those described in the embodiments.
[0059] The phishing warning method provided by the phishing warning device 1 is implemented by software. When implemented by software, the programs constituting this software are installed on an information processing device (computer). These programs may be distributed to users by being recorded on removable media such as a CD-ROM, or by being downloaded to the user's computer via a network. Furthermore, these programs may be provided to the user's computer as a web service via a network without being downloaded. [Explanation of symbols]
[0060] 1. Phishing warning device 10 Control Unit 11 Data Acquisition Unit 12. Discrepancy Calculation Unit 13 Warning selection section 14 Warning display section 20 Memory section
Claims
1. A data acquisition unit that acquires at least one piece of data, including location information or usage time, which can be estimated to be a normal value and may be a factor in reducing the user's attention, at a predetermined timing, A deviation calculation unit calculates the degree of deviation of the data acquired by the data acquisition unit from the normal state, A phishing warning device comprising: a warning display unit that, when at least one data point with a deviation of a predetermined degree or higher is acquired, displays a warning message indicating that there is a high possibility of being deceived by a phishing scam.
2. A data acquisition unit acquires at least one piece of data at a predetermined time, including an indicator of the user's workload for which the normal value can be estimated, which may be a factor that reduces the user's attention span. A deviation calculation unit calculates the degree of deviation of the data acquired by the data acquisition unit from the normal state, A phishing warning device comprising: a warning display unit that, when at least one data point with a deviation of a predetermined degree or higher is acquired, displays a warning message indicating that there is a high possibility of being deceived by a phishing scam.
3. A data acquisition unit that acquires at least one piece of data at a predetermined time, which may be a factor that reduces the user's attention span and whose normal value can be estimated, A deviation calculation unit calculates the degree of deviation of the data acquired by the data acquisition unit from the normal state, A warning display unit that, if at least one data point with a deviation of a predetermined degree or higher is obtained, displays a warning message indicating that there is a high possibility of being deceived by a phishing scam, A phishing warning device comprising: a warning selection unit that selects a warning message according to the type of data in which the degree of deviation exceeds a predetermined level.
4. A data acquisition unit that acquires at least one piece of data at a predetermined time, which may be a factor that reduces the user's attention span and whose normal value can be estimated, A deviation calculation unit calculates the degree of deviation of the data acquired by the data acquisition unit from the normal state, A warning display unit that, if at least one data point with a deviation of a predetermined degree or higher is obtained, displays a warning message indicating that there is a high possibility of being deceived by a phishing scam, A phishing warning device comprising: a warning selection unit that selects a warning message and a display mode for the warning message according to the number of data points whose deviation degree exceeds a predetermined level.
5. The phishing warning device according to any one of claims 1 to 4, wherein the data acquisition unit acquires the data at a predetermined timing when the user checks the email.
6. The phishing warning device according to any one of claims 1 to 4, wherein the deviation degree calculation unit learns the fluctuation pattern of the normal value and calculates the degree of deviation from the fluctuation pattern.
7. The phishing warning device according to claim 2, wherein the warning display unit displays the warning message when the deviation degree remains above a predetermined level for a predetermined period of time or longer.
8. The phishing warning device according to claim 3, wherein the warning selection unit selects the warning message and the display mode of the warning message according to the degree of deviation.
9. The phishing warning device according to claim 4, wherein the warning selection unit selects the warning message and the display mode of the warning message by weighting according to the type of data in which the degree of deviation exceeds a predetermined level.
10. A data acquisition step that acquires at least one piece of data, including location information or usage time, which can be estimated to be a normal value and may be a factor in reducing the user's attention, at a predetermined time; A deviation calculation step is performed to calculate the degree of deviation of the data acquired in the data acquisition step from the normal state, A phishing warning method in which a computer performs a warning display step of presenting a warning message indicating that there is a high possibility of being deceived by a phishing scam if at least one data point with a deviation of a predetermined degree or higher is obtained.
11. A data acquisition step of acquiring at least one data point at a predetermined time, which includes an indicator of the user's workload for which the normal value can be estimated, that may be a factor in reducing the user's attention, A deviation calculation step is performed to calculate the degree of deviation of the data acquired in the data acquisition step from the normal state, A phishing warning method in which a computer performs a warning display step of presenting a warning message indicating that there is a high possibility of being deceived by a phishing scam if at least one data point with a deviation of a predetermined degree or higher is obtained.
12. A data acquisition step that acquires at least one piece of data at a predetermined time from which a normal value can be estimated, which may be a factor that reduces the user's attention span, A deviation calculation step is performed to calculate the degree of deviation of the data acquired in the data acquisition step from the normal state, If at least one data point with a deviation of a predetermined degree or higher is obtained, a warning selection step is performed to select a warning message indicating a high probability of being deceived by a phishing scam, according to the type of data point with a deviation of a predetermined degree or higher. A phishing warning method performed by a computer, comprising a warning display step of presenting the selected warning message.
13. A data acquisition step that acquires at least one piece of data at a predetermined time from which a normal value can be estimated, which may be a factor that reduces the user's attention span, A deviation calculation step is performed to calculate the degree of deviation of the data acquired in the data acquisition step from the normal state, If at least one data point with a deviation of a predetermined degree or higher is obtained, a warning selection step is performed to select a warning message indicating a high probability of being deceived by a phishing scam, and the manner in which the warning message is displayed, according to the number of data points with a deviation of a predetermined degree or higher. A phishing warning method performed by a computer, comprising a warning display step of presenting the selected warning message.
14. A phishing warning program for causing a computer to function as a phishing warning device according to any one of claims 1 to 4.
Citation Information
Patent Citations
Security administrative support system and security administrative support method
JP2017211858A
Watching device, watching system, method and program which monitor account transaction of financial institution of user
JP2021163043A