Phishing site detection system and phishing site detection method
The system detects and analyzes potential phishing sites at the domain registration stage, using real-time monitoring and machine learning to identify and automate responses, addressing the challenge of early phishing site detection and countermeasure development.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- HITACHI LTD
- Filing Date
- 2023-03-23
- Publication Date
- 2026-07-22
Smart Images

Figure 0007893774000001 
Figure 0007893774000002 
Figure 0007893774000003
Abstract
Description
Technical Field
[0001] The present invention relates to a phishing site detection system and a phishing site detection method.
Background Art
[0002] Due to the increasing damage caused by phishing year by year, technologies for detecting phishing sites and suppressing damage have been researched and developed. As such technologies, for example, there is a technology for detecting whether a site is a phishing site from the visual structure of the site, the URL string, etc. There is also a technology for examining access logs and determining whether there has been access to a phishing site in the past.
[0003] By detecting phishing sites in this way, it becomes possible to prevent access to the phishing site and the damage caused thereby, and to support post-incident security investigations.
[0004] As a conventional technology related to phishing site detection as described above, a technology for accurately detecting an unknown phishing site (see Patent Document 1) has been proposed.
[0005] This technology includes an acquisition unit that acquires an access log including the type and size of resources accessed to configure a web page in a browser, an analysis unit that acquires, for each web page, a set of resource information consisting of the type and size of the resources from the access log as configuration information of the web page, and a detection unit that calculates the similarity between the configuration information of the web page and each of the configuration information stored in a blacklist, and detects the web page as a phishing site if there is a known phishing site whose similarity is equal to or greater than a threshold value. It relates to a detection device provided with
[0006] In addition, a reliability evaluation device (see Patent Document 2) that can easily evaluate the reliability of a domain has also been proposed.
[0007] This device relates to a reliability evaluation device comprising: an acquisition unit that periodically acquires the registration price of a domain for each domain name unit for which a price has been set; a determination unit that, when a new domain is observed, determines that a predetermined period prior to the observation time is the registration time of the domain; and a calculation unit that calculates the reliability of the domain based on the registration price of the new domain at the registration time. [Prior art documents] [Patent Documents]
[0008] [Patent Document 1] Japanese Patent Publication No. 2022-2036 [Patent Document 2] Japanese Patent Publication No. 2021-93010 [Non-patent literature]
[0009] [Non-Patent Document 1] Ruofan Liu, Yun Lin, Xianglin Yang, Siang Hwee Ng, Dinil Mon Divakaran, Jin Song Dong: Inferring Phishing Intention via Webpage Appearance and Dynamics: A Deep Vision Based Approach, Proc. the 31st USENIX conference on Security Symposium (SEC 2022), pp. 1633-1650 (2022).https: / / www.usenix.org / conference / usenixsecurity22 / presentation / liu-ruofan [Overview of the Initiative] [Problems that the invention aims to solve]
[0010] To facilitate early detection of phishing sites and to understand and counter attack methods through monitoring attacker activity, one technique involves intentionally entering information from a dummy account used for baiting into a phishing site. The attacker will obtain the account information from a phishing site and attempt to log in using that information. In this case, the attacker will be lured into a pre-prepared decoy environment and their behavior in that environment will be monitored.
[0011] On the other hand, phishing sites are known to be short-lived. Therefore, by the time a phishing site is reported as public information, it is often already down.
[0012] If a phishing site is down, it becomes impossible to input dummy account information for baiting attacks, making it difficult to observe the triggers for subsequent attacks, the behavior of attackers, and to use those observations to develop countermeasures.
[0013] Therefore, the objective of the present invention is to provide a technology that enables the detection of phishing sites and the inducing of attacks at an earlier stage than in the past. [Means for solving the problem]
[0014] The phishing site detection system of the present invention, which solves the above problems, comprises: a communication device that accesses a network; a storage device that holds attribute information relating to a phishing site; a process that detects domains that may be used for phishing attacks in the network based on the attribute information; a process that accesses the detected domain and detects the activation of a candidate phishing site; a process that observes predetermined events at the candidate phishing site; and a computing device that applies the results of the observation to a determination rule that defines trends regarding the events at the phishing site and performs a process to determine whether the candidate phishing site is a phishing site. The computing device further performs a process to output at least one of the observation results and the determination results to a predetermined device, and when detecting the domain, it compares the information of each registered domain in the network with the attribute information to detect domains that may be phishing against known legitimate site domains, and when detecting activation, it periodically polls the detected domains to detect their activation, and when polling, it performs control to make the polling interval shorter than a predetermined value for domains that match or are similar to the detected domain, or for domains after activation detection rather than before. It is characterized by the following: [Effects of the Invention]
[0015] According to the present invention, it becomes possible to detect a phishing site and induce an attack at a timing earlier than before.
Brief Description of the Drawings
[0016] [Figure 1] It is a diagram showing a configuration example of a phishing site detection system according to Example 1 of the present invention. [Figure 2] It is a diagram showing an example of a list of domain generation rules according to Example 1 of the present invention. [Figure 3] It is a diagram showing an example of a list of detected sites according to Example 1 of the present invention. [Figure 4] It is a diagram showing an overall processing flow according to Example 1 of the present invention. [Figure 5] It is a diagram showing a processing flow of phishing candidate domain detection according to Example 1 of the present invention. [Figure 6] It is a diagram showing a processing flow of site activation detection according to Example 1 of the present invention. [Figure 7] It is a diagram showing a processing flow of site observation according to Example 1 of the present invention. [Figure 8] It is a diagram showing a processing flow of phishing site determination according to Example 1 of the present invention. [Figure 9] It is a diagram showing a processing flow of screen drawing according to Example 1 of the present invention. [Figure 10] It is a diagram showing an example of a screen according to Example 1 of the present invention. [Figure 11] It is a diagram showing a configuration example of a phishing site detection system according to Example 2 of the present invention. [Figure 12] It is a diagram showing a processing flow of automatic credential input according to Example 2 of the present invention. [Figure 13] It is a diagram showing a processing flow of tracking an account for inducement according to Example 2 of the present invention. [Figure 14] It is a diagram showing a processing flow of automatic analysis of a specimen according to Example 2 of the present invention. [Figure 15]This figure shows an example configuration of a phishing site detection system according to Embodiment 3 of the present invention. [Modes for carrying out the invention]
[0017] The embodiments of the present invention will be described below with reference to the drawings. However, the present invention is not to be construed as being limited to the embodiments described below. It will be readily apparent to those skilled in the art that the specific configuration can be modified without departing from the spirit or intent of the present invention. In the configuration of the invention described below, identical or similar components or functions are denoted by the same reference numerals, and redundant descriptions are omitted.
[0018] The designations "First," "Second," "Third," etc., used in this specification are for the purpose of identifying constituent elements and do not necessarily limit their number or order.
[0019] The positions, sizes, shapes, and ranges of each component shown in the drawings, etc., may not represent the actual positions, sizes, shapes, and ranges, etc., in order to facilitate understanding of the invention. Therefore, the present invention is not limited to the positions, sizes, shapes, and ranges, etc., disclosed in the drawings, etc. [Example 1] Example 1 describes the process of a basic phishing site detection system, which adds potentially phishing sites to the monitoring target at the domain registration stage, and determines whether a site is a phishing site or not, along with additional information such as the target of the attack, when the site is activated. <System Configuration> Embodiments of the present invention will be described in detail below with reference to the drawings. Figure 1 is a network configuration diagram including the phishing site detection system 101 of this embodiment. The phishing site detection system 101 shown in Figure 1 is a computer system that enables the detection of phishing sites and the inducing of attacks at an earlier stage than conventional systems.
[0020] The phishing site detection system 101 according to this embodiment shows a network configuration in which a user terminal 116 operated by the user and the internet 118 are connected via a network 117. The phishing site detection system 101 is a CPU (Central Processing Unit) 10 The computer system comprises a CPU 103, a main memory 104 for storing data necessary for the CPU 103 to execute processing, a storage device 105 such as a hard disk or flash memory with a large capacity for storing large amounts of data, an interface 102 for communicating with other devices, an input / output device 106 for input / output such as a keyboard and display, and a communication channel 107 connecting these devices. The communication channel 107 is, for example, an information transmission medium such as a bus or cable.
[0021] Of these, the CPU 103 is a computing unit that implements the necessary functions by executing the phishing candidate domain detection program 108, the site activation detection program 109, the site observation program 110, the phishing site determination program 111, and the screen drawing program 112, which are stored in the main memory 104.
[0022] Of these, the phishing candidate domain detection program 108 is executed to implement the function of detecting phishing candidate domains.
[0023] Furthermore, by running the site activation detection program 109, a function to detect the activation of potential phishing sites is implemented.
[0024] Furthermore, by executing the site observation program 110, the function to observe potential phishing sites is implemented.
[0025] Furthermore, by executing the phishing site detection program 111, a function to detect phishing sites based on the observation results described above is implemented.
[0026] Furthermore, by executing the screen drawing program 112, the function to output information obtained by the above-mentioned programs 108 to 111 is implemented.
[0027] Furthermore, the storage device 105 stores a domain generation rule list 113 for managing domain generation rules, a detected site list 114 for managing detected phishing candidate sites, and an observation result storage area 115 for storing observation results.
[0028] Each of the above programs and data may be stored in memory 104 or storage device 105 in advance, or they may be installed (loaded) from input / output device 106 or from other devices via IF 102 when needed.
[0029] It should be noted that the configuration of the phishing site detection system 101 described in Figure 1 is merely an example and is not limited to this configuration. Therefore, it is also conceivable that the necessary functions and configurations may be implemented through the cooperation of multiple devices. <Example Data Structure> Next, we will explain the various types of information used by the phishing site detection system 101 of this embodiment. Figure 2 shows an example of the domain generation rule list 113 in this embodiment.
[0030] As shown in Figure 2, the domain generation rule list 113 is composed of, for example, domain ID 1131, domain 1132, and domain generation rule 1133.
[0031] Of these, Domain ID 1131 is a field that stores identification information to uniquely identify each domain that may be a target for detecting phishing sites. In Example 1, a number is stored as the identification information for Domain ID 1131.
[0032] Furthermore, domain 1132 represents each (legitimate) domain that may be targeted for detection of phishing sites. For example, domain ID 1131 "0" indicates that the base domain is "example.com". This means that the domain "example.com" will be targeted for detection, and This means that domains similar to the domain name will be detected as potential phishing sites.
[0033] Furthermore, domain generation rule 1133 represents a similar domain generation rule for detecting domains similar to the given domain. For example, domain ID 1131 is "0" In the case of In, he is targeted using techniques such as "typosquatting" and "homographs." This means that domains like this can be generated.
[0034] Note that the list of domain generation rules explained in Figure 2 is just one example and is not limited to this.
[0035] Next, Figure 3 shows an example of a detected site list 114. As shown in Figure 3, the detected site list 114 is composed of, for example, a detected site ID 1141, a domain ID 1142, a detected domain 1143, a generation rule 1144, a last check date and time 1145, and a status 1146.
[0036] Of these, the detection site ID 1141 is a field that stores identification information to uniquely identify a domain detected on the internet 118, for example. In Example 1, a number is stored as the identification information for the detection site ID 1141.
[0037] Furthermore, Domain ID 1142 is a field that stores the identification information, or ID, of the (legitimate) domain from which the detected site originated. The value of Domain ID 1142 is the value of Domain ID 1132 in Domain Generation Rule 1133, that is, the ID value of the legitimate domain before it was altered by typosquatting, homographing, etc. For example, an entry for a site with Detection Site ID 1141 "0" indicates that it corresponds to a domain with Domain ID "0". In other words, it was generated as a malicious derivative of "example.com". Each detected domain will have a detection site ID of "0" for site ID 1141.
[0038] Furthermore, detected domain 1143 represents the domain of the detected site, which is a potential phishing site. For example, a domain with detected site ID 1141 being "0" is "examp1e.com". This indicates that something is the case.
[0039] Furthermore, generation rule 1144 represents the generation rule that led to the generation of the domain of the detected site. For example, a domain with detected site ID 1141 being "0" indicates that it was generated from the base domain using the "homograph" rule.
[0040] Furthermore, the last confirmation date and time 1145 represents the most recent date and time when a status check was performed by polling the detected site. For example, the last confirmation date and time for a site with detected site ID 1141 being "0" is "2023-01-01 04:00:00". The present invention stores in the last confirmation date and time 1145 The data format is not limited to the time being recorded. Any data format that allows for time identification, such as Unixtime, may be used.
[0041] Furthermore, status 1146 represents the operational status of the detected site at the time of the final verification. For example, a domain with detected site ID 1141 being "0" indicates that it was in an "operationally terminated" state, i.e., its lifespan had ended, at the time of the final verification.
[0042] The list of detected sites explained in Figure 3 is just one example and is not limited to this list. <Example Flow: Overall Flow> The actual procedure for the phishing site detection method in this embodiment will be described below with reference to the diagrams. The various operations corresponding to the phishing site detection method described below are realized by a program that the phishing site detection system 101 reads into memory or the like and executes. This program consists of code for performing the various operations described below.
[0043] Figure 4 shows an example of the flow of the phishing site detection method in this embodiment, specifically the phishing site detection performed by the phishing site detection system 101 of Example 1. This is a flowchart that explains the overview of knowledge.
[0044] In this flow, the phishing site detection system 101 first periodically performs the following process (step 401).
[0045] The phishing site detection system 101 detects a potential phishing domain (step 402). Details of the process in step 402 will be described later with reference to Figure 5.
[0046] Next, the phishing site detection system 101 performs site activation detection on the phishing candidate domains detected in step 402 (step 403). Details of the process in step 403 will be described later with reference to Figure 6.
[0047] Next, the phishing site detection system 101 performs predetermined observations on the phishing candidate sites that have been found to be operational following the detection in step 403 (step 404). Details of the processing in step 404 will be described later with reference to Figure 7.
[0048] Next, the phishing site detection system 101 determines whether the phishing candidate site is actually a phishing site or not based on the observation results in step 404 described above (step 405), and then terminates the process. Details of the process in step 405 will be described later with reference to Figure 8.
[0049] Note that the processing flow of the phishing site detection system described in Figure 4 is just one example and is not limited to it. <Example Flow: Detection of Potential Phishing Domains> Figure 5 is a flowchart illustrating an example of the phishing candidate domain detection process (step 402) performed by the phishing site detection system 101 of Example 1.
[0050] The phishing candidate domain detection program 108, executed by the CPU 103, starts the process described below upon receiving an execution command.
[0051] First, the phishing candidate domain detection program 108 retrieves the domain generation rule 1133 for each domain from the domain generation rule list 113 held in the storage device 105 (step 501).
[0052] Next, the phishing candidate domain detection program 108 generates domains to monitor based on the domain generation rule 1133 obtained in step 501 (step 502).
[0053] For example, against the legitimate domain 1132, "example.com", a domain that could be targeted by typosquatting, "examplw.com", is generated as a potential phishing domain.
[0054] Next, the phishing candidate domain detection program 108 detects, for example, the internet. 118 Obtain the latest domain list from each registrar and WHOIS system (Step 503).
[0055] Next, the phishing candidate domain detection program 108 performs the following processing for each domain in the domain list obtained in step 503 (step 504).
[0056] The phishing candidate domain detection program 108 compares the domain obtained in step 503 with the phishing candidate domain generated in step s502, and if they match, saves the domain to the detected site list 114 (step 505).
[0057] Once processing is complete for each domain in the domain list obtained in step 503, the phishing candidate domain detection program 108 terminates.
[0058] The method for detecting potential phishing domains, as explained in Figure 5, is merely an example and is not limited to it. For example, in the example above, potential phishing domains are detected using information about the domain string, but other information such as registrar information or certificate information may also be used. Furthermore, domains that appear to be phishing domains may be generated using methods other than those described in the example above. For example, a system could possess phishing domains that have actually been exploited and generate new candidate domains based on their spoofing rules. <Example Flow: Site Activation Detection> Figure 6 is a flowchart illustrating an example of the site activation detection process (step 403) performed by the phishing site detection system 101 of Example 1.
[0059] The site activation detection program 109, executed by the CPU 103, starts the process described below upon receiving an execution command.
[0060] The site activation detection program 109 retrieves the values of the detected domain 1143, which is a phishing candidate, and its state 1146 from the list of detected sites 114 held in the storage device 105 (step 601).
[0061] Next, the site activation detection program 109 performs the following processing for each of the detected domains 1143 acquired in step 601 whose status 1146 is "pre-operational" (step 602).
[0062] The site activation detection program 109 accesses the domain (step 603).
[0063] Next, if the site activation detection program 109 receives a response from the domain in response to the access in step 603, it updates the status 1146 of the detected site list 1144 for that domain to "Active" (step 604). Once processing is complete for all domains whose status 1146 is "Not Active," the program terminates.
[0064] The site activation detection process described in Figure 6 is merely an example and is not limited thereto. For example, the polling interval for accessing a phishing candidate domain, i.e., a phishing candidate site, to determine whether or not it is activated may be a predetermined percentage of the average phishing survival period (e.g., half a year, one-third of a year, etc.).
[0065] Furthermore, it is preferable to dynamically control the polling interval for each domain by estimating the characteristics of the site and setting the polling interval shorter than the default value for sites that are likely to be short-lived, i.e., have a lifespan below a certain standard, or by making the polling interval for a site that has become "operational" by a certain percentage longer than before. <Example Flow: Site Observation> Figure 7 is a flowchart illustrating an example of the site observation process (step 404) performed by the phishing site detection system 101 of Example 1.
[0066] When the site observation and detection program 110, executed by the CPU 103, receives an execution instruction, it starts the process described below.
[0067] The site observation program 110 retrieves the phishing candidate domain 1143 and its status 1146 from the detected site list 114 (step 701).
[0068] Next, the site observation program 110 performs the following processing for each domain among the acquired domains 1143 whose status 1146 is "operating" (step 702).
[0069] The site observation program 110 accesses the domain (step 703).
[0070] Next, the site observation program 110 saves the response result from the domain to the observation result storage area 115 (step 704). This response result can be expected to include, for example, screen data of the website's top page, objects contained in that screen (e.g., icons, UI, text, etc.), or HTML data.
[0071] Next, if the site observation program 110 receives no response from the domain, it updates the status 1146 of the detected site list 114 for that domain to "Service terminated" (step 705). Once processing is complete for all domains with a status of "Service in progress", the program terminates.
[0072] Note that the site observation processing method described in Figure 7 is just one example and is not limited thereto. <Example Flowchart: Phishing Site Detection> Figure 8 is a flowchart illustrating an example of the phishing site determination process (step 405) performed by the phishing site detection system 101 of Example 1.
[0073] The phishing site detection program 111, executed by the CPU 103, starts the process described below when it receives an execution instruction.
[0074] The phishing site detection program 111 retrieves the values of the detected domain 1143 and its state 1146 for phishing candidates from the list of detected sites 114 held in the storage device 105 (step 801).
[0075] Next, the phishing site detection program 111 performs the following processing for each of the detected domains 1143 whose status 1146 is "operating" among the domains whose values were obtained in step 801 above (step 802).
[0076] The phishing site detection program 111 obtains the observation results for the domain from the observation result storage area 115 (step 803). These observation results are obtained by executing the flow shown in Figure 7.
[0077] Next, the phishing site detection program 111 obtains external information related to the domain (step 804). External information may include, for example, the site's DNS information, WHOIS information, registrar information, certificate information, etc.
[0078] Next, the phishing site detection program 111 determines whether the observation results for the domain (obtained in step 803) and various information related to the domain (obtained in step 804) have changed since the previous observation.
[0079] If no change is found as a result of this determination, the processing related to the domain is terminated. If a change is found (step 805: Yes), the phishing site detection program 111 proceeds to step 806 (step 805).
[0080] Next, the phishing site detection program 111 applies the information relating to the domain (obtained in steps 803 and 804 above) to a determination rule (e.g., a determination model that has learned the relationship between the trends of such trends and the likelihood of it being a phishing site using a machine learning engine) that defines trends in events that are likely to be observed on phishing sites (e.g., events that constitute the observation results above, such as the presence or absence of a specific string in the URL, the presence or number of specific icons or UI on the screen, and the presence or absence of download syntax in the HTML code), and determines whether or not it is a phishing site (step 806).
[0081] As mentioned above, the method for determining whether a site is a phishing site, as described in Figure 8, is just one example and is not limited to this.
[0082] Furthermore, while the above explanation only shows the part that determines whether or not it is a phishing site, if it is determined to be a phishing site, it may be further performed to detect and identify credential input objects etc. on the page, and to estimate the service or brand that the domain is targeting based on information such as the domain string and logos misused on the site. <Example Flow: Screen> drawing > The phishing site detection system 101, in addition to the process described in Figure 4, also displays a screen for showing various information to the user. drawing The process is executed. Figure 9 shows the screen displayed when the phishing site detection system 101 of Example 1 is executed. drawing This is a flowchart illustrating an example of the process.
[0083] Screen executed by CPU103 drawing When program 112 receives an execution command from, for example, user terminal 116, it starts the process described below.
[0084] screen drawingProgram 112 obtains information related to the site to be rendered from the list of detected sites 114 (step 901). Here, it is assumed that a list is obtained that includes entries consisting of detected site ID 1141.
[0085] Next, screen drawing Program 112 retrieves observation results related to the site to be plotted from the observation result storage area 115 (step 902).
[0086] Next, screen drawing Program 112 delivers screen data containing information about the site to be drawn to the user terminal 116 for drawing (step 903), and then terminates processing.
[0087] Note that the screen explained in Figure 9 drawing This method is just one example and is not limited to it.
[0088] Figure 10 shows an example of a phishing site detection system screen 1000 generated by a program that constitutes the phishing site detection system 101 of Example 1.
[0089] Screen 1000 in Figure 10 includes Site Overview 1001 and Details 1002. Of these, Site Overview 1001 is drawing This section provides basic information about the detected phishing site. For example, it includes values for the detected site, domain, detected domain, generation rule, last checked date and time, and status.
[0090] On the other hand, detail 1002 is, drawing This report provides detailed information about the detected phishing site. For example, it may include screenshots of the phishing site, a determination of whether or not it is a phishing site, and an estimate of the target service or brand.
[0091] If the observation reveals an attack target or an input form for credential theft, it may be displayed on the screenshot along with its likelihood. Furthermore, various judgment and estimation results may also include their likelihoods to assist the user's decision-making. These likelihoods can be identified using a judgment model trained and generated by the machine learning engine mentioned earlier.
[0092] Note that the phishing site detection system screen shown in Figure 10 is just one example and is not limited to this.
[0093] As already mentioned, the number of phishing attacks is increasing year by year, so there is a demand to detect phishing sites early, observe attackers' behavior, understand attack methods, and use that information to develop countermeasures. On the other hand, there is no technology aimed at early detection of phishing attack inducements, and challenges remain regarding the early detection and observation of attacks in this context.
[0094] According to the above-described embodiment 1, the phishing site detection system 101 adds potentially phishing sites to its monitoring target at the domain registration stage, and determines whether the site is a phishing site or not, along with additional information such as the target of the attack, when the site is activated. This enables earlier detection of phishing sites and the induction of attacks. [Example 2] Example 2 describes the processing of a phishing site detection system that includes support functions for analyzing the baiting and attack mechanisms of phishing sites, enabling more advanced and labor-saving analysis. Below, Example 2 will be described focusing on the differences from Example 1.
[0095] Figure 11 shows an example configuration of the phishing site detection system 1101 according to Embodiment 2 of the present invention. The configuration of the computer system in Embodiment 2 is the same as that of Embodiment 1. Also, the hardware configuration of the phishing site detection system 1101 in Embodiment 2 is the same as that of Embodiment 1.
[0096] On the other hand, the program configuration of Example 2 includes, in addition to that of Example 1, a credential auto-input program 1112, a referral account tracking program 1113, and a sample auto-analysis program 1114.
[0097] Furthermore, the processes of the phishing candidate domain detection program 1108, site activation detection program 1109, site observation program 1110, phishing site determination program 1111, and screen drawing program 1115 in Example 2 are the same as those in Example 1. Also, the data structure of each piece of information held in the storage device 1105 in Example 2 is the same as in Example 1.
[0098] Note that the configuration of the phishing site detection system 1101 according to Example 2, as described in Figure 11, is just one example and is not limited thereto.
[0099] Figure 12 is a flowchart illustrating an example of the credential auto-input process performed by the phishing site detection system 1101 of Example 2.
[0100] The credential auto-input program 1112, executed by the CPU 1103, will, for example, start the process described below when it receives an execution command from the user terminal 1119. ru.
[0101] The credential auto-entry program 1112 accesses the phishing site for which credentials are to be entered (as identified in the method of Example 1) (step 1201).
[0102] Next, the credential auto-entry program 1112 detects the credential entry form and login button on the phishing site (step 1202). This detection is performed, for example, using visual information or structural information such as HTML of the site.
[0103] Next, the credential auto-input program 1112 inputs the credentials into the input form detected in step 1202 (step 1203). The credentials are assumed to have been provided in advance by the user terminal 1119 and are appropriately stored in the storage device 1105 or main memory 1104.
[0104] Next, the credential auto-entry program 1112 clicks the login button on the aforementioned phishing site and terminates the process (step 1204).
[0105] The above process automates not only the detection and activation of phishing sites but also the input of credentials, thereby reducing the time overhead caused by manual intervention. This improves the success rate of observing and luring attacks by inputting credentials before the short-lived phishing site attacks end.
[0106] The method for automatically entering credentials, as explained in Figure 12, is just one example and is not limited to this.
[0107] Figure 13 is a flowchart illustrating an example of the baiting account tracking process performed by the phishing site detection system 1101 of Example 2.
[0108] When the scam account tracking program 1113, executed by the CPU 1103, receives an execution command from the user terminal 1119, it starts the process described below.
[0109] The solicitation account tracking program 1113 checks whether the solicitation account (the credential information automatically entered in Figure 12) has been compromised at the account breach verification site (step 1301). The account breach verification site can be, for example, one from an existing service, which can be appropriately selected and used.
[0110] Next, the phishing account tracking program 1113 checks if the malware analysis results in the online sandbox (an existing one is selected and used as appropriate) contain phishing account information, and then terminates the process (step 1302).
[0111] For example, a malicious third party might hardcode the credentials of an account stolen from another person into malware in order to automatically exploit that account. In that case, it would be necessary to check whether the leaked credentials are exposed in the malware analysis results due to that hardcoding.
[0112] The above process automates the verification and tracking of whether accounts leaked for citation purposes have been compromised, thereby reducing the effort required for analysis.
[0113] Note that the method for tracking citation accounts explained in Figure 13 is just one example, and there are other methods as well. Not limited.
[0114] Figure 14 is a flowchart illustrating an example of the automated sample analysis process performed by the phishing site detection system 1101 of Example 2.
[0115] When the automated sample analysis program 1114, executed by the CPU 1103, receives an execution command from the user terminal 1119, it starts the process described below.
[0116] The automated sample analysis program 1114 accesses the phishing site to be analyzed (which has already been determined and identified in the flow chart in Figure 8) (step 1401).
[0117] Next, the automated sample analysis program 1114 determines whether the response result of the site has changed since the last observation (step 1402). If there is no change (step 1402: No), the processing for the site is terminated; if there is a change (step 1402: Yes), the program proceeds to step 1403.
[0118] Next, the automated sample analysis program 1114 attempts to acquire the sample (step 1403). For example, if a site automatically downloads a sample upon access, the sample will be acquired. Even if this is not the case, the sample will be downloaded through actions such as clicking on links or icons containing the word "download" on the site.
[0119] Next, the automated sample analysis program 1114 processes the sample obtained in step 1403. Submit to the malware analysis system (step 1404). This malware analysis system is, for example, For example, this could include online malware analysis services or on-premise analysis systems.
[0120] Next, the automated sample analysis program 1114 receives the results of the sample analysis performed in step 1404 from various analysis systems, stores them in the observation result storage area 115 (step 1405), and terminates the process.
[0121] By automating the acquisition and analysis of samples from phishing sites through the above process, we aim to reduce costs and overhead associated with manual processes, thereby saving labor and improving the success rate of observation and baiting.
[0122] The automated sample analysis process described in Figure 14 is just one example and is not limited thereto.
[0123] According to Example 2, the phishing site detection system 1101 has a phishing site detection function similar to that of Example 1, as well as support functions for analyzing the causes of phishing sites and attacks. This enables a more advanced and labor-saving analysis of phishing sites and attacks associated with them. [Example 3] Example 3 describes the processing of a phishing site detection system that enables cloud-based service provision by sharing various judgment results externally via the network, in addition to on-premise phishing site detection and analysis functions.
[0124] The following describes Example 3, focusing on the differences from Example 2. Figure 15 shows an example configuration of the phishing site detection system 1501 according to Example 2 of the present invention. Example 3 The configuration of the computer system is the same as in Example 2.
[0125] The network configuration including the phishing site detection system 1501 in Example 3 is implemented. In addition to the configuration in Example 2, it may further include an external user terminal 1522.
[0126] In this embodiment 3, each program executes processing in response to requests not only from user terminals 1519 within the network but also from external user terminals 1522, and returns the results to the external user terminals 1522 via the internet 1521. This enables the provision of services in the cloud.
[0127] The program in Example 3 is identical to that in Example 2. Furthermore, the processes of the phishing candidate domain detection program 1508, site activation detection program 1509, site observation program 1510, phishing site determination program 1511, credential automatic input program 1512, baiting account tracking program 1513, sample automatic analysis program 1514, and screen rendering program 1515 in Example 3 are identical to those in Example 2. Also, the data structure of the information held in the storage device 1505 in Example 3 is identical to that of Example 2.
[0128] Note that the configuration of the phishing site detection system 1501 according to Example 3, as described in Figure 15, is an example and is not limited thereto.
[0129] According to Example 3, the phishing site detection system 1501 is similar to Example 2. The system provides internal users with phishing site detection and analysis functions, while also providing the same information to external users via the Internet. This enables the provision of services in the cloud.
[0130] Furthermore, each program in each embodiment may be used for purposes other than attracting attacks by security researchers. For example, it can be used in a SOC / CSIRT to protect the domain of one's own organization or its own services, or in an MSS as a domain monitoring service for any service.
[0131] Although the best mode for carrying out the present invention has been described in detail above, the present invention is not limited thereto and can be modified in various ways without departing from its essence.
[0132] This embodiment enables the detection of phishing sites and the inducing of attacks at an earlier stage than in the past.
[0133] The following is made clear by this specification: In the phishing site detection system of this embodiment, the computing device may further perform a process to output at least one of the observation results and the determination results to a predetermined device.
[0134] This allows for the rapid notification of timely information to those responsible for dealing with phishing sites, thereby ensuring their awareness. Ultimately, this enables the detection of phishing sites and the inception of attacks at an earlier stage than before.
[0135] Furthermore, in the phishing site detection system of this embodiment, the computing device may, when detecting the domain, compare the information of each registered domain in the network with the attribute information to detect domains that are known to be potentially phishing sites.
[0136] According to this, it becomes possible to accurately identify and detect malicious domains that mimic the domains of legitimate websites and induce user confusion, etc. In turn, it becomes possible to make the process more conventional. This allows for earlier detection of phishing sites and the inducing of attacks.
[0137] Furthermore, in the phishing site detection system of this embodiment, the computing device may periodically poll the detected domain to detect its activation.
[0138] According to this, it becomes possible to accurately and comprehensively detect the event of a phishing site being created on a given domain, even when only the domain has been acquired and the site has not yet been launched or operated. In other words, it becomes possible to detect phishing sites and induce attacks at an earlier stage than before.
[0139] Furthermore, in the phishing site detection system of this embodiment, the computing device may perform control such that, when polling, the polling interval is shorter for domains that match or are similar to the detected domain, or shorter for domains that are detected after activation than before.
[0140] This makes it possible to accurately detect and deal with phishing sites that only survive for a short period of time. In other words, it enables the detection of phishing sites and the inducing of attacks at an earlier stage than before.
[0141] Furthermore, in the phishing site detection system of this embodiment, the computing device may perform the determination by applying at least one of the following pieces of information obtained through observation—the URL, screen information, and code structure of the phishing candidate site—to the determination rule.
[0142] This allows for efficient and accurate determination of whether a site is a phishing site or not. Consequently, it enables earlier detection of phishing sites and the inducing of attacks compared to conventional methods.
[0143] Furthermore, in the phishing site detection system of this embodiment, the computing device may estimate the service or brand being attacked by applying at least one of the following pieces of information—the string constituting the URL, the object included in the screen information, and the predetermined code included in the code configuration—to the determination rule when making the determination.
[0144] This allows for accurate determination of whether a site is a phishing site, along with efficient estimation of its target. Consequently, it enables earlier detection of phishing sites and the inception of attacks compared to conventional methods.
[0145] Furthermore, in the phishing site detection system of this embodiment, the computing device may also detect a credential input form on the detected phishing site and automatically input the attack inducement credentials into the input form.
[0146] This allows for the rapid and reliable execution of attack inducements, and consequently, enables the detection of phishing sites and the inducing of attacks at an earlier stage than before.
[0147] Furthermore, in the phishing site detection system of this embodiment, the calculation device automatically inputs the credentials leaked via the phishing site, It may also be stated that information regarding the propagation or misuse of such credentials is obtained from at least one of the credential information leakage verification system and the malware analysis system.
[0148] This makes it possible to accurately and quickly detect the misuse of deliberately leaked credentials. In turn, it enables the detection of phishing sites and the inception of attacks at an earlier stage than before.
[0149] Furthermore, in the phishing site detection system of this embodiment, the computing device may access the detected phishing site, obtain a sample from the phishing site, and analyze the sample using a malware analysis system.
[0150] This allows for the rapid acquisition of samples (e.g., downloadable free software containing malware) and analysis of their impact. Ultimately, this enables the detection of phishing sites and the inception of attacks at an earlier stage than before.
[0151] Furthermore, in the phishing site detection method of this embodiment, the information processing device may further perform a process to output at least one of the observation results and the determination results to a predetermined device.
[0152] Furthermore, in the phishing site detection method of this embodiment, the information processing device may, when detecting the domain, compare the information of each registered domain in the network with the attribute information to detect domains that are known to be phishing sites.
[0153] Furthermore, in the phishing site detection method of this embodiment, the information processing device may periodically poll the detected domain to detect its activation.
[0154] Furthermore, in the phishing site detection method of this embodiment, the information processing device may perform control during polling to shorten the polling interval to a predetermined value as the observed or estimated site lifespan for domains that match or are similar to the detected domain becomes shorter, or as the period after detection becomes shorter than the period before detection.
[0155] Furthermore, in the phishing site detection method of this embodiment, the information processing device may perform the determination by applying at least one of the following pieces of information obtained through observation—the URL, screen information, and code structure of the phishing candidate site—to the determination rule.
[0156] Furthermore, in the phishing site detection method of this embodiment, the information processing device may, when making the determination, estimate the service or brand being attacked by applying at least one of the following pieces of information to the determination rule: the string constituting the URL, the object included in the screen information, and the predetermined code included in the code configuration.
[0157] Furthermore, in the phishing site detection method of this embodiment, the information processing device may also detect a credential input form on the detected phishing site and automatically input the attack inducement credentials into the input form.
[0158] Furthermore, in the phishing site detection method of this embodiment, the information processing device is the Regarding credentials leaked via the aforementioned phishing site through automatic input, information regarding the propagation or misuse of such credentials may be obtained from at least one of the credential information leak confirmation system and the malware analysis system.
[0159] Furthermore, in the phishing site detection method of this embodiment, the information processing device may access the detected phishing site, obtain a sample from the phishing site, and analyze the sample using a malware analysis system. [Explanation of Symbols]
[0160] 101 Phishing Site Detection System 102 IF (Communication Equipment) 103 CPU (computing unit) 104 Main Memory 105 Storage device 106 Input / Output Devices 107 Communication Channels 108 Phishing Candidate Domain Detection Program 109 Site Activation Detection Program 110 Site Observation Program 111 Phishing Site Detection Program 112 Screen drawing program 113 List of Domain Generation Rules List of 114 sample sites 115 Observation result storage area 116 User terminals 117 Network 118 Internet
Claims
1. A communication device that accesses the network, A storage device that holds attribute information about phishing sites, The network includes a computing device that performs the following: a process of detecting domains that may be used for phishing attacks based on attribute information; a process of accessing the detected domains and detecting the activation of phishing candidate sites; a process of observing predetermined events at the phishing candidate sites; and a process of applying the results of the observations to a determination rule that defines trends regarding the events at phishing sites to determine whether the phishing candidate site is a phishing site. Equipped with, The aforementioned computing device is The process further involves outputting at least one of the observation results and the determination results to a predetermined device. In detecting the aforementioned domain, the information of each registered domain in the network is compared with the attribute information to detect domains that may be phishing sites that are known in advance. In detecting the aforementioned activation, the detected domain is periodically polled to detect its activation. During the polling, the system implements a control mechanism that shortens the polling interval to a predetermined value for domains that match or are similar to the detected domain, or for domains whose observed or estimated site lifespan is shorter, or for domains whose activation is detected more recently than for domains whose activation is detected. A phishing site detection system characterized by [this feature].
2. The aforementioned computing device is In making the aforementioned determination, the determination is made by applying at least one of the following pieces of information obtained through the observation—the URL, screen information, and code structure of the phishing candidate site—to the determination rules. The phishing site detection system according to feature 1.
3. The aforementioned computing device is In making the determination, the service or brand being attacked is estimated by applying at least one of the following pieces of information—the string constituting the URL, the object included in the screen information, and the predetermined code included in the code structure—to the determination rule. The phishing site detection system according to feature 2.
4. The aforementioned computing device is The system detects a credential input form on the aforementioned phishing site and automatically enters the attack-inducing credentials into that input form. The phishing site detection system according to feature 1.
5. The aforementioned computing device is Regarding the credentials leaked via the phishing site through the aforementioned automatic input, information regarding the propagation or misuse of said credentials is obtained from at least one of the credential information leak confirmation system and the malware analysis system. The phishing site detection system according to feature 4.
6. The aforementioned computing device is The process involves accessing the detected phishing site, obtaining a sample from the phishing site, and analyzing the sample using a malware analysis system. The phishing site detection system according to feature 1.
7. Information processing device, It comprises a communication device that accesses the network and a storage device that holds attribute information about phishing sites, In the aforementioned network, the following processes are executed: detecting domains that may be used for phishing attacks based on attribute information; accessing the detected domains and detecting the activation of phishing candidate sites; observing predetermined events at the phishing candidate sites; and applying the results of the observations to a determination rule that defines trends regarding the events at phishing sites to determine whether the phishing candidate site is a phishing site. Further processing is performed to output at least one of the observation results and the determination results to a predetermined device. In detecting the aforementioned domain, the information of each registered domain in the network is compared with the attribute information to detect domains that may be phishing sites that have been identified in advance. In detecting the aforementioned activation, the detected domain is periodically polled to detect its activation, During the polling, the polling interval is shortened to a predetermined value for domains that match or are similar to the detected domain, or for domains with shorter observed or estimated site lifespans, or for domains that are detected after activation rather than before. A method for detecting phishing sites characterized by the following.
8. The aforementioned information processing device In making the aforementioned determination, the determination is made by applying at least one of the following pieces of information obtained through the observation—the URL, screen information, and code structure of the phishing candidate site—to the determination rules. The phishing site detection method according to feature 7.
9. The aforementioned information processing device In making the determination, the service or brand being attacked is estimated by applying at least one of the following pieces of information—the string constituting the URL, the object included in the screen information, and the predetermined code included in the code structure—to the determination rule. The phishing site detection method according to feature 8.
10. The aforementioned information processing device In the detected phishing site, a credential input form is detected, and the credentials used to induce the attack are automatically entered into the input form. The phishing site detection method according to feature 7.
11. The aforementioned information processing device Regarding the credentials leaked via the phishing site through the aforementioned automatic input, information regarding the propagation or misuse of said credentials is obtained from at least one of the credential information leak confirmation system and the malware analysis system. The phishing site detection method according to feature 10.
12. The aforementioned information processing device The system accesses the detected phishing site, obtains a sample from the phishing site, and analyzes the sample using a malware analysis system. The phishing site detection method according to feature 7.