Information processing device, information processing method, and program
The information processing device separates and optimizes communication flow data into two-point, additional, and statistical information to reduce data size and efficiently detect security risks, addressing the high analytical load and cost issues of existing systems.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- NEC CORP
- Filing Date
- 2022-08-25
- Publication Date
- 2026-07-29
AI Technical Summary
Existing network security systems struggle with high analytical loads and high-performance processing requirements, making it difficult to deploy them across wide areas due to cost considerations, and they are limited in analyzing and recording large amounts of communication data across corporate networks.
An information processing device that separates communication flow data into two-point information, additional information, and statistical information, checks for new data, records and optimizes it, and manages it efficiently to minimize data size and detect security risks.
The solution minimizes the data size of communication flows to be recorded and efficiently detects unusual communication behavior by analyzing two-point information, reducing the need for high-performance processing environments and enabling widespread deployment.
Smart Images

Figure 0007896420000001 
Figure 0007896420000002 
Figure 0007896420000003
Abstract
Description
Technical Field
[0001] The present invention relates to an information processing apparatus, an information processing method, and a program.
Background Art
[0002] In recent years, while cyberattacks have become more diverse and complex, in corporate networks, the use of cloud services and remote access has increased, and the number of connections of new IT devices such as IoT (Internet of Things) devices and mobile terminals has been increasing. In such a situation, the concept of a zero-trust security model that does not neglect security precautions even in a corporate network has been called for, and the importance of network security has been further increasing.
[0003] On the other hand, when a security incident occurs, it is important to quickly investigate the cause, clarify the scope of influence, and then address the issues of the current network to prevent security incidents from occurring. This series of actions is called network forensics, and it is based on leaving various records indicating the communication status of the network. Note that while the number of IT devices connected to the corporate network is increasing and the amount of communication data is also expanding, high computer resources (processing performance, storage capacity) are required to record and preserve all communication contents, and enormous costs are incurred to perform all recording and preservation.
[0004] Corporate network security measures typically involve placing firewall devices at the boundary with the external network, or deploying Web Application Firewalls (WAFs) in front of servers providing web services to counter external attacks. Furthermore, many security measures also include the deployment of Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS) to enhance security. However, these devices have limitations in their processing capabilities, as they are designed for detailed analysis of communication content, and therefore cannot analyze all communications flowing through the corporate network. Additionally, these devices are generally expensive, making it difficult to deploy them in various locations within the corporate network. Consequently, in many cases, security measures are limited to communications entering the corporate network from the outside.
[0005] Therefore, there is a need for technologies that can efficiently record and preserve large amounts of communication data across a wide range of corporate networks while conserving computer resources, as well as technologies that can analyze the communication status across a wide range of corporate networks and detect security risks.
[0006] In contrast, for example, Patent Document 1 discloses a technique for generating historical spatial data by aggregating historical data of state quantities representing the communication state for each aggregation item, and for detecting changes in the communication state of an information and communication network based on the differences that occur in the observed data of state quantities representing the communication state, using the generated historical spatial data as a reference. [Prior art documents] [Patent Documents]
[0007] [Patent Document 1] Japanese Patent Publication No. 2008-252427 [Overview of the Initiative] [Problems that the invention aims to solve]
[0008] However, the technology described in Patent Document 1 has a high analytical load and requires the preparation of a high-performance processing environment, making it difficult to deploy multiple systems over a wide area due to cost considerations.
[0009] One example of the object of the present invention is to provide an information processing device, an information processing method, and a program that solve the above-mentioned problems. [Means for solving the problem]
[0010] An information processing device according to a first aspect of the present invention includes a storage processing unit that separates communication flow data into two-point information which is information relating to the source and destination of a communication and information indicating the content of the communication, additional information which has information indicating the location where the communication flow data was captured, and statistical information which has the date and time of the communication, the number of packets and the number of octets, and checks whether the two-point information is new and performs recording processing of the two-point information and the statistical information, and a management unit which aggregates the two-point information and performs optimization processing.
[0011] In a second aspect of the present invention, the information processing method involves a storage processing unit separating communication flow data into two-point information, which includes information about the source and destination of the communication and information indicating the content of the communication; additional information, which includes information indicating the location where the communication flow data was captured; and statistical information, which includes the date and time of the communication, the number of packets, and the number of octets. The unit then checks whether the two-point information is new and records the two-point information and the statistical information. The management unit aggregates the two-point information and performs optimization processing.
[0012] A program according to a third aspect of the present invention causes a computer to separate communication flow data into two-point information, which is information relating to the source and destination of a communication and information indicating the content of the communication; additional information, which has information indicating the location where the communication flow data was captured; and statistical information, which has the date and time of the communication, the number of packets, and the number of octets; to check whether the two-point information is new or not; to record the two-point information and the statistical information; to aggregate the two-point information; and to execute an optimization process. [Effects of the Invention]
[0013] According to the present invention, by extracting information between two points communicating from the data of a communication flow and managing the information between the two points separately from statistical information (number of octets, number of packets), the data size of the communication flow to be recorded can be minimized. [Brief explanation of the drawing]
[0014] [Figure 1] This figure shows an example of the basic configuration of an information processing device according to the present invention. [Figure 2] This figure shows an example configuration of an information processing system according to the embodiment. [Figure 3] This figure shows an example configuration of an information processing device according to the embodiment. [Figure 4] This figure shows an example of communication flow data according to the embodiment. [Figure 5] This figure shows an example of a two-point information list according to the embodiment. [Figure 6] This figure shows an example of additional information according to the embodiment. [Figure 7] This figure shows an example of statistical information according to the embodiment. [Figure 8] This flowchart shows an example of a procedure for recording communication flow data according to the embodiment. [Figure 9] This flowchart shows an example of the processing procedure performed by the data retrieval unit according to the embodiment. [Figure 10] This is a flowchart of an example of a variable processing procedure according to the embodiment. [Figure 11] This is a diagram showing the information between two points before the variable conversion process. [Figure 12] This is a diagram showing the information between two points after the variable conversion process. [Figure 13] This is a diagram showing an example of the value of each risk level. [Figure 14] This is a flowchart of an example of the processing procedure of the risk inspection unit for the information between two points at risk level 1 according to the embodiment. [Figure 15] This is a flowchart of an example of the processing procedure of the risk inspection unit for the information between two points at risk level 2 according to the embodiment. [Figure 16] This is a diagram showing an example of the data size of each item of the communication flow data that has not been divided. [Figure 17] This is a diagram showing an example of the data size of each item of the information between two points among the divided communication flow data. [Figure 18] This is a diagram showing an example of the data size of each item of the additional information among the divided communication flow data. [Figure 19] This is a diagram showing an example of the data size of each item of the statistical information among the divided communication flow data.
Mode for Carrying Out the Invention
[0015] Hereinafter, embodiments of the present invention will be described. However, the following embodiments do not limit the invention according to the claims. Also, not all combinations of features described in the embodiments are essential for the solution means of the invention.
[0016] [Basic Configuration Example of Information Processing Device] FIG. 1 is a diagram showing a basic configuration example of an information processing device according to the present embodiment. As shown in FIG. 1, the information processing device 1 includes, for example, a storage processing unit 2 and a management unit 3.
[0017] The storage processing unit 2 receives communication flow data from the network and performs processing. The storage processing unit 2 separates the communication flow data into information between two points and statistical information, checks whether it is new information between two points, and performs recording processing of the information between two points and statistical information.
[0018] Management Unit 3 performs processing to further aggregate and optimize the recorded two-point information, and provides a mechanism that allows operators to search and view time-series communication flow data.
[0019] Each component operates independently, but their processing is coordinated via point-to-point information. Furthermore, each component may or may not be located on the same hardware or operating system, as long as they can communicate with each other. Also, the configuration shown in Figure 1 is just one example and is not limited to this configuration.
[0020] According to the configuration of this embodiment, by extracting information between two points communicating from the communication flow data and managing the two-point information separately from statistical information (number of octets, number of packets), the data size of the communication flow to be recorded can be minimized.
[0021] [Example of an information processing system configuration] Figure 2 shows an example configuration of the information processing system according to this embodiment. As shown in Figure 2, the information processing device 1 collects communication flow data from the network NW and processes it. The network NW includes, for example, routers R1 to R4, servers Se1 to Se3, and terminals C1 to C6.
[0022] Servers Se1 to Se3 provide services via the network (NW). Terminals C1 to C6 access the service via the network (NW). Regarding network connections for terminals and servers, this includes both wired and wireless connections. This is also acceptable. Furthermore, the configuration shown in Figure 2 is just one example, and the number of routers, servers, and terminals is not limited to this.
[0023] [Example of an information processing device configuration] Figure 3 shows an example of the configuration of an information processing device according to this embodiment. As shown in Figure 3, the information processing device 1A includes, for example, a storage processing unit 2, a management unit 3, a determination unit 4, a handling unit 5, and a first storage unit 6. The memory processing unit 2 includes, for example, a communication flow data receiving unit 21 and a two-point information extraction unit 22. The management unit 3 includes, for example, a data retrieval unit 31, a two-point information inspection unit 32, and a second storage unit 33. The determination unit 4 includes, for example, a risk inspection unit 41 and a third storage unit 42. The handling unit 5 includes, for example, an action execution unit 51.
[0024] The first storage unit 6 stores point-to-point information. In this embodiment, point-to-point information refers to information about the source and destination of a communication, as well as information indicating the content of the communication. The information stored in the first storage unit 6 will be described later.
[0025] The communication flow data receiving unit 21 receives communication flow data from the router, such as sFlow, NetFlow, or IPFIX. Alternatively, the communication flow data receiving unit 21 captures packets of communication flowing through a specific interface of the router, generates communication flow data that summarizes a series of communication flows, and receives the generated communication flow data.
[0026] The two-point information extraction unit 22 divides the received communication flow data into three parts: two-point information, additional information, and statistical information. In this embodiment, the additional information is information indicating the location where the communication flow data was captured, such as "Interface 1 of R1". In this embodiment, the statistical information is information such as the date and time of the communication, the number of packets, and the number of octets.
[0027] The two-point information extraction unit 22 checks whether either the source port number or the destination port number included in the two-point information is a value indicating a well-known port (1023 or less) or a port number value indicating a specific service specified by the operator. A well-known port is a port reserved for use by a service or protocol. If the two-point information extraction unit 22 includes a fixed port, it determines that the port number on the other end of the communication is an ephemeral port temporarily assigned for communication and processes that port number as a variable in the two-point information. An ephemeral port is, for example, a port that is not intended for fixed use by a specific purpose or protocol and can be freely used by software or protocols. The two-point information extraction unit 22 also adds the value of the port number that was targeted for variableization to the statistical information.
[0028] After determining whether to convert the information between two points and performing the necessary processing, the two-point information extraction unit 22 queries the first storage unit 6 to check whether information identical to the extracted two-point information already exists. If identical information does not exist, the two-point information extraction unit 22 records the two-point information in the first storage unit 6. At this time, if the two-point information extraction unit 22 has performed the variable conversion process, it specifies, for example, 1 as the risk level. If the two-point information extraction unit 22 has not performed the variable conversion process (i.e., it cannot determine that both the source and destination ports are fixed ports), it specifies, for example, 2 as the risk level. The risk level represents the communication status, as will be described later.
[0029] The two-point information extraction unit 22 queries the first storage unit 6 to check whether information identical to the extracted additional information already exists. If the two-point information extraction unit 22 does not have identical information, it records the additional information in the first storage unit 6.
[0030] The two-point information extraction unit 22 obtains an ID that identifies the two-point information and the additional information, adds it to the statistical information, and stores the statistical information in the second recording unit 33 of the management unit 3. If records of the two-point information and the additional information already exist, the two-point information extraction unit 22 stores the statistical information, with the ID that identifies the two-point information and the additional information, and the port number variable added, in the second recording unit 33.
[0031] The data retrieval unit 31 processes the recorded communication flow data so that it can be viewed in the same format as that used by general devices. For example, the data retrieval unit 31 searches for point-to-point information and statistical information according to search conditions specified by the operator, and combines and outputs the information using the ID (identification information) of each piece of information.
[0032] The two-point information inspection unit 32 checks whether the source port number or destination port number can be made into variables for the two-point information with risk level 2 recorded in the first storage unit 6. The processing method will be described later.
[0033] The second storage unit 33 stores information extracted by the two-point information extraction unit 22 of the storage processing unit 2.
[0034] The determination unit 4 determines whether there are any concerns from a network security perspective based on the point-to-point information. The determination unit 4 determines the level of security risk based on whether similar point-to-point communication has occurred in the past, whether the point-to-point information meets a certain frequency requirement, and whether the communication behavior conforms to the communication protocol.
[0035] The risk inspection unit 41 processes the point-to-point information recorded in the first storage unit 6 according to its risk level value. For example, the risk inspection unit 41 performs a risk assessment from a security perspective on point-to-point information with a risk level of 1 or higher. In doing so, the risk inspection unit 41 compares this information with information on the operation specifications of various protocols registered in the third storage unit 42 and information on prohibited communication content (IP address, port number, protocol) that the operator has registered in advance. Based on the risk assessment result, the risk inspection unit 41 notifies the operator, for example, via the action execution unit 51, that communication requiring caution has occurred. Alternatively, based on the risk assessment result, the risk inspection unit 41 executes a process that the operator has registered in advance on the route via the action execution unit 51.
[0036] The third memory unit 42 stores information regarding the operating specifications of various protocols and information on prohibited communication content that the operator has registered in advance.
[0037] The response unit 5 takes action based on the risk level determined by the determination unit 4. These actions include, for example, displaying information to the operator, providing notifications via sound or light, sending emails, and implementing routing control such as configuring access control lists for routers or changing communication paths.
[0038] The action execution unit 51 notifies the risk inspection unit 41 of the information it outputs. The action execution unit 51 then processes the route output by the risk inspection unit 41.
[0039] According to this embodiment, the memory processing unit 2 and the management unit 3 extract information between two points communicating from the communication flow data, and manage the information between the two points separately from statistical information (number of octets, number of packets), thereby minimizing the data size of the communication flow to be recorded. Furthermore, according to this embodiment, the determination unit 4 can efficiently detect unusual communication behavior by analyzing extracted two-point information rather than all communication flow data.
[0040] [Example of g-flow data] Next, we will explain an example of communication flow data. Figure 4 shows an example of communication flow data according to this embodiment. As shown in Figure 4, the communication flow data includes, for example, a source IP (Internet Protocol) address, a source port number, a source netmask, a source AS (Autonomous System) number, a destination IP address, a destination port number, a destination netmask, a destination AS number, a ToS (Type of Service), information indicating the protocol, TCP flags, information indicating the capture location, the number of packets, the number of octets, the communication time (ms), and information indicating the date and time of occurrence.
[0041] Of the above, the source IP address, source port number, source netmask, source AS number, destination IP address, destination port number, destination netmask, destination AS number, ToS, protocol information, and TCP flags are point-to-point information (g11). Information indicating the capture location is supplementary information (g12). Information showing the number of packets, octets, communication time, and date and time of occurrence is statistical information (g13). Note that the example shown in Figure 4 is just one example, and the communication flow data is not limited to this example.
[0042] [Example of a list of information between two points] Next, we will explain an example of a list of two-point information stored in the first memory unit 6. Figure 5 shows an example of a two-point information list according to this embodiment. As shown in Figure 5, the two-point information list associates, for example, an ID (identification information) with the source IP address, source port number, source netmask, source AS number, destination IP address, destination port number, destination netmask, destination AS number, ToS, protocol information, TCP flags, and risk level. In the TCP flags, SYN indicates that there is a record of a connection establishment request in the communication flow, ACK indicates that there is a record of a receive response in the communication flow, and FIN indicates that there is a record of a connection termination request in the communication flow. Note that the example shown in Figure 5 is just one example, and the list of information between two points is not limited to this.
[0043] [Risk Level] Here, we will explain the risk levels with reference to Figure 5. In this embodiment, the risk levels are set to, for example, 0, 1, 2, 3, and 4. The risk levels are set by the risk inspection unit 41 of the determination unit 4.
[0044] For example, if the risk inspection unit 41 has performed variable processing, it sets the risk level to 1. If the risk inspection unit 41 has not performed variable processing (i.e., it cannot determine that both the source and destination ports are fixed ports), it sets the risk level to 2. The variable processing will be described later.
[0045] [Example of additional information] Next, we will explain an example of additional information. Figure 6 shows an example of additional information according to this embodiment. As shown in Figure 6, the additional information is information about the capture location, for example, information indicating the location of a router interface. The additional information may be, for example, "Router R1 Interface 1", "Router R1 Interface 10", "Router R4 Interface 2", etc. Also, as shown in Figure 6, an ID is assigned to the additional information.
[0046] [Example of a list of statistical information] Next, we will explain an example of statistical information stored in the second memory unit 33. Figure 7 shows an example of statistical information according to this embodiment. As shown in Figure 7, the statistical information includes, for example, information representing the date and time of occurrence, an ID of the two-point information, an ID of the capture location, the number of packets, the number of octets, the communication time (ms), and variables. Note that the example shown in Figure 7 is just one example, and the statistical information is not limited to this.
[0047] [Example of a procedure for recording communication flow data] Next, an example of the communication flow data recording process procedure will be described. Figure 8 is a flowchart showing an example of the communication flow data recording process procedure according to this embodiment.
[0048] (Step S1) The communication flow data receiving unit 21 of the memory processing unit 2 acquires communication flow data from the network NW.
[0049] (Step S2) The two-point information extraction unit 22 of the memory processing unit 2 extracts the source port and destination port included in the acquired communication flow data. The two-point information extraction unit 22 determines whether either the source port number or the destination port number is a value indicating a well-known port of 1023 or less, or a port number value indicating a specific service specified by the operator. In this embodiment, well-known ports of 1023 or less, and ports indicating a specific service specified by the operator are referred to as "fixed ports". In other words, the two-point information extraction unit 22 determines whether either the source port or the destination port is a fixed port. If either the source port or the destination port is a fixed port (Step S2; YES), the two-point information extraction unit 22 proceeds to the process in Step S3. If the source port and destination port are not fixed ports (Step S2; NO), the two-point information extraction unit 22 proceeds to the process in Step S4.
[0050] (Step S3) The two-point information extraction unit 22 determines that the port number on the other end of the communication is an ephemeral port temporarily assigned for communication because the two-point information includes a fixed port. The two-point information extraction unit 22 processes the port number of the fixed port as a variable in the two-point information.
[0051] (Step S4) The two-point information extraction unit 22 refers to the first storage unit 6 and checks whether the same information as the extracted two-point information is already stored in the first storage unit 6. If the two-point information extraction unit 22 finds that the same information as the extracted two-point information is already stored in the first storage unit 6 (Step S4; YES), it proceeds to the process in Step S9. If the two-point information extraction unit 22 finds that the same information as the extracted two-point information is not stored in the first storage unit 6 (Step S4; NO), it proceeds to the process in Step S5.
[0052] (Step S5) The two-point information extraction unit 22 determines whether or not variable processing has been performed. If variable processing has not been performed (Step S5; NO), the two-point information extraction unit 22 proceeds to the process in Step S6. If variable processing has been performed (Step S5; YES), the two-point information extraction unit 22 proceeds to the process in Step S7.
[0053] (Step S6) The two-point information extraction unit 22 sets the risk level to 2 because it has not performed variable processing (it cannot determine that both the source and destination ports are fixed ports). After processing, the two-point information extraction unit 22 proceeds to the processing in step S8.
[0054] (Step S7) The two-point information extraction unit 22 sets the risk level to 1 because it has performed variable processing. After processing, the two-point information extraction unit 22 proceeds to the processing in step S8.
[0055] (Step S8) The two-point information extraction unit 22 stores the set risk level in the first storage unit 6, associating it with the two-point information. At this time, the first storage unit 6 assigns an ID to the stored two-point information.
[0056] (Step S9) The two-point information extraction unit 22 obtains an ID for the two-point information stored in step S8. Alternatively, the two-point information extraction unit 22 obtains an ID for the two-point information that was determined to be identical in step S4.
[0057] (Step S10) The two-point information extraction unit 22 refers to the first storage unit 6 and checks whether the same information as the additional information is already stored in the first storage unit 6. If the two-point information extraction unit 22 finds that the same information as the extracted additional information is already stored in the first storage unit 6 (Step S10; YES), it proceeds to the process in step S12. If the two-point information extraction unit 22 finds that the same information as the extracted additional information is not stored in the first storage unit 6 (Step S10; NO), it proceeds to the process in step S11.
[0058] (Step S11) The two-point information extraction unit 22 stores additional information in the first storage unit 6 because no identical information exists. At this time, the first storage unit 6 assigns an ID to the stored additional information.
[0059] (Step S12) The two-point information extraction unit 22 obtains an ID for the additional information stored in step S11. Alternatively, the two-point information extraction unit 22 obtains an ID for the additional information that was determined to be the same in step S10.
[0060] (Step S13) The two-point information extraction unit 22 associates the two-point information and the ID of the additional information with the statistical information.
[0061] (Step S14) The two-point information extraction unit 22 stores the associated statistical information in the second storage unit 33.
[0062] [Example of processing performed by the data retrieval unit] Next, we will explain an example of processing performed by the data retrieval unit 31 of the management unit 3. Figure 9 is a flowchart showing an example of the processing procedure performed by the data retrieval unit according to this embodiment.
[0063] (Step S101) The data retrieval unit 31 determines whether the information between two points is at risk level 2, which is the target of processing. If the risk level is 2 (Step S101; YES), the data retrieval unit 31 proceeds to the processing in step S102. If the risk level is not 2 (Step S101; NO), the data retrieval unit 31 terminates the processing.
[0064] (Step S102) The data search unit 31 determines whether there is any other point-to-point information with the same destination IP address and destination port number combination. If there is any other point-to-point information with the same destination IP address and destination port number combination (Step S102; YES), the data search unit 31 proceeds to step S103. If there is no other point-to-point information with the same destination IP address and destination port number combination (Step S102; NO), the data search unit 31 terminates the process.
[0065] (Step S103) The data search unit 31 determines whether the number of point-to-point information entries with the same destination IP address and destination port number combination is greater than or equal to a certain number. If the number of point-to-point information entries with the same destination IP address and destination port number combination is greater than or equal to a certain number (Step S103; YES), the data search unit 31 proceeds to the process in Step S104. If the number of point-to-point information entries with the same destination IP address and destination port number combination is less than a certain number (Step S103; NO), the data search unit 31 terminates the process.
[0066] (Step S104) The data retrieval unit 31 determines that the port number associated with the destination IP address is a fixed port that provides a specific service, and performs processing to convert it into a variable.
[0067] [Example of variable processing] Next, an example of variable processing will be described. Figure 10 is a flowchart of an example of the variable processing procedure according to this embodiment.
[0068] (Step S201) The two-point information extraction unit 22 extracts the source port number that is opposite to the destination port number that has been determined to be a fixed port in the two-point information, and makes it a variable in the two-point information (variable creation).
[0069] (Step S202) The two-point information extraction unit 22 changes the risk level of the variableized two-point information to 1.
[0070] (Step S203) The two-point information extraction unit 22 searches for statistical information associated with the ID of the processed two-point information.
[0071] (Step S204) The two-point information extraction unit 22 records the source port number, which was extracted as a variable value of the statistical information found during the search, as a variable value.
[0072] (Step S205) The two-point information extraction unit 22 checks whether the same content as the two-point information that has been processed as a variable exists in the first storage unit 6. If the two-point information extraction unit 22 finds that the same content as the two-point information that has been processed as a variable exists in the first storage unit 6 (Step S205; YES), it proceeds to the process in step S206. If the two-point information extraction unit 22 finds that the same content as the two-point information that has been processed as a variable does not exist in the first storage unit 6 (Step S205; NO), it terminates the process.
[0073] (Step S206) The two-point information extraction unit 22 retains the IDs that were assigned earlier and deletes the two-point information for the IDs that were assigned later.
[0074] (Step S207) The two-point information extraction unit 22 searches the second storage unit 33 for statistical information associated with the deleted ID.
[0075] (Step S208) The two-point information extraction unit 22 changes the ID value of the two-point information found during the search to a retained ID value.
[0076] Thus, the two-point information extraction unit 22 performs variable processing on the destination port number of the two-point information being transmitted using the same IP address and port number, which it has determined to be a fixed port, as shown in Figure 10.
[0077] An example of variableization processing will be explained using Figures 11 and 12. Figure 11 shows the information between two points before variableization processing. Figure 12 shows the information between two points after variableization processing. In the example shown in Figures 11 and 12, the port number "23457" for the IP address "172.31.1.200" is determined to be a fixed port, and the IDs "5", "6", "10", "11", "15", and "16" of the point-to-point information are converted into variables. In this example, as shown in Figures 11 and 12, after the variable conversion process, the point-to-point information for "5" and "10", and for "6" and "11" become identical, so the point-to-point information for "10" and "11" is deleted.
[0078] Through the operation of the flow data recording device 33 and the management unit 3, communication flow data is separated into point-to-point information, additional information, and statistical information, and recorded in an optimized format. In this embodiment, the data search unit 31 performs the process of assembling the recorded communication flow data so that it can be viewed in the format shown in Figure 4. The data search unit 31 searches for point-to-point information and statistical information according to the search conditions specified by the operator, combines them using the ID of each piece of information, and outputs them. With these mechanisms, according to this embodiment, it is possible to record communication flow data that is easy to read while reducing the size of the data to be recorded.
[0079] [Risk Level] Next, I will explain some examples of risk levels. The determination unit 4 starts processing after a certain period of communication flow data has been recorded in the first storage unit 6 and the second storage unit 33. The risk inspection unit 41 performs processing according to the risk level value of the two-point information recorded in the first storage unit 6. Figure 13 shows examples of the values for each risk level.
[0080] As shown in Figure 13, risk level "0" indicates "normal, everyday communication." Risk level "1" indicates "communication via a fixed port where it is not possible to determine whether it is normal, everyday communication." Risk level "2" indicates "communication via an unknown port where it is not possible to determine whether it is normal, everyday communication." Risk level "3" indicates "communication that has been judged to pose a security risk." Risk level "4" indicates "communication that has been judged to pose a security risk that requires countermeasures." Risk level "10" indicates "exceptional communication." Note that the risk level values and descriptions shown in Figure 13 are examples only and are not limited to these.
[0081] First, we will explain the processing of the risk assessment unit for two-point information at risk level 1. Figure 14 is a flowchart of an example of the processing procedure of the risk assessment unit for two-point information at risk level 1 according to this embodiment.
[0082] The Risk Assessment Department 41 searches for information between two points with risk level 1 and sequentially checks the risk situation. (Step S301) The risk inspection unit 41 checks the protocol value and determines whether the protocol is TCP. If the protocol is TCP (Step S301; YES), the risk inspection unit 41 proceeds to step S302. If the protocol is not TCP (Step S301; NO), the risk inspection unit 41 proceeds to step S305.
[0083] (Step S302) If it is TCP, the risk inspection unit 41 performs TCP-specific checks. Specifically, the risk inspection unit 41 checks from the value of the TCP flag whether connection processing is being performed correctly in accordance with the protocol specifications.
[0084] (Step S303) Communication flow data may capture a series of communication processes divided by time. Therefore, if the TCP flag value is not "SYN, ACK, FIN", the risk inspection unit 41 searches for point-to-point information where all values except the TCP flag value are the same, and integrates it with the TCP flag value of that point-to-point information to check the status of the connection processing. Through this process, the risk inspection unit 41 checks whether the TCP flag value is invalid or not. If the TCP flag value is invalid (Step S303; YES), the risk inspection unit 41 proceeds to step S304. If the TCP flag value is not invalid (Step S303; NO), the risk inspection unit 41 proceeds to step S306.
[0085] (Step S304) If the TCP flag value is invalid, the risk inspection unit 41 determines that it is invalid, for example, if it is only SYN or only FIN, and changes the risk level of the two-point information to 4. After processing, the risk inspection unit 41 terminates the processing related to the risk level.
[0086] (Step S305) If the protocol is not TCP, the risk inspection unit 41 compares the port number or protocol value with the information on various protocol operation specifications registered in the third storage unit 42 to determine whether the specification is one in which round-trip communication occurs, i.e., whether it is communication that performs reply processing. For example, if the port number is "53" and the protocol is "UDP", it is determined that it is communication such as a name resolution request to the Domain Name System (DNS), and therefore communication indicating a reply to the request occurs. If the risk inspection unit 41 determines that it is communication that performs reply processing (Step S305; YES), it proceeds to the process in step S306. If the risk inspection unit 41 determines that it is not communication that performs reply processing (Step S305; NO), it proceeds to the process in step S308.
[0087] (Step S306) In the case of such two-point information, the risk inspection unit 41 searches whether or not two-point information indicating a reply process exists, in accordance with the protocol specifications. If no two-point information indicating a reply process exists (Step S306; YES), the risk inspection unit 41 proceeds to step S307. If two-point information indicating a reply process exists (Step S306; NO), the risk inspection unit 41 proceeds to step S308.
[0088] (Step S307) If no two-point information indicating a reply process exists, the risk inspection unit 41 changes the risk level to 3. However, if, for example, information is shared from a network monitoring device operating separately from this system that a response communication was not possible due to a failure, it is also possible to take this information into account and set the risk level to 0. After processing, the risk inspection unit 41 terminates the processing related to the risk level.
[0089] (Step S308) The risk inspection unit 41 obtains statistical information associated with the two-point information that has been confirmed to be communicating in accordance with the protocol specifications, regardless of the protocol value, from the second storage unit 33, and confirms the communication frequency (frequency of occurrence of two-point information during a certain period).
[0090] (Step S309) The risk inspection unit 41 checks for the presence of two-point information where the destination IP address and destination port number are the same, but the source IP address and source port number are different.
[0091] (Step S310) The risk inspection unit 41 determines whether the communication frequency is greater than or equal to a certain number for the same destination IP address and destination port number. If the communication frequency is greater than or equal to a certain number (Step S310; YES), the risk inspection unit 41 proceeds to the process in Step S311. If the communication frequency is less than a certain number (Step S310; NO), the risk inspection unit 41 terminates the processing related to the risk level.
[0092] (Step S311) If the risk inspection unit 41 detects a certain number of communications to the same destination IP address and destination port number, it determines that the communications are normal and routine communications and changes the risk level to 0. However, if the risk inspection unit 41 detects communications that match those registered in the third storage unit 42, it changes the risk level to 3 or 4. After processing, the risk inspection unit 41 terminates the processing related to the risk level.
[0093] Next, we will describe the processing of the risk assessment unit for two-point information at risk level 2. Figure 15 is a flowchart of an example of the processing procedure of the risk assessment unit for two-point information at risk level 2 according to this embodiment.
[0094] The risk assessment unit 41 searches for two-point information at risk level 2 and sequentially checks the risk situation. (Step S401) The risk inspection unit 41 searches the first storage unit 6 for the presence of point-to-point information where the source IP address and destination IP address are the same.
[0095] (Step S402) If the risk inspection unit 41 finds matching two-point information, it determines whether or not there is any information among them where the destination port number indicates a fixed port. If the risk inspection unit 41 finds information where the destination port number indicates a fixed port (Step S402; YES), it proceeds to the process in Step S403. If the risk inspection unit 41 finds no information where the destination port number indicates a fixed port (Step S402; NO), it proceeds to the process in Step S406.
[0096] (Step S403) The risk inspection unit 41 confirms the communication service specifications indicated by the fixed port from the information in the third storage unit 42.
[0097] (Step S404) The risk inspection unit 41 performs communication using the ephemeral port and determines whether the information between the two points matches the operation. If the information between the two points matches the operation (Step S404; YES), the risk inspection unit 41 proceeds to the process in step S405. If the information between the two points matches the operation (Step S404; NO), the risk inspection unit 41 proceeds to the process in step S406.
[0098] (Step S405) If a communication service is found that uses an ephemeral port to initiate communication separately on both the sending and receiving sides, the point-to-point information can be determined to be a secondary communication by that communication service and therefore a normal communication. For example, this case applies when a series of communication operations are performed using TFTP (Trivial File Transfer Protocol). However, since the port number is not the same each time, the risk inspection unit 41 changes the risk level for such point-to-point information from 0 to 10, which signifies an exception. After processing, the risk inspection unit 41 terminates the processing related to the risk level.
[0099] (Step S406) If it cannot be determined that the two-point information is a secondary communication process resulting from the communication of other two-point information, the risk inspection unit 41 changes the risk level to 3 as a communication that should be viewed with caution. Furthermore, if the risk level is changed for all processing of two-point information with a risk level of 3, the risk inspection unit 41 also checks for the presence of two-point information indicating reverse communication using the same IP address and port number. If such information exists, the risk inspection unit 41 determines that the two-point information is a response communication and changes the risk level for it to the same value.
[0100] Furthermore, if the risk inspection unit 41 detects point-to-point information with a risk level of 3 or higher, it notifies the operator via the action execution unit 51 of the response unit 5 that a communication requiring attention has occurred. The operator can choose from various notification methods, such as display on a screen, sound, light illumination, or email notification. For point-to-point information with risk level 4, operators can perform actions that they have registered in advance. These actions could include configuring access control lists on routers or changing communication paths. Alternatively, they could manipulate network connections and communication paths via an SDN (Software Defined Networking) controller that controls the network.
[0101] For example, the operator of the information processing device 1A checks the content of the notified point-to-point information via the flow data management device. If the operator determines that the communication is normal and without risk, the operator can change the risk level by operating the information processing device 1A. The operator can change the risk level from, for example, 3 to 2 or 0 by operating the information processing device 1A. In addition, the operator can operate the information processing device 1A to register the point-to-point information as problem-free in the third storage unit 42 of the determination unit 4. If the point-to-point information is registered as problem-free in the third storage unit 42, the operator can automatically change the risk level to 0 during the inspection process in the risk inspection unit 41. Note that for point-to-point information with a risk level of 3, the risk level may be changed to 0 or 1 over time, depending on the risk level of newly generated point-to-point information, or after undergoing a variableization process.
[0102] As described above, the operation of the determination unit 4 and the response unit 5 does not target all received communication flow data, but rather eliminates duplicate information and narrows the target to two-point information with security risks before performing analysis and countermeasures from a security perspective. As a result, according to this embodiment, it becomes possible to perform analysis processing even in environments where tens of thousands or hundreds of thousands of communication flow data are generated per second.
[0103] [Data size of communication flow data] Here, we will explain an example of the data size of communication flow data. Figure 16 shows an example of the data size of each item in undivided communication flow data. As shown in Figure 16, the source IP address is 4 bytes, the source port number is 2 bytes, the source netmask is 1 byte, the source AS number is 4 bytes, the destination IP address is 4 bytes, the destination port number is 2 bytes, the destination netmask is 1 byte, and the destination AS number is 4 bytes. In addition, ToS is 1 byte, the protocol is 1 byte, the TCP plug is 1 byte, the capture location is 8 bytes, the packet count is 4 bytes, the octet count is 4 bytes, the communication time [ms] is 2 bytes, and the occurrence date and time are 8 bytes. Note that in Figure 16, the communication flow data is shown divided vertically for illustrative purposes, but in reality it is a single, undivided data. Thus, the data size per communication flow data entry is 51 bytes.
[0104] Figure 17 shows an example of the data size of each item in the two-point information obtained by dividing the communication flow data. As shown in Figure 17, the two-point information consists of 4 bytes for the ID, 4 bytes for the source IP address, 2 bytes for the source port number, 1 byte for the source netmask, 4 bytes for the source AS number, 4 bytes for the destination IP address, and 2 bytes for the destination port number. In addition, the destination netmask is 1 byte, the destination AS number is 4 bytes, ToS is 1 byte, the protocol is 1 byte, the TCP plug is 1 byte, and the risk level is 1 byte. Note that in Figure 17, the two-point information is shown divided vertically for illustrative purposes, but in reality it is a single, undivided data. When communication flow data is divided using the method of this embodiment, the information between two points is 30 bytes, as shown in Figure 17.
[0105] Figure 18 shows an example of the data size of each item of additional information when the communication flow data is divided. As shown in Figure 18, the additional information consists of an ID of 4 bytes and a capture location of 8 bytes. When communication flow data is divided using the method of this embodiment, the additional information is 12 bytes, as shown in Figure 18.
[0106] Figure 19 shows an example of the data size of each item in the statistical information obtained by dividing the communication flow data. As shown in Figure 19, the statistical information consists of 8 bytes for the date and time of occurrence, 4 bytes for the point-to-point information ID, 4 bytes for the capture location ID, 4 bytes for the number of packets, 4 bytes for the number of octets, 2 bytes for the communication time [ms], and 2 bytes for the variables. When the communication flow data is divided using the method of this embodiment, the additional information is 28 bytes, as shown in Figure 18.
[0107] Thus, the total number of bytes increases by 18 bytes after splitting, compared to 51 bytes before splitting the communication flow data. However, verification shows that in a typical corporate network where similar communication between two points is repeated many times, the data size recorded using the method of this embodiment is approximately 55% of that when the communication flow data is not split.
[0108] For example, let's assume an environment where 1 million instances of the same two-point communication are recorded, with 1,000 locations for capturing communication flows (number of additional information items), and 20,000 communication flows per second. In this environment, if communication flow data is recorded using the method of this embodiment, the daily data size will be 29 megabytes for the two-point information and 12 kilobytes for the additional information. The statistical information will be approximately 45 gigabytes. If the communication data flow is recorded in a format that does not differentiate, the data size will be approximately 82 gigabytes per day. Therefore, in this example, the data size can be reduced by approximately 55% according to this embodiment.
[0109] Thus, in this embodiment, the data size required to record the received communication flow data can be reduced to nearly half the size required when the communication flow data is not divided, through the recording and management operations of the storage processing unit 2 and the management unit 3.
[0110] Furthermore, the analysis and countermeasures performed by the determination unit and the countermeasure unit 5 in this embodiment from a security perspective can significantly reduce the amount of communication flow data to be analyzed. For example, if a company uses a system that automatically registers work start information in the attendance system when a terminal is started at the start of work, in an environment with 10,000 employees (10,000 terminals), at least 10,000 communication flows will occur during the work start time. Also, if there are multiple locations where communication flows are captured and communication flows are captured redundantly, the number could potentially increase several times over.
[0111] Even in such an environment, applying the method of this embodiment sets the two-point information representing this communication flow to risk level 0, thus excluding it from analysis from a security perspective. Furthermore, according to this embodiment, even in an environment where a large amount of communication flow data is generated, normal communication flows that occur on a daily basis can be selected during operation and automatically excluded from analysis. Moreover, according to this embodiment, analysis processing can be concentrated on communication flows that are not normally seen, thus reducing processing costs.In addition, according to this embodiment, since the system learns the communication flows that flow periodically and the decisions made by the operator during operation, it can be operated without requiring special skills.
[0112] [Differentiation] In this embodiment, the risk inspection unit 41 is responsible for performing risk level determination processing for each initially assigned risk level value and determining whether countermeasures should be taken. In a modified example, this role may be extended to detect server equipment providing services from all the point-to-point information recorded in the first storage unit 6, and to determine whether there are any security risks based on the service content (port number) and number of services provided by the server equipment.
[0113] In a modified example, by sorting a list of point-to-point information by destination IP address and extracting information where the destination port number is a fixed port rather than a variable, it is possible to determine that the device with the destination IP address is a server device. In the modified version, by examining which fixed port number the extracted destination IP address is receiving communications on, the content and number of services can be determined. In the modified version, this information can be notified to the operator via a risk mitigation device, allowing the operator to determine whether or not they are receiving communications for services they did not intend. In the modified version, by registering the role of each server device (port numbers for permitted communications) in the third storage unit 42, security risks can be automatically determined and addressed without the operator's judgment.
[0114] Furthermore, in the modified version, the management unit 3 can combine the point-to-point information from the first storage unit 6 with the occurrence date and time data of the statistical information from the second storage unit 33 to investigate the occurrence status of point-to-point information (specific point-to-point communication) over time. If the occurrence status of point-to-point information has periodicity, the modified version can predict the future occurrence status of that point-to-point information by using methods such as the Holt-Winters method. In addition, the modified version can quickly detect changes in communication conditions that are different from the norm by comparing the predicted value with the actual situation. Thus, the modified version can be applied not only to analysis from a security perspective but also to fault detection and other applications.
[0115] The information processing device 1 (or 1A) described above may have a computer system inside. The program for causing the information processing device 1 (or 1A) to perform the above-described processes may be stored on a computer-readable recording medium of the information processing device 1 (or 1A), and the above processes may be performed by the computer of the information processing device 1 (or 1A) reading and executing this program. Here, a computer-readable recording medium refers to a magnetic disk, magneto-optical disk, CD-ROM, DVD-ROM, semiconductor memory, etc. Alternatively, this computer program may be distributed to a computer via a communication line, and the computer that receives the distribution may execute the program. Furthermore, the above program may be intended to implement some of the functions of the respective processing units described above. It may also be a so-called differential file (differential program) that can implement the aforementioned functions in combination with programs already recorded in the computer system.
[0116] The computer system of the information processing device 1 (or 1A) may include, for example, a CPU (Central Processing Unit), main memory, auxiliary memory, an interface, and a non-volatile recording medium. The CPU may perform processing to be carried out by the information processing device 1 (or 1A) according to a program.
[0117] While embodiments of this invention have been described in detail above with reference to the drawings, the specific configuration is not limited to these embodiments and includes designs and the like that do not depart from the spirit of this invention. [Explanation of Symbols]
[0118] 1,1A... Information processing equipment, 2...Memory processing unit, 3...Management Department, 4...judgment section, 5... Handling section, 6...first storage section, 21...Communication flow data receiving unit, 22... Information extraction unit between two points, 31...Data Retrieval Unit, 32... Information Inspection Department between 2 points, 33...Second memory section, 41…Risk Inspection Department, 42...Third memory section, 51…Action Execution Department,
Claims
1. The communication flow data is separated into two-point information, which includes information about the source and destination of the communication and information indicating the content of the communication; additional information, which includes information indicating the location where the communication flow data was captured; and statistical information, which includes the date and time of the communication, the number of packets, and the number of octets. The two-point information is checked to see if it is new, and the two-point information and the statistical information are recorded in association with identifiers corresponding to the two-point information. The information between the two points is aggregated, and an optimization process is performed. It is checked whether either the source port number or the destination port number included in the aforementioned two-point information is a value indicating a well-known port or a port number value indicating a specified service. If the information between the two points includes a fixed port, the port number of the communication counterpart included in the information is determined to be an ephemeral port temporarily assigned for communication, and the port number is processed to become a variable in the information between the two points. The value of the port number that was the subject of the variableization is to be added to the statistical information. Information processing device.
2. After performing the variable determination and processing, it is checked whether the same information as the two-point information is already stored in the first storage unit. If the same information is not stored, the information between the two points is recorded in the first storage unit. If the aforementioned variableization process is performed, the risk level representing the communication status is set to risk level 1, which indicates that it is not possible to determine whether the communication via the fixed port is normal or not. If the aforementioned variable processing is not performed, the risk level is set to risk level 2, which indicates that it is not possible to determine whether the communication from an unknown port is normal, routine communication or not. The information processing apparatus according to claim 1.
3. Check whether the same information as the additional information is already stored in the first storage unit, If identical information does not exist, the additional information is stored in the first storage unit. The information processing apparatus according to claim 2.
4. Obtain identification information that identifies the two-point information and the additional information, add the obtained identification information to the statistical information and record it in the second storage unit, If the two-point information and the additional information are already stored in the second storage unit, the statistical information, which includes the identification information that identifies the two-point information and the additional information, and a port number variable, is stored in the second storage unit. The information processing apparatus according to claim 3.
5. Based on the information between the two points mentioned above, a determination is made as to whether there are any concerns from a network security perspective, and the risk level representing the communication status is changed or determined. For the risk level determined above, one of the following actions will be taken: outputting information to a predetermined output destination corresponding to the risk level, configuring the router's access control list, or changing the communication path. An information processing device according to any one of claims 1 to 4.
6. A first storage unit for storing the information between two points, and a second storage unit for storing the information between two points and the additional information, wherein the processing operation starts after the communication flow data for a certain period of time has been recorded. The information processing apparatus according to claim 5.
7. The information processing device is The communication flow data is separated into two-point information, which includes information about the source and destination of the communication and information indicating the content of the communication; additional information, which includes information indicating the location where the communication flow data was captured; and statistical information, which includes the date and time of the communication, the number of packets, and the number of octets. The two-point information is checked to see if it is new, and the two-point information and the statistical information are recorded in association with identifiers corresponding to the two-point information. It is checked whether either the source port number or the destination port number included in the aforementioned two-point information is a value indicating a well-known port or a port number value indicating a specified service. If the information between the two points includes a fixed port, the port number of the communication counterpart included in the information is determined to be an ephemeral port temporarily assigned for communication, and the port number is processed to become a variable in the information between the two points. The value of the port number that was the subject of the variableization is added to the statistical information, The information between the two points is aggregated, and an optimization process is performed. Information processing methods.
8. On the computer, The communication flow data is separated into two-point information, which includes information about the source and destination of the communication and information indicating the content of the communication; additional information, which includes information indicating the location where the communication flow data was captured; and statistical information, which includes the date and time of the communication, the number of packets, and the number of octets. The system then verifies whether the two-point information is new and records the two-point information and the statistical information, associating them with identifiers corresponding to the two-point information. The system will then verify whether either the source port number or the destination port number included in the aforementioned two-point information is a value indicating a well-known port, or a port number value indicating a specified service. If the information between the two points includes a fixed port, the port number of the communication counterpart included in the information is determined to be an ephemeral port temporarily assigned for communication, and the port number is treated as a variable in the information between the two points. The value of the port number that was the subject of the variableization is to be added to the statistical information. The information between the two points is aggregated, and an optimization process is performed. program.