Email analysis device, email analysis system, and email analysis method

JP7897777B2Active Publication Date: 2026-07-30HITACHI LTD
View PDF 6 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
HITACHI LTD
Filing Date
2022-11-14
Publication Date
2026-07-30

Smart Images

  • Figure 0007897777000001
    Figure 0007897777000001
  • Figure 0007897777000002
    Figure 0007897777000002
  • Figure 0007897777000003
    Figure 0007897777000003
Patent Text Reader

Abstract

To detect indication of attack from a received mail, and support the analysis.SOLUTION: A mail analyzer comprises a processor and a storage unit. The processor is configured to: classify malware included in a mail into families; store a classification result in the storage unit; analyze a reception tendency for each family, by using the classification result stored in the storage unit; and output data in which a result related to the analysis of the reception tendency is described on a screen.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a mail analysis apparatus, a mail analysis system, and a mail analysis method.

Background Art

[0002] Mail exists as a major infection route in cyberattacks. It is known that various types of malware carry out attacks via mail. For example, Emotet, which has been popular in recent years, has various attack methods, and many of them are reported to utilize mail at the initial stage of operation. In addition, there is also a report that among various infection routes in various malware, attacks via mail are most frequently observed. From such a situation, it is important to block malware attacks via mail, take preventive measures in advance, and perform analysis. Here, there is a technology for detecting suspicious mails included in mails arriving at a self-organized network based on attachment files, mail destination information, etc. This technology is implemented, for example, as a security appliance in the layer of a mail server, and suppresses damage by blocking suspicious mails before they reach users. On the other hand, the analysis after detection is basically entrusted to the hands of analysts or operators. Malware has a type called malware family, and the types are diverse. Therefore, it is not realistic to analyze all malware, and it is desirable to focus on detecting and analyzing the malware that is popular at each time.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Non-Patent Documents

[0004]

Non-Patent Document 1

[0005] [Non-Patent Document 2] Rupinder Paul Khandpur, et al.: Crowdsourcing Cybersecurity: Cyber ​​Attack Detection using Social Media, 2017 ACM on Conference on Information and Knowledge Management (CIKM'17), pp.1049-1057 (2017). https: / / dl.acm.org / doi / 10.1145 / 3132847.3132866 [Overview of the project] [Problems that the invention aims to solve]

[0006] As mentioned earlier, malware attacks via email are a threat, and blocking attacks, taking proactive measures, and analyzing them are crucial. On the other hand, malware is categorized into various types called malware families, and these families are diverse. Therefore, it is not practical to analyze all malware, and it is desirable to focus on detecting and analyzing malware that is prevalent at any given time.

[0007] Information on prevalent malware can be obtained from reports published by security vendors and public institutions. However, since these reports are created after detection and analysis by experts within each organization, there is a time lag between the emergence of a threat and its reporting. For this reason, in order to understand malware threats affecting one's own organization and mitigate damage, it is desirable for the organization to understand the attack trends (reception trends) for each malware family and conduct analysis. On the other hand, the number of malware families is large, and analysis requires specialized knowledge, making the implementation cost high and highly dependent on individual expertise.

[0008] Given this situation, technologies related to email and technologies for obtaining highly timely information have been proposed. The technology disclosed in Patent Document 1 is thought to detect suspicious emails and generate alerts according to the user's characteristics. However, it is thought to focus on the detection of suspicious emails, and support for trend detection and analysis is outside its scope. Also, it provides alerts to each user rather than to analysts, so its purpose is also considered to be different. The technology disclosed in Non-Patent Document 1 is thought to detect suspicious emails using communication patterns and email characteristics. However, similar to the technology disclosed in Patent Document 1, it is thought to focus on the detection of suspicious emails, and support for trend detection and analysis is outside its scope. The technology disclosed in Non-Patent Document 2 is thought to detect cyberattacks from SNS posts. Because it extracts information from SNS, it tends to be faster than official reports, but it is thought to be inherently uncertain. Also, it is thought that it is impossible to detect information that does not appear on SNS, especially trends that are only seen within the organization.

[0009] As described above, while there are many technologies focused on detecting suspicious emails containing malware, there is little focus on supporting the identification and analysis of trends. This is a challenge because it involves high implementation costs and is highly dependent on individual expertise. [Means for solving the problem]

[0010] A typical example of the present invention is as follows: The email analysis device comprises a processor and a memory unit. , a communication interface, The processor classifies malware contained in emails into families, stores the classification results in the memory, and uses the classification results stored in the memory to analyze the receiving trends for each family. Through the interface, threat information is obtained from external sites outside the email analysis device, and the relationship between the threat information and the receiving trends for each family is analyzed. Output data that displays the results of the analysis on the screen.

[0011] A typical example of the present invention is as follows: The email analysis system comprises the email analysis device and a terminal to which data from the email analysis device is output.

[0012] A typical example of the present invention is as follows: The email analysis method comprises a processor and a memory unit. A mail analysis device equipped with a communication interface. This method involves using [a specific method] to process emails. In addition to gaining an advantage, The steps involve storing the acquired emails in the storage unit and dividing the malware contained in the emails stored in the storage unit into families. They are similar, The steps include storing the classification results in a memory unit, and analyzing the reception trends for each family using the classification results stored in the memory unit. The steps include: obtaining threat information from external sites outside the email analysis device via an interface; analyzing the relationship between the threat information and receiving trends for each family; and determining the relationship. The system includes the step of outputting data that displays the results of the analysis on a screen. [Effects of the Invention]

[0013] According to the present invention, it is expected that the system will automatically detect signs of attacks for each malware family and provide supporting information regarding the detected signs, thereby semi-automating and streamlining the analysis and reducing the costs and reliance on human expertise involved in detecting and analyzing malware attacks via email. [Brief explanation of the drawing]

[0014] [Figure 1] This figure shows an example configuration of the email analysis system according to the first embodiment. [Figure 2] This figure shows an example of a list of detected emails. [Figure 3] It is a diagram showing an example of a list of detected malware. [Figure 4] It is a diagram showing an example of a list of malware families. [Figure 5] It is a diagram showing an example of a list of alerts. [Figure 6] It is a diagram showing an example of an overview of the overall processing flow. [Figure 7] It is a diagram showing an example of the processing flow of detecting email acquisition. [Figure 8] It is a diagram showing an example of the processing flow of malware family classification. [Figure 9] It is a diagram showing an example of the processing flow of extracting reception tendencies. [Figure 10] It is a diagram showing an example of the processing flow of alert generation. [Figure 11] It is a diagram showing an example of the processing flow of screen description. [Figure 12] It is a diagram showing an example of the display screen of the email analysis system. [Figure 13] It is a diagram showing a configuration example of the email analysis system according to the second embodiment. [Figure 14] It is a diagram showing an example of a list of threat information. [Figure 15] It is a diagram showing an example of a list of threat hunting rules. [Figure 16] It is a diagram showing an example of the overall processing flow. [Figure 17] It is a diagram showing an example of the processing flow of threat relevance analysis. [Figure 18] It is a diagram showing an example of the processing flow of threat information association. <o000111>It is a diagram showing an example of the processing flow of attack target estimation. [Figure 20] It is a diagram showing an example of the processing flow of threat hunting rule generation. [Figure 21] It is a diagram showing a configuration example of the email analysis system according to the third embodiment. [Figure 22] It is a diagram showing an example of the processing flow of report provision. [Modes for carrying out the invention]

[0015] Embodiments of the present invention will be described below with reference to the drawings. However, the present invention is not to be construed as being limited to the embodiments described below. It will be readily apparent to those skilled in the art that the specific configuration can be modified without departing from the spirit or intent of the present invention. In the configurations described below, identical or similar configurations or functions are denoted by the same reference numeral, and redundant explanations may be omitted. The designations "1st," "2nd," "3rd," etc., used in this specification are for identification purposes only and do not necessarily limit the number or order. The positions, sizes, shapes, and ranges of each component shown in the drawings, etc., may not represent the actual positions, sizes, shapes, and ranges, etc., in order to facilitate understanding of the invention. Therefore, the present invention is not limited to the positions, sizes, shapes, and ranges, etc., disclosed in the drawings, etc. Examples of various types of information may be described using terms such as "table," "list," and "queue," but these types of information may also be represented by other data structures. For example, various types of information such as "XX table," "XX list," and "XX queue" may be referred to as "XX information." When describing identification information, terms such as "identification information," "identifier," "name," "ID," and "number" are used, and these terms are interchangeable. In embodiments, processing performed by executing a program may be described. Here, the computer executes the program using a processor (e.g., CPU, GPU) and performs processing defined by the program using memory resources (e.g., memory) and interface devices (e.g., communication ports). Therefore, the main entity performing the processing by executing the program may be the processor. Similarly, the main entity performing the processing by executing the program may be a device, system, computer, node, etc., having a processor. The main entity performing the processing by executing the program may be an arithmetic unit, and may include dedicated circuits that perform specific processing. Here, dedicated circuits include, for example, FPGAs (Field Programmable Gate Arrays), ASICs (Application Specific Integrated Circuits), CPLDs (Complex Programmable Logic Devices), etc. The program may be installed on the computer from the program source. The program source may be, for example, a program distribution server or a storage medium readable by the computer. If the program source is a program distribution server, the program distribution server includes a processor and storage resources for storing the program to be distributed, and the processor of the program distribution server may distribute the program to other computers. In addition, in some embodiments, two or more programs may be implemented as a single program, or one program may be implemented as two or more programs. Furthermore, the scope of this invention is not limited to email in the narrow sense. For example, it covers all methods that can distribute malware via URLs or attachments, such as SMS and chat. Hereafter, the scope of this invention will be referred to as "email" for convenience.

[0016] <First Embodiment> The first embodiment will be described with reference to Figures 1-12. The first embodiment describes the processing of an email analysis system when detecting trends and signs of email-based attacks on-premises. The email analysis system relates to technology that detects signs of attacks from a group of received emails and supports their analysis.

[0017] As shown in Figure 1, the email analysis system 101 (email analysis device) is connected to the user terminals (117a-c) operated by the user and the internet 119 via the network (118a, 118b).

[0018] The email analysis system 101 is a computer that, as an example, includes a CPU (Central Processing Unit) 103, a main memory 104 for storing data necessary for the CPU 103 to perform processing, a storage device 105 such as a hard disk or flash memory with a large capacity to store a large amount of data, an interface (IF) (102a, 102b) for communicating with other devices, an input / output device 106 for input and output such as a keyboard and display, and a communication channel 107 connecting these devices. The communication channel 107 is, for example, an information transmission medium such as a bus or cable.

[0019] The CPU 103 (processor) retrieves detected suspicious emails by executing the detected email acquisition program 108 stored in the main memory 104. It classifies the malware family associated with the suspicious email by executing the malware family classification program 109. It extracts the receiving trend (attack trend) for each malware family by executing the receiving trend extraction program 110. It generates an alert by executing the alert generation program 111. It presents the information about the emails acquired and analyzed by the above programs to the user by executing the screen rendering program 112.

[0020] The storage device 105 (storage unit) stores a list of detected emails 113 which stores information on detected suspicious emails, a list of detected malware 114 which stores information on detected malware, a list of malware families 115 which stores information on malware families, and an alert list 116 which stores generated alerts.

[0021] Each of the above programs and data may be pre-stored in memory 104 or storage device 105, or they may be installed (loaded) from input / output device 106 or from other devices via IF(102a, 102b) when needed. Some or all of these computer programs and data may be pre-stored in storage device 105, for example, or may be stored in storage device 105 on the email analysis system 101 from non-temporary storage devices of other devices via IF(102a, 102b) as needed. Alternatively, programs and data may be stored in storage device 105 on the email analysis system 101 from non-temporary storage media (e.g., portable storage media such as external hard disks or USB flash drives) via input / output device 106.

[0022] Note that the configuration of the email analysis system described in Figure 1 is just one example and is not limited to this configuration.

[0023] Next, an example of a list of detected emails will be explained with reference to Figure 2. As shown in Figure 2, the list of detected emails 113 consists of, for example, an email ID 201, a date and time 202, a subject 203, a sender 204, a recipient 205, and an attachment 206.

[0024] Email ID 201 is a field that stores identification information to uniquely identify the target email. In the first embodiment, a number is stored as the identification information in Email ID 201.

[0025] Date and Time 202 represents the date and time the email was received. For example, an entry with email ID 201 "0" indicates that the email was received on January 1, 2022. The data format of the time stored in Date and Time 202 is not particularly limited, as long as it is appropriate. Any data format that allows for time identification, such as Unixtime, may be used.

[0026] Subject 203 represents the subject of the email. For example, it indicates that the subject of the email in entry with email ID 201 being "0" is "Invoice".

[0027] Sender 204 represents the sender's email address for that email. For example, it indicates that the sender's email address for an entry with email ID 201 being "0" is "a@example.com".

[0028] Recipient 205 represents the recipient email address for that email. For example, the recipient email address for the entry with email ID 201 being "0" is "sato@mycompany.example.com".

[0029] Attachment 206 represents the file associated with the email. For example, it represents that the file associated with the email entry with email ID 201 "0" is "1.exe". The data format of the information stored in Attachment 206 is not particularly limited as long as it is appropriate. Any data format can be used, such as a file hash value, a download URL, or any data format associated with the file.

[0030] Note that the list of detected emails shown in Figure 2 is just one example and is not limited to this.

[0031] Next, an example of a list of detected malware will be explained with reference to Figure 3. As shown in Figure 3, the list of detected malware 114 consists of, for example, a malware ID 301, a date and time 302, a file name 303, a family name 304, and an email ID 305.

[0032] Malware ID 301 is a field that stores identification information for uniquely identifying the malware. In the first embodiment, a number is stored as the identification information in Malware ID 301.

[0033] The date and time field 302 represents the date and time the malware was detected. For example, a malware entry with malware ID 301 "0" indicates that the malware was detected on January 1, 2022. The data format of the time stored in date and time field 302 is not particularly limited, as long as it is appropriate. Any data format that allows for time identification, such as Unixtime, may be used.

[0034] File name 303 represents the file name associated with the malware. For example, it indicates that the file name associated with the malware in the entry with malware ID 301 being "0" is "1.exe".

[0035] Family name 304 represents the malware family name associated with the malware in question. For example, the malware family name associated with the malware entry with malware ID 301 "0" is "Family A".

[0036] Email ID 305 represents Email ID 201 associated with the malware. For example, malware in an entry with malware ID 301 "0" is associated with the email with email ID 201 "0". Here, "associated" means that it was attached to the email, or that the email body contained a download URL, etc.

[0037] Note that the list of detected malware shown in Figure 3 is just one example and is not limited to this list.

[0038] Next, an example of a malware family list will be explained with reference to Figure 4. As shown in Figure 4, the malware family list 115 consists of, for example, a malware family ID 401, a first observation date and time 402, a last observation date and time 403, a family name 404, a file name 405, and a malware ID 406.

[0039] Malware family ID 401 is a field that stores identification information for uniquely identifying a malware family. In the first embodiment, a number is stored as the identification information in malware family ID 401.

[0040] The first observation date and time 402 represents the date and time when the malware family was first observed. For example, a malware family entry with malware family ID 401 "0" indicates that it was first observed on January 1, 2021. The data format of the time stored in the first observation date and time 402 is not particularly limited, as long as it is appropriate. Any data format that allows for time identification, such as Unixtime, may be used.

[0041] The last observation date and time 403 represents the date and time when the malware family was last observed. For example, a malware family entry with malware family ID 401 "0" indicates that it was last observed on January 3, 2021. The data format of the time stored in the last observation date and time 403 is not particularly limited, as long as it is appropriate. Any data format that allows for time identification, such as Unixtime, may be used.

[0042] Family name 404 represents the malware family name. For example, an entry with malware family ID 401 being "0" indicates that the malware family name is "Family A".

[0043] File name 405 represents the file name associated with the malware family. For example, entry 401 with malware family ID "0" indicates that the file names associated with the malware family are "1.exe" and "fuga.pdf".

[0044] Malware ID 406 represents the malware ID 301 that was classified into that malware family among the detected malware. For example, a malware entry with malware family ID 401 "0" represents malware with malware IDs "0" and "3".

[0045] Note that the list of malware families explained in Figure 4 is just one example and is not limited to this list.

[0046] Next, an example of an alert list will be explained with reference to Figure 5. As shown in Figure 5, the alert list 116 consists of, for example, an alert ID 501, a date and time 502, a family name 503, an event 504, an observation count 505, a variation 506, and an alert statement 507.

[0047] Alert ID 501 is a field that stores identification information to uniquely identify the alert. In the first embodiment, a number is stored as the identification information in Alert ID 501.

[0048] The date and time field 502 represents the date and time the alert was issued. For example, an alert entry with alert ID 501 "0" indicates that the alert was issued on January 1, 2022. The data format of the time stored in date and time field 502 is not particularly limited, as long as it is appropriate. Any data format that allows for time identification, such as Unixtime, may be used.

[0049] Family name 503 represents the malware family name associated with the alert. For example, the malware family name associated with the alert entry with alert ID 501 being "0" is "Family A".

[0050] Event 504 represents the event associated with the alert. For example, the event associated with the alert entry with alert ID 501 being "0" represents an "increasing trend".

[0051] The observation count of 505 represents the number of malware instances associated with the alert observed at that time. For example, for an alert entry with alert ID 501 and an entry value of "0", it indicates that "1,000" instances of malware associated with the alert were observed at that time.

[0052] Fluctuation 506 represents the change in the number of malware instances observed at that time from the previous observation. For example, for an alert entry with alert ID 501 and value "0", the number of malware instances observed at that time has increased by "+600" from the previous observation.

[0053] Alert message 507 represents the description of the alert. For example, the description of the alert for an entry with alert ID 501 "0" is "The number of Family A hits is on the rise."

[0054] Note that the alert list shown in Figure 5 is just one example and is not limited to this.

[0055] Next, the processes performed by the email analysis system 101 will be described with reference to Figure 6. Figure 6 is a flowchart illustrating the overview of the processes performed by the email analysis system 101 of the first embodiment.

[0056] The email analysis system 101 (specifically, the CPU 103) periodically performs the process described below (step 601).

[0057] First, the email analysis system 101 obtains a list of suspicious emails (step 602). Details of obtaining the list of suspicious emails in step 602 will be explained later using Figure 7.

[0058] Next, the email analysis system 101 classifies the malware associated with the acquired suspicious emails into malware families (step 603). Details of the malware family classification in step 603 will be explained later using Figure 8.

[0059] Next, the email analysis system 101 extracts receiving trends for each malware family (step 604). Details of the receiving trend extraction in step 604 will be explained later using Figure 9.

[0060] Next, the email analysis system 101 generates alerts based on the extracted receiving trends (step 605). Details of the alert generation in step 605 will be explained later using Figure 10.

[0061] The email analysis system 101 performs the above processing on suspicious emails detected during the period, and terminates the process after completion. Note that the processing flow of the email analysis system described in Figure 6 is an example and is not limited thereto.

[0062] Next, with reference to Figure 7, an example of the detected email acquisition process performed by the email analysis system 101 of the first embodiment will be described.

[0063] The detection email acquisition program 108, executed by the CPU 103, starts the process described below when it receives an execution command.

[0064] The detected email acquisition program 108 acquires detected emails from the security appliance (step 701). Here, the security appliance detects suspicious emails and provides a list of the detected suspicious emails to the email analysis system 101 and the detected email acquisition program 108 via an appropriate interface (IF102, input / output device 106, etc.).

[0065] Next, the detected email acquisition program 108 saves information about the detected suspicious email to the detected email list 113 (step 702).

[0066] Next, the detection email acquisition program 108 extracts information about malware from the detection email list 113 (step 703).

[0067] Next, the detection email acquisition program 108 saves the extracted malware information to the list of detected malware 114 and terminates the process (step 704).

[0068] The method for acquiring detected emails, as explained in Figure 7, is merely an example and is not limited thereto. For example, the function for detecting suspicious emails may be integrated into the email analysis system. Furthermore, data related to suspicious emails may be input from an appropriate non-temporary storage medium via the input / output device 106.

[0069] Next, with reference to Figure 8, an example of the malware family classification process performed by the email analysis system 101 of the first embodiment will be described.

[0070] When the malware family classification program 109, executed by CPU 103, receives an execution command, it begins the process described below.

[0071] The malware family classification program 109 scans the detected malware list 114 and obtains malware information (step 801). Here, the malware family classification program 109 obtains a list that, as an example, includes entries consisting of malware ID 301.

[0072] Next, the malware family classification program 109 performs the following actions on malware information that has not yet been classified, based on the list of malware information it has acquired (step 802). If there is no malware information that has not yet been classified, the process is terminated. If there is one or more pieces of malware information that has not yet been classified, the program proceeds to step 803.

[0073] The malware family classification program 109 retrieves information about the malware file (step 803).

[0074] Next, the malware family classification program 109 retrieves email information about the malware (step 804).

[0075] Next, the malware family classification program 109 classifies the malware using file information and email information (step 805). For example, it may classify the malware using file surface information, binary information, execution behavior information, etc. It may also classify the malware using email subject, sender email address, message content, etc. Furthermore, it may classify the malware using both methods in combination.

[0076] Next, the malware family classification program 109 reflects the classification results in the family name 304 of the detected malware list 114 (step 806). If no new malware families are found, the information from the detected malware list 114 is saved to the malware family list 115, and the process is terminated.

[0077] On the other hand, if a new malware family exists, the malware family classification program 109 sets a new malware family ID 401 for the new malware family and saves the new malware family information to the malware family list 115. It also saves other malware family information stored in the detected malware list 114 to the malware family list 115. Then, it terminates the process (step 807).

[0078] Note that the malware family classification method described in Figure 8 is just one example and is not limited to it.

[0079] Next, with reference to Figure 9, an example of the receiving trend extraction process performed by the email analysis system 101 of the first embodiment will be described.

[0080] When the CPU 103 executes the reception trend extraction program 110, it starts the process described below.

[0081] The receiving trend extraction program 110 scans the detected malware list 114 and obtains malware information (step 901). Here, the receiving trend extraction program 110 obtains a list that includes entries consisting of malware ID 301.

[0082] Next, the receiving trend extraction program 110 performs the following processing for each malware family based on the list of acquired malware information (step 902).

[0083] The receiving trend extraction program 110 calculates the daily number of incoming malware families (step 903).

[0084] Next, the reception trend extraction program 110 uses the number of receptions up to the day before the most recent day to build a predictive model that predicts the number of receptions for each malware family (step 904).

[0085] Next, the reception trend extraction program 110 predicts the number of receptions for the day using a prediction model that predicts the number of receptions of malware families, and then compares the prediction of the prediction model with the actual value of the most recent day. If the discrepancy between the two is greater than a threshold, it detects that there is a change in trend (step 905). At this point, if processing has been completed for all malware families, the process is terminated.

[0086] The method for extracting receiving trends, as explained in Figure 9, is merely an example and is not limited to it. For example, in addition to changes in the trend of the number of received emails, a rule-based method may be used to register suspicious subject lines, sender domains, etc., of related emails in a detection list and detect emails that match that list. Alternatively, anomalies may be detected using characteristics of the email body, etc.

[0087] Next, with reference to Figure 10, an example of the alert generation process performed by the email analysis system 101 of the first embodiment will be described.

[0088] When the CPU 103 executes the reception trend extraction program 110, it starts the process described below.

[0089] The receiving trend extraction program 110 receives the results of the receiving trend extraction process described above (step 1001). Here, the receiving trend extraction program 110 receives, as an example, a change in the trend that is the target of issuing an alert.

[0090] The receiving trend extraction program 110 performs the following processing for each malware family in which a change in trend has been detected, which is the target of issuing an alert (step 1002). If there are no targets for issuing an alert, the process is terminated.

[0091] The reception trend extraction program 110 identifies events according to the type of change (step 1003). For example, if there is a gradual increase or decrease, it is identified as "increasing trend" or "decreasing trend," and if there is a sudden increase or decrease without any prior signs, it is identified as "abnormal."

[0092] Next, the reception trend extraction program 110 generates an alert message according to the identified event (step 1004).

[0093] Next, the receiving trend extraction program 110 saves the alert message generated in step 1004 along with other metadata related to the alert to the alert list 116 (step 1005). At this point, if processing has been completed for all alert targets, the process is terminated.

[0094] The alert generation method described in Figure 10 is merely an example and is not limited thereto. For example, a template-based method or a data-to-text method may be used to generate the alert text. Furthermore, the granularity and nature of the generated alerts may be varied according to the role and skill level of the target analyst, such as providing text that assists in deeper analysis for expert analysts, or showing simple information to analysts who screen alerts and perform triage. The settings for the granularity and nature of the alerts may be made via the input / output device 106 or via IF102a (in other words, the user terminal).

[0095] In addition, the email analysis system 101 performs screen rendering processing to display various information to the user, separate from the processing described in Figure 6. Figure 11 is a flowchart illustrating an example of screen rendering processing performed by the email analysis system 101 of the first embodiment.

[0096] When the screen rendering program 112, executed by the CPU 103, receives an execution instruction, it starts the process described below.

[0097] The screen rendering program 112 obtains the number of detected malware families to be rendered from the detected malware list 114 (step 1101).

[0098] The screen rendering program 112 retrieves alerts related to the malware family to be rendered from the alert list 116 (step 1102).

[0099] The screen rendering program 112 renders information about the malware family to be rendered on the screen (step 1103), and then terminates processing.

[0100] Note that the screen rendering method described in Figure 11 is just one example and is not limited to it.

[0101] Next, with reference to Figure 12, an example of a screen displaying email analysis results generated by the program of the email analysis system 101 of the first embodiment will be described.

[0102] The screen in Figure 12 includes the family name 1201, the detection progress 1202, and the alert list 1203.

[0103] Family name 1201 is the family name of the malware family.

[0104] Detection Trend 1202 shows the trend in the number of detections of a malware family. Detection Trend 1202 includes information such as a line graph visualizing the daily trend in the number of detections of a malware family over time. For comparison, information on other malware families, threat information obtained from external sources, etc., may also be depicted side by side. Figure 12 shows an example of information on other malware families, where the trend in the number of detections of Family B is plotted as a line. Areas of interest (areas that should be alerted) may also be highlighted, and in Figure 12, areas where an increase or decrease in the number of detections of Family A is observed are highlighted using symbols (warning marks).

[0105] Alert list 1203 is a list of alerts related to malware families. For example, each alert includes the alert ID, date and time, family name, event, number of occurrences, variation, and alert message.

[0106] By displaying the information described above, it is expected that the visibility of information related to malware families will be improved, and the cost and reliance on individual expertise in email analysis will be reduced.

[0107] The example provided here shows a display screen based on the analysis results of each program according to the first embodiment, but this is merely an example, and the display format of the screen is not limited to this. For example, any information related to email or malware families may be displayed in any format.

[0108] Tasks related to detecting and analyzing signs of attacks via email have been challenging due to their high implementation costs and reliance on individual expertise, as they heavily depend on the analyst's knowledge.

[0109] In addressing this issue, according to the first embodiment, the email analysis system 101 automatically detects signs of attacks for each malware family, thereby reducing the implementation costs and reliance on human intervention involved in detecting and analyzing malware attacks via email. As a result, it can contribute from an economic standpoint.

[0110] <Second Embodiment> Next, the second embodiment will be described with reference to Figures 13-20. The second embodiment describes the processing of an email analysis system that further reduces the reliance on human expertise and costs associated with analysis by providing more advanced analysis support functions. The second embodiment will be described below, focusing on the differences from the first embodiment, and explanations similar to those above may be omitted.

[0111] Figure 13 shows an example configuration of the email analysis system 1301 according to the second embodiment. As shown in Figure 13, the email analysis system 1301 (email analysis device) can communicate with an external site 1326 via the internet 1325 and acquire data from the external site 1326. In the second embodiment, each program can perform more advanced analysis semi-automatically by using not only emails detected by security appliances, etc., and acquired malware information, but also threat information provided by the external site 1326.

[0112] The hardware configuration of the email analysis system 1301 in the second embodiment is the same as in the first embodiment. However, the program in the second embodiment further includes a threat relevance analysis program 1311, a threat information linking program 1312, an attack target estimation program 1313, and a threat hunting rule generation program 1314, compared to the first embodiment.

[0113] The processes executed by the detection email acquisition program 1308, malware family classification program 1309, receiving trend extraction program 1310, alert generation program 1315, and screen rendering program 1316 in the second embodiment are the same as in the first embodiment.

[0114] The data structure of the second embodiment further includes a threat information list 1320 and a threat hunting rule list 1321, compared to the first embodiment. The detected email list 1317, detected malware list 1318, malware family list 1319, and alert list 1322 of the second embodiment are the same as those of the first embodiment.

[0115] Note that the configuration of the email analysis system according to the second embodiment, as described in Figure 13, is merely an example and is not limited thereto.

[0116] Next, an example of a threat information list will be explained with reference to Figure 14. As shown in Figure 14, the threat information list 1320 consists of, for example, a threat information ID 1401, a collection date 1402, a URL 1403, and information content 1404.

[0117] Threat information ID 1401 is a field that stores identification information to uniquely identify the threat information. For example, a number might be stored as the identification information in Threat information ID 1401.

[0118] The collection date 1402 represents the date and time the threat information was collected. For example, a threat information entry with threat information ID 1401 being "0" indicates that the information was collected on January 1, 2022. The data format of the time stored in collection date 1402 is not particularly limited, as long as it is appropriate. Any data format that allows for time identification, such as Unixtime, may be used.

[0119] URL1403 represents the URL from which the threat information was obtained. For example, a threat information entry with Threat Information ID 1401 being "0" indicates that the threat information was obtained from "blog.example.com / article / 1.html".

[0120] Information content 1404 represents the content of the information included in the threat information. Information content 1404 consists of a type and content. For example, the threat information entry with threat information ID 1401 "0" contains three pieces of information: information about threats in emails sent from "a@example.com", information about threats with "invoice" as the subject, and information about threats with "mal.example.com" as the URL.

[0121] Note that the threat information list explained in Figure 14 is just an example and is not limited to it. Information content 1404 may include, for example, information about Indicators of Compromise (IOCs) such as IP addresses, domains, URLs, and hash values. Alternatively, information content 1404 may be information about IOCs (for example, the type and content of the IOC).

[0122] Next, an example of a threat hunting rule list will be explained with reference to Figure 15. As shown in Figure 15, the threat hunting rule list 1321 consists of, for example, a threat hunting rule ID 1501, a creation date 1502, a type 1503, a rule 1504, an email ID 1505, and a malware ID 1506.

[0123] Threat Hunting Rule ID 1501 is a field that stores identification information to uniquely identify a threat hunting rule. For example, a number might be stored as the identification information in Threat Hunting Rule ID 1501.

[0124] The creation date 1502 represents the date and time the threat hunting rule was created. For example, a threat hunting rule entry with threat hunting rule ID 1501 and value "0" indicates that it was created on January 1, 2022. The data format of the time stored in creation date 1502 is not particularly limited, as long as it is appropriate. Any data format that allows for time identification, such as Unixtime, may be used.

[0125] Type 1503 represents the type of threat hunting rule. For example, an entry with threat hunting rule ID 1501 being "0" indicates that the type is subject.

[0126] Rule 1504 represents the rule body of a threat hunting rule. For example, the rule for an entry with threat hunting rule ID 1501 being "0" is "Invoice.*".

[0127] Email ID 1505 represents email ID 201 related to a threat hunting rule. For example, a threat hunting rule with entry ID 1501 being "0" represents emails with email IDs "0" and "2". Here, "related" means that the email had an attachment, or that the email body contained a download URL, etc.

[0128] Malware ID 1506 represents malware ID 301, which is associated with a threat hunting rule among the detected malware. For example, a threat hunting rule with entry ID 1501 as "0" indicates that malware ID 301 is associated with malware with IDs "0" and "1".

[0129] Note that the list of threat hunting rules explained in Figure 15 is just one example and is not limited to this.

[0130] Next, the processes performed by the email analysis system 1301 will be described with reference to Figure 16. Figure 16 is a flowchart illustrating the overview of the processes performed by the email analysis system 1301 of the second embodiment.

[0131] The email analysis system 1301 (specifically, the CPU 1303) periodically performs the process described below (step 1601).

[0132] First, a list of suspicious emails is obtained (Step 1602). The flow for obtaining the list of suspicious emails is the same as that described using Figure 7 in the first embodiment.

[0133] Next, the malware associated with the suspicious email is classified into malware families (Step 1603). The malware family classification flow is the same as that described using Figure 8 in the first embodiment.

[0134] Next, the receiving trend (targeting trend) is extracted for each malware family (step 1604). The receiving trend extraction flow is the same as that described using Figure 9 in the first embodiment.

[0135] Next, we analyze the relationship between the extracted receiving trends and commonly occurring threats (Step 1605). The details of the threat relevance analysis will be explained later using Figure 17.

[0136] Next, the extracted reception trends are linked to threat information (Step 1606). The details of linking threat information will be explained later using Figure 18.

[0137] Next, we estimate the target of the attack (Step 1607). The details of target estimation will be explained later using Figure 19.

[0138] Next, we generate threat hunting rules (step 1608). The details of generating threat hunting rules will be explained later using Figure 20.

[0139] Next, an alert is generated based on the extracted reception trends (step 1609). The alert generation flow is the same as that described using Figure 10 in the first embodiment.

[0140] The above process will be applied to any suspicious emails detected during the period, and the process will be terminated once it is complete.

[0141] Note that the processing flow of the email analysis system described in Figure 16 is just one example and is not limited to it.

[0142] Next, with reference to Figure 17, an example of the threat relevance analysis process performed by the email analysis system 1301 of the second embodiment will be described.

[0143] The threat relevance analysis program 1311, executed by CPU 1303, begins the process described below upon receiving an execution command.

[0144] The threat relevance analysis program 1311 scans the detected malware list 1318 and retrieves malware information (step 1701). Here, it retrieves a list that includes entries consisting of malware ID 301.

[0145] The threat relevance analysis program 1311 performs the following actions for each malware family based on the list of malware information it has obtained (step 1702).

[0146] The threat relevance analysis program 1311 calculates the daily inception count for each malware family (step 1703).

[0147] Next, the threat relevance analysis program 1311 retrieves information about the malware family from an external site 1326 (step 1704).

[0148] Next, the threat relevance analysis program 1311 compares the daily number of received malware families with information obtained from an external site 1326 and determines whether there is a correlation (step 1705). For example, it obtains the daily number of mentions of the malware family from an external site, such as an SNS site. If there is a correlation between the number of detections of the malware family by the security appliance and the daily trend of mentions on the SNS site, it determines that the threat related to the malware family is likely to be a mass-distribution attack, which is commonly seen. Otherwise, it determines that it is likely to be a targeted attack targeting only a specific organization. The determination result is also reflected in the alert message 507. At this point, if processing has been completed for all malware families, the process is terminated.

[0149] The threat relevance analysis method described in Figure 17 is just one example and is not limited to it.

[0150] Next, with reference to Figure 18, an example of the threat information linking process performed by the email analysis system 1301 of the second embodiment will be described.

[0151] The threat intelligence linking program 1312, executed by CPU 1303, starts the process described below upon receiving an execution command.

[0152] The threat intelligence linking program 1312 obtains threat intelligence from an external site (step 1801).

[0153] Next, the threat information linking program 1312 saves the acquired threat information to the threat information list 1320 (step 1802). At this time, it extracts the information content 1404 from the acquired threat information.

[0154] Next, scan alert list 1322 to retrieve alert information (step 1803).

[0155] Next, the threat intelligence linking program 1312 performs the following processing for each alert based on the list of acquired alert information (step 1804).

[0156] The threat intelligence linking program 1312 retrieves information about the email or file that triggered the alert (step 1805).

[0157] Next, the threat information linking program 1312 links the information in the email or file that triggered the alert with the information contained in the threat information if they match (step 1806). For example, it links the emails if the malicious sender email address contained in the threat information matches the sender email address of the email that triggered the alert. It also reflects the information about the linked threat information in the alert message 507. At this point, if processing has been completed for all alerts, the process is terminated.

[0158] The method of linking threat information, as explained in Figure 18, is just one example and is not limited to this.

[0159] Next, with reference to Figure 19, an example of the attack target estimation process performed by the email analysis system 1301 of the second embodiment will be described.

[0160] When the attack target estimated program 1313, executed by CPU 1303, receives an execution instruction, it starts the process described below.

[0161] The attack target estimation program 1313 scans the alert list 1322 and retrieves alert information (step 1901).

[0162] Next, the attack target estimation program 1313 performs the following processing for each alert based on the list of alert information it has acquired (step 1902).

[0163] The attack target estimation program 1313 retrieves information about the email that generated the alert (step 1903).

[0164] Next, the attack target estimation program 1313 estimates that if a common part is found in the destination domain of the alert source, it is an attack by a malware family targeting an organization or region associated with that part (step 1904). For example, if all emails related to the alert are addressed to email addresses in the same domain, it estimates that it is an attack by a malware family targeting an organization in that domain. The estimation result is then reflected in the alert message 507. At this point, if processing has been completed for all alerts, the process is terminated.

[0165] The method for estimating the target of an attack, as explained in Figure 19, is merely an example and is not limited to it. For example, the target of an attack may be estimated using information from the recipient's email address, such as the recipient's region, job title, and previous employment.

[0166] Furthermore, analysis can be performed on a per-target basis. For example, if the same threat is detected with a certain degree of variation across different regions, it can be inferred that these are attacks targeting the core hours of each region, or automated attacks utilizing bots.

[0167] Next, with reference to Figure 20, an example of the threat hunting rule generation process performed by the email analysis system 1301 of the second embodiment will be described.

[0168] The threat hunting rule generation program 1314, executed by CPU 1303, starts the process described below upon receiving an execution command.

[0169] The threat hunting rule generation program 1314 scans the alert list 1322 and retrieves alert information (step 2001).

[0170] Next, the threat hunting rule generation program 1314 performs the following processing for each alert based on the list of alert information it has acquired (step 2002).

[0171] The threat hunting rule generation program 1314 retrieves information about the email or file that triggered the alert (step 2003).

[0172] Next, the threat hunting rule generation program 1314 generates threat hunting rules (step 2004) by extracting common parts such as the subject and file name of the emails and then converting the remaining parts into regular expressions. For example, if the subject lines of emails related to alerts are "Invoice", "Invoice 20220101", and "Regarding the Invoice", and all share the common string "Invoice", the program extracts the common part "Invoice" and then converts the string that follows it into a regular expression to generate a threat hunting rule for subject lines "Invoice.*".

[0173] Next, the threat hunting rule generation program 1314 saves the generated threat hunting rules to the threat hunting rule list 1321 (step 2005). At this point, if processing has been completed for all alerts, the process is terminated.

[0174] The method for generating threat hunting rules described in Figure 20 is merely an example and is not limited thereto. For example, rules for threat hunting other than email may be created. Specifically, malware detection rules may be created using the results of executing malware samples attached to emails. Furthermore, threat hunting rules may be extracted from publicly available rules using their relevance to detected threats, etc. Publicly available rules can be obtained via appropriate interfaces (IF1302a, IF1302b, input / output device 1306).

[0175] According to the second embodiment, the email analysis system 1301 provides a program that detects signs of malware attacks via email, similar to the first embodiment, while also providing more advanced support for analysis, such as by utilizing external information, thereby reducing the implementation costs and reliance on individual expertise for the analysis.

[0176] Furthermore, in the second embodiment, threat hunting rules used for threat detection are generated, and by using these generated threat hunting rules, it may be possible to discover threats that were overlooked by the security appliance. Therefore, it can be expected that the comprehensiveness of detection will also improve.

[0177] Furthermore, the email analysis system 1301 of the second embodiment can, as an example, perform processing to display a screen in the same manner as the first embodiment. In addition, the email analysis system 1301 can perform processing to display the information reflected in the second embodiment on the screen in an appropriate display manner.

[0178] The email analysis system 1301 may, for example, display an alert message that adds to the receiving trends indicating that the results of the threat relevance analysis indicate a mass-mailing attack or an attack targeting a specific organization.

[0179] The email analysis system 1301 may, for example, display an alert message in addition to the receiving trend indicating that the results of threat information linking are common with threat information published on an external site. It may also display information such as the name of the external site from which the threat information was obtained.

[0180] Furthermore, the email analysis system 1301 may display an alert message that adds the results of the attack target estimation to the receiving trend. For example, an alert message such as "There has been an incoming attack from Family A targeting Organization X" may be displayed.

[0181] <Third Embodiment> Next, the third embodiment will be described with reference to Figures 21 and 22. The third embodiment describes the processing of the email analysis system when providing analysis functions and analysis results not only to the organization itself but also to external organizations. The third embodiment will be described below, focusing on the differences from the first and second embodiments, and explanations similar to those above may be omitted.

[0182] Figure 21 shows an example configuration of the email analysis system 2101 according to the third embodiment. As shown in Figure 21, the email analysis system 2101 (email analysis device) communicates with an external organization 2128 (specifically, a terminal of the external organization) via the Internet 2126. In the third embodiment, each program executes processing in response to requests not only from user terminals 2124 within the network but also from the external organization 2128, and returns the results to the external organization 2128 via the Internet 2126. This makes it possible to provide analysis functions and analysis results to external organizations.

[0183] The hardware configuration of the email analysis system 2101 in the third embodiment is the same as in the first embodiment. However, the program in the third embodiment further includes a report provision program 2116 compared to the first embodiment.

[0184] Furthermore, the processes executed by the detection email acquisition program 2108, the malware family classification program 2109, the reception trend extraction program 2110, the threat relevance analysis program 2111, the threat information linking program 2112, the attack target estimation program 2113, the threat hunting rule generation program 2114, the alert generation program 2115, and the screen rendering program 2117 in the third embodiment are the same as in the second embodiment.

[0185] The data structure in the third embodiment is the same as in the second embodiment.

[0186] Note that the configuration of the email analysis system according to the third embodiment, as described in Figure 21, is merely an example and is not limited thereto.

[0187] Referring to Figure 22, an example of the report provision process performed by the email analysis system 2101 of the third embodiment will be described.

[0188] When the report-providing program 2116, executed by CPU 2103, receives an execution instruction, it starts the process described below.

[0189] The report provision program 2116 receives a request for report provision from an external organization 2128 (step 2201).

[0190] Next, the report provision program 2116 scans the alert list 2123 and retrieves the alert information (step 2202).

[0191] Next, the report delivery program 2116 extracts and provides alerts from the alert list 2123 that are related to the requesting external organization (step 2203).

[0192] The method of providing reports described in Figure 22 is merely an example and is not limited to it.

[0193] According to the third embodiment, the email analysis system 2101 provides email analysis functions to internal users on-premises, similar to the first and second embodiments, while also providing the same information to external organizations via the Internet 2126. This makes it possible to provide analysis functions and analysis results to external organizations as well. Furthermore, by building the email analysis system 2101 on the cloud, it becomes possible to provide the service in a cloud-based format. Alternatively, instead of providing the service via the Internet, the email analysis system 2101 itself may be provided and installed within the external organization.

[0194] Furthermore, when analyzing threats, it is also possible to utilize information from external organizations. For example, if the detected trends are common to both the external organization and your own organization, you can assume that it is a mass-distribution type attack; if they are not common, you can assume that it is a targeted attack aimed at one of the organizations.

[0195] Although embodiments have been described above, the present invention is not limited to the embodiments described above, and various modifications are possible. For example, it is possible to add, delete, or replace some of the configurations of the embodiments with other configurations.

[0196] Users utilizing user terminals are, for example, users of an organization operating an email analysis system. These users include analysts within the organization. The number of user terminals can be determined as appropriate. The number of terminals from external organizations can also be determined as appropriate.

[0197] The email analysis system (101, 1301, 2101) can output data for displaying the screen to a display via input / output devices (106, 1306, 2106). Furthermore, the email analysis system (101, 1301, 2101) can output data for displaying the screen to an external device (user terminal, external organization's terminal, etc.) via a network. Users can then view the screen content using a display connected to their terminal. Alternatively, the data for displaying the screen may be stored on a storage medium via the input / output devices (106, 1306, 2106), and this storage medium may be connected to an appropriate device, with the display connected to that device performing the screen display.

[0198] For example, if suspicious emails to be processed are provided by an external organization, the email analysis system 2101 can also process the provided suspicious emails. Here, data may be input to the email analysis system 2101 via IF(2102b). Alternatively, data may be input from the input / output device 2106 using a storage medium that stores the provided suspicious emails.

[0199] The granularity and characteristics of alerts may be configured by an external organization. These configurations may be made via the input / output device 2106 or via IF2102b (in other words, via the external organization's terminal).

[0200] External sites (1326) include, for example, information dissemination sites and social networking sites of public institutions. [Explanation of Symbols]

[0201] 101: Email analysis system (email analysis device) 102:IF 103: CPU (Processor) 104: Main memory 105: Storage device (storage unit) 106: Input / Output Devices 107: Communication Channel 108: Detection email acquisition program 109: Malware Family Classification Program 110: Reception trend extraction program 111: Alert generation program 112: Screen rendering program 113: List of detected emails 114: List of detected malware 115: List of Malware Families 116: Alert List 117a~c: User terminals 118a, 118b: Network 119: Internet

Claims

1. A mail analysis device comprising a processor, a memory unit, and a communication interface, The aforementioned processor, The malware contained in the email is classified into families, and the classification results are stored in the storage unit. Using the classification results stored in the memory unit, the reception trends for each family are analyzed. Through the aforementioned interface, threat information is obtained from an external site outside the email analysis device. The relationship between the aforementioned threat information and the reception trends for each family is analyzed. Output data that displays the results of the aforementioned correlation analysis on the screen. A mail analysis device characterized by the following features.

2. The email analysis device according to claim 1, The aforementioned processor, The system links the threat information with the family information to matching information, and outputs the data that reflects the resulting information. A mail analysis device characterized by the following features.

3. The email analysis device according to claim 1, The aforementioned processor, Based on the recipient information of the aforementioned email, the attack target of the aforementioned family is estimated, and the data reflecting the resulting information is output. A mail analysis device characterized by the following features.

4. The email analysis device according to claim 1, The aforementioned processor, Based on the common parts of the email containing the malware, a threat hunting rule for threat detection is generated, and the generated threat hunting rule is stored in the memory unit. The system detects emails to be processed using the threat hunting rules stored in the memory unit. A mail analysis device characterized by the following features.

5. The email analysis device according to claim 1, The aforementioned processor, Using the results of executing the malware contained in the email, a threat hunting rule, which is a rule for malware detection, is generated, and the generated threat hunting rule is stored in the memory unit. The system detects emails to be processed using the threat hunting rules stored in the memory unit. A mail analysis device characterized by the following features.

6. The email analysis device according to claim 1, The aforementioned processor, By extracting rules relevant to the threat detected from the email from publicly available threat detection rules, threat hunting rules for threat detection are obtained, and the obtained threat hunting rules are stored in the memory unit. The system detects emails to be processed using the threat hunting rules stored in the memory unit. A mail analysis device characterized by the following features.

7. The email analysis device according to claim 1, The aforementioned processor, Through the interface, requests are received from terminals of a second organization, which is different from the first organization operating the email analysis device, and the data related to the second organization is output to the terminals of the second organization. A mail analysis device characterized by the following features.

8. The email analysis device according to claim 1, The aforementioned processor, The system outputs the data, which includes an alert message explaining the location of an alert in the aforementioned reception trend. A mail analysis device characterized by the following features.

9. The email analysis device according to claim 1, The system includes a user terminal used by a user of the first organization that operates the email analysis device, which outputs data from the email analysis device. A mail analysis system characterized by the following features.

10. The email analysis system according to claim 9, The aforementioned email analysis device is Operated on-premises by the aforementioned first organization, A mail analysis system characterized by the following features.

11. The email analysis system according to claim 10, The email analysis device is capable of communicating with the aforementioned email analysis device and further comprises a terminal of a second organization different from the first organization, The aforementioned email analysis device is The interface is used to obtain requests from the terminal of the second organization and to output data related to the second organization to the terminal of the second organization. A mail analysis system characterized by the following features.

12. The email analysis device according to claim 1, The terminal comprises a second organization, which is different from the first organization that operates the email analysis device, and is capable of communicating with the aforementioned email analysis device. The aforementioned email analysis device is Through the interface, requests are received from the terminal of the second organization, and data related to the second organization is output to the terminal of the second organization. The aforementioned email analysis device is It is built on the cloud and provides cloud-based services. A mail analysis system characterized by the following features.

13. A method for analyzing emails using an email analysis device comprising a processor, a memory unit, and a communication interface, The processor retrieves the email and stores the retrieved email in the storage unit. The processor classifies the malware contained in the emails stored in the memory into families and stores the classification results in the memory. The processor uses the classification results stored in the memory to analyze the reception trends for each family, The processor acquires threat information from an external site outside the email analysis device via the interface. The processor analyzes the relationship between the threat information and the reception trends for each family, The processor outputs data that displays the results of the correlation analysis on the screen. A method for analyzing emails characterized by the following features.

14. A program that causes a processor to execute the email analysis method described in Claim 13.