Malignant Site Survival Period Prediction System and Malignant Site Survival Period Prediction Method
The system predicts malicious site lifespans to automate the creation of blocking and monitoring lists, addressing high costs and expertise reliance in existing technologies.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- HITACHI LTD
- Filing Date
- 2023-03-23
- Publication Date
- 2026-07-30
AI Technical Summary
Existing technologies face high operational costs and reliance on individual expertise in creating blocking and monitoring lists for malicious sites due to the vast number and daily increase of malicious websites, without providing information on their lifespan.
A system and method that predicts the lifespan of malicious sites by observing events and applying determination rules, allowing for the generation of targeted blocking and monitoring lists based on predicted lifespans.
Reduces operational costs and reliance on expertise by automating the creation of blocking and monitoring lists through lifespan prediction, enhancing efficiency and resource management.
Smart Images

Figure 0007897815000001 
Figure 0007897815000002 
Figure 0007897815000003
Abstract
Description
Technical Field
[0001] The present invention relates to a malignant site survival period prediction system and a malignant site survival period prediction method.
Background Art
[0002] Blocking malignant sites is effective in suppressing damage. Also, periodically observing such malignant sites is useful for elucidating attacks and detecting attack signs. For this reason, there are services that provide a blocking list of malignant sites and monitoring services. Also, as a method for blocking communication to malignant sites, there is communication control that utilizes a blocking list. This is implemented in a layer such as a forward proxy, etc., where malignant sites for which communication is to be blocked in advance are registered, and when communication that matches the list is detected, the damage is suppressed by blocking the communication.
[0003] As a conventional technique for dealing with such malignant sites, for example, a technique (see Patent Document 1) that enables detection of access to unknown malignant sites and reduces the burden associated with such detection has been proposed.
[0004] This technique is a monitoring system having an observation device and an analysis device connected to the observation device via a communication line. The observation device includes a data observation unit that collects information regarding access by a user to a web page, and a transmission unit that transmits the information collected by the data observation unit to the analysis device. The analysis device includes a reception unit that receives the information transmitted from the observation device, a detection unit that detects a specific page transition method based on the information received by the reception unit, and an analysis unit that determines the malignancy of the content downloaded from the access to the web page based on the detection result of the specific page transition method, and an analysis target determination unit that determines only the content determined to be suspected of malignancy by the analysis unit as the target of analysis. to be analyzed. It pertains to a monitoring system provided with an analysis target determination unit.
Prior Art Documents
[0005] [Patent Document 1] Japanese Patent Publication No. 2016-45887 [Non-patent literature]
[0006] [Non-Patent Document 1] Nappa, A., Xu, Z., Rafique, MZ, Caballero, J., and Gu, G.: CyberProbe: Towards Internet-Scale Active Detection of Malicious Servers, Proc. 2014 Network and Distributed System Security Symposium (NDSS2014), pp.1-15(2014). https: / / www.google.com / url?sa=t&rct=j&q=&esrc=s&source=web&cd=&ved=2ahUKEwiGmd-D0tD8AhXbZt4KHUyqCQoQ FnoECAUQAQ&url=https%3A%2F%2Flirias.kuleuven.be%2Fretrieve%2F384185&usg=AOvVaw3rKJj5MIzX684yxfDdtlzk [Non-Patent Document 2] Soska, K. and Christin, N.: Automatically detecting vulnerable websites before they turn malicious, Proc. the 23rd USENIX conference on Security Symposium (SEC2014), pp. 625-640 (2014). https: / / www.usenix.org / conference / usenixsecurity14 / technical-sessions / presentation / soska [Overview of the Initiative] [Problems that the invention aims to solve]
[0007] However, the number of malicious websites is countless and increases daily. Therefore, it is unrealistic to block or monitor all of them. Therefore, it is necessary to create blocking lists and monitoring lists that focus on the highest priority items based on the current situation, but such work is costly and highly dependent on individual expertise.
[0008] Conventional technologies exist that monitor websites and detect malicious sites based on page transition information, etc. However, no proposals have been made to provide information on the lifespan of malicious sites that would contribute to inventorying / selecting sites to be blocked / monitored.
[0009] There are also methods that detect active malignant sites through observation. However, providing information about the properties and lifespan of malignant sites is outside the scope of these methods.
[0010] In other words, as mentioned above, while there are many conventional technologies that focus on monitoring malicious sites, no technology has been proposed for the purpose of inventorying / selecting malicious sites to be blocked / monitored. Therefore, the large operational costs and high reliance on individual expertise involved in building the blocking and monitoring lists mentioned earlier have not been resolved.
[0011] Therefore, the objective of the present invention is to provide a technology that can reduce the operational costs and reliance on individual expertise involved in building blocking lists and monitoring lists by predicting the lifespan of malicious sites. [Means for solving the problem]
[0012] The malicious site survival time prediction system of the present invention, which solves the above problems, comprises a communication device that accesses a network, a storage device that holds information on each malicious site in the network, a process that accesses each of the malicious sites and observes predetermined events at the said malicious site, and a determination rule that defines the relationship between the trend of said events at the malicious site and the survival time of the said malicious site, based on the results of the observation. And, regarding the aforementioned malicious site, external information that has been made public on the aforementioned network Apply In the aforementioned network The system is characterized by comprising: a processing unit that predicts the lifespan of malicious sites; and a computing unit that performs a processing to select predetermined malicious sites according to their lifespans and generate a blocking list or a monitoring list. Furthermore, the present invention provides a method for predicting the survival time of a malicious site, wherein the information processing device comprises a communication device that accesses a network and a storage device that holds information on each malicious site in the network, and performs a process of accessing each of the malicious sites and observing predetermined events at the malicious site, and a determination rule that defines the relationship between the trend of the events at the malicious site and the survival time of the malicious site, based on the results of the observation. And, regarding the aforementioned malicious site, external information that has been made public on the aforementioned network Apply In the aforementioned network The system is characterized by performing a process to predict the lifespan of malicious sites, and a process to select predetermined malicious sites from among them according to their lifespans and generate a blocking list or a monitoring list. [Effects of the Invention]
[0013] According to the present invention, by predicting the lifespan of malicious sites, it is possible to reduce the operational costs and reliance on individual expertise involved in building blocking lists and monitoring lists. [Brief explanation of the drawing]
[0014] [Figure 1] This figure shows an example configuration of a malignant site survival time prediction system according to Embodiment 1 of the present invention. [Figure 2] This figure shows an example of a list of malignant sites according to Example 1 of the present invention. [Figure 3] This figure shows an example of an observation result storage area according to Example 1 of the present invention. [Figure 4] It is a diagram showing the overall processing flow according to Example 1 of the present invention. [Figure 5] It is a diagram showing the processing flow of malignant site observation according to Example 1 of the present invention. [Figure 6] It is a diagram showing the processing flow of survival period prediction according to Example 1 of the present invention. [Figure 7] It is a diagram showing the processing flow of screen description according to Example 1 of the present invention. [Figure 8] It is a diagram showing an example of a screen according to Example 1 of the present invention. [Figure 9] It is a diagram showing the processing flow of list construction according to Example 1 of the present invention. [Figure 10] It is a diagram showing a configuration example of a malignant site survival period prediction system according to Example 2 of the present invention. [Figure 11] It is a diagram showing the processing flow of determination of observation interval according to Example 2 of the present invention. [Figure 12] It is a diagram showing the processing flow of property prediction according to Example 2 of the present invention. [Figure 13] It is a diagram showing the processing flow of background prediction according to Example 2 of the present invention. [Figure 14] It is a diagram showing a configuration example of a malignant site survival period prediction system according to Example 3 of the present invention.
Mode for Carrying Out the Invention
[0015] Hereinafter, examples of the present invention will be described with reference to the drawings. However, the present invention is not to be construed as being limited to the description of the examples shown below. Those skilled in the art can easily understand that the specific configuration can be changed without departing from the spirit or gist of the present invention. In the configuration of the invention described below, the same or similar configurations or functions are denoted by the same reference numerals, and duplicate descriptions are omitted.
[0016] The designations "First," "Second," "Third," etc., used in this specification are for the purpose of identifying constituent elements and do not necessarily limit their number or order.
[0017] The positions, sizes, shapes, and ranges of each component shown in the drawings, etc., may not represent the actual positions, sizes, shapes, and ranges, etc., in order to facilitate understanding of the invention. Therefore, the present invention is not limited to the positions, sizes, shapes, and ranges, etc., disclosed in the drawings, etc. [Example 1] Example 1 describes the processing of a malicious site survival time prediction system when aiming to reduce the operational costs and reliance on individual expertise associated with building blocking lists and monitoring lists by predicting the survival time of malicious sites on-premises. <Network Configuration> Embodiments of the present invention will be described in detail below with reference to the drawings. Figure 1 is a network configuration diagram including the malignant site survival time prediction system 101 in this embodiment.
[0018] The malicious site survival time prediction system 101 shown in Figure 1 is a computer system that can reduce the operational costs and reliance on human expertise associated with building block lists and monitoring lists by predicting the survival time of malicious sites.
[0019] The malignant site survival time prediction system 101 according to Example 1 is connected to a user terminal 114 operated by the user via the Internet 116 and network 115. Therefore, It is also acceptable to consider the entire system, including user terminal 114, as a malicious site survival time prediction system.
[0020] The malignant site survival time prediction system 101 uses a CPU (Central Processing Unit) 10 It comprises 3, main memory 104, storage device 105, IF (interface) 102, input / output device 106, and communication path 107 connecting these devices.
[0021] Of these, IF102 is a communication device for communicating with other devices such as the user terminal 114.
[0022] Furthermore, the CPU (Central Processing Unit) 103 is stored in the main memory 104. By executing the malicious site observation program 108, the observation of malicious sites is performed, and By executing the survival period prediction program 109, the survival period of the connected site is predicted. By executing the screen rendering program 110, the processing results from each of the above programs (information such as observation results, malignancy level, and response priority) are output. By executing the list construction program 111, the functions of blocking malicious sites and generating a list of observations are implemented.
[0023] Furthermore, the main memory 104 is composed of volatile memory elements that store the data necessary for the CPU 103 to execute processing.
[0024] Furthermore, the storage device 105 is composed of non-volatile memory elements such as hard disks and flash memory that have the capacity to store a large amount of data.
[0025] Furthermore, the input / output device 106 is a device that performs input and output such as a keyboard and a display.
[0026] Furthermore, the communication channel 107 is an information transmission medium such as a bus or cable that connects these devices.
[0027] The aforementioned storage device 105 also stores a list of malicious sites 112 for managing malicious sites, and an observation result storage area 113 for storing observation results.
[0028] Each of the above programs and data may be stored in the main memory 104 or storage device 105 in advance, or they may be installed (loaded) from the input / output device 106 or from other devices via IF 102 when needed.
[0029] Note that the configuration of the malignant site survival time prediction system described in Figure 1 is just one example and is not limited thereto. <Example Data Structure> Next, we will explain the various types of information used by the malignant site survival time prediction system 101 of this embodiment. Figure 2 shows an example of the malignant site list 112.
[0030] As shown in Figure 2, the list of malicious sites 112 is composed of, for example, a connection ID 201, a connection destination 202, an observation span 203, an observation date and time 204, and a predicted survival period 205.
[0031] Of these, the connection destination ID 201 is a field that stores identification information to uniquely identify the connection destination to be observed. In Example 1, a number is stored as the identification information for the connection destination ID 201.
[0032] Furthermore, destination 202 is a field that stores the URL of the destination being observed. For example, the destination corresponding to the entry with destination ID 201 "0" is "search.example.com / This indicates that it is ".
[0033] Furthermore, the observation span 203 represents the frequency at which the connection destination is observed. For example, for entries with connection destination ID 201 of "0", it indicates that an observation will be attempted every 4 hours.
[0034] Furthermore, the observation date and time 204 represents the date and time when the connection destination was observed. For example, among entries where the connection destination ID 201 is "0", the most recent observation was made on January 1, 2023 at 04:00:00. The present invention is not limited to the data format of the time stored in the observation date and time 204. Any data format that allows for time identification, such as Unixtime, is acceptable. You may use it.
[0035] Furthermore, the predicted survival period 205 represents the predicted survival period for the destination (the malicious site) in question. For example, for destination ID 201 being "0", the prediction of the survival period from that point in time is represented using the latest observation result from "04:00:00 on January 1, 2023".
[0036] The list of malicious websites explained in Figure 2 is just one example and is not limited to this list.
[0037] Figure 3 shows an example of the observation result storage area 113. As shown in Figure 3, the observation result storage area 113 is composed of, for example, a connection ID 301, a connection destination 302, an observation date and time 303, a status code 304, and content 305.
[0038] Of these, the connection destination ID 301 is a field that stores identification information to uniquely identify the connection destination to be observed. In Example 1, a number is stored as the identification information for the connection destination ID 301.
[0039] Furthermore, the destination 302 is a field that stores the URL of the destination being observed. For example, the destination corresponding to the entry with destination ID 301 "0" is "search.example.com / This indicates that it is ".
[0040] Furthermore, the observation date and time 303 represents the date and time when the connection destination was observed. For example, among entries where the connection destination ID 301 is "0", the most recent observation was made at "04:00:00 on January 1, 2023". The present invention is not limited to the data format of the time stored in the observation date and time 303. Any data format that allows for the determination of time, such as Unixtime, may be used.
[0041] Furthermore, status code 304 is a field that stores the status code of the connection destination at the time of observation. For example, it indicates that the status code was "200" when a connection destination with connection destination ID 301 "0" was observed at "04:00:00 on January 1, 2023". Note that status codes are codes that the destination server responds to as an HTTP response, and there are various types such as informational responses, success responses, redirect messages, client error responses, and server error responses.
[0042] Furthermore, content 305 is a field that stores the content obtained from the connection destination at the time of observation. For example, it indicates that the content obtained when the connection destination with connection destination ID 301 "0" was observed at "04:00:00 on January 1, 2023" was "1.exe". Note that the information stored as an observation result is not limited to this.
[0043] Note that the observation result storage area explained in Figure 3 is just one example and is not limited to it. <Example Flow: Overall Flow> The actual procedure of the malignant site survival time prediction method in this embodiment will be described below with reference to the diagram. The various operations corresponding to the malignant site survival time prediction method described below are realized by a program that the malignant site survival time prediction system 101 reads into memory or the like and executes. This program consists of code for performing the various operations described below.
[0044] Figure 4 is a diagram showing an example of the malignant site survival time prediction method in Example 1, and specifically, it is a diagram that explains the overview of the processes performed by the malignant site survival time prediction system 101. —This is a chart.
[0045] Here, the malignant site survival prediction system 101 periodically performs the process described below (step 401).
[0046] First, the malignant site survival prediction system 101 observes malignant sites (step 402). A detailed flow chart of this malignant site observation will be described later using Figure 5.
[0047] Next, the malignant site survival prediction system 101 predicts the survival period of the malignant site using the observation results from step 402 (step 403). The detailed flow of this survival period prediction will be described later with reference to Figure 6.
[0048] The malignant site survival time prediction system 101 performs the above process for all malignant sites and then terminates the flow.
[0049] Note that the processing flow of the malignant site survival time prediction system described in Figure 4 is just one example and is not limited thereto. <Flowchart example: Malignant site observation> Figure 5 shows the results of Example 1. Predicting the survival time of malignant websites This is a flowchart illustrating an example of the malicious site observation process (step 402 described above) performed by system 101.
[0050] The malicious site observation program 108, executed by the CPU 103, starts the process described below when it receives an execution command from, for example, the user terminal 114.
[0051] The malicious site observation program 108 obtains a list of target connection destinations from the malicious site list 112 (step 501). Here, it is assumed that a list containing entries consisting of connection destination ID 201 is obtained.
[0052] Next, the malicious site observation program 108 sets the variable i, which represents the connection destination ID in the malicious site list 112, to an initial value of 0 (step 502).
[0053] Next, the malicious site observation program 108 starts processing the connection destination with connection destination ID i (step 503).
[0054] Next, the malicious site observation program 108 refers to the observation date and time 204 and observation span 203 of the most recent entry in the malicious site list 112, and calculates the elapsed time from the last observation date and time of the connection destination to the execution of the program, thereby determining whether the connection destination has reached the observation span (step 504).
[0055] If, as a result of this determination, the connection destination has not reached the observation span (step 504: No), the malicious site observation program 108 terminates processing related to the connection destination and proceeds to step 507.
[0056] On the other hand, if, as a result of the above determination, the connection destination has reached the observation span (step 504: Yes), the malicious site observation program 108 proceeds to step 505.
[0057] Next, the malicious site observation program 108 performs an observation of the connection destination (step 505). For this observation, for example, it accesses the connection destination using a browser and obtains the response result. An example of a response result is assumed to be the status code already mentioned. can.
[0058] Next, the malicious site observation program 108 saves the observation results obtained in step 505 described above to an entry in the observation result storage area 113 corresponding to the destination ID of the destination (step 506).
[0059] Next, the malicious site observation program 108 adds 1 to the variable i and proceeds to step 508 (step 507).
[0060] Next, the malicious site observation program 108 compares the variable i with the number of connection destinations that can be obtained by referring to the list of malicious sites 112.
[0061] If, as a result of this comparison, the variable i is less than the number of connections (step 508: No), the malicious site observation program 108 returns to step 503.
[0062] On the other hand, if the above comparison results show that variable i exceeds the number of connections (step 508: Yes), the malicious site observation program 108 terminates processing (step 508).
[0063] The method for observing malicious sites, as explained in Figure 5, is just one example and is not limited to this. <Flowchart example: Survival time prediction> Figure 6 shows the results of Example 1. Predicting the survival time of malignant websites This flowchart illustrates an example of the survival time prediction process performed by System 101.
[0064] When the survival time prediction program 109, executed by the CPU 103, receives an execution command from the user terminal 114, it starts the process described below.
[0065] The survival prediction program 109 obtains a list of target connections from the list of malignant sites 112 (step 601). Here, it is assumed that a list is obtained that includes entries consisting of connection ID 201.
[0066] Next, the survival prediction program 109 sets the variable i, which represents the destination ID of the malignant site list 112, to an initial value of 0 (step 602).
[0067] Next, the survival prediction program 109 starts processing for the destination with destination ID i (step 603).
[0068] Next, the survival period prediction program 109 refers to the observation result storage area 113 and checks if there are any additional observation results for the connection destination since the last prediction (step 604).
[0069] If no additional observation results are found at this point (Step 604: No), the survival period prediction program 109 terminates processing related to the connection destination and proceeds to Step 608.
[0070] On the other hand, if additional observation results are available (Step 604: Yes), the survival prediction program 109 proceeds to Step 605.
[0071] Next, the survival time prediction program 109 obtains external information related to the connection destination (step 605). This external information may include, for example, WHOIS information, DNS information, certificate information, etc.
[0072] Next, the survival period prediction program 109 applies the observation results obtained from the observation result storage area 113 and the external information obtained in step 605 to a predetermined judgment rule (e.g., an engine that has learned the relationship between trends regarding predetermined events at a malignant site and the survival period of the malignant site) to predict the survival period of the connected site (step 606).
[0073] The aforementioned events could include various factors such as the type of status code in the response from the malicious site, the role of the malicious site, and external information from the WHOIS database.
[0074] Next, the survival prediction program 109 saves the survival prediction result obtained in step 606 to the predicted survival period 205 of the entry corresponding to the destination ID of the destination in the list of malignant sites 112 (step 607).
[0075] Next, the survival prediction program 109 adds 1 to the variable i and proceeds to step 609 (step 608).
[0076] Next, the survival prediction program 109 compares the variable i with the number of destinations that can be obtained by referring to the list of malignant sites 112 (step 609).
[0077] If, as a result of the above comparison, the variable i is less than the number of connections (step 609: No), the survival prediction program 109 returns to step 603.
[0078] Furthermore, if, as a result of the above comparison, the variable i exceeds the number of connections (step 609: Yes), the survival prediction program 109 terminates processing (step 609).
[0079] The survival period prediction method described in Figure 6 is merely an example and is not limited thereto. For example, the survival period of the connection target may be predicted using information other than that described in the example above. Furthermore, the observation span may be varied based on the predicted properties of the connection target. For example, those that can change their properties in a short period of time may be observed at short intervals, while those with a long survival period but whose properties do not change during that period may be observed at long intervals. <Example Flow: Screen Rendering> The malignant site survival time prediction system 101 performs screen rendering processing to display various information to the user, separate from the processing described in Figure 4. Figure 7 is a flowchart illustrating an example of screen rendering processing performed by the malignant site survival time prediction system 101 of Embodiment 1.
[0080] When the screen rendering program 110, executed by the CPU 103, receives an execution command from the user terminal 114, it starts the process described below.
[0081] The screen rendering program 110 obtains a list of target connection destinations from the malicious site list 112 (step 701). Here, it is assumed that a list containing entries consisting of connection destination ID 201 is obtained.
[0082] The screen rendering program 110 retrieves the observation results from the connected device from the observation result storage area 113 (step 702). Here, it is assumed that a list containing entries consisting of connection ID 301 is retrieved.
[0083] The screen rendering program 110 generates screen data containing information about the connection destination to be drawn, distributes this data to the user terminal 114 for display (step 703), and then terminates the process.
[0084] Note that the screen rendering method described in Figure 7 is just one example and is not limited to it.
[0085] Figure 8 shows an example of a malignant site survival time prediction result display screen 800 generated by the screen display program 110 in the malignant site survival time prediction system 101 of Example 1 and displayed on the user terminal 114.
[0086] Screen 800 in Figure 8 includes an overview of the malignant site 801, a predicted survival period 802, and observation results 803.
[0087] Of these, the malicious site summary 801 provides basic information about the target of the connection. For example, it includes information such as the connection ID, connection destination, observation span, observation date and time, and predicted survival period.
[0088] Furthermore, the predicted survival period 802 is the result of predicting the survival period for the connection destination.
[0089] Furthermore, observation result 803 is the result of observing the destination being described, and includes information such as destination ID, destination, observation date and time, status code, content, and format.
[0090] The content mentioned above could include files that malicious websites offer for download, as well as screen data containing status codes.
[0091] As described above, by displaying the predicted lifespan of the connection destination, it is expected that this will be helpful to users, including analysts, when creating monitoring lists and blocking lists.
[0092] In this example, the displayed screen is based on the execution results of each program related to Example 1, but this is just one example and is not limited to this. For example, any information related to the connection destination may be displayed in any format. <Example Flow: Providing a Blocking List> The malignant site survival time prediction system 101 performs a list construction process separately from the process described in Figure 4. Figure 9 is a flowchart illustrating an example of the block list provision process performed by the malignant site survival time prediction system 101 of Example 1.
[0093] When the list building program 111, executed by the CPU 103, receives an execution instruction from the user terminal 114, it starts the process described below.
[0094] The list building program 111 accepts a specification of the maximum number of items in the list from the user's terminal 114 (step 901).
[0095] The list building program 111 retrieves information about malicious sites from the list of malicious sites 112 (step 902).
[0096] Furthermore, the list building program 111 extracts malicious sites from the list of malicious sites 112 in order of the longest predicted survival time, up to the upper limit accepted in step 901 (step 903).
[0097] The list building program 111 outputs the group of malicious sites extracted in step 903 as a blocking list (step 904) and terminates processing. At this time, it is conceivable that the program may cooperate with other devices, such as network devices that are actually responsible for blocking communications, via IF102.
[0098] Note that the list construction method described in Figure 9 is just one example and is not limited thereto. For example, the list may be constructed considering other factors such as the malignancy of the connected target, in addition to the predicted survival period.
[0099] Furthermore, lists may be created with consideration for their intended use. For example, when monitoring malicious sites, it is desirable to obtain as many different monitoring results as possible. Therefore, a possible strategy for the monitoring list would be to prioritize adding malicious sites that frequently change their content. In addition, although the user entered the maximum number of entries in the above example, the system may also incorporate features to maximize the blocking performance of the blocking list and the monitoring capability of the monitoring list, taking into account resources such as the capacity of the blocking list and the number of entries that the monitoring system can observe, by utilizing predicted lifespans, etc.
[0100] While blocking and monitoring malicious websites is useful, the sheer number of malicious sites is immense and increases daily, making it impractical to block or monitor them all. Therefore, it is necessary to create blocking and monitoring lists that prioritize sites based on their current status and other factors, but this presents challenges such as high implementation costs and reliance on individual expertise.
[0101] According to Example 1, the malicious site survival time prediction system 101 predicts the survival time of malicious sites and automatically constructs blocking lists and monitoring lists using the results. This is expected to reduce the operational costs and reliance on individual expertise associated with constructing blocking lists and monitoring lists. [Example 2] Example 2 describes the processing of a malignant site survival time prediction system that includes support functions for observing and analyzing malignant sites, enabling more advanced and labor-saving analysis. Below, Example 2 will be described focusing on the differences from Example 1.
[0102] Figure 10 shows an example configuration of the malignant site survival period prediction system 1001 according to Embodiment 2 of the present invention. The configuration of the computer system in Embodiment 2 is the same as that of Embodiment 1. Furthermore, the hardware configuration of the malignant site survival period prediction system in Embodiment 2 is the same as that of Embodiment 1.
[0103] The program configuration of Example 2 includes, in addition to that of Example 1, an observation interval setting program 1012, a property prediction program 1013, and a background prediction program 1014. Furthermore, the processing of the malignant site observation program 1008, survival period prediction program 1009, screen drawing program 1010, and list construction program 1011 in Example 2 is the same as in Example 1.
[0104] The data structure of Example 2 is the same as that of Example 1.
[0105] Note that the configuration of the malignant site survival time prediction system according to Example 2, as described in Figure 10, is an example and is not limited thereto. <Example Flowchart: Determining Observation Intervals> Figure 11 shows the results of Example 2. Predicting the survival time of malignant websites This flowchart illustrates an example of the observation interval setting process performed by System 1001.
[0106] When the observation interval setting program 1012, executed by the CPU 1003, receives an execution instruction from the user terminal 114, it starts the process described below.
[0107] The observation interval setting program 1012 obtains a list of target connection destinations from the malicious site list 1015 (step 1101). Here, it is assumed that a list containing entries consisting of connection destination IDs is obtained.
[0108] Next, the observation interval setting program 1012 sets the variable i, which represents the destination ID of the malicious site list 1015, to an initial value of 0 (step 1102).
[0109] Next, the observation interval setting program 1012 starts processing for the destination with destination ID i (step 1103).
[0110] Next, the observation interval setting program 1012 refers to the observation result storage area 1016 and checks whether there have been any changes in the observation results or external information items for the connected destination (step 1104).
[0111] If the above checks reveal any changes (Step 1104: Yes), the observation interval setting program 1012 terminates processing related to the connection destination and proceeds to Step 1107.
[0112] On the other hand, if no change is found as a result of the above check (Step 1104: No), the observation interval setting program 1012 proceeds to Step 1105.
[0113] Next, the observation interval setting program 1012 lengthens the observation span of the connected device by a certain percentage, for example, compared to the default value (step 1105).
[0114] Next, the observation interval setting program 1012 reflects the extended observation span from step 1105 into the list of malicious sites 1015 (step 1106).
[0115] Next, the observation interval setting program 1012 adds 1 to the variable i and proceeds to step 1108 (step 1107).
[0116] Next, the observation interval setting program 1012 compares the variable i with the number of destinations that can be obtained by referring to the list of malicious sites 1015 (step 1108).
[0117] If, at this point, the variable i is less than the number of connections (step 1108: No), the observation interval setting program 1012 returns to step 1103.
[0118] On the other hand, if the variable i exceeds the number of connections (Step 1108: Yes), the observation interval setting program 1012 terminates processing.
[0119] The method for determining the observation interval, as explained in Figure 11, is merely an example and is not limited thereto. For example, the observation span may be shortened if there are changes in the observation results or external information. <Flow example: Property prediction> Figure 12 shows the results of Example 1. Predicting the survival time of malignant websitesThis flowchart illustrates an example of the property prediction process performed by system 1001.
[0120] When the property prediction program 1013, executed by the CPU 1003, receives an execution command from the user terminal 114, it starts the process described below.
[0121] The property prediction program 1013 obtains a list of target connection destinations from the malicious site list 1015 (step 1201). Here, it is assumed that a list containing entries consisting of connection destination IDs is obtained.
[0122] Next, the property prediction program 1013 sets the variable i, which represents the connection destination ID of the malicious site list 1015, to an initial value of 0 (step 1202).
[0123] Next, the property prediction program 1013 starts processing the connection destination with connection destination ID i (step 1203).
[0124] Next, the property prediction program 1013 refers to the observation result storage area 1016 and checks if there are any additional observation results for the connection destination since the last prediction (step 1204).
[0125] If this check reveals no additional observation results (Step 1204: No), the property prediction program 1013 terminates processing related to the connection destination and proceeds to Step 1207.
[0126] On the other hand, if the above confirmation yields additional observation results (Step 1204: Yes), Property prediction Program 1013 proceeds to step 1205.
[0127] Next, the property prediction program 1013 obtains external information related to the connection destination (step 1205). This external information may include, for example, WHOIS information, DNS information, certificate information, etc.
[0128] Next, the property prediction program 1013 applies the observation results obtained up to this point and the external information acquired in step 1205 to a predetermined judgment rule to predict the properties of the connection destination (step 1206). Here, properties refer to things like sites where the content changes rapidly in a short period of time, sites where the properties do not change until termination, etc. Furthermore, the judgment rule described above can be imagined as, for example, a judgment engine obtained through machine learning based on the relationship between the values of each item contained in the observation results and external information and the properties of malicious sites.
[0129] Next, the property prediction program 1013 adds 1 to the variable i and proceeds to step 1108 (step 1207).
[0130] Next, the property prediction program 1013 compares the variable i with the number of destinations that can be obtained by referring to the list of malicious sites 1015 (step 1208).
[0131] If, as a result of the above comparison, the variable i is less than the number of connections (step 1208: No), the property prediction program 1013 returns to step 1203.
[0132] On the other hand, if the above check confirms that the variable i exceeds the number of connection destinations (Step 1208: Yes), the property prediction program 1013 terminates processing (Step 1208).
[0133] The property prediction processing method described in Figure 12 is just one example and is not limited thereto. <Example Flow: Background Prediction> Figure 13 shows the results of Example 1. Predicting the survival time of malignant websites This flowchart illustrates an example of background prediction processing performed by system 1001.
[0134] When the background prediction program 1014, executed by the CPU 1003, receives an execution command from the user terminal 114, it starts the process described below.
[0135] The background prediction program 1014 obtains a list of target destinations from the malicious site list 1015 (step 1301). Here, it is assumed that a list containing entries consisting of destination IDs is obtained.
[0136] Next, the background prediction program 1014 determines the destination of the malicious site list 1015. The variable i, which represents the ID, is initialized to 0 (Step 1302).
[0137] Next, the background prediction program 1014 starts processing the connection destination with connection destination ID i (step 1303).
[0138] Next, the background prediction program 1014 refers to the observation result storage area 1016 and checks if there are any additional observation results for the connection destination since the last prediction (step 1304).
[0139] If, as a result of the above check, no additional observation results are found (Step 1304: No), the background prediction program 1014 terminates processing related to the connection destination and proceeds to Step 1307.
[0140] On the other hand, if the above checks reveal additional observation results (Step 1304: Yes), the background prediction program 1014 proceeds to Step 1305.
[0141] Next, the background prediction program 1014 obtains external information related to the connection destination (step 1305). This external information may include, for example, WHOIS information, DNS information, and certificate information.
[0142] Next, the background prediction program 1014 uses the observation results obtained so far and the external information acquired in step 1305 to predict the background of the connection destination (step 1306). Here, the background refers to, for example, attack groups or malware associated with the connection destination.
[0143] Next, the background prediction program 1014 adds 1 to the variable i and proceeds to step 1108 (step 1307).
[0144] Next, the background prediction program 1014 compares the variable i with the number of destinations that can be obtained by referring to the list of malicious sites 1015 (step 1308).
[0145] If, as a result of the above comparison, the variable i is less than the number of connections (step 1308: No), the background prediction program 1014 returns to step 1303.
[0146] On the other hand, if the variable i exceeds the number of connections (step 1308: Yes), the background prediction program 1014 terminates processing (step 1308).
[0147] Note that the background prediction processing method described in Figure 13 is just one example and is not limited thereto.
[0148] According to Example 2, the malignant site survival period prediction system 1001, in addition to the malignant site survival period prediction function similar to that in Example 1, is equipped with support functions such as an observation interval setting function, a property prediction function, and a background prediction function. This enables more advanced and labor-saving implementation of malignant site survival period prediction and related list construction. [Example 3] Example 3 describes the processing of a malicious site survival time prediction system that enables cloud service provision by sharing the judgment results externally via a network, in addition to on-premises malicious site survival time prediction. Below, Example 2 will be described, focusing on the differences from Example 1.
[0149] Figure 14 shows an example of the configuration of the malignant site survival period prediction system 1401 according to Embodiment 3 of the present invention. The configuration of the computer system in Embodiment 3 is the same as that in Embodiment 1.
[0150] The hardware configuration of the malignant site survival time prediction system 1401 in Example 3 may include an external user terminal 1420 in addition to the configuration of Example 2.
[0151] In Example 3, each program executes processing in response to requests not only from user terminals 1417 within the network but also from external user terminals 1420, and returns the results to the external user terminals 1420 via the internet 1419. This enables the provision of services in the cloud.
[0152] The program in Example 3 is identical to that in Example 2. Furthermore, the processes executed by the malignant site observation program 1408, survival period prediction program 1409, screen drawing program 1410, list construction program 1411, observation interval setting program 1412, property prediction program 1413, and background prediction program 1414 in Example 3 are identical to those in Example 2. Additionally, the data structure in Example 3 is identical to that of Example 2.
[0153] The configuration of the malignant site survival time prediction system 1401 according to Example 3, as described in Figure 14, is an example and is not limited thereto.
[0154] According to Example 3, the malicious site survival time prediction system 1401, similar to Examples 1 and 2, can provide a malicious site survival time prediction function to internal users on-premises while also providing the same information to external users via the Internet 1419. This enables the provision of services in the cloud.
[0155] Although the best mode for carrying out the present invention has been described in detail above, the present invention is not limited thereto and can be modified in various ways without departing from its essence.
[0156] According to this embodiment, by predicting the lifespan of malicious sites, it becomes possible to reduce the operational costs and reliance on individual expertise involved in building blocking lists and monitoring lists.
[0157] The description herein makes it clear at least the following: In the malignant site survival time prediction system of this embodiment, the computing device may further perform a process of outputting the observation results, the prediction results, and at least one of the block list or the monitoring list to a predetermined device.
[0158] According to this, those responsible for dealing with malicious websites will be able to efficiently recognize various information about those websites, including their lifespan, and the timeliness of their response will also improve.
[0159] Furthermore, in the malignant site survival period prediction system of this embodiment, the computing device may predict the survival period by applying external information publicly available on the network regarding the malignant site to the judgment rules, in addition to the observation results.
[0160] According to this, various information such as WHOIS information and DNS information, including the domain, country, and owner of the malicious site, can be applied to the survival time prediction algorithm, effectively improving the accuracy of survival time predictions.
[0161] Furthermore, in the malignant site survival period prediction system of this embodiment, the computing device estimates the properties, including the role of the malignant site, based on the observation results and the external information, The results of this estimation may also be applied to the judgment rule to predict the survival period.
[0162] According to this, it becomes possible to accurately predict the lifespan of malware by taking into account the tendency for the lifespan to differ depending on the role of the malware distribution site and the management / command site that issues instructions to such malware over a certain period of time.
[0163] Furthermore, in the malicious site survival time prediction system of this embodiment, the computing device may apply the observation results and the external information to a predetermined algorithm to predict the attack group or malware associated with the malicious site, and then apply the results of the prediction to the judgment rule to predict the survival time.
[0164] According to this, it is expected that the accuracy of predicting the lifespan of a malicious site can be further improved by taking into account the operator's location, the country to which it belongs, the targeted systems and services, and past trends in commonly used malware, etc., in order to predict the attack group and malware used by the malicious site.
[0165] Furthermore, in the malignant site survival time prediction system of this embodiment, the computing device may generate a list of sites to be monitored or blocked according to the role of the malignant site, as indicated by the survival time prediction result.
[0166] According to this, for example, it becomes possible to generate a highly accurate list based on the reasoning that sites responsible for distributing malware should be blocked quickly, and sites that give instructions to malware distribution sites should be continuously monitored.
[0167] Furthermore, in the malicious site survival period prediction system of this embodiment, the computing device may further perform a process to maximize the blocking list or the monitoring list based on the predicted survival period and the resource performance that can handle blocking or observing the malicious sites.
[0168] According to this, it becomes possible to efficiently generate and subsequently utilize blocking lists and monitoring lists within the limits of the resources available for maintaining and managing such lists.
[0169] Furthermore, in the malignant site survival time prediction method of this embodiment, the information processing device may further perform a process to output the observation results, the prediction results, and at least one of the blocking list or the monitoring list to a predetermined device.
[0170] Furthermore, in the malignant site survival period prediction method of this embodiment, the information processing device may predict the survival period by applying external information publicly available on the network regarding the malignant site to the judgment rule, in addition to the observation results.
[0171] Furthermore, in the malignant site survival period prediction method of this embodiment, the information processing device may estimate the properties, including the role of the malignant site, based on the observation results and the external information, and apply the results of the estimation to the judgment rule to predict the survival period.
[0172] Furthermore, in the malicious site survival time prediction method of this embodiment, the information processing device may apply the observation results and the external information to a predetermined algorithm to predict the attack group or malware associated with the malicious site, and then apply the results of the prediction to the judgment rule to predict the survival time.
[0173] Furthermore, in the malicious site survival time prediction method of this embodiment, the information processing device may generate a list of sites to be monitored or blocked according to the role of the malicious site, as indicated by the survival time prediction result.
[0174] Furthermore, in the malicious site survival period prediction method of this embodiment, the information processing device may further perform a process to maximize the blocking list or the monitoring list based on the predicted survival period and the resource performance that can handle blocking or observing the malicious site. [Explanation of Symbols]
[0175] 101 Malignant Site Survival Time Prediction System 102 IF (Communication Equipment) 103 CPU (computing unit) 104 Main Memory 105 Storage device 106 Input / Output Devices 107 Communication Channels 108 Malignant Site Observation Program 109 Survival Prediction Program 110 Screen rendering program 111 List Construction Program 112 List of malicious websites 113 Observation result storage area 114 User terminals 115 Network 116 Internet
Claims
1. A communication device that accesses the network, A storage device that holds information on each malicious site in the aforementioned network, A computing device that performs the following processes: accessing each of the aforementioned malicious sites and observing predetermined events at said malicious sites; applying the results of the observation and external information publicly available on the network regarding said malicious sites to a determination rule that defines the relationship between the trend of said events at said malicious sites and the lifespan of said malicious sites in the network to predict the lifespan of said malicious sites in the network; and selecting predetermined malicious sites from among the aforementioned malicious sites according to the lifespan and generating a blocking list or a monitoring list. A malignant site survival time prediction system characterized by comprising the following features.
2. The aforementioned computing device is The process further involves outputting the observation results, the prediction results, and at least one of the block list or the monitoring list to a predetermined device. The malignant site survival time prediction system according to claim 1.
3. The aforementioned computing device is Based on the observation results and the external information, the properties, including the role of the malignant site, are estimated, and the results of this estimation are also applied to the judgment rules to predict the survival period. The malignant site survival time prediction system according to claim 1.
4. The aforementioned computing device is The results of the observations and the external information are applied to a predetermined algorithm to predict the attack group or malware associated with the malicious site, and the results of the prediction are also applied to the judgment rule to predict the survival period. The malignant site survival time prediction system according to feature 3.
5. The aforementioned computing device is The predicted survival time results generate a list of sites to be monitored or blocked according to their role as malicious sites. The malignant site survival time prediction system according to feature 4.
6. The aforementioned computing device is Based on the predicted survival time and the resource capacity available to address the blocking or monitoring of malicious sites, the system further performs a process to maximize the blocking list or the monitoring list. The malignant site survival time prediction system according to claim 5.
7. Information processing device, A communication device that accesses the network and a storage device that holds information on each malicious site in the network, The process involves accessing each of the aforementioned malicious sites and observing predetermined events at those sites; applying the observation results and external information publicly available on the network regarding those malicious sites to a determination rule that defines the relationship between the trend of events at those malicious sites and the lifespan of those malicious sites in order to predict the lifespan of those malicious sites on the network; and selecting predetermined sites from among the aforementioned malicious sites according to their lifespans and generating a blocking list or a monitoring list. A method for predicting the survival period of malignant sites, characterized by the features described above.
8. The aforementioned information processing device The process further involves outputting the observation results, the prediction results, and at least one of the block list or the monitoring list to a predetermined device. The method for predicting the survival period of malignant sites according to feature 7.
9. The aforementioned information processing device Based on the observation results and the external information, the properties, including the role of the malignant site, are estimated, and the results of this estimation are also applied to the judgment rule to predict the survival period. The method for predicting the survival period of malignant sites according to feature 7.
10. The aforementioned information processing device The results of the observations and the external information are applied to a predetermined algorithm to predict the attack group or malware associated with the malicious site, and the results of the prediction are also applied to the judgment rule to predict the survival period. The method for predicting the survival period of malignant sites according to feature 9.
11. The aforementioned information processing device The predicted survival time results generate a list of sites to be monitored or blocked according to their role as malicious sites. The method for predicting the survival period of malignant sites according to feature 10.
12. The aforementioned information processing device Based on the predicted survival time and the resource capacity available to address the blocking or monitoring of malicious sites, the process of maximizing the blocking list or the monitoring list is further executed. The method for predicting the survival period of malignant sites according to feature 11.