Information search method, information search device, and program
Patent Information
- Application Number
- JP2024564167
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Filing Date
- 2025-05-28
- Publication Date
- 2025-08-20
Abstract
Description
Information search method, information search device, and program
[0001] The present disclosure relates to an information search method and an information search device for searching a database for information related to cyber attacks, and a program for searching a database for information related to cyber attacks.
[0002] Traditionally, security analysts at security operations centers investigate malware that poses a security threat by utilizing databases that collect cyber threat intelligence (CTI) based on indicator of compromise (IoC) information that shows traces of cyber attacks.
[0003] Rastogi, N., Dutta, S., Zaki, MJ, Gittens, A., & Aggarwal, C. (2020). Malont: An ontology for malware threat intelligence. In Deployable Machine Learning for Security Defense: First International Workshop, MLHat 2020, San Diego, CA, USA, August 24, 2020, Proceedings 1 (pp. 28-44). Springer International Publishing.
[0004] If security analysts can know to what extent the malware they are investigating is related to which field (e.g., homes, mobile devices, factories, infrastructure, etc.), they will be able to take effective measures against that malware.
[0005] Therefore, an object of the present disclosure is to provide an information search method and the like that can output the degree of relevance of malware registered in a database to each field.
[0006] An information retrieval method according to one aspect of the present disclosure is an information retrieval method for retrieving information about cyber attacks from a database including a plurality of domain objects and a plurality of relationship objects, wherein each of the plurality of domain objects includes type information indicating a type of the domain object, and at least one of the plurality of domain objects further includes label information linked to the type information and indicating a field related to the domain object, each of the plurality of relationship objects includes linking information linking one domain object of the plurality of domain objects with another domain object, each of the type information is information indicating one of a plurality of types including a type indicating malware, and each of the label information is information indicating one or more of a plurality of fields, and for one or more non-malware type domain objects of the plurality of domain objects including type information indicating a type other than malware, one or more of the plurality of relationship objects a first association degree calculation step of calculating a first association degree between the non-malware type domain object and each of the plurality of fields based on one or more fields indicated by one or more label information included in one or more domain objects associated with the non-malware type domain object using association information included in the relationship object; an associated domain object calculation step of calculating, for each of the one or more malware type domain objects including type information indicating malware among the plurality of domain objects, one or more associated non-malware type domain objects including type information indicating a type other than malware that are associated with the malware type domain object using association information included in one or more relationship objects among the plurality of relationship objects; and, for each of the one or more malware type domain objects, calculating a first association degree between the one or more malware type domain objects and each of the one or more associated non-malware type domain objects based on the first association degree for each of the one or more associated non-malware type domain objects calculated in the associated domain object calculation step.The method includes a second relevance degree calculation step of calculating a second relevance degree with each of the plurality of fields, and an output step of outputting the second relevance degree calculated by the second relevance degree calculation step for at least one of the one or more malware-type domain objects to an external device.
[0007] An information retrieval device according to one aspect of the present disclosure is an information retrieval device that searches for information regarding cyber attacks from a database including a plurality of domain objects and a plurality of relationship objects, wherein each of the plurality of domain objects includes type information indicating a type of the domain object, and at least one of the plurality of domain objects further includes label information linked to the type information and indicating a field related to the domain object, each of the plurality of relationship objects includes linking information linking one domain object of the plurality of domain objects with another domain object, each of the type information is information indicating one of a plurality of types including a type indicating malware, and each of the label information is information indicating one or more of a plurality of fields, and for one or more non-malware type domain objects of the plurality of domain objects including type information indicating a type other than malware, a first association degree calculation unit that calculates a first association degree between the non-malware type domain object and each of the plurality of fields based on one or more fields indicated by one or more label information included in one or more domain objects associated with the non-malware type domain object using association information included in one or more relationship objects; a related domain object calculation unit that calculates, for each of the one or more malware type domain objects including type information indicating malware among the plurality of domain objects, one or more related non-malware type domain objects including type information indicating a type other than malware that are associated with the malware type domain object using association information included in one or more relationship objects among the plurality of relationship objects; and a related domain object calculation unit that calculates, for each of the one or more malware type domain objects, a first association degree between the non-malware type domain object and each of the plurality of fields based on the first association degree for each of the one or more related non-malware type domain objects calculated by the related domain object calculation unit.The malware-type domain object detection system includes a second relevance degree calculation unit that calculates a second relevance degree with each of the plurality of fields, and an output unit that outputs the second relevance degree calculated by the second relevance degree calculation unit to an external device for at least one of the one or more malware-type domain objects.
[0008] A program according to one aspect of the present disclosure is a program for causing a computer to execute a process of searching for information on cyber attacks from a database including a plurality of domain objects and a plurality of relationship objects, wherein each of the plurality of domain objects includes type information indicating a type of the domain object, and at least one of the plurality of domain objects further includes label information linked to the type information and indicating a field related to the domain object, and each of the plurality of relationship objects includes linking information linking one domain object of the plurality of domain objects with another domain object, each of the type information is information indicating any one of a plurality of types including a type indicating malware, and each of the label information is information indicating any one or more of a plurality of fields, and the process includes: searching for information on cyber attacks from a database including a plurality of domain objects and a plurality of relationship objects for each of one or more non-malware type domain objects of the plurality of domain objects including type information indicating a type other than malware, a first degree of association calculation step of calculating a first degree of association between the non-malware type domain object and each of the plurality of fields based on one or more fields indicated by one or more label information included in one or more domain objects associated with the non-malware type domain object using association information included in one or more relationship objects among the relationship objects; a related domain object calculation step of calculating, for each of the one or more malware type domain objects including type information indicating malware among the plurality of domain objects, one or more related non-malware type domain objects including type information indicating a type other than malware that are associated with the malware type domain object using association information included in one or more relationship objects among the plurality of relationship objects; and, for each of the one or more malware type domain objects, based on the first degree of association for each of the one or more related non-malware type domain objects calculated by the related domain object calculation step,The method includes a second relevance degree calculation step of calculating a second relevance degree between the malware-type domain object and each of the plurality of fields, and an output step of outputting the second relevance degree calculated by the second relevance degree calculation step for at least one of the one or more malware-type domain objects to the outside.
[0009] According to an information search method etc. relating to one aspect of the present disclosure, it is possible to output the degree of relevance of malware registered in a database to each field.
[0010] FIG. 1 is a block diagram showing the configuration of an information retrieval system according to the first embodiment. FIG. 2 is a schematic diagram showing the data structure of threat information according to the first embodiment. FIG. 3 is a block diagram showing the configuration of an information retrieval device according to the first embodiment. FIG. 4 is a schematic diagram showing an example of a category table according to the first embodiment. FIG. 5 is a schematic diagram showing an example of a state in which a security analyst inputs a search query. FIG. 6 is a schematic diagram showing an example of an image generated by an output unit according to the first embodiment. FIG. 7 is a sequence diagram of information retrieval processing performed by the information retrieval system according to the first embodiment. FIG. 8 is a flowchart of category table update processing performed by the information retrieval device according to the first embodiment. FIG. 9 is a flowchart of first relevance calculation processing performed by a first relevance calculation unit according to the first embodiment. FIG. 10 is a flowchart of first search processing performed by the information retrieval device according to the first embodiment. FIG. 11 is a flowchart of search result information calculation processing performed by the information retrieval device according to the first embodiment. FIG. 12 is a flowchart of related domain object calculation processing performed by a related domain object calculation unit according to the first embodiment. Fig. 13 is a flowchart of second relevance degree calculation processing performed by a second relevance degree calculation unit according to Embodiment 1. Fig. 14 is a block diagram showing a configuration of an information retrieval device according to Embodiment 2. Fig. 15 is a schematic diagram showing an example of an image generated by an output unit according to Embodiment 2. Fig. 16A is a flowchart 1 of second search processing performed by an information retrieval device according to Embodiment 2. Fig. 16B is a flowchart 2 of second search processing performed by an information retrieval device according to Embodiment 2.
[0011] (How one aspect of the present disclosure was achieved) When a system that a security analyst is responsible for is subjected to a cyber attack by malware, the security analyst collects information about the malware and takes measures against the malware based on the collected information.
[0012] However, for example, in cases where the vulnerabilities targeted by the malware being addressed exist in systems in various fields, if a security analyst simply limits the measures they take against the malware to systems in a specific field related to the system they are responsible for, the measures they take against the malware may not be sufficient.
[0013] In response to this, the inventors considered that if security analysts could know to what extent the malware is related to which field when taking measures against the malware, the security analysts would be able to take effective measures against the malware.
[0014] Based on this idea, the inventors conducted extensive experiments and studies to find an information search method that would enable them to determine to what extent the malware being investigated is related to which field.
[0015] As a result, the inventors have come up with the information search method, information search device, and program according to the present disclosure below.
[0016] An information retrieval method according to one aspect of the present disclosure is an information retrieval method for retrieving information about cyber attacks from a database including a plurality of domain objects and a plurality of relationship objects, wherein each of the plurality of domain objects includes type information indicating a type of the domain object, and at least one of the plurality of domain objects further includes label information linked to the type information and indicating a field related to the domain object, each of the plurality of relationship objects includes linking information linking one domain object of the plurality of domain objects with another domain object, each of the type information is information indicating one of a plurality of types including a type indicating malware, and each of the label information is information indicating one or more of a plurality of fields, and for one or more non-malware type domain objects of the plurality of domain objects including type information indicating a type other than malware, one or more of the plurality of relationship objects a first association degree calculation step of calculating a first association degree between the non-malware type domain object and each of the plurality of fields based on one or more fields indicated by one or more label information included in one or more domain objects associated with the non-malware type domain object using association information included in the relationship object; an associated domain object calculation step of calculating, for each of the one or more malware type domain objects including type information indicating malware among the plurality of domain objects, one or more associated non-malware type domain objects including type information indicating a type other than malware that are associated with the malware type domain object using association information included in one or more relationship objects among the plurality of relationship objects; and, for each of the one or more malware type domain objects, calculating a first association degree between the one or more malware type domain objects and each of the one or more associated non-malware type domain objects based on the first association degree for each of the one or more associated non-malware type domain objects calculated in the associated domain object calculation step.The method includes a second relevance degree calculation step of calculating a second relevance degree with each of the plurality of fields, and an output step of outputting the second relevance degree calculated by the second relevance degree calculation step for at least one of the one or more malware-type domain objects to an external device.
[0017] According to the above information search method, a second degree of relevance indicating the degree of relevance of the malware registered in the database to each field is output.
[0018] Therefore, a security analyst using the above information search method can know to what extent the malware being investigated is related to which field by referring to the second relevance degree for the malware.
[0019] The plurality of fields may also include at least two of a home field indicating a field related to housing, a mobility field indicating a field related to moving objects, a factory field indicating a field related to factories, an infrastructure field indicating a field related to infrastructure, and a building field indicating information related to buildings.
[0020] As a result, a second degree of association is output indicating the degree of association with each field for at least two of the residential field, the mobile field, the factory field, and the infrastructure field for the malware registered in the database.
[0021] Therefore, a security analyst using the above information search method can find out to what extent the malware being investigated is related to at least two of the following fields: residential, mobile, factory, and infrastructure.
[0022] Furthermore, each of the multiple domain objects further includes name information indicating the name of the domain object linked to the type information included in the domain object, and the method further includes a query acquisition step of acquiring one or more search queries, and a calculation step of calculating, for each of the one or more malware-type domain objects, the number of matching names that match the one or more search queries from among one or more names indicated by one or more name information included in one or more domain objects linked to the malware-type domain object, using linking information included in one or more relationship objects among the multiple relationship objects, and in the output step, the one or more malware-type domain objects may be sorted in descending order of the number of matching names, and the second degree of relevance may be output based on the result of the sorting.
[0023] This makes it possible to sort the malware in order of increasing relevance to the search query, and output a second relevance level indicating the degree of relevance of each piece of malware to each field.
[0024] Therefore, a security analyst using the above information search method can know to what extent each piece of malware is related to which field, with the malware sorted in order of relevance to the search query.
[0025] Furthermore, each of the multiple domain objects further includes name information indicating a name of the domain object linked to the type information included in the domain object, and the method further includes a query acquisition step of acquiring one or more search queries, and a calculation step of, for each of the one or more malware-type domain objects, calculating a minimum value of standardized Levenshtein distances between the one or more search queries and each of one or more names indicated by one or more name information included in one or more domain objects linked to the malware-type domain object using linking information included in one or more relationship objects among the multiple relationship objects, and calculating an average distance that is an average value of the minimum values for each of the one or more names, and in the output step, sorting the one or more malware-type domain objects in order of shortest average distance, and outputting the second degree of relevance based on the sorting result.
[0026] This makes it possible to sort the malware in order of increasing relevance to the search query, and output a second relevance level indicating the degree of relevance of each piece of malware to each field.
[0027] Therefore, a security analyst using the above information search method can know to what extent each piece of malware is related to which field, with the malware sorted in order of relevance to the search query.
[0028] In addition, in the second degree of association calculation step, an average value of the first degrees of association for each of the one or more associated non-malware type domain objects may be calculated as the second degree of association.
[0029] This allows the second degree of association to be calculated through relatively simple calculation processing.
[0030] An information retrieval device according to one aspect of the present disclosure is an information retrieval device that searches for information regarding cyber attacks from a database including a plurality of domain objects and a plurality of relationship objects, wherein each of the plurality of domain objects includes type information indicating a type of the domain object, and at least one of the plurality of domain objects further includes label information linked to the type information and indicating a field related to the domain object, each of the plurality of relationship objects includes linking information linking one domain object of the plurality of domain objects with another domain object, each of the type information is information indicating one of a plurality of types including a type indicating malware, and each of the label information is information indicating one or more of a plurality of fields, and for one or more non-malware type domain objects of the plurality of domain objects including type information indicating a type other than malware, a first association degree calculation unit that calculates a first association degree between the non-malware type domain object and each of the plurality of fields based on one or more fields indicated by one or more label information included in one or more domain objects associated with the non-malware type domain object using association information included in one or more relationship objects; a related domain object calculation unit that calculates, for each of the one or more malware type domain objects including type information indicating malware among the plurality of domain objects, one or more related non-malware type domain objects including type information indicating a type other than malware that are associated with the malware type domain object using association information included in one or more relationship objects among the plurality of relationship objects; and a related domain object calculation unit that calculates, for each of the one or more malware type domain objects, a first association degree between the non-malware type domain object and each of the plurality of fields based on the first association degree for each of the one or more related non-malware type domain objects calculated by the related domain object calculation unit.The malware-type domain object detection system includes a second relevance degree calculation unit that calculates a second relevance degree with each of the plurality of fields, and an output unit that outputs the second relevance degree calculated by the second relevance degree calculation unit to an external device for at least one of the one or more malware-type domain objects.
[0031] According to the information search device, a second degree of association indicating the degree of association with each field of the malware registered in the database is output.
[0032] Therefore, a security analyst using the information search device can refer to the second relevance degree for the malware being investigated to find out to what extent the malware is related to which field.
[0033] A program according to one aspect of the present disclosure is a program for causing a computer to execute a process of searching for information on cyber attacks from a database including a plurality of domain objects and a plurality of relationship objects, wherein each of the plurality of domain objects includes type information indicating a type of the domain object, and at least one of the plurality of domain objects further includes label information linked to the type information and indicating a field related to the domain object, and each of the plurality of relationship objects includes linking information linking one domain object of the plurality of domain objects with another domain object, each of the type information is information indicating any one of a plurality of types including a type indicating malware, and each of the label information is information indicating any one or more of a plurality of fields, and the process includes: searching for information on cyber attacks from a database including a plurality of domain objects and a plurality of relationship objects for each of one or more non-malware type domain objects of the plurality of domain objects including type information indicating a type other than malware, a first degree of association calculation step of calculating a first degree of association between the non-malware type domain object and each of the plurality of fields based on one or more fields indicated by one or more label information included in one or more domain objects associated with the non-malware type domain object using association information included in one or more relationship objects among the relationship objects; a related domain object calculation step of calculating, for each of the one or more malware type domain objects including type information indicating malware among the plurality of domain objects, one or more related non-malware type domain objects including type information indicating a type other than malware that are associated with the malware type domain object using association information included in one or more relationship objects among the plurality of relationship objects; and, for each of the one or more malware type domain objects, based on the first degree of association for each of the one or more related non-malware type domain objects calculated by the related domain object calculation step,The method includes a second relevance degree calculation step of calculating a second relevance degree between the malware-type domain object and each of the plurality of fields, and an output step of outputting the second relevance degree calculated by the second relevance degree calculation step for at least one of the one or more malware-type domain objects to the outside.
[0034] According to the program, a second degree of association indicating the degree of association with each field for the malware registered in the database is output.
[0035] Therefore, a security analyst using the above program can refer to the second relevance of the malware being investigated to know to what extent the malware is related to which field.
[0036] A specific example of an information search device according to one aspect of the present disclosure will be described below with reference to the drawings. Each embodiment shown here represents a specific example of the present disclosure. Therefore, the numerical values, shapes, components, the arrangement and connection of the components, steps (processes), and the order of steps shown in the following embodiments are merely examples and are not intended to limit the present disclosure. Furthermore, each figure is a schematic diagram and is not necessarily an exact illustration. In each figure, substantially identical components are assigned the same reference numerals, and redundant explanations are omitted or simplified.
[0037] (First Embodiment) <Configuration> FIG. 1 is a block diagram showing the configuration of an information retrieval system 1 according to the first embodiment.
[0038] As shown in FIG. 1, the information retrieval system 1 includes an information retrieval device 100 , a threat information collection server 200 , a threat information distribution server 300 , and a network 400 .
[0039] The threat information distribution server 300 is connected to the network 400 and distributes threat information to external devices connected to the network 400 .
[0040] The threat information is a database that stores information about cyber attacks. Here, as a non-limiting example, the threat information will be described as a database in STIX (Structured Threat Information eXpression) format.
[0041] FIG. 2 is a schematic diagram showing the data structure of threat information distributed by the threat information distribution server 300. As shown in FIG.
[0042] As shown in FIG. 2, the threat information includes a plurality of domain objects 610 (corresponding to domain objects 610a, 610b, and 610c in FIG. 2) and a plurality of relationship objects 620 (corresponding to relationship objects 620a and 620b in FIG. 2).
[0043] As shown in FIG. 2 , the domain object 610 includes type information 611 (corresponding to type information 611a, type information 611b, type information 611c, type information 611d, and type information 611e in FIG. 2 ), identification information 612 (corresponding to identification information 612a, identification information 612b, identification information 612c, identification information 612d, and identification information 612e in FIG. 2 ), update information 613 (corresponding to update information 613a, update information 613d, and update information 613e in FIG. 2 ), name information 614 (corresponding to name information 614a, name information 614b, and name information 614c in FIG. 2 ), and label information 615 (corresponding to label information 615a, label information 615b, and label information 615c in FIG. 2 ), which are linked to one another.
[0044] The type information 611 is information indicating any one of a plurality of types including a type indicating malware. Here, as a non-limiting example, the plurality of types will be described as including, other than the type indicating malware, a type indicating a domain name, a type indicating a report, and a type indicating a relationship.
[0045] Of these multiple types, the domain object 610 includes one of a type indicating malware, a type indicating a domain name, and a type indicating a report, and the relationship object 620 includes a type indicating a relationship. In other words, an object that includes one of a type indicating malware, a type indicating a domain name, and a type indicating a report is the domain object 610, and an object that includes a type indicating a relationship is the relationship object 620.
[0046] The identification information 612 is information indicating an identifier for identifying the domain object 610 or the relationship object 620 .
[0047] The update information 613 is information indicating the date and time when the domain object 610 or the relationship object 620 was last updated. In this description, it is assumed that the domain object 610 and the relationship object 620 that have never been updated do not include the update information 613.
[0048] The name information 614 is information indicating the name of the domain object 610 or the relationship object 620 .
[0049] The names indicated by the name information 614 include, for example, the malware name, the IP address name related to the cyber attack, the domain name related to the cyber attack, the URL name related to the cyber attack, the malware file name, the malware file hash value, etc.
[0050] The label information 615 is information indicating a field to which the domain object 610 is related. Here, as a non-limiting example, the fields indicated by the label information 615 will be described as including a home field indicating a field related to a home, a mobility field indicating a field related to a moving object, a factory field indicating a field related to a factory, an infrastructure field indicating a field related to infrastructure, and a building field indicating a field related to a building.
[0051] If a domain object 610 relates to multiple disciplines, the domain object 610 may include label information 615 that indicates each of the multiple disciplines.
[0052] Additionally, if the field associated with a domain object 610 is unknown or if there is no field associated with the domain object 610, the domain object 610 may not include label information 615.
[0053] As shown in FIG. 2, a relationship object 620 includes type information 611, identification information 612, update information 613, and linking information 621 (corresponding to linking information 621a and linking information 621b in FIG. 2), which are linked to each other.
[0054] The linking information 621 is information that links one domain object 610 with another domain object 610 among the multiple domain objects 610 included in the threat information.
[0055] Returning to FIG. 1, the description of the information retrieval system 1 will continue.
[0056] The threat information collection server 200 is connected to the network 400 and the information retrieval device 100, and acquires and stores threat information distributed from the threat information distribution server 300 via the network 400.
[0057] The information retrieval device 100 is connected to the threat information collection server 200 and the network 400, and retrieves information about cyber-attacks from the threat information stored in the threat information collection server 200. The information retrieval device 100 is a device that is used, for example, by a security analyst 500 when a system that the analyst is responsible for is subjected to a cyber-attack by malware, to collect information about the malware and take measures against the malware based on the collected information.
[0058] The information search device 100 is realized, for example, by a computer device including a processor, a memory, an input / output interface, and a communication interface, in which the processor executes a program stored in the memory.
[0059] FIG. 3 is a block diagram showing the configuration of the information retrieval device 100. As shown in FIG.
[0060] As shown in FIG. 3, the information search device 100 includes a first relevance degree calculation unit 10, a second relevance degree calculation unit 20, a related domain object calculation unit 30, an output unit 40, a query acquisition unit 50, a calculation unit 60, a field table storage unit 70, and a communication unit 80.
[0061] The communication unit 80 communicates with external devices, including the threat information collection server 200.
[0062] The first relevance degree calculation unit 10 calculates, for each of one or more non-malware type domain objects including type information 611 indicating a type other than malware among the multiple domain objects 610 included in the threat information stored by the threat information collection server 200, a first relevance degree between the non-malware type domain object and each of multiple fields based on one or more fields indicated by one or more label information 615 included in one or more domain objects linked to the non-malware type domain object using linking information 621 included in one or more relationship objects 620 among the multiple relationship objects 620 included in the threat information.
[0063] In the first embodiment, the first degree-of-association calculation unit 10 will be described as calculating the first degree of association by performing a first degree-of-association calculation process.
[0064] The specific processing content of the first relevance degree calculation processing will be described later.
[0065] Then, the first degree of association calculation unit 10 generates a field table in which one or more non-malware type domain objects are associated with the first degrees of association calculated for the non-malware type domain objects.
[0066] FIG. 4 is a schematic diagram showing an example of a field table generated by the first relevance degree calculation unit 10. As shown in FIG.
[0067] 4, the field table is a table that associates an identifier for identifying a non-malware-type domain object with a first degree of relevance for each field, and an increase or decrease in the first degree of relevance for each field. Here, the increase or decrease in the first degree of relevance for each field refers to the increase or decrease in the first degree of relevance for each field that is newly generated by the first degree of relevance calculation unit 10 this time, relative to the first degree of relevance for each field that was previously generated by the first degree of relevance calculation unit 10.
[0068] The field table shown in Figure 4 indicates, for example, that a non-malware domain object identified by the identifier "domain-name--3c10e93f-798e-5a26-a0c1" has a first degree of association with the home field of 0.66 and an increase / decrease of +0.11, a first degree of association with the mobility field of 0 and no increase / decrease, a first degree of association with the factory field of 0.33 and an increase / decrease of -0.17, a first degree of association with the infrastructure field of 0 and no increase / decrease, and a first degree of association with the building field of 0 and no increase / decrease.
[0069] Returning to FIG. 3, the description of the information retrieval device 100 will continue.
[0070] The category table storage unit 70 stores the category table generated by the first degree-of-relevance calculation unit 10 .
[0071] The related domain object calculation unit 30 calculates, for each of one or more malware-type domain objects including type information 611 indicating malware among the multiple domain objects 610 included in the threat information stored by the threat information collection server 200, one or more related non-malware-type domain objects including type information indicating a type other than malware that are linked to the malware-type domain object using linking information 621 included in one or more relationship objects 620 among the multiple relationship objects 620 included in the threat information.
[0072] In the first embodiment, the related domain object calculation unit 30 performs the related domain object calculation process to calculate the one or more related non-malware type domain objects.
[0073] The specific processing content of the related domain object calculation processing will be described later.
[0074] The second relevance degree calculation unit 20 calculates, for each of one or more malware-type domain objects among the multiple domain objects 610 included in the threat information stored in the threat information collection server 200, a second relevance degree between the malware-type domain object and each of the multiple fields based on the first relevance degree for each of the one or more related non-malware-type domain objects calculated by the related domain object calculation unit 30.
[0075] Here, the second relevance degree calculation unit 20 is explained as calculating the average value of the first relevance degrees for each of one or more related non-malware type domain objects calculated by the related domain object calculation unit 30 as the second relevance degree between the malware type domain object and each of the multiple fields.
[0076] In the first embodiment, the second degree-of-association calculation unit 20 will be described as calculating the second degree of association by performing a second degree-of-association calculation process.
[0077] The specific processing content of the second relevance degree calculation processing will be described later.
[0078] The query acquisition unit 50 acquires one or more search queries.
[0079] Here, as an example that is not necessarily limited to this, the query acquisition unit 50 is described as having an input interface and acquiring one or more search queries input via the input interface by a user using the information search device 100, for example, a security analyst 500.
[0080] Here, the search query is information that a security analyst 500 uses to collect information about malware when a cyber attack by malware occurs on a system that the security analyst 500 is responsible for.
[0081] The search query may be, for example, IoC information that indicates traces of a cyber attack that remain on a system that has been subjected to a cyber attack by malware.
[0082] FIG. 5 is a schematic diagram showing an example of how a security analyst 500 inputs a search query into an input interface provided in the query acquisition unit 50. As shown in FIG.
[0083] As shown in Figure 5, the query acquisition unit 50 acquires one or more search queries, such as IoC information input by a security analyst 500 that indicates traces of a cyber-attack, such as a suspicious IP address, a suspicious domain name, a suspicious URL, a suspicious executable file name, or a hash value of a suspicious executable file, or information indicating a field related to the system that has been attacked by a cyber-attack.
[0084] The one or more search queries acquired by the query acquisition unit 50 may include, for example, a name that matches the name indicated by the name information 614, such as a malware name, an IP address name related to a cyber attack, a domain name related to a cyber attack, a URL name related to a cyber attack, a malware file name, a malware file hash value, etc.
[0085] Returning to FIG. 3, the description of the information retrieval device 100 will continue.
[0086] The calculation unit 60 calculates, for each of one or more malware-type domain objects included in the threat information stored in the threat information collection server 200, the number of matching names that match one or more search queries acquired by the query acquisition unit 50 from among the names indicated by one or more name information 614 included in one or more domain objects linked to the malware-type domain object, using linking information 621 included in one or more relationship objects 620 out of the multiple relationship objects 620 included in the threat information.
[0087] The output unit 40 outputs to the outside the second relevance degree calculated by the second relevance degree calculation unit 20 for at least one of one or more malware-type domain objects included in the threat information stored in the threat information collection server 200.
[0088] At this time, the output unit 40 sorts the one or more malware-type domain objects in order of the number of matching names calculated by the calculation unit 60, and outputs the second degree of association based on the sorting result.
[0089] Here, as an example that is not necessarily limited to this, the output unit 40 is described as having a display, generating an image indicating a second degree of relevance for at least one of one or more malware-type domain objects included in the threat information stored by the threat information collection server 200, and displaying the generated image on the display, thereby outputting the second degree of relevance.
[0090] FIG. 6 is a schematic diagram showing an example of an image generated by the output unit 40. As shown in FIG.
[0091] As shown in FIG. 6 , the image output by the output unit 40 includes a category selection bar 91 , a search query list 92 , a search result display area 93 , and a details display area 94 .
[0092] The field selection bar 91 is a selection bar that allows a user of the information search device 100 , for example, a security analyst 500 , to select one field from among a plurality of target fields indicated by the label information 615 .
[0093] The options included in the category selection bar 91 may further include an option to select no category.
[0094] The search query list 92 is a list of one or more search queries acquired by the query acquisition unit 50 , that is, a list of one or more search queries input by a user who uses the information search device 100 .
[0095] The search result display area 93 is an area that displays the second relevance degree with each of multiple fields for each of one or more malware-type domain objects to be displayed, arranged from top to bottom in order of the number of matching names.
[0096] Here, the one or more malware-type domain objects to be displayed are malware-type domain objects whose second relevance to the field selected by the field selection bar 91 is greater than zero.
[0097] In each row of the search result display area 93, for one malware-type domain object, (1) the malware name indicated by the name information 614 included in the malware-type domain object, (2) the number of matching names, (3) the field indicated by the label information 615 included in the malware-type domain object, and (4) the second degree of relevance with each of the multiple fields and the amount of increase or decrease in the second degree of relevance. Here, the amount of increase or decrease in the second degree of relevance is the amount of increase or decrease in the second degree of relevance for each field newly generated this time by the second degree of relevance calculation unit 20 relative to the second degree of relevance for each field previously generated by the second degree of relevance calculation unit 20.
[0098] The detailed display area 94 is an area that displays the relationship between one malware-type domain object selected by a user using the information search device 100 from among one or more malware-type domain objects displayed in the search result display area 93, i.e., a malware-type domain object with a check mark in the malware name column in the search result display area 93, and each of one or more search queries acquired by the query acquisition unit 50.
[0099] Here, it is displayed that (1) the malware-type domain object selected by the user and having the malware name “alpha” is linked to a non-malware-type domain object having the file name “collect_log.exe” and a non-malware-type domain object having the domain name “test.com” by one or more linking information 621 included in one or more relationship objects 620, (2) the non-malware-type domain object having the file name “collect_log.exe” has a first degree of association with the “home field” of 0.66 and its increase / decrease is +0.16, and (3) the non-malware-type domain object having the domain name “test.com” has a first degree of association with the “home field” of 0.2 and its increase / decrease is +0.2.
[0100] Here, the file name “collect_log.exe” and the domain name “test.com” are both character strings contained in one or more search queries acquired by the query acquisition unit 50 .
[0101] <Operation> The operation performed by the information retrieval system 1 having the above configuration will be described below.
[0102] The information search system 1 performs information search processing to search for information about cyber attacks from a database of threat information.
[0103] FIG. 7 is a sequence diagram of the information search process performed by the information search system 1. As shown in FIG.
[0104] As shown in FIG. 7, the threat information collection server 200 requests the latest threat information from the threat information distribution server 300 every time a predetermined time period (e.g., one day) has elapsed. In other words, when a predetermined time period has elapsed since the previous request for threat information, the threat information collection server 200 requests the latest threat information from the threat information distribution server 300 (step S101).
[0105] Then, the threat information distribution server 300 transmits the latest threat information to the threat information collection server 200 (step S102).
[0106] When the latest threat information is transmitted from the threat information distribution server 300, the threat information collection server 200 updates the threat information stored therein with the latest threat information (step S103).
[0107] When the threat information collection server 200 updates the threat information, the information retrieval device 100 requests the updated threat information from the threat information collection server 200 (step S104).
[0108] The threat information collection server 200 then transmits the updated threat information to the information retrieval device 100 (step S105).
[0109] When the updated threat information is transmitted from the threat information collection server 200, the information retrieval device 100 executes a category table update process using the threat information to update the category table (step S106).
[0110] When one or more search queries are input by a user using the information search device 100, the information search device 100 acquires the input one or more search queries (step S107).
[0111] Then, the information retrieval device 100 requests threat information from the threat information collection server 200 (step S108).
[0112] Then, the threat information collection server 200 transmits the stored threat information to the information retrieval device 100 (step S109).
[0113] When threat information is sent from the threat information collection server 200, the information search device 100 performs a first search process using the threat information, the search query obtained in the processing of step S108, and the field table updated in the processing of step S106, to search for information regarding cyber attacks (step S110).
[0114] Then, the information retrieval device 100 outputs the search results (step S111).
[0115] FIG. 8 is a flowchart of the field table update process performed by the information search device 100.
[0116] As shown in Figure 8, when the field table update process is started, the first relevance degree calculation unit 10 executes the first relevance degree calculation process to calculate, for each of one or more non-malware type domain objects included in the threat information stored in the threat information collection server 200, the first relevance degree between the non-malware type domain object and each of the multiple fields (step S200).
[0117] FIG. 9 is a flowchart of the first degree-of-relationship calculation process performed by the first degree-of-relationship calculation unit 10.
[0118] As shown in Figure 9, when the first relevance degree calculation process is started, the first relevance degree calculation unit 10 creates a list of identifiers of one or more non-malware domain objects included in the threat information stored in the threat information collection server 200 (hereinafter also referred to as the "first identifier list") (step S300).
[0119] After creating the first identifier list, the first degree-of-association calculation unit 10 selects one unselected identifier from the first identifier list (step S310). Here, the unselected identifier refers to an identifier included in the first identifier list that has not yet been selected by the processing of step S310 in the loop processing formed by the processing of step S310 to the processing of step S330: Yes (described later).
[0120] When an unselected identifier is selected, the first relevance degree calculation unit 10 refers to all of the one or more label information contained in all of the domain objects 610 linked to the non-malware type domain object identified by the selected identifier using the linking information contained in one or more relationship objects 620 included in the threat information stored in the threat information collection server 200, and calculates the proportion of the number of occurrences of each of the multiple fields among the number of occurrences of all fields as the first relevance degree between the non-malware type domain object and each of the multiple fields (step S320).
[0121] After calculating the first degree of association between the non-malware domain object and each of the multiple fields, the first degree of association calculation unit 10 checks whether there are any unselected identifiers among the identifiers included in the first identifier list (step S330).
[0122] In the process of step S330, if there is an unselected identifier (step S330: Yes), the first degree-of-relevance calculation unit 10 performs the process of step S310 again.
[0123] In the process of step S330, if there is no unselected identifier (step S330: No), the first degree-of-association calculation unit 10 ends the first degree-of-association calculation process.
[0124] Returning to FIG. 8, the description of the field table update process will be continued.
[0125] When the first relevance degree calculation process is completed, that is, when the processing of step S200 is completed, the first relevance degree calculation unit 10 updates the field table stored in the field table storage unit 70 based on the first relevance degree between the non-malware type domain object and each of the multiple fields calculated for each of one or more non-malware type domain objects (step S210).
[0126] When the process of step S210 is completed, the information search device 100 ends the category table update process.
[0127] FIG. 10 is a flowchart of the first search process performed by the information search device 100.
[0128] As shown in FIG. 10, when the first search process is started, the information search device 100 performs a search result information calculation process (step S400).
[0129] FIG. 11 is a flowchart of the search result information calculation process performed by the information search device 100.
[0130] As shown in FIG. 11, when the search result calculation process is started, the related domain object calculation unit 30 creates an identifier list (hereinafter also referred to as the “second identifier list”) of one or more malware-type domain objects included in the threat information stored in the threat information collection server 200 (step S500).
[0131] After creating the second identifier list, the related domain object calculation unit 30 performs a related domain object calculation process (step S510).
[0132] FIG. 12 is a flowchart of the related domain object calculation process performed by the related domain object calculation unit 30.
[0133] 12, when the related domain object calculation process starts, the related domain object calculation unit 30 selects one unselected identifier from the second identifier list (step S600). Here, the unselected identifier refers to an identifier that has not yet been selected by the process of step S600 in the loop process formed by the processes of steps S600 to S620: Yes (described later) among the identifiers included in the second identifier list.
[0134] When an unselected identifier is selected, the related domain object calculation unit 30 calculates one or more related non-malware type domain objects that include type information indicating a type other than malware and are linked to the malware type domain object identified by the selected identifier using linking information 621 contained in one or more relationship objects 620 included in the threat information stored by the threat information collection server 200 (step S620).
[0135] After calculating one or more associated non-malware type domain objects, the associated domain object calculation unit 30 checks whether or not there is an unselected identifier among the identifiers included in the second identifier list (step S620).
[0136] In the process of step S620, if there is an unselected identifier (step S620: Yes), the related domain object calculation unit 30 performs the process of step S600 again.
[0137] In the process of step S620, if there is no unselected identifier (step S620: No), the related domain object calculation unit 30 ends the related domain object calculation process.
[0138] Returning to FIG. 11 again, the description of the search result information calculation process will be continued.
[0139] When the related domain object calculation process is completed, that is, when the process of step S510 is completed, the second degree-of-relationship calculation unit 20 performs a second degree-of-relationship calculation process (step S520).
[0140] FIG. 13 is a flowchart of the second degree-of-association calculation process performed by the second degree-of-association calculation unit 20.
[0141] 13, when the second degree-of-association calculation process is started, the second degree-of-association calculation unit 20 selects one unselected identifier from the second identifier list (step S700). Here, the unselected identifier refers to an identifier included in the second identifier list that has not yet been selected by the process of step S700 in the loop formed by the processes of steps S700 to S720: Yes (described later).
[0142] When an unselected identifier is selected, the second relevance degree calculation unit 20 calculates the average value of the first relevance degrees for each of one or more related non-malware type domain objects calculated by the search result information calculation process for the malware type domain object including the selected identifier as the second relevance degree between the malware type domain object and each of the multiple fields (step S710).
[0143] After calculating the second degree of association between the malware-type domain object and each of the multiple fields, the second degree of association calculation unit 20 checks whether there are any unselected identifiers among the identifiers included in the second identifier list (step S720).
[0144] In the process of step S720, if there is an unselected identifier (step S720: Yes), the second degree-of-relevance calculation unit 20 performs the process of step S700 again.
[0145] In the process of step S720, if there is no unselected identifier (step S720: No), the second degree-of-association calculation unit 20 ends the second degree-of-association calculation process.
[0146] Returning to FIG. 11 again, the description of the search result information calculation process will be continued.
[0147] When the second relevance degree calculation process is completed, that is, when the process of step S520 is completed, the information retrieval device 100 ends the search result information calculation process.
[0148] Returning to FIG. 10, the first search process will be described.
[0149] When the search result information calculation process is completed, that is, when the process of step S400 is completed, the calculation unit 60 calculates the number of matching names for each malware-type domain object (step S410).
[0150] After calculating the number of matching names for each malware-type domain object, the output unit 40 sorts the malware-type domain objects in descending order of the number of matching names (step S420).
[0151] After sorting the malware-type domain objects in descending order of the number of matching names, the output unit 40 checks whether or not a category has been selected using the category selection bar 91 (step S430).
[0152] In the processing of step S430, if a field is selected using the field selection bar 91 (step S430: Yes), the output unit 40 limits the malware-type domain objects to be output to malware-type domain objects whose second relevance degree with the selected field is greater than 0 (step S440).
[0153] After limiting the malware-type domain objects to be output, if there are any malware-type domain objects among the malware-type domain objects to be output that have the same second degree of relevance with the selected field, the output unit 40 sorts these malware-type domain objects in descending order of the amount of increase or decrease (step S450).
[0154] In the process of step S430, if no field is selected using the field selection bar 91 (step S430: No), or if the process of step S450 is completed, the information retrieval device 100 ends the first search process.
[0155] Second Embodiment Hereinafter, an information retrieval device according to a second embodiment will be described, which is configured by partially modifying the configuration of the information retrieval device 100 according to the first embodiment.
[0156] The information retrieval device according to the second embodiment performs a second retrieval process in place of the first retrieval process performed by the information retrieval device 100 according to the first embodiment.
[0157] <Configuration> FIG. 14 is a block diagram showing the configuration of an information retrieval device 100a according to the second embodiment.
[0158] As shown in FIG. 14, the information retrieval device 100a is configured by changing the calculation unit 60 of the information retrieval device 100 according to the first embodiment to a calculation unit 60a and changing the output unit 40 to an output unit 40a.
[0159] For each of one or more malware-type domain objects included in the threat information stored in the threat information collection server 200, the calculation unit 60a calculates the minimum value of the standardized Levenshtein distance between each of the one or more search queries and each of the names indicated by one or more name information 614 included in one or more domain objects 610 linked to the malware-type domain object using the linking information 621 included in one or more relationship objects 620 included in the threat information, and calculates an average distance which is the average value of the minimum values for each of the one or more names.
[0160] Here, the standardized Levenshtein distance between character string A and character string B is a value obtained by dividing the Levenshtein distance between character string A and character string B by the number of characters in either character string A or character string B, whichever is greater.
[0161] The output unit 40a outputs to the outside the second relevance degree calculated by the second relevance degree calculation unit 20 for at least one of one or more malware-type domain objects included in the threat information stored in the threat information collection server 200.
[0162] In this case, the output unit 40a sorts the one or more malware-type domain objects in order of shortest average distance calculated by the calculation unit 60a, and outputs the second degree of association based on the result of the sorting.
[0163] Here, as an example that is not necessarily limited to this, the output unit 40a is described as having a display, generating an image indicating a second degree of relevance for at least one of one or more malware-type domain objects included in the threat information stored by the threat information collection server 200, and outputting the second degree of relevance by displaying the generated image on the display.
[0164] FIG. 15 is a schematic diagram showing an example of an image generated by the output unit 40a.
[0165] As shown in FIG. 15, the image output by the output unit 40 a includes a category selection bar 91 , a search query list 92 , a search result display area 93 a , and a details display area 94 .
[0166] The search result display area 93a is an area that displays the second relevance degree with each of multiple fields for each of one or more malware-type domain objects to be displayed, arranged from top to bottom in order of shortest average distance.
[0167] Here, the one or more malware-type domain objects to be displayed are malware-type domain objects whose second relevance to the field selected by the field selection bar 91 is greater than zero.
[0168] In each row of the search result display area 93a, for one malware-type domain object, (1) the malware name indicated by the name information 614 included in the malware-type domain object, (2) the average distance, (3) the distance of each type (here, the domain name (test.com) and the file name (collect_log.exe)) that matches the type of the search query, (4) the field indicated by the label information 615 included in the malware-type domain object, and (5) the second relevance degree with each of the multiple fields and the increase / decrease amount of the second relevance degree are displayed in correspondence with each other.
[0169] <Operation> The information retrieval device 100a configured as described above performs a second search process instead of the first search process performed by the information retrieval device 100 according to the first embodiment.
[0170] 16A and 16B are flowcharts of the second search process performed by the information search device 100a.
[0171] In the second search process shown in Figures 16A and 16B, the processes of steps S830 to S850 are the same as the processes of steps S430 to S450 in the first search process, respectively, with output unit 40 replaced by output unit 40a.
[0172] Therefore, since the processes of steps S830 to S850 have already been explained, the explanation will be omitted here, and the explanation will focus on the processes of steps S800 to S810.
[0173] As shown in Figures 16A and 16B, when the second search process is started, the related domain object calculation unit 30 creates an identifier list (hereinafter also referred to as the "third identifier list") of one or more malware-type domain objects included in the threat information stored in the threat information collection server 200 (step S800).
[0174] After the third identifier list is created, the calculation unit 60a selects one unselected identifier from the third identifier list (step S801). Here, the unselected identifier refers to an identifier included in the third identifier list that has not yet been selected by the processing of step S801 in the loop processing formed by the processing of step S801 to the processing of step S808: Yes (described later).
[0175] When an unselected identifier is selected, the calculation unit 60a calculates one or more associated non-malware type domain objects that are linked to the malware type domain object identified by the selected identifier and that include type information indicating a type other than malware, and creates a set of associated non-malware type domain objects that include type information indicating the type for each of the multiple types (step S802).
[0176] After generating the sets for each of the multiple types, the calculation unit 60a selects one unselected search query from the one or more search queries acquired by the query acquisition unit 50 (step S803). Here, the unselected search query refers to a search query that has not yet been selected by the processing of step S803 in the loop processing formed by the processing of step S803 to the processing of step S806: Yes (described later) among the one or more search queries acquired by the query acquisition unit 50.
[0177] When an unselected search query is selected, the calculation unit 60a selects a set of related non-malware domain objects whose type matches the type of the selected search query, and calculates the standardized Levenshtein distance between each of the names indicated by the name information 614 included in the selected set and the selected search query (step S804).
[0178] After calculating the standardized Levenshtein distance between each of the names and the selected search query, the calculation unit 60a calculates the minimum of these standardized Levenshtein distances as the distance of the selected search query type (step S805).
[0179] After calculating the distance of the selected search query type, the calculation unit 60a checks whether or not there is an unselected search query among the one or more search queries (step S806).
[0180] In the process of step S806, if there is an unselected search query (step S806: Yes), the calculation unit 60a performs the process of step S804 again.
[0181] In the processing of step S806, if there are no unselected search queries (step S806: No), the calculation unit 60a calculates the average value of one or more distances calculated for each of the one or more search queries as the average distance between the one or more search queries and the malware-type domain object identified by the selected identifier (step S807).
[0182] After calculating the average distance between one or more search queries and the malware-type domain object identified by the selected identifier, the calculation unit 60a checks whether there are any unselected identifiers in the third identifier list (step S808).
[0183] In the process of step S808, if there is an unselected identifier (step S808: Yes), the calculation unit 60a performs the process of step S801 again.
[0184] In the process of step S808, if there are no unselected identifiers (step S808: No), the information retrieval device 100a performs a search result information calculation process (step S809).
[0185] When the search result calculation process is completed, the output unit 40a sorts the malware-type domain objects in order of shortest average distance (step S810).
[0186] When the process of step S810 is completed, the process proceeds to step S830.
[0187] In the process of step S830, if no field is selected using the field selection bar 91 (step S830: No), or if the process of step S850 is completed, the information retrieval device 100a terminates the second search process.
[0188] (Supplementary Note) As described above, the first and second embodiments have been described as examples of the technology disclosed in this application. However, the present disclosure is not limited to these embodiments. As long as they do not deviate from the spirit of the present disclosure, various modifications that would occur to a person skilled in the art to the present embodiments, or forms constructed by combining components of different embodiments or modifications, may also be included within the scope of one or more aspects of the present disclosure.
[0189] A comprehensive or specific aspect of the present disclosure may be realized as a system, an apparatus, a method, an integrated circuit, a program, or a non-transitory recording medium such as a computer-readable CD-ROM. It may also be realized as any combination of a system, an apparatus, a method, an integrated circuit, a program, and a non-transitory recording medium. For example, the present disclosure may be realized as a program that causes a computer device to execute the processing performed by the information search device 100.
[0190] The present disclosure is widely applicable to systems for searching information about cyber attacks, etc.
[0191] REFERENCE SIGNS LIST 1 Information retrieval system 10 First relevance degree calculation unit 20 Second relevance degree calculation unit 30 Relevant domain object calculation unit 40, 40a Output unit 50 Query acquisition unit 60, 60a Calculation unit 70 Category table storage unit 80 Communication unit 91 Category selection bar 92 Search query list 93, 93a Search result display area 94 Detailed display area 100, 100a Information retrieval device 200 Threat information collection server 300 Threat information distribution server 400 Network 500 Security analyst 610, 610a, 610b, 610c Domain object 611, 611a, 611b, 611c, 611d, 611e Type information 612, 612a, 612b, 612c, 612d, 612e Identification information 613, 613a, 613d, 613e Update information 614, 614a, 614b, 614c Name information 615, 615a, 615b, 615c Label information 620, 620a, 620b Relationship objects 621, 621a, 621b Linking information
Claims
1. An information retrieval method for retrieving information about a cyber-attack from a database including a plurality of domain objects and a plurality of relationship objects, comprising: each of the plurality of domain objects includes type information indicating a type of the domain object; At least one of the plurality of domain objects further includes label information associated with the type information and indicating a field related to the domain object; each of the plurality of relationship objects includes linking information linking one domain object among the plurality of domain objects with another domain object; each of the type information indicates one of a plurality of types including a type indicating malware; Each of the label information is information indicating one or more of a plurality of fields, a first association degree calculation step of calculating, for each of one or more non-malware type domain objects among the plurality of domain objects including type information indicating a type other than malware, a first association degree between the non-malware type domain object and each of the plurality of fields based on one or more fields indicated by one or more label information included in one or more domain objects associated with the non-malware type domain object by association information included in one or more relationship objects among the plurality of relationship objects; an associated domain object calculation step of calculating, for each of one or more malware type domain objects including type information indicating malware among the plurality of domain objects, one or more associated non-malware type domain objects including type information indicating a type other than malware, which are associated with the malware type domain object by linking information included in one or more relationship objects among the plurality of relationship objects; a second relevance degree calculation step of calculating, for each of the one or more malware-type domain objects, a second relevance degree between the malware-type domain object and each of the plurality of fields based on the first relevance degree for each of the one or more associated non-malware-type domain objects calculated in the associated domain object calculation step; an output step of outputting the second degree of relevance calculated in the second degree of relevance calculation step to an external device for at least one of the one or more malware-type domain objects. Information search methods.
2. The plurality of fields include at least two of a home field indicating a field related to a home, a mobility field indicating a field related to a moving body, a factory field indicating a field related to a factory, an infrastructure field indicating a field related to an infrastructure, and a building field indicating a field related to a building.
2. The information retrieval method according to claim 1.
3. Each of the plurality of domain objects further includes name information that indicates a name of the domain object and is associated with the type information included in the domain object; moreover, a query acquisition step of acquiring one or more search queries; a calculation step of calculating, for each of the one or more malware-type domain objects, the number of one or more names that match the one or more search queries from one or more names indicated by one or more pieces of name information included in one or more domain objects linked to the malware-type domain object, based on linking information included in one or more relationship objects among the plurality of relationship objects; In the output step, the one or more malware-type domain objects are sorted in descending order of the number of matching names, and the second degree of association is output based on the result of the sorting.
3. The information retrieval method according to claim 1.
4. Each of the plurality of domain objects further includes name information that indicates a name of the domain object and is associated with the type information included in the domain object; moreover, a query acquisition step of acquiring one or more search queries; a calculation step of calculating, for each of the one or more malware-type domain objects, a minimum value of standardized Levenshtein distances between each of the one or more search queries and one or more names indicated by one or more name information included in one or more domain objects linked to the malware-type domain object using linking information included in one or more relationship objects among the plurality of relationship objects, and calculating an average distance which is an average value of the minimum values for each of the one or more names, In the output step, the one or more malware-type domain objects are sorted in order of shortest average distance, and the second degree of association is output based on the result of the sorting.
3. The information retrieval method according to claim 1.
5. In the second degree of association calculation step, an average value of the first degrees of association for each of the one or more associated non-malware-type domain objects is calculated as the second degree of association.
3. The information retrieval method according to claim 1.
6. An information retrieval device that retrieves information about a cyber-attack from a database including a plurality of domain objects and a plurality of relationship objects, each of the plurality of domain objects includes type information indicating a type of the domain object; At least one of the plurality of domain objects further includes label information associated with the type information and indicating a field related to the domain object; each of the plurality of relationship objects includes linking information linking one domain object among the plurality of domain objects with another domain object; each of the type information indicates one of a plurality of types including a type indicating malware; Each of the label information is information indicating one or more of a plurality of fields, a first degree-of-relationship calculation unit that calculates, for each of one or more non-malware type domain objects among the plurality of domain objects that include type information indicating a type other than malware, a first degree of relevance between the non-malware type domain object and each of the plurality of fields based on one or more fields indicated by one or more pieces of label information included in one or more domain objects linked to the non-malware type domain object using linking information included in one or more relationship objects among the plurality of relationship objects; an associated domain object calculation unit that calculates, for each of one or more malware type domain objects including type information indicating malware among the plurality of domain objects, one or more associated non-malware type domain objects including type information indicating a type other than malware, linked to the malware type domain object by linking information included in one or more relationship objects among the plurality of relationship objects; a second relevance degree calculation unit that calculates, for each of the one or more malware-type domain objects, a second relevance degree between the malware-type domain object and each of the plurality of fields based on the first relevance degree for each of the one or more associated non-malware-type domain objects calculated by the associated domain object calculation unit; an output unit that outputs the second degree of association calculated by the second degree of association calculation unit to an outside for at least one of the one or more malware-type domain objects. Information retrieval device.
7. A program for causing a computer to execute a process of searching for information about a cyber-attack from a database including a plurality of domain objects and a plurality of relationship objects, each of the plurality of domain objects includes type information indicating a type of the domain object; At least one of the plurality of domain objects further includes label information associated with the type information and indicating a field related to the domain object; each of the plurality of relationship objects includes linking information linking one domain object among the plurality of domain objects with another domain object; each of the type information indicates one of a plurality of types including a type indicating malware; Each of the label information is information indicating one or more of a plurality of fields, The process comprises: a first association degree calculation step of calculating, for each of one or more non-malware type domain objects among the plurality of domain objects including type information indicating a type other than malware, a first association degree between the non-malware type domain object and each of the plurality of fields based on one or more fields indicated by one or more label information included in one or more domain objects associated with the non-malware type domain object by association information included in one or more relationship objects among the plurality of relationship objects; an associated domain object calculation step of calculating, for each of one or more malware type domain objects including type information indicating malware among the plurality of domain objects, one or more associated non-malware type domain objects including type information indicating a type other than malware, which are associated with the malware type domain object by linking information included in one or more relationship objects among the plurality of relationship objects; a second relevance degree calculation step of calculating, for each of the one or more malware-type domain objects, a second relevance degree between the malware-type domain object and each of the plurality of fields based on the first relevance degree for each of the one or more associated non-malware-type domain objects calculated in the associated domain object calculation step; an output step of outputting the second degree of relevance calculated in the second degree of relevance calculation step to an external device for at least one of the one or more malware-type domain objects. program.