Analysis device, status reference device, and analysis method, reference method, analysis program, reference program and security risk judgment system executed by these devices

TWI934812BActive Publication Date: 2026-08-01INTERNET INITIATIVE JAPAN INC
View PDF 6 Cites 0 Cited by

Patent Information

Authority / Receiving Office
TW · TW
Patent Type
Patents
Current Assignee / Owner
INTERNET INITIATIVE JAPAN INC
Filing Date
2025-10-20
Publication Date
2026-08-01

Smart Images

  • Figure TWG2TB001904157_001
    Figure TWG2TB001904157_001
  • Figure TWG2TB001904157_002
    Figure TWG2TB001904157_002
  • Figure TWG2TB001904157_003
    Figure TWG2TB001904157_003
Patent Text Reader

Abstract

This invention discloses an analysis apparatus comprising: an analysis object acquisition unit that acquires the website URL of the analysis object website; an analysis execution unit that analyzes one or more pages within the website published by the website URL, extracting cookies issued by one or more pages, set web storage, or external communication URLs of external communications occurring; and an analysis item registration unit that maps the website URL to cookies, web storage, or external communication URLs issued by pages within the website, and registers them in a manner obtainable by a service identification device as described later. This allows for the extraction of cookies issued by one or more pages within the website published by the website URL, set web storage, or external communication URLs of external communications occurring, and registration in a manner obtainable by a service identification device for each website.
Need to check novelty before this filing date? Find Prior Art

Claims

1. An analysis apparatus comprising: an analysis target acquisition unit that acquires a website URL of an analysis target website; an analysis execution unit that analyzes one or more pages within the website published by the website URL; and an analysis item registration unit that associates the website URL with a cookie, web storage, or an external communication URL issued by a page within the website, and registers the URL in a manner obtainable via a service identification device; wherein... The analysis execution unit comprises: a website access unit that uses a virtual browser to specify the website URL, sends a request to a proxy device, and receives a response from the proxy device; and a status extraction unit that extracts security risks from the response; wherein the proxy device comprises: a request determination unit that receives the request sent from the virtual browser and determines the security risk of the request URL specified in the request; a request forwarding unit that forwards the request, which has been determined by the request determination unit to be normal, to the server operating the target website of the analysis, wherein the target website of the analysis is the target website for which the services used by the target website of the analysis are identified; a response analysis unit that receives and analyzes the response from the server; and a response feedback unit that sends the response back to the virtual browser.

2. The analytical apparatus as described in claim 1, wherein, The response analysis department determines the security risk from the response sent from the server, and the response feedback department sends the response that has been determined by the response analysis department to have no security risk back to the virtual browser.

3. The analysis apparatus as described in claim 1 further includes a request blocking unit that blocks the request when the request determination unit has determined that the request URL is abnormal.

4. The analytical apparatus as described in claim 3, wherein, When the request blocking unit determines that the request URL is abnormal, it generates a new response indicating that the request URL has a security risk and sends it back to the virtual browser.

5. The analysis apparatus as described in claim 2, further comprising a response blocking unit that blocks the transmission of the response when the response analysis unit has determined that the response contains a security risk.

6. The analytical apparatus as described in claim 5, wherein, The response blocking unit further generates a new response indicating that the page contained in the response has a security risk when the response analysis unit has determined that the response has a security risk, and sends it back to the virtual browser.

7. The analytical apparatus as described in claim 1, wherein, If the status code of the response sent from the server is not 200, the response analysis department determines that the page contained in the response is an unreferenceable page.

8. The analytical apparatus as described in claim 1, wherein, The virtual browser is launched to send the request to the server operating the website being analyzed in order to specify the website URL of the website being analyzed, and to receive the response from the server.

9. The analytical apparatus as described in claim 1, wherein, The analysis execution unit further includes a link extraction unit that extracts the page URL of the linked page from the response. The website access unit further specifies the page URL of the linked page, sends a request to the proxy device, and receives a response from the proxy device.

10. The analysis apparatus as described in claim 1, further comprising a status registration unit that maps the page URLs of one or more pages to the status codes of the responses to the requests for which the page URLs have been specified and to the security risks, and registers them in a status database.

11. A status reference device comprising: a status acquisition unit that acquires from a status database logged by the analysis device as described in claim 10 the page URLs of one or more pages, the status code of the response to the request for which the page URLs are specified, and the security risk; and a status output unit that outputs the page URLs of one or more pages, the status code of the response to the request for which the page URLs are specified, and the security risk to a user terminal.

12. An analysis method, performed by a computer, comprising the following stages: obtaining the website URL of a target website; and analyzing one or more pages within the website containing the URL; wherein, The analysis phase includes the following stages: using a virtual browser to specify the website URL, sending a request to a proxy device on a computer equipped with a security risk assessment method, and receiving a response from the proxy device; and extracting security risks from the response; wherein the security risk assessment method includes the following stages: receiving the request sent from the virtual browser and determining the security risk of the request URL specified in the request; forwarding the request, which has been determined to be normal by the assessment stage, to a server operating the target website, wherein the target website is the object website whose services are identified; receiving and analyzing the response from the server; and sending the response back to the virtual browser.

13. The analysis method as described in claim 12 further comprises the following stage: mapping the page URLs of one or more pages to the status codes and security risks of the responses to the request for the specified page URLs and logging them into a status database.

14. A reference method performed by a computer, the reference method comprising the following stages: obtaining from a status database logged by the analysis method described in claim 13 the page URLs of one or more pages, the status codes of the responses to the requests specifying the page URLs, and the security risks; and outputting the page URLs of one or more pages, the status codes of the responses to the requests specifying the page URLs, and the security risks to a user terminal.

15. An analysis program that causes a computer to execute the following procedures: obtaining the website URL of a target website; and analyzing one or more pages within the website published by the website URL; wherein, The analysis program causes the computer to perform the following procedures: using a virtual browser to specify the website URL, sending a request to an agent device of a computer equipped with a security risk assessment program, and receiving a response from the agent device; and extracting security risks from the response; the security risk assessment program causes the computer to perform the following procedures: receiving the request sent from the virtual browser and determining the security risk of the request URL specified in the request; forwarding the request, which has been determined by the assessment program to be normal, to a server operating the target website of the analysis, wherein the target website of the analysis is the target website that is identified as using the services of the target website of the analysis; receiving and analyzing the response from the server; and sending the response back to the virtual browser.

16. The analysis program of request item 15 further causes the computer to perform the following procedure: mapping the page URLs of one or more pages to the status codes of the responses to the request for the specified page URLs and the security risks, and logging them into a status database.

17. A reference program that causes a computer to perform the following procedure: obtaining the page URLs of one or more pages and the status codes and security risks of the responses to the requests for specified page URLs from the status database accessed by executing the analysis program as described in claim 16; and outputting the page URLs of one or more pages and the status codes and security risks of the responses to the requests for specified page URLs to a user terminal.

18. A security risk assessment system comprising: an analysis device as described in claim 1; a reference device as described in claim 11; and a status database containing data that maps page URLs of one or more pages to status codes and security risks in response to requests specifying those page URLs.