Threat intelligence generation device and threat intelligence generation method

The threat intelligence generation device integrates and analyzes information from multiple organizations to generate actionable intelligence, addressing the limitations of current methods by enhancing information sharing and analysis for effective cyber threat response.

WO2025203830A1PCT designated stage Publication Date: 2025-10-02HITACHI LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/JP2024/039608
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-03-28
Filing Date
2024-11-07
Publication Date
2025-10-02

AI Technical Summary

Technical Problem

Current methods for generating and sharing threat intelligence are hindered by the lack of integration of information across multiple organizations, sensitivity of shared information, and inadequate analysis methods, leading to ineffective prediction of cyberattack patterns.

Method used

A threat intelligence generation device that collects and integrates incident-related information from multiple organizations, identifies victim users and devices, compares and filters common points to generate actionable intelligence while preventing information leaks.

Benefits of technology

Enables the generation and sharing of comprehensive threat intelligence by integrating information from diverse sources while ensuring confidentiality, facilitating effective response to cyber threats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2024039608_02102025_PF_FP_ABST
    Figure JP2024039608_02102025_PF_FP_ABST
Patent Text Reader

Abstract

This threat intelligence generation device identifies an affected user and / or affected equipment of an incident that occurred in a first organization provided with the threat intelligence generation device, collects first incident-related information about the affected user and / or affected equipment that has been identified, collects second incident-related information about an affected user and / or affected equipment of an incident which occurred in a second organization different from the first organization and which is the same as the incident that occurred in the first organization, checks the first incident-related information and the second incident-related information against each other to extract commonalities, excludes information having a low probability of being the threat intelligence from among the commonalities, and presents the commonalities that were not excluded.
Need to check novelty before this filing date? Find Prior Art

Description

Threat intelligence generation device and threat intelligence generation method Incorporation by Reference

[0001] This application claims priority from Japanese Patent Application No. 2024-54144, filed on March 28, 2024, the contents of which are incorporated herein by reference.

[0002] The present invention relates to a threat intelligence generation device and a threat intelligence generation method.

[0003] In recent years, cyber attacks against various organizations, including government agencies, companies, research institutes, and schools, have become more frequent, and each organization is increasingly aware of the importance of cybersecurity and is therefore required to take measures. However, cyber attacks are becoming more sophisticated and complex, and in order to take measures, more advanced and continuous information gathering is required.

[0004] Information about cyber attacks includes the attacker's objectives, methods, and targets, and is collectively referred to as threat intelligence.

[0005] Currently, there are several challenges to generating and utilizing threat intelligence to deal with cyberattacks. Specifically, information sharing regarding cyberattacks is personal and unsystematic, resulting in a lack of cooperation between different organizations. Another challenge to information sharing is the existence of sensitive information. Much of the information held by organizations is highly confidential, making it difficult to share with other organizations. This is one of the factors that limits the generation of effective threat intelligence and the prediction of attack patterns.

[0006] Another issue is the lack of an established method for analyzing cyber-attack-related information with high accuracy and generating threat intelligence. The motives, objectives, and methods used by cyber attackers change daily, and responding to this requires immediate and accurate information collection and analysis, but there is a lack of appropriate methods and tools for this.

[0007] Regarding threat intelligence against cyber threats, for example, Patent Document 1 (JP 2019-40533 A) describes an information processing device having: "a registration unit that, when a first system receives information related to a cyber attack from a first user terminal, stores the information in a storage device in a state accessible from a second user terminal that can access the first system, converts the data structure of the information into a state usable in a second system different from the first system, and stores the information in the storage device accessible from the second system, or stores the information in the second system; and an output unit that, when other information related to a cyber attack is added to the second system, converts the other information received by the first system from the second system or the storage device into a state accessible from the second user terminal and outputs the converted information."

[0008] According to the technology described in Patent Literature 1, information can be collected from various information sources, aggregated, and accumulated to generate threat intelligence that can be accessed from other systems. In addition, the shared threat intelligence includes information indicating the access range, such as TLP (Traffic Light Protocol), making it possible to control the access range.

[0009] However, the technology described in Patent Literature 1 cannot integrate information held by multiple organizations to generate new threat intelligence. Furthermore, shared sensitive information is controlled by TLP or the like, and while this method can control access to common information, it cannot integrate and analyze sensitive information held by each organization.

[0010] The present invention has been made in consideration of the above points, and aims to enable the generation and sharing of threat intelligence by integrating information obtained from multiple different organizations while preventing information leaks.

[0011] The present application includes a number of means for solving at least some of the above-mentioned problems, examples of which are as follows.

[0012] In order to solve the above-mentioned problems, one embodiment of the threat intelligence generation device of the present invention is a threat intelligence generation device that generates threat intelligence related to incidents caused by cyber attacks, and is equipped with one or more computing devices, one or more memory resources, and one or more storage devices, and is characterized in that the computing device identifies at least one of the victim users and victim devices of the incident that occurred in a first organization where the threat intelligence generation device is located, collects first incident-related information related to the identified victim users and at least one of the victim devices, collects second incident-related information related to at least one of the victim users and victim devices of an incident that occurred in a second organization different from the first organization and is the same as the incident that occurred in the first organization, compares the first incident-related information with the second incident-related information to extract common points, excludes information from the extracted common points that is unlikely to be the threat intelligence, and presents the common points that were not excluded.

[0013] According to the present invention, it is possible to generate and share threat intelligence by integrating information obtained from multiple different organizations while preventing information leaks.

[0014] Problems, configurations, and effects other than those described above will become apparent from the following description of the embodiments.

[0015] FIG. 1 is a diagram illustrating an example of the configuration of a threat intelligence generation support system according to an embodiment of the present invention. FIG. 2 is a diagram illustrating an example of the configuration of a general computer. FIG. 3 is a diagram illustrating an example of the data structure of a user data table. FIG. 4 is a diagram illustrating an example of the data structure of a device data table. FIG. 5 is a diagram illustrating an example of the data structure of a history data table. FIG. 6 is a diagram illustrating an example of the data structure of an attribute list table. FIG. 7 is a diagram illustrating an example of the data structure of a configuration information table. FIG. 8 is a diagram illustrating an example of the data structure of a whitelist table. FIG. 9 is a diagram illustrating an example of the data structure of an attack group profile table. FIG. 10 is a flowchart illustrating an example of a threat intelligence generation process. FIG. 11 is a diagram illustrating an example of a display of an intelligence generation operation screen as a UI (User Interface) screen. FIG. 12 is a diagram illustrating an example of a display of a time-series event drawing screen as a UI screen.

[0016] An embodiment of the present invention will be described below with reference to the drawings. In all drawings illustrating an embodiment, identical components are generally designated by the same reference numerals, and repeated description thereof will be omitted. In the following embodiments, components (including element steps, etc.) are not necessarily essential unless otherwise specified, or when they are clearly considered essential in principle. Furthermore, when the terms "consisting of A," "composed of A," "having A," or "including A" are used, other elements are not excluded unless otherwise specified, or when it is clearly considered that only that element is included. Similarly, in the following embodiments, when referring to the shape, positional relationship, etc. of components, etc., these terms include those that are substantially similar or similar to the shape, etc., unless otherwise specified, or when they are clearly considered otherwise in principle.

[0017] <Configuration Example of Threat Intelligence Generation Support System 100> FIG. 1 shows a configuration example of a threat intelligence generation support system 100 according to an embodiment of the present invention.

[0018] The threat intelligence generation support system 100 collects information related to cyberattacks from various organizations, such as government agencies, companies, research institutes, and schools, and generates and shares new threat intelligence related to the cyberattacks from commonalities among the information. By sharing threat intelligence, each organization can identify the attacking group behind incidents caused by cyberattacks and respond appropriately to the incidents.

[0019] The threat intelligence generation support system 100 has a threat intelligence generation device 120 provided in an information using organization 101, and information providing devices 140 provided in each of multiple information providing organizations 102. The threat intelligence generation device 120 and the multiple information providing devices 140 are connected via a network (not shown) such as the Internet.

[0020] The threat intelligence generation device 120 of the information using organization 101 collects incident-related information about users and devices that have been affected by incidents caused by cyber attacks that have occurred within the information using organization 101, and also collects incident-related information about users and devices that have been affected by incidents that have occurred at the information providing organization 102 where the same incident as the incident in question has occurred, integrates this information, and generates threat intelligence about the incident in question.

[0021] The threat intelligence generation device 120 has the following functional blocks: an input unit 121, a victim user / device identification unit 122, an information collection unit 123, an information analysis unit 124, a filtering unit 125, and an output unit 126. The threat intelligence generation device 120 also has the following tables: a user data table 112, a device data table 113, a history data table 114, an attribute list table 115, a configuration information table 116, a whitelist table 117, and an attack group profile table 118.

[0022] The threat intelligence generation device 120 is realized by a general computer such as a personal computer or a server computer, for example.

[0023] 2 shows an example of the configuration of a general computer 150 that constitutes the threat intelligence generation device 120. The computer 150 has an arithmetic unit 151, a storage unit 152, an auxiliary storage unit 153, an input unit 154, an output unit 155, and a communication unit 156.

[0024] The arithmetic unit 151 is made up of a processor such as a CPU (Central Processing Unit). The storage device 152 is made up of memory resources such as a DRAM (Dynamic Random Access Memory). The auxiliary storage device 153 is made up of storage such as a HDD (Hard Disk Drive) or an SSD (Solid State Drive). The input device 154 is made up of a keyboard, mouse, media drive, etc. The output device 155 is made up of a display, speakers, etc. The communication device 156 is made up of an Ethernet card, Wi-Fi adapter, etc.

[0025] The computer 150 serving as the threat intelligence generation device 120 realizes the functional blocks of an input unit 121, a victim user / device identification unit 122, an information collection unit 123, an information analysis unit 124, a filtering unit 125, and an output unit 126 by the calculation unit 151 executing a predetermined program stored in the memory device 152.

[0026] The program executed by the arithmetic unit 151 may be stored in advance in the storage unit 152, or may be downloaded from a predetermined server or the like via a removable medium (CD-ROM, flash memory, etc.) or a network such as the Internet, stored in the auxiliary storage unit 153, which is a non-transitory storage medium, and read out from the auxiliary storage unit 153 to the storage unit 152 when needed. For this reason, it is desirable that the computer 150 has an interface for reading data from removable media.

[0027] Furthermore, the threat intelligence generation device 120 may be realized by one physical or logical computer, or by two or more physical or logical computers, which may be distributed over a network.

[0028] Returning to Fig. 1, the input unit 121 accepts various operations and inputs from a security operator or the like. For example, the input unit 121 accepts incident designation information (e.g., a hash value of malware) that is input by the security operator or the like using a UI screen and that is used to designate an incident for which threat intelligence is to be generated. Note that the incident designation information may be manually input by the security operator or the like, or may be automated by some method.

[0029] The victim user / device identification unit 122 identifies users and devices that have been victimized by an incident that has occurred in the information using organization 101 and is specified by the incident specification information.

[0030] The information collection unit 123 collects incident-related information (corresponding to the first incident-related information of the present invention) related to the victim user / device identified by the victim user / device identification unit 122. The information collection unit 123 also transmits an information use request including incident designation information to the information providing device 140 of each information providing organization 102.

[0031] The information analysis unit 124 acquires incident-related information (corresponding to the second incident-related information of the present invention) about victim users and devices at each information providing organization 102, collected by the information providing device 140 of each information providing organization 102. The information analysis unit 124 also compares the incident-related information collected within the information using organization 101 with the incident-related information about victim users and devices acquired from each information providing organization 102 (corresponding to the second incident-related information of the present invention), and extracts commonalities.

[0032] The filtering unit 125 excludes common points of the incident-related information extracted by the information analysis unit 124 that are unlikely to be threat intelligence, and outputs to the output unit 126 those that are likely to be threat intelligence.

[0033] In response to a predetermined operation by a security operator or the like, the output unit 126 generates an intelligence generation operation screen 1001 (FIG. 11) or a time-series event drawing screen 1101 (FIG. 12) as a UI screen and displays them on the output device 155.

[0034] The user data table 112 , the device data table 113 , the history data table 114 , the attribute list table 115 , the configuration information table 116 , the whitelist table 117 , and the attack group profile table 118 are stored in the auxiliary storage device 153 of the computer 150 .

[0035] The user data table 112 is a table that stores data relating to users such as employees who belong to the information using organization 101 .

[0036] 3 shows an example of the data structure of the user data table 112. The user data table 112 has fields 201 to 204 for storing information indicating job type, job position, and organization in association with a user ID.

[0037] Field 201 stores a user ID, which is an identifier for uniquely identifying a user. Field 202 stores information indicating the user's occupation. Field 203 stores information indicating the user's position. Field 204 stores information indicating the organization to which the user belongs.

[0038] By recording the job type, job position, and industry in the user data table 112, if an attack group targets a specific job type, job position, or industry, it is possible to generate threat intelligence that indicates which job type, job position, or industry the incident is targeting by matching the job types, job positions, and industries of victim users in each organization. Note that if there is any attribute information targeted by the attack group other than the job type, job position, and industry, this information may be added to the user data table 112.

[0039] Returning to Fig. 1, the equipment data table 113 is a table that stores data on equipment, such as computers used in the information using organization 101, that may be subject to incident damage.

[0040] 4 shows an example of the data structure of the device data table 113. The device data table 113 has fields 301 to 302 for storing information indicating the type and OS (Operating System) in association with the device ID.

[0041] Field 301 stores a device ID, which is an identifier that uniquely identifies a device. Field 302 stores information that indicates the type of device. Field 303 stores information that indicates the OS of the device. Note that if there is attribute information of the device targeted by the attack group, such as the OS version or the model lot number in addition to the model and OS, this information may be added to the device data table 113.

[0042] Returning to Fig. 1, the history data table 114 is a table in which information relating to users belonging to the information using organization 101 and events occurring in devices owned by the information using organization 101 is stored in chronological order.

[0043] 5 shows an example of the data structure of the history data table 114. The history data table 114 has fields 401 to 407 for storing information representing a timestamp, a user ID, a device ID, importance, a type, and a type value in association with an event ID.

[0044] Field 401 stores an event ID, which is an identifier that uniquely identifies the event that has occurred. Field 402 stores a timestamp that indicates the time when the event occurred to a user or device. Field 403 stores the user ID of the user who caused the event to occur or the user who uses the device on which the event occurred. Field 404 stores the device ID 301 of the device on which the event occurred. Note that if the event that has occurred is related only to the user and not to the device, field 404 may be left blank.

[0045] Information indicating the importance of an event is stored in field 405. For example, if a security appliance determines that an event occurred when a device accessed a website and issues an alert because the security appliance judges the access to be suspicious, the importance of the event may be increased.

[0046] Field 406 stores information indicating the type of event that has occurred. It is desirable to collect a variety of events, including those that at first glance do not seem to be related to user or device incidents. By comparing various pieces of information, commonalities among incidents that have occurred in each organization can be calculated. Field 407 stores the value of the type of event stored in field 406.

[0047] Events may be collected from application programs used by users, such as browsers, schedulers, mailers, etc. For example, email texts may be matched using PSI (private set intersection) encryption so that the email texts can be matched in an encrypted state.

[0048] Returning to Figure 1, the attribute list table 115 is a table that stores the types of attributes to be matched to generate threat intelligence, the matching method for each attribute, and the like.

[0049] 6 shows an example of the data structure of the attribute list table 115. The attribute list table 115 has fields 501 to 505 for storing attribute items, confidentiality (or sensitivity), matching methods, and time windows in association with attribute IDs.

[0050] Field 501 stores an attribute ID for uniquely identifying each attribute. Field 502 stores attribute items to be matched. Field 503 stores information indicating whether each attribute is confidential. Information on highly confidential attributes is matched in a PSI-encrypted state to prevent leaks to other organizations. Field 504 stores the attribute matching method. Possible matching methods include exact matches and partial matches, such as extracting topics from the body of an email and calculating exact or partial matches for those topics. Topics may be extracted using a keyword dictionary prepared in advance or natural language processing. Field 505 stores the time window within which a match is determined. Even if attribute values ​​are the same, if events with those attribute values ​​occurred at different dates and times, the two events are considered to be related to different incidents. For this reason, attributes are matched within the time window. Therefore, the time window stored in field 505 is used for processing, such as excluding events that did not occur within the time window by the filtering unit 125.

[0051] Returning to Fig. 1, the configuration information table 116 is a table in which configuration information of the network devices and the like owned by the information using organization 101 is stored.

[0052] 7 shows an example of the data structure of the configuration information table 116. The configuration information table 116 has fields 601 to 605 for storing IP addresses, host names, categories, and device names in association with device IDs.

[0053] Field 601 stores a device ID for uniquely identifying a device that constitutes the IT (Information Technology) environment of each organization. Field 602 stores the IP (Internet Protocol) address of the device. Field 603 stores the host name of the device. Field 604 stores the category of the device. Field 605 stores the device name of the device. The device name is used to abstract the device identified by the IP address.

[0054] Returning to Figure 1, the whitelist table 117 is a table that stores information that has been determined in advance to have a low probability of becoming threat intelligence. The whitelist table 117 is used by the filtering unit 125.

[0055] 7 shows an example of the data structure of the whitelist table 117. The whitelist table 117 has fields 701 to 703 for storing items and values ​​of the items in association with the information ID of information that has been determined in advance to have a low probability of becoming threat intelligence.

[0056] Field 701 stores an information ID for uniquely identifying information that has been determined in advance to have a low probability of becoming threat intelligence. Field 702 stores an item of data to be excluded. Field 703 stores a value of the data to be excluded.

[0057] Returning to Figure 1, the attack group profile table 118 is generated in advance for each attack group based on publicly known information, and stores the characteristics of each attack group.

[0058] FIG. 9 shows an example of the data structure of the attack group profile table 118.

[0059] The attack group profile table 118 has fields 801 to 803 for storing items and their values ​​in association with item IDs. Field 801 stores an item ID for uniquely identifying an item that characterizes an attack group. Field 802 stores an item that characterizes an attack group. Field 803 stores the value of each item.

[0060] Returning to Figure 1, in response to an information use request sent from the threat intelligence generation device 120, if an incident damage corresponding to the incident designation information included in the information use request has occurred, the information providing device 140 of the information providing organization 102 provides the threat intelligence generation device 120 with incident-related information related to each user and each device that has suffered the incident damage.

[0061] Like the threat intelligence generation device 120, the information providing device 140 is realized by a general computer 150 (Figure 2), and the computing device 151 of the computer 150 executes a predetermined program stored in the memory device 152 to realize the functional blocks of the input unit 131, the victim user / device identification unit 132, and the information collection unit 133.

[0062] The input unit 131 accepts an information utilization request from the threat intelligence generation device 120 and outputs incident specification information (e.g., malware hash value, etc.) included in the information utilization request to the victim user / device identification unit 122.

[0063] The victim user / device identification unit 132 identifies users and devices that have suffered incident damage in the information providing organization 102, as specified by the incident specification information.

[0064] The information collection unit 133 collects incident-related information about the victim user / device identified by the victim user / device identification unit 132 and transmits it to the threat intelligence generation device 120.

[0065] The information providing device 140 also has a user data table 112, a device data table 113, and a history data table 114. The data structure of each table is the same as that of the tables assigned the same reference numerals in the threat intelligence generation device 120, and therefore a description thereof will be omitted.

[0066] In addition, the input unit 121, victim user / device identification unit 122, information collection unit 123, user data table 112, device data table 113, and history data table 114 may be omitted from the threat intelligence generation device 120, and threat intelligence may be generated based on incident-related information regarding victim users and devices collected from multiple information providing organizations 102.

[0067] <Threat Intelligence Generation Processing> FIG. 10 is a flowchart showing an example of threat intelligence generation processing by the threat intelligence generation support system 100.

[0068] The threat intelligence generation process is initiated, for example, when a security operator or the like belonging to the information using organization 101 inputs incident designation information (e.g., malware hash value, etc.) to the intelligence generation operation screen 1001 (Figure 11) displayed by the output unit 126 of the threat intelligence generation device 120 to specify the incident for which threat intelligence is to be generated, and the input unit 121 accepts the input.

[0069] First, the victim user / device identification unit 122 of the threat intelligence generation device 120 identifies users and devices that have suffered incident damage in the information using organization 101, as specified by the incident specification information (step S101).

[0070] For example, if the incident designation information is a hash value of malware, the victim user / device identification unit 122 identifies the victim device by checking the log of each device, etc., to identify the device that has or executed the file with the hash value. In addition, the victim user is identified by identifying the user who is using the identified victim device.

[0071] Next, the information collection unit 123 collects incident-related information relating to victim users and victim devices within the information using organization 101 (step S102).

[0072] Here, the incident-related information collected by the information collection unit 123 includes information on users and devices themselves stored in the user data table 112 and the device data table 113, information on organizations to which users belong, and chronological information on users and devices stored in the history data table 114. Furthermore, a security operator may investigate an incident and analyze the infection route and malware obtained as a result, and collect information such as the services targeted by the attack and the stolen information. Furthermore, the incident-related information may be collected from outside the organization, such as the Information-Technology Promotion Agency (IPA).

[0073] Next, the information collection unit 123 sends an information usage request including incident designation information to the information providing device 140 of each information providing organization 102 (step S103), and collects incident-related information regarding victim users and victim devices in each information providing organization 102 (step S104).

[0074] Next, the information analysis unit 124 of the threat intelligence generation device 120 compares the incident-related information regarding victim users and victim devices within the information utilization organization 101 collected in step S102 with the incident-related information regarding victim users and victim devices within the information providing organization 102 collected in step S104 (step S105).

[0075] The incident-related information is matched by referring to the attribute list table 115 and using a matching method that is predefined for each attribute item.

[0076] For example, if the occupation of the victim user of an incident within the information use organization 101 is a researcher, the matching method corresponding to the occupation in the attribute list table 115 (Figure 6) is an exact match, so a match is made to determine whether the occupation of the victim user of an incident within the information providing organization 102 is a researcher.

[0077] Furthermore, when comparing incident-related information for victim devices, the configuration information table 116 (FIG. 7) for each organization is referenced as necessary, and the information is abstracted before being compared. For example, if the victim device of the incident is connected to IP address (192.0.2.1), the connection to IP address (192.0.2.1) is converted to a connection to the default gateway before being compared. This makes it possible to abstract and compare local IP addresses that differ depending on the organization.

[0078] Next, the filtering unit 125 refers to the whitelist table 117 (Figure 8) and, from the common points obtained as a result of the information analysis unit 124 comparing the incident-related information of the information using organization 101 and the information providing organization 102, excludes those that are unlikely to be threat intelligence, and outputs those that are likely to be threat intelligence to the output unit 126 (step S106).

[0079] Possible filtering methods include referring to the whitelist table 117, or, for example, comparing users or groups of devices that have been affected by a common incident with users or groups of devices that have not been affected by that incident, and if there is no significant difference, excluding them because they are not highly correlated with the presence or absence of an incident.

[0080] Next, the output unit 126 displays the input from the filtering unit 125 on the intelligence generation operation screen 1001 (FIG. 11) as a UI screen (step S107).

[0081] <Regarding the intelligence generation operation screen 1001> Fig. 11 shows an example of the display of the intelligence generation operation screen 1001. The intelligence generation operation screen 1001 is provided with a search window 1002, a matching result display field 1003, an attribution result display field 1004, and a risk score display field 1005.

[0082] The search window 1002 is used by a security operator or the like belonging to the information using organization 101 to input incident specification information that specifies an incident for which threat intelligence is to be generated.

[0083] The matching result display field 1003 displays a graph showing the degree of commonality in the attributes of the incident-related information of the information using organization 101 and the information providing organization 102 in descending order, expressed as a percentage.

[0084] In the example display of Figure 11, the same incident occurred in eight organizations (eight infections), 100% of the organizations where the incident occurred belonged to the electric power industry, and 90% of the victimized users were researchers. Therefore, it can be seen that there is a high probability that the incident was an attack targeting researchers in the electric power industry. However, if many of the information-using organizations 101 and information-providing organizations 102 belong to the same industry, the degree of commonality in that industry will be easily calculated as a common point. To avoid such problems, normalization can be performed.

[0085] In this embodiment, the number of infected organizations is displayed as the number of incidents, but the number of victimized users or victimized devices may also be displayed.

[0086] The attribution result display field 1004 compares the threat intelligence generated based on the matching results with the attack group profile table 118, and displays the attack group responsible for the incident in descending order of likelihood along with the probability score. In the display example of Figure 11, it is displayed that the probability score indicating the likelihood that the incident was an attack by attack group A is 90, and the probability score indicating the likelihood that the incident was an attack by attack group B is 80.

[0087] In the risk score display column 1005, users who have been determined not to be currently victims of an incident based on the results of the matching but who are close to the target of an attack and therefore have a high probability of becoming victims of an incident in the future, or who have already been attacked but have not yet detected the attack, are displayed in order of increasing risk together with their risk scores. In the display example of Figure 11, users A and B are shown to be at high risk of becoming victims of an incident.

[0088] <Display Example of Time-Series Event Drawing Screen 1101> FIG. 12 shows a display example of the time-series event drawing screen 1101 displayed as a UI screen by the output unit 126. As shown in FIG.

[0089] The time-series event drawing screen 1101 is displayed in response to a predetermined operation by a security operator, etc. The time-series event drawing screen 1101 displays a directed graph in which common events obtained as a result of matching victim users and victim devices, and uncommon events that are highly likely to be related to the incident and have a high degree of suspiciousness, are expressed as nodes.

[0090] The display example in Figure 12 shows the time series events of two devices A and B that were damaged when a common event, "Malware XXX executed," occurred, and shows that before the damage occurred, common events (such as "connection to Y.Y.Y.Y" and "launch of process X") and uncommon events (such as "connection to X.X.X.X") occurred. Common events may be a common attack that caused the incident. Uncommon events may be the cause of the same incident but may be a slight change in the attack method, etc., and security operators and others can use the directed graph to search for threat intelligence.

[0091] The present invention is not limited to the above-described embodiments, and various modifications are possible. For example, the above-described embodiments have been described in detail to clearly explain the present invention, and the present invention is not necessarily limited to those having all of the described configurations. Furthermore, it is possible to replace part of the configuration of one embodiment with or add to the configuration of another embodiment.

[0092] Furthermore, some or all of the aforementioned configurations, functions, processing units, processing means, etc. may be implemented in hardware, for example, by designing them as integrated circuits. Furthermore, the aforementioned configurations, functions, etc. may be implemented in software by a processor interpreting and executing programs that implement the respective functions. Information such as programs, tables, and files that implement the respective functions may be stored in memory, a recording device such as a hard disk or SSD, or a recording medium such as an IC card, SD card, or DVD. Furthermore, the control lines and information lines shown are those considered necessary for explanation, and do not necessarily represent all control lines and information lines in the product. In reality, it can be assumed that almost all components are interconnected.

Claims

1. A threat intelligence generation device that generates threat intelligence related to incidents caused by cyber attacks, comprising one or more computing devices, one or more memory resources, and one or more storage devices, wherein the computing device: identifies at least one of a victim user and a victim device of an incident that occurred in a first organization where the threat intelligence generation device is located; collects first incident-related information related to the identified victim user and / or victim device; collects second incident-related information related to at least one of a victim user and a victim device of an incident that occurred in a second organization different from the first organization and is the same as the incident that occurred in the first organization; compares the first incident-related information with the second incident-related information to extract common points; excludes information that is unlikely to be the threat intelligence from the extracted common points; and presents the common points that were not excluded.

2. A threat intelligence generation device as described in claim 1, characterized in that when the computing device compares the first incident-related information with the second incident-related information, it compares highly sensitive information in an encrypted state.

3. A threat intelligence generation device as described in claim 1, characterized in that when matching the first incident-related information with the second incident-related information, the computing device abstracts local information that differs for each organization and then matches the information.

4. A threat intelligence generation device as described in claim 1, characterized in that the computing device matches the first incident-related information with the second incident-related information within a predetermined time window.

5. A threat intelligence generation device as described in claim 1, characterized in that the computing device displays a time series event drawing screen that chronologically shows events that are common to at least one of the victim users and victim devices of the same incident that occurred in the first organization and the second organization, and events that are not common but are highly suspicious.

6. A threat intelligence generation method by a threat intelligence generation device that generates threat intelligence related to incidents caused by cyber attacks, the threat intelligence generation method comprising one or more computing devices, one or more memory resources, and one or more storage devices, the threat intelligence generation method comprising: a step in which the computing device identifies at least one of a victim user and a victim device of the incident that occurred in a first organization where the threat intelligence generation device is located; a step in which the computing device collects first incident-related information related to at least one of the identified victim user and the victim device; a step in which the computing device collects second incident-related information related to at least one of a victim user and a victim device of an incident that occurred in a second organization different from the first organization and is the same as the incident that occurred in the first organization; a step in which the computing device compares the first incident-related information with the second incident-related information to extract commonalities; and a step in which the computing device excludes information that is unlikely to be the threat intelligence from the extracted commonalities. and a step of presenting the commonalities that were not excluded.

Citation Information

Patent Citations

  • Black list extraction device, extraction method and extraction program

    JP2013152497A

  • Analysis device, and method and program for registering vicious communication destination

    JP2015082769A

  • Information processing system and information processing method

    JP2023019432A

  • Relay device, network monitoring system, and program

    WO2016194123A1