Estimation device

The system constructs a domain name timeline, extracts features, and trains a machine learning model to predict domain name malicious use, enhancing accuracy by addressing inaccuracies in existing technologies.

WO2026029164A1PCT designated stage Publication Date: 2026-02-05NT T INC
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
PCT/JP2025/027248
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-08-01
Filing Date
2025-07-31
Publication Date
2026-02-05

AI Technical Summary

Technical Problem

Existing domain name risk estimation technologies using machine learning suffer from inaccuracies, leading to false positives for expired malicious domain names and missed detections of reacquired legitimate domain names being abused.

Method used

A system that constructs a domain name timeline from historical data, extracts features, labels malicious use, and trains a machine learning model to predict risk using labeled features, enabling accurate estimation of domain name malicious use.

Benefits of technology

Accurately estimates the risk of domain name malicious use by improving prediction accuracy and addressing false positives and negatives.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2025027248_05022026_PF_FP_ABST
    Figure JP2025027248_05022026_PF_FP_ABST
Patent Text Reader

Abstract

This estimation device constructs, on the basis of the operation history of a designated domain name, a timeline (Domain Timeline) indicating the operation state in time series of the domain name. Thereafter, the estimation device extracts, from the timeline of the domain name, a feature amount related to the operation of the domain name at each time point. Then, the estimation device assigns, to each feature amount related to the operation of the domain name at each extracted time point, a label indicating whether the domain name has been malignantly used or not within a predetermined number of days from the time point. Thereafter, the estimation device trains, using the label-assigned feature quantity as teaching data, a machine learning model that adopts, as input, the feature quantity related to the operation of the domain name at each time point in a prescribed period and outputs an estimation result of the risk value of the malignant use of the domain name at a designated time point.
Need to check novelty before this filing date? Find Prior Art

Description

estimation device

[0001] The present invention relates to an estimation device for accurately estimating the risk of a domain name being maliciously used.

[0002] To date, many techniques for detecting malicious domain names using machine learning have been proposed. For example, there is a technique that uses the characteristics of malicious domain names themselves or information related to malicious domain names to learn the characteristics of malicious domain names and determine whether a new domain name is malicious (Patent Documents 1 and 2). These techniques make it possible to identify domain names that have been involved in malicious activities with a certain degree of accuracy.

[0003] Patent No. 6196008 Patent No. 6315640

[0004] However, because the above technology makes its judgments based on a large amount of learning data accumulated over time, there is a possibility that domain names previously determined to be malicious may still be determined to be malicious (false positive) even if they have expired or been sanitized. Furthermore, the above technology may not determine (overlook) a domain name that was previously used for legitimate services as malicious if it is reacquired and abused. In other words, the accuracy of the above technology in determining whether a domain name is malicious or not is not necessarily high. As a result, it has not been possible to accurately estimate the risk of a domain name being used maliciously.

[0005] Therefore, an object of the present invention is to solve the above-mentioned problems and to accurately estimate the risk of domain names being maliciously used.

[0006] In order to solve the above-mentioned problems, the present invention is characterized by comprising: a construction unit that constructs a timeline showing the chronological operation status of a specified domain name based on the operation history of the domain name; a feature extraction unit that extracts feature values ​​related to the operation of the domain name at each point in time from the domain name timeline; a labeling unit that assigns a label to each feature value related to the operation of the domain name at each point in time indicating whether the domain name has been maliciously used within a predetermined number of days from the point in time; and a learning unit that uses the labeled feature values ​​as training data to train a machine learning model that inputs the feature values ​​related to the operation of the domain name at each point in time during a predetermined period and outputs an estimated result of the risk value of malicious use of the domain name at a specified point in time.

[0007] According to the present invention, it is possible to accurately estimate the risk of a domain name being maliciously used.

[0008] FIG. 1 is a diagram showing an example of a processing procedure executed by an estimation device. FIG. 2 is a diagram showing an example of the configuration of an estimation device. FIG. 3 is a diagram showing an example of a Domain Timeline. FIG. 4 is a diagram showing a list of Features extracted from the Domain Timeline and an example of feature values ​​(feature quantities) corresponding to the case shown in FIG. 3. FIG. 5 is a diagram showing an example of a Domain Timeline to which a Risk Timeline has been added. FIG. 6 is a flowchart showing an example of a learning procedure for an estimation model executed by the estimation device. FIG. 7 is a flowchart showing an example of a processing procedure for estimating a risk value executed by the estimation device. FIG. 8 is a diagram showing an example of a computer that executes an estimation program.

[0009] DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS Hereinafter, a description will be given of an embodiment of the present invention with reference to the drawings, but the present invention is not limited to the embodiment.

[0010] [Overview] An overview of the estimation device of this embodiment will be described using Fig. 1. The estimation device estimates the risk value of malicious use of a domain name at any point in time from the past to the immediate future. The processing performed by the estimation device is divided into two phases: Training and Predicting.

[0011] [Training] First, when the estimation device receives input of a domain name whose identity has already been revealed, it builds data (Domain Timeline) showing the operational status of the domain name from the past up to a certain point in time (for example, changes in domain name registration information such as WHOIS, DNS (Domain Name System) settings, and TLS (Transport Layer Security) certificates) (S1: Building Domain Timeline).

[0012] Next, the estimation device extracts features related to the use of the domain name at each point in time from the past up to a certain point in time (S2: Extracting Features), and then, based on the ground truth, the estimation device identifies the point in time at which the domain name was maliciously used and attaches a label to the features related to the use of the domain name at each point in time extracted in S2 (S3: Labeling).

[0013] The estimation device then builds a machine learning model (ML Model) through machine learning using the feature quantities related to the use of the domain name at each point in time to which the label was assigned in S3 as training data (S4: Building ML Model).

[0014] [Predicting] The estimation device constructs a Domain Timeline for the Target Domain Name (the domain name for which the risk value of malicious use is to be estimated) in the same manner as in S1, and extracts feature quantities related to the operation of the domain name at each point in time in the same manner as in S2.

[0015] Then, the estimation device estimates the risk value of malicious use of the target domain name at each point in time using the ML model constructed in training (S5: Predicting Risks). This allows the estimation device to predict, for example, when the target domain name will be maliciously used (for example, used in an attack).

[0016] The estimation device estimates the risk value of malicious use of a domain name at any point in time from the past to the immediate future. Therefore, the estimation device may estimate the risk value of malicious use of a domain name at a point in time in the future, or may estimate the risk value of malicious use of a domain name at a point in time in the past.

[0017] [Configuration Example] Next, a configuration example of the estimation device 10 will be described with reference to Fig. 2. The estimation device 10 includes, for example, an input / output unit 11, a communication unit 12, a storage unit 13, and a control unit 14.

[0018] The input / output unit 11 is an interface that controls the input and output of various data. The input / output unit 11 receives input such as a domain name for which a risk value of malicious use is to be estimated. The communication unit 12 is an interface for communicating with an external device via a network. For example, the communication unit 12 acquires registration information, DNS settings, TLS certificates, etc. for a specified domain name from an external device via the network.

[0019] The storage unit 13 stores data, programs, etc. that are referenced when the control unit 14 executes various processes. The storage unit 13 is realized by a semiconductor memory element such as a random access memory (RAM) or a flash memory, or a storage device such as a hard disk or an optical disk. For example, the storage unit 13 stores parameters of a machine learning model (estimation model) learned by the control unit 14.

[0020] The control unit 14 controls the entire estimation device 10. The functions of the control unit 14 are realized, for example, by a CPU (Central Processing Unit) executing a program stored in the storage unit 13.

[0021] The control unit 14 includes a learning unit 140 and an estimation unit 150. The learning unit 140 learns a machine learning model (estimation model). The estimation unit 150 estimates the risk value of malicious use of the Target Domain Name using the learned estimation model.

[0022] [Learning Unit] First, a description will be given of the learning unit 140. The learning unit 140 includes a first constructing unit 141, a first feature extracting unit 142, a labeling unit 143, and a learning processing unit 144.

[0023] [First Construction Unit] The first construction unit 141 collects the operation history of a domain name (e.g., historical data such as WHOIS records, DNS records, and TLS certificates) and constructs a timeline (Domain Timeline) showing the chronological operation status of the domain name. For example, the first construction unit 141 constructs a Domain Timeline (see FIG. 3 ) showing the changes in each item in the operation history in chronological order.

[0024] Domain Timeline is information that shows the chronological changes in domain name registration, DNS settings, and TLS certificates for a domain name `example.com`. This Domain Timeline is intended to understand the life cycle of a domain name.

[0025] For example, the first construction unit 141 tracks when and how the registration information of the domain name itself in the WHOIS record, such as 'Registrar', 'Creation Date', 'Expiry Date', and 'Domain Status', has changed.

[0026] The first construction unit 141 also tracks when and how 'MNAME', 'RNAME', and 'SERIAL' in the DNS SOA (Start Of Authority) record in the DNS record have changed.

[0027] In addition, the first construction unit 141 tracks when and how 'Issuer.C', 'Issuer.CN', 'Issuer.O', 'validity.not_before', 'validity.not_after', and 'Subject.CN' have changed among the certificates that are currently required for use in TLS certificates on Web / HTTPS.

[0028] Then, the first constructor 141 constructs a Domain Timeline (see FIG. 3 ) that shows the tracking results of each of the above items in chronological order. Note that the first constructor 141 may construct a Domain Timeline that includes tracking results of other items, not just the above items.

[0029] [Domain Timeline Example] Figure 3 shows an example of the Domain Timeline for a certain domain name. The domain name in question had been used for legitimate purposes for over 10 years, but was dropped and caught by an attacker, left unused for about a year, and then suddenly used for malicious purposes.

[0030] For example, the WHOIS timeline of the Domain Timeline shown in Figure 3 shows that the registrar changed from Foo Inc. to Bar Ltd. at some point. We can also see that the Creation Date was maintained at 2009-10-10, but expired and was re-registered on 2021-12-28. We can also see that the Expiry Date was extended every year from 2019-10-10 to 2021-10-10, but then expired.

[0031] Also, from the SOA timeline of the Domain Timeline shown in FIG. 3, it can be seen that the MNAME changed from ns.foo.test to ns.suspended.test, and then changed to ns.bar.test.

[0032] Furthermore, the transitions between Issuer.0 and Not After in the TLS timeline shown in Figure 3 reveal that the domain name registrar began using a BazCert Corp. certificate while it was still Foo Inc., but there were gaps due to the certificate expiring several times. It also reveals that the certificate expired (2021-06-03) before the domain name expired (2021-10-10). Furthermore, it reveals that the domain name registrar changed from Foo Inc. to Bar Ltd. some time later, and the QuxCert, Inc. certificate began to be activated.

[0033] [First Feature Extraction Unit] The first feature extraction unit 142 refers to the Domain Timeline of the above-mentioned domain name and extracts features related to the operation of the domain name at each point in time.

[0034] In addition, the estimation device 10 of this embodiment uses Features that are independent of content (e.g., content such as the website of the domain name) so that it can estimate the risk value of malicious use of a domain name at any point in time from the past to the immediate future.

[0035] This is because if the estimation device 10 uses Features that depend on the content of the website of the domain name, it may not be able to estimate the risk value if it is unable to obtain that content, or it may become difficult to estimate the risk value by keeping up with changes in all the content of the domain name.

[0036] Fig. 4 shows a list of Features extracted from the Domain Timeline and an example of feature values ​​(feature amounts) corresponding to the example shown in Fig. 3. For example, the first feature amount extraction unit 142 extracts the following feature amounts for each of (1) WHOIS, (2) SOA, and (3) TLS certificate (TLS) from data obtained before a certain point in time on the Domain Timeline (for example, 2022-11-22 shown in Fig. 3).

[0037] (1) WHOIS 1. Unique items in historical WHOIS records from the past to the present (time of feature extraction) For example, the first feature extraction unit 142 extracts features that capture the history of changes in the lifecycle of a domain name, such as changes in the registrant of the domain name or changes in the status of the domain name, from the historical WHOIS record. For example, the first feature extraction unit 142 extracts, as features, how many different values ​​have been registered in the past (the number of unique items) for the fields of Registar, Creation Date, Expiry Date, and Domain Status in the WHOIS record from the past to the time of feature extraction.

[0038] 2. Number of days between creation / expiration / update date and the present time For example, the first feature extraction unit 142 extracts a feature that captures how long has passed since the occurrence of a change in the lifecycle until the feature extraction time. For example, the first feature extraction unit 142 extracts, as a feature, the number of days until the feature extraction time for each of the Creation Date, Expiry Date, and Updated Date of the WHOIS record from the past until the feature extraction time.

[0039] 3. Domain status of the latest WHOIS record up to the present time: For example, the first feature extraction unit 142 extracts the domain status (e.g., clientTransferProhibited) of the latest WHOIS record as a feature for determining whether a domain name is normally available at the time of feature extraction.

[0040] 4. Minimum / Average / Median / Maximum Number of Days Between WHOIS Updates For example, the first feature extraction unit 142 extracts a feature that captures how frequently a WHOIS record has been updated from the past until the feature extraction time point. For example, the first feature extraction unit 142 extracts the minimum, average, median, and maximum number of days between updates of multiple WHOIS records from the past until the feature extraction time point as the feature.

[0041] 5. Difference in number of days between the update / creation / expiry date of the latest WHOIS record and the previous one For example, the first feature extraction unit 142 extracts a feature for determining whether an event that caused a change in a WHOIS record was for a legitimate purpose. For example, the first feature extraction unit 142 extracts, as a feature, the difference in the updated date, creation date, and expiry date of the latest WHOIS record and the WHOIS record immediately preceding it at the time of feature extraction.

[0042] 6. True / false value indicating whether the registrar / domain status of the latest WHOIS record is different from the previous one. For example, the first feature extraction unit 142 extracts a feature for determining whether the event that caused the latest WHOIS record to be changed was for a legitimate purpose. For example, the first feature extraction unit 142 extracts, as a feature, whether the Registrar and Domain Status fields are different between the latest WHOIS record at the time of feature extraction and the WHOIS record immediately preceding it.

[0043] (2) SOA 7. Number of unique items in historical SOA records from the past to the present. Changes in DNS SOA records indicate changes in the lifecycle of a domain name. Therefore, the first feature extraction unit 142 extracts features that capture the history of changes in the lifecycle of a domain name from the SOA record. For example, the first feature extraction unit 142 extracts, as a feature, the number of different values ​​registered in the mname, rname, and serial fields of the SOA record from the past to the time of feature extraction (the number of unique items).

[0044] 8. Number of days between the date in the latest SOA data and the current time For example, the first feature extraction unit 142 extracts a feature that captures how long has passed since the change in the domain name's lifecycle until the feature extraction time. For example, the first feature extraction unit 142 extracts the number of days from the date in the latest SOA record until the feature extraction time as the feature.

[0045] 9. Minimum / Average / Median / Maximum Number of Days of SOA Update Interval For example, the first feature extraction unit 142 extracts a feature that captures how frequently an SOA record has been updated from the past until the feature extraction time point. For example, the first feature extraction unit 142 extracts the minimum, average, median, and maximum number of days of the update interval between multiple SOA records from the past until the feature extraction time point as the feature.

[0046] 10. Difference in number of days between the date of the latest SOA record and the previous oneFor example, the first feature extraction unit 142 extracts a feature for determining whether a lifecycle event that caused a change in an SOA record was caused by a legitimate purpose. For example, the first feature extraction unit 142 extracts, as a feature, the difference in date between the latest SOA record and the SOA record immediately preceding it at the time of feature extraction.

[0047] 11. True / false value indicating whether the name server / rname of the latest SOA record is different from the previous one. For example, the first feature extraction unit 142 extracts a feature for determining whether the event that caused the latest SOA record to be changed was for a legitimate purpose. For example, the first feature extraction unit 142 extracts, as a feature, whether the mname and rname items are different between the latest SOA record and the previous SOA record at the time of feature extraction.

[0048] (3) TLS 12. Number of Unique Items in Historical TLS Records from the Past to the Present A change in a TLS certificate signifies a change in the lifecycle of a domain name. Therefore, the first feature extraction unit 142 extracts features that effectively capture the history of changes in the lifecycle of a domain name from the historical TLS record. For example, the first feature extraction unit 142 extracts, as features, how many different values ​​have been registered in the past for the issuer.C, issuer.CN, issuer.O, validity.not_before, validity.not_after, and subject.CN fields of the TLS record from the past to the time of feature extraction.

[0049] 13. Number of days between the not_before / not_after / updated date in the latest TLS data and the current time For example, the first feature extraction unit 142 extracts from the TLS record a feature that captures how long has passed since the change in the domain name's lifecycle until the feature extraction time. For example, the first feature extraction unit 142 extracts, as a feature, the number of days from the not_before, not_after, and updated dates in the latest TLS record until the feature extraction time.

[0050] 14. Minimum / Average / Median / Maximum Number of Days of TLS Update Interval For example, the first feature extraction unit 142 extracts a feature that captures how frequently TLS records have been updated from the past until the feature extraction time point. For example, the first feature extraction unit 142 extracts the minimum, average, median, and maximum number of days of the update interval between multiple TLS records from the past until the feature extraction time point as the feature.

[0051] 15. Difference in number of days between the update / not_before / not_after date of the latest TLS record and the previous oneFor example, the first feature extraction unit 142 extracts a feature for distinguishing whether the event that caused the TLS record change was a normal domain name update for a legitimate purpose.For example, the first feature extraction unit 142 extracts, as a feature, the difference in the Updated Date, not_before, and not_after dates of the latest TLS record and the TLS record immediately preceding it at the time of feature extraction.

[0052] 16. True / false value of whether issuer.C / CN / O / subject.CN of the latest TLS record is different from the previous one. For example, the first feature extraction unit 142 extracts a feature for distinguishing whether the event that caused the latest TLS change was for a legitimate purpose. For example, the first feature extraction unit 142 extracts, as a feature, whether the items issuer.C, issuer.CN, issuer.O, and subject.CN of the latest TLS record and the TLS record immediately preceding it at the time of feature extraction are different.

[0053] [Labeling Unit] Returning to the explanation of Fig. 2, the labeling unit 143 assigns, to each feature related to the use of the domain name at each point in time, a correct label indicating whether or not the domain name has been maliciously used within a predetermined number of days (N days) from that point in time.

[0054] For example, the labeling unit 143 assigns a correct answer label of "risky (Positive)" to the feature of the domain name at each time point extracted by the first feature extraction unit 142 if a history of malicious use has been confirmed within N days after the relevant time point. On the other hand, the labeling unit 143 assigns a correct answer label of "no risk (Negative)" to the feature of the domain name at each time point if a history of malicious use has not been confirmed within N days after the relevant time point.

[0055] Note that N is an adjustable parameter. For example, when N=30, if the domain name used at a phishing site on January 30, 2024 is known, the labeling unit 143 assigns a label of "no risk (negative)" to the feature of that domain name before January 1, 2024, and assigns a label of "risk (positive)" to the feature after January 1, 2024.

[0056] [Learning Processing Unit] The learning processing unit 144 performs machine learning of a machine learning model (estimation model) using, as training data, the feature quantities of a domain name at each time point and the labels assigned to those feature quantities extracted by the first feature quantity extraction unit 142. This estimation model is a model that takes the feature quantities of a domain name (Target Domain Name) at each time point as input and outputs an estimated result of the risk value of malicious use of the domain name at a specified time point (performs risk prediction).

[0057] Various algorithms can be applied to the above supervised machine learning, but since the problem setting can be defined so that the domain name has features at each point in time and a binary label (positive / negative), any binary classification algorithm can be applied.

[0058] [Estimation Unit] The estimation unit 150 estimates the risk value of malicious use of the Target Domain Name using the estimation model learned by the learning unit 140. For example, the estimation unit 150 inputs the feature amount of the Target Domain Name at each time point into the learned estimation model, and outputs the estimated result of the risk value of malicious use of the Target Domain Name output by the estimation model.

[0059] The estimation unit 150 includes a second construction unit 151, a second feature extraction unit 152, and an estimation processing unit 153. The second construction unit 151 collects the operation history of the Target Domain Name (for example, historical data such as WHOIS records, DNS records, and TLS certificates) and constructs a Domain Timeline for the Target Domain Name. The construction of the Domain Timeline here is similar to the construction of the Domain Timeline by the first construction unit 141, and therefore will not be described here.

[0060] The second feature extraction unit 152 extracts feature amounts related to the operation of the Target Domain Name at each point in time by referring to the Domain Timeline of the Target Domain Name constructed by the second construction unit 151. The extraction of feature amounts here is similar to the extraction of feature amounts by the first feature extraction unit 142, and therefore a description thereof will be omitted.

[0061] The estimation processing unit 153 refers to the learned estimation model and estimates the risk value of the Target Domain Name being maliciously used within the next N days based on the features of the Target Domain Name at each point in time extracted by the second feature extraction unit 152.

[0062] The risk value is expressed as a predicted probability obtained as the output of an estimation model, for example. The predicted probability takes a continuous value between 0 and 1, with values ​​closer to 0 indicating "no risk (negative)" and values ​​closer to 1 indicating "risk (positive)."

[0063] [Output Processing Unit] The output processing unit 160 outputs the risk value of the Target Domain Name being maliciously exploited within the next N days, as estimated by the estimation unit 150. For example, the output processing unit 160 outputs, as a Risk Timeline, the time-series transition of the predicted probability of the risk value of the Target Domain Name at each point in time, as output by the estimation processing unit 153. For example, the output processing unit 160 may display the Risk Timeline together with the Domain Timeline of the Target Domain Name constructed by the second construction unit 151 (see FIG. 5 ).

[0064] Furthermore, the output processing unit 160 may output, in addition to the predicted probability of the risk value, the feature amount that contributed to the predicted probability. For example, the output processing unit 160 uses an XAI (eXplainable Artificial Intelligence) technique to output the feature amount that contributed to the predicted probability of the risk value.

[0065] For example, the output processing unit 160 uses SHAP (SHapley Additive exPlanations) as an XAI method. SHAP is a method that explains how much a feature value input to a machine learning model that outputs a certain predicted probability contributes to that predicted probability, and outputs SHAP Values ​​that indicate the contribution of each feature value. For example, based on the SHAP Values, the output processing unit 160 outputs the top positive / negative features that contributed to the prediction of the risk value at each time point.

[0066] For example, as shown in FIG. 5, when the pointer is placed on a risk value at a certain time point on the Risk Timeline, the output processing unit 160 displays the Top Positive / Negative Features that contributed to the prediction of the risk value at that time point.

[0067] In this way, the estimation device 10 can predict and output not only the risk value of a domain name at a certain point in time, but also changes in the risk value of the domain name as a timeline.The estimation device 10 can also output the top positive / negative features that contributed to the risk value prediction at each point in time.

[0068] [Example of Processing Procedure] Next, an example of processing procedure executed by the estimation device 10 will be described with reference to Fig. 6 and Fig. 7. First, an example of the learning procedure of the estimation model executed by the estimation device 10 will be described with reference to Fig. 6.

[0069] The first construction unit 141 of the learning unit 140 collects the operation history of the specified domain name (S11), and constructs a Domain Timeline for the specified domain name based on the operation history of the specified domain name (S12).

[0070] After S12, the first feature extraction unit 142 extracts feature amounts related to the use of the domain name at each time point from the timeline of the domain name (S13).Then, the labeling unit 143 assigns a correct answer label to each feature amount related to the use of the domain name at each time point, indicating whether the domain name has been maliciously used within a predetermined number of days from that time point (S14).

[0071] After S14, the learning processing unit 144 performs machine learning of the estimation model using the feature amounts of the domain name at each time point and the labels assigned to the feature amounts as training data (S15).

[0072] Next, an example of the processing procedure for estimating a risk value executed by the estimation device 10 will be described with reference to Fig. 7. The second construction unit 151 of the estimation unit 150 collects the operation history of the target domain name (S21), and constructs a domain timeline for the domain name based on the operation history of the target domain name (S22).

[0073] After S22, the second feature extraction unit 152 extracts features related to the operation of the target domain name at each time point from the domain timeline of the target domain name constructed in S21 (S23).

[0074] After S23, the estimation processing unit 153 refers to the learned estimation model and estimates the risk value of the Target Domain Name being maliciously used within the next N days based on the feature values ​​of the Target Domain Name extracted at each point in time in S23 (S24).

[0075] After S24, the output processing unit 160 outputs the estimated result of the risk value that the Target Domain Name will be maliciously used within the next N days, which was estimated in S24 (S25).

[0076] By performing the above process, the estimation device 10 can output an estimation result of the risk value of malicious use of a domain name at any point in time from the past to the immediate future.

[0077] [System Configuration, etc.] The components of each unit shown in the figure are conceptual functional units and do not necessarily have to be physically configured as shown. In other words, the specific form of distribution and integration of each device is not limited to that shown, and all or part of them can be functionally or physically distributed and integrated in any unit depending on various loads, usage conditions, etc. Furthermore, all or any part of the processing functions performed by each device can be realized by a CPU and a program executed by the CPU, or can be realized as hardware using wired logic.

[0078] Furthermore, among the processes described in the above embodiments, all or part of the processes described as being performed automatically can be performed manually, or all or part of the processes described as being performed manually can be performed automatically using a known method.In addition, the information including the processing procedures, control procedures, specific names, various data and parameters shown in the above documents and drawings can be changed as desired unless otherwise specified.

[0079] [Program] The above-described estimation device 10 can be implemented by installing a program (estimation program) as package software or online software on a desired computer. For example, by executing the above-described program on an information processing device, the information processing device can function as the estimation device 10. The information processing device referred to here includes mobile communication terminals such as smartphones, mobile phones, and PHS (Personal Handyphone Systems), as well as terminals such as PDAs (Personal Digital Assistants).

[0080] 8 is a diagram showing an example of a computer that executes an estimation program. The computer 1000 includes, for example, a memory 1010 and a CPU 1020. The computer 1000 also includes a hard disk drive interface 1030, a disk drive interface 1040, a serial port interface 1050, a video adapter 1060, and a network interface 1070. These components are connected by a bus 1080.

[0081] The memory 1010 includes a read-only memory (ROM) 1011 and a random access memory (RAM) 1012. The ROM 1011 stores a boot program such as a basic input / output system (BIOS). The hard disk drive interface 1030 is connected to a hard disk drive 1090. The disk drive interface 1040 is connected to a disk drive 1100. A removable storage medium such as a magnetic disk or optical disk is inserted into the disk drive 1100. The serial port interface 1050 is connected to a mouse 1110 and a keyboard 1120, for example. The video adapter 1060 is connected to a display 1130, for example.

[0082] The hard disk drive 1090 stores, for example, an OS 1091, an application program 1092, a program module 1093, and program data 1094. That is, the programs that define the processes executed by the above-described estimation device 10 are implemented as program modules 1093 in which computer-executable code is written. The program modules 1093 are stored, for example, in the hard disk drive 1090. For example, the program modules 1093 for executing processes similar to those of the functional configuration of the estimation device 10 are stored in the hard disk drive 1090. Note that the hard disk drive 1090 may be replaced with an SSD (Solid State Drive).

[0083] Data used in the processing of the above-described embodiment is stored as program data 1094, for example, in the memory 1010 or the hard disk drive 1090. The CPU 1020 then reads the program module 1093 or the program data 1094 stored in the memory 1010 or the hard disk drive 1090 into the RAM 1012 as necessary and executes them.

[0084] The program module 1093 and program data 1094 may not necessarily be stored in the hard disk drive 1090, but may also be stored in a removable storage medium and read by the CPU 1020 via the disk drive 1100 or the like. Alternatively, the program module 1093 and program data 1094 may be stored in another computer connected via a network (such as a local area network (LAN) or a wide area network (WAN)). The program module 1093 and program data 1094 may then be read by the CPU 1020 from the other computer via the network interface 1070.

[0085] The functions of the elements disclosed herein may be implemented using circuitry or processing circuitry including general-purpose processors, special-purpose processors, integrated circuits, application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), conventional circuits, and / or combinations thereof that are programmed using one or more programs stored in one or more memories or otherwise configured to perform the disclosed functions. A processor is considered processing circuitry or circuitry because it includes transistors and other circuitry. A processor may also be a programmed processor that executes a program stored in a memory. In this disclosure, a circuit, unit, or means is hardware that performs the recited functions or hardware that is programmed to perform the recited functions. The hardware may be any hardware disclosed herein that is programmed or configured to perform the recited functions.

[0086] There is a memory that stores a computer program including computer instructions. These computer instructions provide the logic and routines that enable hardware (e.g., processing circuitry or circuitry) to perform the methods disclosed herein. The computer program may be implemented in commonly known forms as a computer-readable storage medium, a computer program product, a memory device, a recording medium such as a CD-ROM or DVD, and / or memory in an FPGA or ASIC.

[0087] REFERENCE SIGNS LIST 10 Estimation device 11 Input / output unit 12 Communication unit 13 Storage unit 14 Control unit 140 Learning unit 141 First construction unit 142 First feature amount extraction unit 143 Labeling unit 144 Learning processing unit 150 Estimation unit 151 Second construction unit 152 Second feature amount extraction unit 153 Estimation processing unit 160 Output processing unit

Claims

1. An estimation device comprising: a construction unit that constructs a timeline showing the chronological operation status of a specified domain name based on the operation history of the domain name; a feature extraction unit that extracts feature values ​​related to the operation of the domain name at each point in time from the domain name timeline; a labeling unit that assigns a label to each feature value related to the operation of the domain name at each point in time indicating whether the domain name has been maliciously used within a predetermined number of days from the point in time; and a learning unit that uses the labeled feature values ​​as training data to train a machine learning model that inputs the feature values ​​related to the operation of the domain name at each point in time during a predetermined period and outputs an estimated result of the risk value of malicious use of the domain name at a specified point in time.

2. The estimation device described in claim 1, further comprising an estimation unit that inputs feature values ​​at each point in time for a domain name for which a risk value of malicious use is to be estimated into the machine learning model after training, and outputs the estimated result of the risk value of malicious use of the domain name at a specified point in time output by the machine learning model.

3. The estimation device according to claim 2, characterized in that the estimation unit outputs a time series of estimated results of the risk value of malicious use of the domain name over a predetermined period of time.

4. The estimation device according to claim 1, characterized in that the domain name operation history is the operation history of the domain name recorded in at least one of a WHOIS record, a DNS (Domain Name System) record, and a TLS (Transport Layer Security) certificate.

Citation Information

Patent Citations

  • Domain detection program, domain detection method, and information processing apparatus

    JP2023176639A

  • Determination device, determination method, and determination program

    WO2022044334A1