Proxy device, analysis device, reference device, and method, program, and system executed by these devices

The proxy and analysis devices enhance security by determining and blocking risky requests and responses, and registering security risks, addressing malware vulnerabilities in service identification devices.

WO2026094127A1PCT designated stage Publication Date: 2026-05-07INTERNET INITIATIVE JAPAN INC
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
INTERNET INITIATIVE JAPAN INC
Filing Date
2024-10-28
Publication Date
2026-05-07

AI Technical Summary

Technical Problem

Existing service identification devices are vulnerable to malware infection when analyzing external requests, as they directly interact with potentially malicious destinations.

Method used

A proxy device is introduced to determine the security risk of request URLs, forward normal requests to servers, analyze responses, and block risky requests or responses, while an analysis device extracts and registers security risks from site URLs, cookies, and external communication URLs.

Benefits of technology

Enhances security by preventing malware infection and enabling comprehensive analysis and registration of security risks associated with website services, providing secure and reliable service identification.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2024038431_07052026_PF_FP_ABST
    Figure JP2024038431_07052026_PF_FP_ABST
Patent Text Reader

Abstract

This proxy device comprises: a request determination unit 105 that receives a request transmitted from a virtual browser, and determines the security risk of a requested URL specified by the request; a request transfer unit 101 that transfers a request, the requested URL of which is determined to be normal by the request determination unit 105, to a server 30 that operates a site to be analyzed, said site to be analyzed being a target site where services used on the site are identified; a response analysis unit 102 that receives and analyzes a response from the server 30; and a response return unit 103 that returns the response to the virtual browser. This makes it possible to prevent an analysis device 10 from receiving responses that pose a security risk.
Need to check novelty before this filing date? Find Prior Art

Description

Proxy devices, analysis devices, reference devices, methods, programs, and systems performed by these devices.

[0001] The present invention relates to a proxy device, an analysis device, a reference device, a security risk determination method, an analysis method, a reference method, a security risk determination program, an analysis program, a reference program, and a security risk determination system.

[0002] A service identification device is known that launches an internet browser, accesses a website to be analyzed, monitors HTTP requests to extract the URL of the external request, and identifies the service corresponding to the domain and path of the URL of the external request by referring to an external service database (see, for example, Patent Document 1). However, with such a method, if the destination of the external request is malicious, the service identification device may become infected with malware or the like. [Prior Art Documents] [Patent Documents] [Patent Document 1] Japanese Patent Application Publication No. 2018-185741 General disclosure

[0003] (Item 1) The proxy device may include a request determination unit that receives a request sent from a virtual browser and determines the security risk of the request URL specified in the request. The proxy device may also include a request forwarding unit that forwards the request, for which the request URL has been determined to be normal by the request determination unit, to a server operating a site to be analyzed, wherein the site to be analyzed is a target site for which the services used on the site to be analyzed are identified. The proxy device may also include a response analysis unit that receives and analyzes a response from the server. The proxy device may also include a response return unit that sends the response back to the virtual browser. (Item 2) The response analysis unit may determine the security risk from the response sent from the server. The response return unit may send the response, for which the response analysis unit has determined to have no security risk, back to the virtual browser. (Item 3) The proxy device may further include a request blocking unit that blocks the request when the request determination unit determines the request URL to be abnormal. (Item 4) When the request blocking unit determines that the request URL is abnormal, it may generate a new response indicating that the request URL has a security risk and send it back to the virtual browser. (Item 5) The proxy device may further include a response blocking unit that blocks the return of the response when the response analysis unit determines that the response has a security risk. (Item 6) When the response analysis unit further determines that the response has a security risk, the response blocking unit may generate a new response indicating that the page included in the response has a security risk and send it back to the virtual browser. (Item 7) When the status code of the response sent from the server is not 200, the response analysis unit may determine that the page included in the response is an inaccessible page.(Item 8) The virtual browser may be activated by the analysis device to send the request to the server that operates the analysis target site by specifying the site URL of the analysis target site, and receive the response from the server.

[0004] (Item 9) The analysis device may include an analysis target acquisition unit that acquires the site URL of the analysis target site. The analysis device may include an analysis execution unit that analyzes one or more pages within the site published at the site URL. The analysis execution unit may have a site access unit that specifies the site URL using the virtual browser, sends the request to the proxy device described in Item 1, and receives the response from the proxy device. The analysis execution unit may have a status extraction unit that extracts security risks from the response.

[0005] (Item 10) The analysis execution unit may further have a link extraction unit that extracts the page URL of the linked page from the response. The site access unit may further send a request to the proxy device by specifying the page URL of the linked page, and receive the response from the proxy device. (Item 11) The analysis device may further include a status registration unit that associates the page URL of the one or more pages, the status code of the response to the request specifying the page URL, and the security risk, and registers them in a status database.

[0006] (Item 12) The reference device may include a status acquisition unit that acquires the status code and security risk of the response to the request specifying the page URL of the one or more pages from the status database registered by the analysis device described in Item 11. The reference device may include a status output unit that outputs the status code and security risk of the response to the request specifying the page URL of the one or more pages to the user terminal.

[0007] (Item 13) A security risk assessment method performed by a computer may include a step of receiving a request sent from a virtual browser and determining the security risk of the request URL specified in the request. The security risk assessment method may include a request step of forwarding the request, for which the request URL has been determined to be normal by the assessment step, to a server operating a site to be analyzed, wherein the site to be analyzed is a target site for which the services used on the site to be analyzed are identified. The security risk assessment method may include a step of receiving and analyzing a response from the server. The security risk assessment method may include a step of sending the response back to the virtual browser.

[0008] (Item 14) The analysis method performed by the computer may include a step of obtaining the site URL of the site to be analyzed. The analysis method may include a step of analyzing one or more pages within the site that is publicly accessible at the site URL. The analysis step may include sending the request to a proxy device equipped with a computer that executes the security risk determination method described in Item 13 by specifying the site URL using the virtual browser, and receiving the response from the proxy device. The analysis step may include a step of extracting security risks from the response. (Item 15) The analysis method may further include a step of registering the page URLs of the one or more pages, the status code of the response to the request specifying the page URL, and the security risks in a status database.

[0009] (Item 16) A referencing method performed by a computer may include the step of obtaining the page URLs of one or more pages, the status code of the response to the request specifying the page URLs, and the security risk from the status database registered by the analysis method described in Item 15. The referencing method may also include the step of outputting the page URLs of one or more pages, the status code of the response to the request specifying the page URLs, and the security risk to a user terminal.

[0010] (Item 17) The security risk assessment program may cause the computer to execute a procedure to receive a request sent from the virtual browser and determine the security risk of the request URL specified in the request. The security risk assessment program may cause the computer to execute a procedure to transfer the request, for which the request URL has been determined to be normal by the assessment procedure, to a server operating the site to be analyzed, wherein the site to be analyzed is a target site for which the services used on the site to be analyzed are identified. The security risk assessment program may cause the computer to execute a procedure to receive and analyze the response from the server. The security risk assessment program may cause the computer to execute a procedure to send the response back to the virtual browser.

[0011] (Item 18) The analysis program may cause the computer to perform a procedure to obtain the site URL of the site to be analyzed. The computer may also perform a procedure to analyze one or more pages within the site that is publicly accessible at the site URL. The analysis procedure may include sending the request to a proxy device equipped with a computer that executes the security risk determination program described in Item 17, specifying the site URL using the virtual browser, and receiving the response from the proxy device. The analysis procedure may include extracting security risks from the response. (Item 19) The analysis program may further cause the computer to perform a procedure to register the status code and security risk of the response to the request specifying the page URLs of the one or more pages in a status database. (Item 20) The reference program may cause the computer to perform a procedure to obtain the status code and security risk of the response to the request specifying the page URLs of the one or more pages from the status database registered by executing the analysis program described in Item 19. The reference program may cause a computer to execute a procedure to output the page URLs of one or more pages, the status code of the response to the request specifying the page URLs, and the security risk to the user terminal.

[0012] (Item 21) The security risk assessment system may include the proxy device described in Item 1. The security risk assessment system may include the analysis device described in Item 9. The security risk assessment system may include the reference device described in Item 12. The security risk assessment system may include a status database in which data is registered that associates the page URLs of one or more pages with the status codes of responses to requests specifying the page URLs and the security risks.

[0013] (Item 22) The security risk assessment system may include an analysis device that identifies the services used on the site under analysis. The security risk assessment system may include a proxy device that mediates between the server operating the site under analysis and the virtual browser launched by the analysis device. The site under analysis may be a target site from which the services used on the site under analysis are identified. The analysis device may perform the step of obtaining the site URL of the site under analysis and sending a request to the proxy device by specifying the site URL using the virtual browser. The proxy device may perform the step of receiving the request sent from the virtual browser and determining the security risk of the request URL specified in the request. The proxy device may perform the step of forwarding the request, which has been determined to be normal, to the server operating the site under analysis. The proxy device may perform the step of receiving and analyzing the response from the server. The proxy device may perform the step of sending the response back to the virtual browser. The analysis device may receive the response from the proxy device, extract security risks from the response, analyze one or more pages within the site published at the site URL based on the response, and register the page URLs of the one or more pages, the status code of the response to the request specifying the page URL, and the security risks in a status database. (Item 23) When the proxy device determines that the request URL is abnormal, it may generate a new response indicating that the request URL has security risks and send it back to the virtual browser. (Item 24) When the proxy device determines that the response has security risks, it may further perform the step of blocking communication with the site to be analyzed.(Item 25) In the blocking stage, if the proxy device determines that there is a security risk in the response, it may further generate a new response indicating that there is a security risk in the pages included in the response and send it back to the virtual browser. (Item 26) The reference device may further perform a step of outputting the page URLs of the one or more pages, the status code of the response to the request specifying the page URLs, and the security risk to the user terminal from the status database registered in the registration stage.

[0014] (Item 27) A security risk determination method performed by one or more devices may include the step of an analysis device obtaining the site URL of a site to be analyzed and sending a request to a proxy device specifying the site URL using a virtual browser, wherein the site to be analyzed is a target site from which the services used on the site to be analyzed are identified. The security risk determination method may include the step of the proxy device receiving the request sent from the virtual browser and determining the security risk of the request URL specified in the request. The security risk determination method may include the step of the proxy device forwarding the request, which has been determined to be normal, to the server operating the site to be analyzed. The security risk determination method may include the step of the proxy device receiving and analyzing the response from the server. The security risk determination method may include the step of the proxy device sending the response back to the virtual browser. The security risk determination method may include the steps of: the analysis device receiving the response from the proxy device, extracting security risks from the response, analyzing one or more pages within the site published at the site URL based on the response, and registering the page URLs of the one or more pages, the status code of the response to the request specifying the page URL, and the security risks in a status database.

[0015] (Item 28) The security risk assessment program may have one or more computers perform a procedure to obtain the site URL of the site to be analyzed, and to send a request to a proxy device by specifying the site URL using a virtual browser, wherein the site to be analyzed is a target site from which the services used on the site to be analyzed can be identified. The security risk assessment program may have one or more computers perform a procedure to receive the request sent from the virtual browser by the proxy device and to determine the security risk of the request URL specified in the request. The security risk assessment program may have one or more computers perform a procedure to forward the request, which the proxy device has determined to be normal, to the server operating the site to be analyzed. The security risk assessment program may have one or more computers perform a procedure to receive and analyze the response from the server by the proxy device. The security risk assessment program may have one or more computers perform a procedure to send the response back to the virtual browser by the proxy device. The security risk assessment program may cause one or more computers to receive the response from the proxy device, extract security risks from the response, analyze one or more pages within the site published at the site URL based on the response, and register the page URLs of the one or more pages, the status code of the response to the request specifying the page URL, and the security risk in a status database.

[0016] It should be noted that the above summary of the invention does not enumerate all of its features. Furthermore, subcombinations of these features may also constitute an invention.

[0017] This shows the schematic configuration of the service identification system according to the first embodiment. This shows the functional configuration of the analysis device. This shows an example of registration information in the site database. This shows an example of data included in the HTTP response sent from the server to be analyzed. This shows an example of registration information in the analysis item database. This shows the analysis flow. This shows the functional configuration of the service identification device. This shows an example of registration information in the service database. This shows an example of registration information in the service database. This shows an example of registration information in the service database. This shows the service identification flow. This shows the functional configuration of the reference device. This shows a screen that displays cookies, web storage, or external communication URLs corresponding to the service used, acquired by the analysis item acquisition unit. This shows a screen that displays the site URL acquired by the analysis item acquisition unit and cookies, web storage, or external communication URLs within the site. This shows the service reference flow. This shows the input screen for the target of analysis. This shows the analysis item reference flow. This shows the schematic configuration of the service identification system according to the second embodiment. This shows the functional configuration of the proxy device. This shows an example of data included in the error response. This shows the security risk determination flow. This shows the functional configuration of the analysis device. This shows an example of registration information in the status database. This shows the analysis flow. This shows the functional configuration of the reference device. This shows a screen that displays status information. The reference flow is shown. An example of a computer configuration is shown.

[0018] (First Embodiment) The present invention will be described below through embodiments of the invention, but the following embodiments are not intended to limit the invention as claimed. Furthermore, not all combinations of features described in the embodiments are necessarily essential to the solution of the invention.

[0019] Figure 1 shows a schematic configuration of the first embodiment of the service utilization identification system (also simply called the system) 1. System 1 is a network system for analyzing a website (also simply called a site) to identify the services used on that site and providing information about the identified services to a user terminal 90 used by the website administrator. System 1 comprises an analysis device 10, a service utilization identification device 50, and a reference device 80. System 1 may further comprise a site database (site DB) 20, an analysis item database (analysis item DB) 40, a service database (service DB) 60, and a service utilization database (service utilization DB) 70. These are connected to each other so as to be able to communicate with each other via a network 99. Note that a database is also referred to as a DB.

[0020] Network 99 is a communication network that connects the analysis device 10, the service identification device 50, the reference device 80, and various databases such as the site database 20 in a manner that enables them to communicate with each other. Network 99 is, for example, the Internet, but is not limited to this. Any communication network that enables communication between these devices and databases may be used, such as a local area network or telephone line, or a network in which multiple communication networks coexist.

[0021] The server 30 to be analyzed is the server that operates the site to be analyzed, which is the target of identifying the services being used. Multiple sites may be analyzed, not just one. In such cases, system 1 accesses multiple servers 30 via network 99. For simplicity, this example shows only one server 30.

[0022] The user terminal 90 is, for example, a terminal device used by the administrator of a website operated by the analysis target server 30. The terminal device may be a computer terminal such as a personal computer, or a mobile terminal such as a smartphone or tablet computer. The user terminal 90 is equipped with a display 91 such as an LCD display and functions as a client terminal that communicates with the reference device 80 to acquire information such as the services used on the website and displays it on the display 91. Multiple user terminals 90, each owned by multiple users, may be included in the system 1, and multiple users may be able to use the system 1.

[0023] The analysis device 10 is a computer device that reads pages within the target site, sends an HTTP / HTTPS request (also simply called a request) to the target server 30 operating the site using a virtual browser, analyzes the received HTTP / HTTPS response (also simply called a response) to extract cookies or external communication URLs, retrieves data stored in the virtual browser's web storage, and registers these retrieved results as analysis items. The analysis items can be used by the service identification device 50, which will be described later. The analysis device 10 has a central processing unit (CPU) and a communication device (neither of which are shown). The analysis device 10 may also be implemented using a cloud (multiple distributed servers or multiple subsystems, etc.). The CPU executes an analysis program to analyze one or more pages within the target site and activates the function of extracting cookies issued on each page, web storage set, and external communication URLs of external communications that occur. The functional configuration of the analysis device 10 will be described later. The analysis program is stored in ROM (not shown), for example, and read by the CPU, or stored in a storage medium such as a CD-ROM, and then read by the CPU using a reading device (not shown) and loaded into RAM to be started. The communication device is a device that can communicate with the service identification device 50, the reference device 80, and various databases via wired or wireless communication over the network 99, and can communicate using protocols such as TCP / IP as an example.

[0024] A virtual browser is a browser that runs on one or more independent virtual machines, or on a container that shares the kernel of the host OS. All the functions of commonly used browsers are also available in virtual browsers, and all the functions of browsers described herein apply to virtual browsers as well.

[0025] Figure 2 shows the functional configuration of the analysis device 10. The analysis device 10 includes an analysis target acquisition unit 11, an analysis execution unit 12, and an analysis item registration unit 13.

[0026] The analysis target acquisition unit 11 is a functional unit that acquires the site URL of the site to be analyzed from the site database 20. However, the method by which the analysis target acquisition unit 11 acquires the site URL is not limited to this; for example, the operator of system 1 may acquire it by inputting the site URL via an input device (not shown).

[0027] The site database 20 is a storage device in which various information, such as the site URL of at least one site to be analyzed, operated by the server 30 to be analyzed, is registered (stored). The storage device may include a hard disk drive (HDD) or the like.

[0028] Figure 3 shows an example of site URL information (URL information) for sites to be analyzed, registered in the site database 20. In this example, three site URLs, such as XXX.com, are registered as sites to be analyzed. Here, a URL generally consists of a scheme, domain, path, parameters, and fragment. The format of the site URLs to be registered in the site database 20 is not particularly limited; for example, the part of the URL after the path (path, parameters, and fragment) may be represented by a regular expression. This URL information may be registered by the operator of system 1 via an input device (not shown).

[0029] The analysis execution unit 12 is a functional unit that analyzes one or more pages within a site that is publicly accessible on a site URL, targeting a site to be analyzed (for example, "XXX.com") obtained from the site database 20 by the analysis target acquisition unit 11, and extracts cookies issued by one or more pages, web storage that is set, or external communication URLs of external communications that occur. The analysis execution unit 12 includes a site access unit 121, an analysis item extraction unit 122, a script execution unit 123, and a link extraction unit 124.

[0030] Here, a cookie is data stored by a browser, and there are two types: persistent cookies and session cookies. Persistent cookies are stored in the storage of the device on which the browser is running for a specified period even after the browser is closed, and are used to retain information such as the contents of the user's shopping cart and language settings. Session cookies are temporary cookies that exist only during the session period and are automatically deleted when the browser is closed, and are used to retain login information when the user moves between pages. Cookies are extracted by parsing the response header and retrieving the browser's cookie storage. Cookies have attributes such as the identifier userPref attribute, Name attribute such as sessionId attribute, Domain attribute (domain attribute) that manages the domain where the cookie is valid, Path attribute (path attribute) that manages the path where the cookie is valid, Expires / Max-Age attribute that manages the expiration date (deletion time) of the cookie, Secure attribute that manages whether it is sent only via HTTPS communication, HttpOnly attribute that manages whether it is prevented from accessing via JavaScript (registered trademark), and SameSite attribute that manages whether it is allowed to send cross-site requests.

[0031] Cookies without a specified domain attribute are only valid for the origin in which they are set. The origin consists of the domain, protocol (such as HTTP or HTTPS), and port number. For example, a cookie set on sub.example.com without a specified domain attribute is only valid on sub.example.com and will not be valid on example.com or other subdomains.

[0032] Cookies with a specified domain attribute are valid for the specified domain and its subdomains. For example, a cookie with the domain attribute example.com is valid for example.com and its subdomains and will be sent for all requests under the specified domain.

[0033] Cookies that do not specify a domain attribute, or that specify the same domain as the website being accessed, are called first-party cookies, while cookies that specify a different domain (external domain) are called third-party cookies.

[0034] Web storage refers to APIs for saving data in a browser, and there are two types: local storage and session storage. Local storage is an API for saving data until it is explicitly deleted within the browser. The data is stored in the browser's data storage area and can be retained even when the browser is closed. Data stored in local storage is shared within the same origin. Session storage is an API for saving data within the browser only for the duration of a single session. The data is stored in the memory area allocated by the browser and is deleted when the browser tab is closed. Note that data stored in web storage is also simply referred to as web storage.

[0035] An external communication URL is a URL designated as the destination for communications occurring on a page, and it belongs to a different domain than the domain of this page.

[0036] The site access unit 121 is a functional unit that uses a virtual browser to specify the site URL (the URL of the site's top page) and sends a request to the analysis target server 30, which operates the site to be analyzed, and receives a response from the analysis target server 30. The site access unit 121 further determines whether there are any link URLs that have not yet been specified among the link URLs extracted by the link extraction unit 124. If there are any link URLs that have not yet been accessed, the site access unit 121 specifies these link URLs and sends a request to the analysis target server 30, and receives a response from the analysis target server 30. By the site access unit 121 specifying link URLs and sending requests to the analysis target server 30 and receiving responses from the analysis target server 30, all pages that can be accessed from the top page can be recursively analyzed.

[0037] The analysis item extraction unit 122 is a functional unit that extracts cookies issued by one or more pages or external communication URLs of external communications generated from the response received by the site access unit 121, and further retrieves data stored in the web storage set in the virtual browser.

[0038] Figure 4 shows an example of data included in an HTTP response sent in response to a request sent to the server 30 to be analyzed (for example, the site URL "XXX.com" registered in the site database 20 in Figure 3). The HTTP / HTTPS response consists of a response line (status line), a response header, and a response body. In this example, the response line contains information 35 about the HTTP protocol version and status code, indicating that the version is HTTP / 1.1 and the status code is 200, meaning the request was processed successfully. The response header contains the date and time the response was generated and the cookie settings 31, indicating that this response was generated at 10:18:14 on June 9, 2024, and that the set cookie is available under the example.com domain. The response body contains an HTML document with a script tag 33 embedded in it. The code in the script tag 33 sends JSON data to https: / / example.com / api and displays the response on the console.

[0039] The analysis item extraction unit 122 is a functional unit that extracts cookies and web storage stored in the virtual browser from the virtual browser, and extracts the external communication URL of external communications that occurred on the site from the virtual browser's communication log. The analysis item extraction unit 122 may also obtain this information from response data. In this case, for example, the analysis item extraction unit 122 extracts the cookie setting 31 "sessionId_app1=abc123; Domain=example.com;" from the response header of the data shown in Figure 4, and the external communication URL setting 32 "https: / / example.com / api" from the response body. Note that the method of extracting information contained in the virtual browser's cookies, web storage, communication log, or response is not particularly limited, and it is possible to extract the information by calling an API such as JavaScript (registered trademark), Python, or Java (registered trademark) from an interface driver that operates the virtual browser.

[0040] The script execution unit 123 is a functional unit that executes a script using a virtual browser if the response sent by the server 30 to be analyzed contains a script. Scripts are generally written in HTML documents, and HTML documents are included in the response body of the HTTP response (see script tag 33 in Figure 3). The execution result of the script can be confirmed, for example, by logs output from the interface driver that operates the virtual browser. This allows for confirmation of the success or failure of the script execution.

[0041] The link extraction unit 124 is a functional unit that extracts the page URL of the linked page from the response sent by the server 30 to be analyzed. The page URL is contained in the HTML document, and the HTML document is included in the response body of the HTTP response (see Figure 4). In this example, the link URL of the link to "page1.html" on the page is extracted by extracting the link tag 34 from the response body. This allows the site access unit 121 to access the linked page.

[0042] When the analysis item registration unit 13 extracts, by the analysis item extraction unit 122, the cookies issued by pages or the external communication URLs of external communications generated from pages within the analysis target site, or when it acquires data from the set web storage, it associates the site URL with the cookies issued by the pages within the site, the set web storage, or the external communication URLs of external communications generated, and registers them in the analysis item database 40 so that they can be acquired by the usage service identification device 50. It is a functional unit for this registration.

[0043] The analysis item database 40 is a storage device in which the correspondence between the site URL and the cookies issued by the pages within the site, the set web storage, or the external communication URLs generated from the pages is registered (stored) by the analysis item registration unit 13. It may have a hard disk drive (HDD) or the like as the storage device.

[0044] FIG. 5 shows an example of analysis information in which the site URL registered in the analysis item database 40 is associated with the cookies issued by the pages within the site, the set web storage, or the external communication URLs generated on the pages. The analysis item database 40 has three tables associating the site URL with the cookies, the site URL with the web storage, and the site URL with the external communication URL. Note that the analysis information may be managed in one table or by other methods.

[0045] The upper table shows the analysis information of the cookies. The analysis information of the cookies includes a site URL (Site URL) column, a page URL (Page URL) column of the page that issued the cookie, a Name attribute (cookie name) "Name" column of the cookie, a Domain attribute "Domain" column, and a control classification "Control Type" column. In this example, the page URL "XXX.com / " of the page with the site URL "XXX.com", the Name attribute "sessionId_app1" of the cookie issued by this page, the Domain attribute "example.com" (see the cookie setting 31 in FIG. 4), and the control classification "3" of this cookie rd"Party Cookie" is registered in association. In addition to these, other attributes that a cookie can have may be registered in the table.

[0046] The middle table shows the analysis information of web storage. The analysis information of web storage includes a Site URL column, a Page URL column of the page where the web storage is set, an Origin "Origin" column, and a Storage Type "Storage Type" column. In this example, the Page URL "XXX.com / XXX" of the page with the Site URL "XXX.com", the Origin "https: / / example1.com" of the web storage set by this page, and the Storage Type "local Storage" are registered in association. In addition to these, other information that the web storage can have, such as Key attributes, may be registered in the table.

[0047] The bottom table shows the analysis information of external communication URLs. The analysis information of external communication URLs includes a Site URL column, a Page URL column of the page where the web storage is set, and an External URL "External URL" column. In this example, the Page URL "XXX.com / YYY" of the page with the Site URL "XXX.com" and the External URL "http: / / anotherdomain1.com" of the external communication that occurs on this page are registered in association. Also, the Page URL "XXX.com / ZZZ" of the page with the Site URL "XXX.com" and the External URL "http: / / anotherdomain2.com" of the external communication that occurs on this page are registered in association.

[0048] According to the analysis device 10 of this embodiment, an analysis target acquisition unit 11 acquires the site URL of the site to be analyzed, an analysis execution unit 12 analyzes one or more pages within the site published at the site URL and extracts cookies issued by one or more pages, web storage set, or external communication URLs of external communications that occur, and an analysis item registration unit 13 associates the site URL with the cookies, web storage, or external communication URLs issued on the pages within the site and registers them so that they can be acquired by the service usage identification device described later. As a result, it is possible to extract cookies issued by one or more pages within the site published at the site URL, web storage set, or external communication URLs of external communications that occur, and to register this data for each site so that it can be acquired by the service usage identification device 50. Not only can the services used by the site to be analyzed be listed and registered, but it is also possible to analyze and examine whether cookies, web storage, or external transmissions are used to access the services used.

[0049] Figure 6 shows the flow of the analysis method performed by the analysis device 10.

[0050] In step S11, the analysis device 10 (analysis target acquisition unit 11) acquires the site URL of the site to be analyzed from the site database 20. There may be multiple sites to be analyzed. As mentioned above, the site database 20 has site URL information (URL information) of the sites to be analyzed registered in it. The URL information may also be acquired by the operator of system 1 via an input device (not shown).

[0051] In step S12, the analysis device 10 (analysis execution unit 12) analyzes the pages within the site published at the site URL and extracts all cookies issued by the pages, web storage settings, or external communication URLs for any external communications that occur. It also extracts all link URLs. First, the site access unit 121 uses a virtual browser to send a request to the analysis target server 30, which operates the analysis target site, specifying the site URL (the URL of the site's top page) or the page URL of the linked page extracted by the link extraction unit 124, and receives a response from the analysis target server 30. Next, the analysis item extraction unit 122 extracts cookies issued by one or more pages or external communication URLs for any external communications that occur from the response received by the site access unit 121, and further obtains data stored in the web storage set in the virtual browser. After that, if the response sent by the analysis target server 30 contains a script, the script execution unit 123 executes the script using the virtual browser. Then, the link extraction unit 124 extracts the page URL of the linked page from the response sent by the server 30 to be analyzed.

[0052] This extracts, for example, cookies with the Name attribute "sessionId_app1" and Domain attribute "example.com" issued by a page with the URL "XXX.com / " on the site being analyzed (see Cookie Settings 31 in Figure 4). Details of the extraction are as described above.

[0053] In step S13, the analysis device 10 (site access unit 121) determines whether there are any link URLs that have not yet been specified among the link URLs extracted by the link extraction unit 124. If there are any link URLs that have not yet been specified, the device returns to step S12; otherwise, it proceeds to S14.

[0054] In step S14, the analysis device 10 (site access unit 121) determines whether there are any unspecified site URLs among the site URLs extracted by the analysis target acquisition unit 11. If there are unspecified site URLs, for example, if the analysis of XXX.com (see Figure 3) has been completed but the analysis of YYY.com and ZZZ.com (see Figure 3) has not yet been completed, the device returns to step S12. If there are no unspecified site URLs (if the analysis of all analysis target sites has been completed), the device proceeds to step S15.

[0055] In step S15, the analysis device 10 (analysis item registration unit 13) associates the site URL with a cookie, web storage, or external communication URL and registers it in the analysis item database 40 (see Figure 5) so that it can be acquired by the service user identification device 50 (acquired by the service user identification method described later). As a result, for example, the site URL "XXX.com / " and the cookie with the Name attribute "sessionId_app1" and domain attribute "example.com" issued by a page on this site (see cookie settings 31 in Figure 4) are associated and registered. In this way, all analysis information is accumulated in the analysis item database 40. Details of the accumulation of analysis information are as described above.

[0056] According to the analysis method of this embodiment, the analysis method is performed by a computer and comprises the steps of: obtaining the site URL of the site to be analyzed; analyzing one or more pages within the site published at the site URL and extracting cookies issued by one or more pages, web storage set, or external communication URLs of external communications that occur; and associating the site URL of the site to be analyzed with the cookies issued by the pages within the site to be analyzed, the web storage set, or external communication URLs that occur on the pages, and registering them so that they can be obtained by the service usage identification method described later. This makes it possible not only to list and register the services used on the site to be analyzed, but also to analyze and examine which means such as cookies and web storage are used to access the services.

[0057] The service utilization identification device 50 is a computer device that identifies the services used by the site under analysis. The service utilization identification device 50 has a CPU and a communication device (neither of which are shown in the diagram). The service utilization identification device 50 may be implemented using a cloud (multiple distributed servers or multiple subsystems, etc.). The CPU performs the function of identifying the services used by the site under analysis by executing a service utilization identification program. The functional configuration of the service utilization identification device 50 will be described later. The service utilization identification program is stored in ROM (not shown), for example, and read by the CPU, or stored in a storage medium such as a CD-ROM, and then read by the CPU using a reader (not shown) and loaded into RAM to be activated. The communication device is a device that can communicate with the analysis device 10, the reference device 80, and various databases via wired or wireless communication over the network 99, and can communicate using protocols such as TCP / IP as an example.

[0058] Figure 7 shows the functional configuration of the service utilization identification device 50. The service utilization identification device 50 includes an analysis item acquisition unit 51, a service utilization identification unit 52, and a service utilization registration unit 53.

[0059] The analysis item acquisition unit 51 is a functional unit that acquires analysis items (correspondence information registered in each of the one or more rows shown in Figure 5) from the analysis item database 40, which include the correspondence between the page URL of the site to be analyzed and the cookies issued by at least one page within the site to be analyzed, the web storage set, or the external communication URL generated on the page. The analysis item acquisition unit 51 acquires analysis items one by one from the analysis item database 40 and transmits them to the service identification unit 52. The analysis item acquisition unit 51 makes it possible to use analysis items analyzed by a separate device (i.e., the analysis device 10) from the service identification device 50.

[0060] The Service Identification Unit 52 is a functional unit that matches cookies, web storage, or external communication URLs included in each analysis item acquired from the analysis item database 40 by the analysis item acquisition unit 51 with the service database 60, and identifies the matching data and corresponding service as a service used on the site. The Service Identification Unit 52 includes an external communication URL matching unit 521, a cookie matching unit 522, and a web storage matching unit 523. Here, a service refers to an external service such as an advertising service or an access analysis service that is executed when a request is sent specifying an external communication URL.

[0061] The service database 60 is a storage device in which one or more service information entries are registered (stored) where cookies, web storage, and external communication URLs are each associated with a service. The storage device may include a hard disk drive (HDD), etc. Associating cookies, web storage, and external communication URLs with a service means associating them with a service ID, name, etc., that can uniquely identify the service. Furthermore, a service is not limited to being represented by its name (referred to as the service name), but may also be represented by its ID. In this embodiment, as an example, a service is represented by its service name.

[0062] Figure 8A shows a portion of the service information registered in the service database 60. The service database 60 has three tables that associate service names with cookies, service names with web storage, and service names with external communication URLs.

[0063] The table in the upper section shows service information that associates cookies with services. This service information includes a Service Name column, a Name column for the cookie's Name attribute (cookie name), and a Domain attribute column. In this example, the service name "InsightPulse" is associated with a cookie whose Name attribute is "app1" and whose Domain attribute is "example.com". In addition to these, the table may also register other attributes that a cookie may have.

[0064] The middle table displays service information that associates web storage with a service. This service information includes a Service Name column and an Origin column for the web storage. In this example, the service name "MetricVision" is associated with the Web Storage Origin "https: / / example1.com" used by the service indicated by this service name. In addition to this, the table may also register other information that the web storage may have, such as Key attributes.

[0065] The table below shows service information that associates external communication URLs with services. This service information includes a "Service Name" column and an "External URL" column. In this example, the service name "AnalyticaFlow" is associated with the external communication URL "anotherdomain2.com" which is specified for accessing the service indicated by this service name.

[0066] In addition to service names, other service information may also be registered in the service database 60. Other service information may include, for example, the type of service such as advertising or access analysis, or the service provider of an external service.

[0067] The external communication URL matching unit 521 is a functional unit that, when an analysis item obtained from the analysis item database 40 includes an external communication URL, extracts data that at least partially matches the external communication URL and the corresponding service name from the service database 60, and obtains this service name as the service to be used. For example, the external communication URL matching unit 521 obtains the data from the second row of the table below that has "anotherdomain2.com" in the ExternalURL column from the analysis information registered in the analysis item database 40 (see Figure 5), performs a partial match search on the ExternalURL column of the service information below registered in the service database 60 using "anotherdomain2.com" as the key (see Figure 8A), and obtains the service name "AnalyticaFlow" from the first row of service information whose ExternalURL column value matches "anotherdomain2.com" as the service to be used.

[0068] The cookie matching unit 522 is a functional unit that, when an analysis item obtained from the analysis item database 40 includes a cookie, extracts services from the service database 60 that at least partially match the cookie in the Name attribute, and, if necessary, extracts data from the service database 60 that at least partially match the cookie in the Name attribute and completely match the Domain attribute, and acquires this service as a service to be used. Here, "if necessary" means, for example, when the type of cookie is a third-party cookie. Furthermore, if there are multiple data in the cookie data of the analysis item that at least partially match in the Name attribute and completely match in the Domain attribute, the cookie matching unit 522 acquires the most frequent service among the multiple services indicated by them as a service to be used.

[0069] Figure 8B shows a portion of an example of service information that associates cookies with services and is registered in the service database 60. In this example, the cookie matching unit 522 extracts three cookies that specify InsightPulse and one cookie that specifies Service2, which exactly match the domain attribute example.com of the cookie in the first row of the analysis item obtained from the upper table of the analysis item database 40 (see Figure 5). Among these, InsightPulse is the service whose Name attribute matches the Name attribute portion app1 of the analysis item the most, so the cookie matching unit 522 obtains InsightPulse as the service being used. Cases in which cookies with matching domain attributes are distinguished by the Name attribute include, for example, cases where InsightPulse manages the login status of the entire platform, and Service2 manages sub-services within the platform. The cookie matching unit 522 can identify the service being used even if there are multiple services that could be accessed by a given cookie.

[0070] The web storage matching unit 523 is a functional unit that, when web storage is included in the analysis items obtained from the analysis item database 40, extracts the service associated with the data in the service database 60 that has a partial match in the origin of the web storage, and acquires this service as a service. For example, the web storage matching unit 523 obtains the first row of analysis items from the middle table of the analysis item database 40, extracts the data from the first row of the middle table of the service database 60 where the origin https: / / example1.com included in it has a partial match (completely unique in this example), and acquires the corresponding service MetricVision as a service to be used.

[0071] The web storage matching unit 523 may extract services associated with data whose Origin attribute is an exact match. Alternatively, it may extract services associated with data whose Origin attribute is a partial or exact match, as well as whose Key attribute is a partial or exact match.

[0072] The Service Registration Unit 53 is a functional unit that, if the Service Identification Unit 52 can identify the service name, registers the site URL and the service used in the Service Database 70. The Service Registration Unit 53 also registers cookies, web storage, or external communication URLs for which the service name could not be identified as data not associated with a service (e.g., Unknown) in the Service Database 70. The Service Registration Unit 53 allows the identified service information to be stored for use by other devices. It can also detect cookies, etc., that are not associated with a service, i.e., cookies that are not functioning.

[0073] The service database 70 is a storage device that registers site URLs and the service names of the services used on those sites. The storage device may include a hard disk drive (HDD) or the like.

[0074] Figure 9 shows an example of service information registered in the service database 70 by the service registration unit 53. The service information is registered in a table format with a "UsingServiceName" column and a "Site URL" column. In this example, the aforementioned site URL "XXX.com" is associated with the service name "InsightPulse" which has been identified as a service used on this site, the site URL "XXX.com" is associated with the service name "MetricVision" which has been identified as a service used on this site, and the aforementioned site URL "XXX.com" is associated with the service name "AnalyticaFlow" which has been identified as a service used on this site. Since the service corresponding to the external communication URL used by the site URL "XXX.com" could not be identified, the site URL "XXX.com" is associated with "Unknown", meaning the service used is unknown.

[0075] According to the service identification device 50 of this embodiment, an analysis item acquisition unit 51 acquires analysis items including the correspondence between the page URL of at least one page within the site to be analyzed and a cookie issued on at least one page, a web storage set, or an external communication URL of an external communication that occurs; a service identification unit 52 matches the analysis items with a service database and identifies the service corresponding to the cookie, web storage, or external communication URL included in the analysis items as a service used at the site to be analyzed; and a service registration unit 53 registers the site URL in correspondence with the service used. Thus, the device can acquire cookies, web storage, or external communication URLs for each site to be analyzed by the analysis device 10, identify the corresponding service used, and register the identified service used in the service database 70.

[0076] Figure 10 shows the flow of the service identification method performed by the service identification device 50.

[0077] In step S21, the service identification device 50 (analysis item acquisition unit 51) acquires all analysis information from the analysis item database 40 (see Figure 5) that has a correspondence between a cookie, web storage, or external communication URL and the site URL of the site to which the analysis item belongs.

[0078] In step S22, the service usage identification device 50 (service usage identification unit 52) ​​matches the analysis items with the service database 60 (see Figures 8A and 8B) to identify the services corresponding to the cookies, web storage, or external communication URLs included in the analysis items as services used on the site being analyzed. First, the external communication URL matching unit 521 extracts data from the service database 60 that at least partially matches the external communication URLs included in the analysis items obtained from the analysis item database 40, and the services that correspond to them. Next, the cookie matching unit 522 extracts data from the service database 60 that at least partially matches the Name attribute and completely matches the Domain attribute of the cookies included in each of the analysis items obtained from the analysis item database 40, and the services that correspond to them, and acquires these services as services used. Here, if there are multiple data in the cookie data of the analysis items that at least partially match the Name attribute and completely match the Domain attribute, the cookie matching unit 522 acquires the most frequent service among the multiple services indicated by them as the service used. Furthermore, the web storage matching unit 523 extracts services from the service database 60 that are associated with data where the Origin attribute of the web storage included in each analysis item obtained from the analysis item database 40 partially matches, and acquires these services as services. Details are as described above. Thus, it is desirable to perform the matching with the service database 60 in the order of matching external communication URLs, matching cookies, and then matching web storage. The certainty of service identification is highest with matching external communication URLs, followed by cookies, and finally web storage, so efficient identification is possible by performing the matching in this order.

[0079] For example, for the analysis information in the second row of the lower table of the analysis item database 40 (see Figure 5) (URL column "XXX.com / ZZZ / ", ExternalURL column "anotherdomain2.com"), the service database 60 (see Figure 8A) is searched using the external URL "anotherdomain2.com" as the key, and the service name "AnalyticaFlow" is obtained as the service being used based on the information in the first row of the lower table. Similarly, for the analysis information in the first row of the upper table of the analysis item database 40 (see Figure 5) (URL column "XXX.com / ", COOKIE column "app1; domain=example.com"), the service database 60 (see Figure 8B) is searched, and three cookies that exactly match the domain attribute example.com and whose Name attribute partially matches app1, specifying InsightPulse, are extracted, thereby obtaining InsightPulse as the service being used. Furthermore, the analysis item in the first row is obtained from the middle table of the analysis item database 40 (see Figure 5), and the data in the first row of the middle table of the service database 60 (Figure 8A) where the Origin https: / / example1.com contained in it partially matches (completely unique in this example) is extracted, and the corresponding service MetricVision is obtained as the service used. Details of obtaining the service used are as described above.

[0080] In step S23, the service identification device 50 (service registration unit 53) registers service information, which associates the site URL with the service used, in the service database 70 (see Figure 9). As a result, for example, the site URL "XXX.com" is associated with the service name "InsightPulse" (see first line of Figure 9), the service name "AnalyticaFlow" (see fourth line of Figure 9), and the service name "MetricVision" (see second line of Figure 9). This allows for the accumulation of service information. Details of the accumulation of service information are as described above.

[0081] In step S24, the service identification device 50 (service registration unit 53) determines whether there is any unregistered analysis information. If there is, the process returns to step S21; otherwise, it terminates. This allows all analysis information to be registered.

[0082] According to the service identification method of this embodiment, the service identification method is executed by a computer and comprises the steps of: acquiring analysis items including the correspondence between a site URL within the site to be analyzed and a cookie, web storage, or external communication URL issued on at least one page within the site to be analyzed; matching the analysis items with a service database to identify the service name corresponding to the cookie, web storage, or external communication URL included in the analysis items as a service used on the site to be analyzed; and registering the site URL and the service in association. The service database contains data that pairs each of the cookie, web storage, and external communication URL with the service name. With this, it is possible to acquire cookies, web storage, or external communication URLs for each site analyzed by the analysis device 10, identify the corresponding service, and register the identified service in the service database 70.

[0083] The reference device 80 is a computer device that outputs services used on the target site, associating them with cookies, web storage, or external communication URLs for accessing those services. The reference device 80 includes a CPU and a communication device (neither of which are shown in the diagram). The reference device 80 may be implemented using a cloud (multiple distributed servers or multiple subsystems, etc.). The CPU activates the function of outputting services used on the target site by executing a service reference program. The functional configuration of the reference device 80 will be described later. The service reference program is stored in ROM (not shown), for example, and read by the CPU, or stored in a storage medium such as a CD-ROM, and then read by the CPU using a reader (not shown) and loaded into RAM to be activated. The communication device is a device that can communicate with the analysis device 10, the service identification device 50, and various databases via wired or wireless communication over the network 99, and can communicate using protocols such as TCP / IP as an example.

[0084] Figure 11 shows the functional configuration of the reference device 80. The reference device 80 includes a service reference unit 81 and an analysis item reference unit 82.

[0085] The service reference unit 81 is a functional unit that outputs the services used by the site to the user terminal 90. The output here may be in the form of output to the user terminal 90's display 91, in the form of transmission to the user terminal 90 as a file, or in any other form. In addition to the services used, the service reference unit 81 may also output cookies, web storage, or external communication URLs corresponding to the services used to the user terminal 90. The service reference unit 81 includes a service acquisition unit 811, a third analysis item acquisition unit 812, and a service output unit 813.

[0086] The service acquisition unit 811 is a functional unit that acquires service usage information registered by the service usage identification device 50 as services used at the site to be analyzed from the service usage database 70. For example, if "XXX.com" is specified as the site to be analyzed, the service acquisition unit 811 acquires all rows from the service usage information registered in the service usage database 70 (see Figure 9) that contain "XXX.com" in the URL column.

[0087] The analysis item acquisition unit (an example of the third analysis item acquisition unit) 812 is a functional unit that, for all service usage information acquired by the service usage acquisition unit 811, uses the service usage name as a key to acquire cookies, web storage, or external communication URLs corresponding to the service used from the service database 60. For example, the analysis item acquisition unit 812 uses the service usage name "AnalyticaFlow" from the service usage information acquired by the service usage acquisition unit 811 as a key to extract service information with a matching service name from the service database 60 shown in Figure 8A, and acquires the external communication URL "anotherdomain2.com" included in this service information.

[0088] The service usage output unit 813 is a functional unit that outputs the service usage acquired by the service usage acquisition unit 811 to the user terminal 90. The service usage output unit 813 further outputs a cookie, web storage, or external communication URL corresponding to the service usage acquired by the analysis item acquisition unit 812.

[0089] Figure 12 shows an example of the display screen of the display 91 showing cookies, web storage, or external communication URLs corresponding to the services used, acquired by the service acquisition unit 811. The screen has a target site display unit 911 and a service usage display unit 912. When a user specifies "XXX.com" as the target URL in the target site display unit 911, the reference device 80 displays the site URL "XXX.com" in the target site display unit 911 and also displays in the service usage display unit 912 the service name used on "XXX.com" acquired by the service acquisition unit 811 from the service usage database 70, and the cookies, web storage, or external communication URLs acquired by the analysis item acquisition unit 812 from the service database 60 as corresponding to that service. As a result, for example, it is displayed that the service InsightPulse is used on the site "XXX.com", and that the cookie specifying InsightPulse has a Name attribute name of app1 and a domain attribute value of example.com.

[0090] The analysis item reference unit 82 is a functional unit that outputs the site URL (which may also be the page URL of each page) and the corresponding cookie, web storage, or external communication URL to the user terminal 90. The output here may be in the form of output to the user terminal 90's display 91, sent to the user terminal 90 as a file, or in any other format. The analysis item reference unit 82 includes an analysis item acquisition unit 821 and an analysis item output unit 822.

[0091] The analysis item acquisition unit (an example of a second analysis item acquisition unit) 821 is a functional unit that refers to the analysis item database 40 and acquires the site URL (which may also be the page URL of each page) and the cookie, web storage, or external communication URL corresponding to the site URL. For example, the analysis item acquisition unit 821 acquires analysis information from the first row of the analysis item database 40 shown in Figure 5, where the page URL is "XXX.com", the Name attribute name is app1, and the domain attribute is example.com.

[0092] The analysis item output unit 822 is a functional unit that outputs the site URL (which may also be the page URL of each page) acquired by the analysis item acquisition unit 821, along with the corresponding cookie, web storage, or external communication URL, to the user terminal 90.

[0093] Figure 13 shows an example of a display screen on a display 91 that shows the site URL (which may also be the page URL of each page) acquired by the analysis item acquisition unit 821, along with the corresponding cookie, web storage, or external communication URL. The screen has a target site display unit 913 and an analysis item display unit 914. When a user specifies "XXX.com" as the target URL in the target site display unit 913, the reference device 80 displays the site URL "XXX.com" in the target site display unit 913 and also displays the cookie, web storage, or external communication URL acquired by the analysis item acquisition unit 821 from the analysis item database 40 corresponding to the page URL "XXX.com" in the analysis item display unit 914. As a result, for example, it is displayed that a cookie with the Name attribute name app1 and the domain attribute example.com has been issued for the top page "XXX.com" on the site "XXX.com".

[0094] According to the reference device 80 of this embodiment, the reference device 81 has a service reference unit 81 which includes a service acquisition unit 811 that acquires service usage registered by the service usage identification device 50 as a service used on the site to be analyzed, an analysis item acquisition unit 812 that acquires cookies, web storage, or external communication URLs associated with the service usage by referring to the service database 60, and a service output unit 813 that outputs the service usage and cookies, web storage, or external communication URLs to the user terminal 90, and an analysis item reference unit 82 which includes an analysis item acquisition unit 812 that acquires analysis items including the correspondence between the site URL of the site to be analyzed and the corresponding cookies, web storage, or external communication URLs, and an analysis item output unit 822 that outputs the site URL included in the analysis items and the corresponding cookies, web storage, or external communication URLs to the user terminal 90. This makes it possible to output the services used on the target site in association with the cookies, web storage, or external communication URLs for accessing the service usage. Not only can the service usage be listed, but the correspondence between the service usage and the analysis items can also be provided to the user.

[0095] Figure 14A shows the flow of the service referencing method performed by the reference device 80.

[0096] In step S31, the user specifies the target site they wish to access. In this example, the user specifies the target site from an input screen output by the reference device 80 to the display 91 of the user terminal 90. Figure 14B shows the target input screen on which the user specifies the target site. The analysis target input screen has an input form 915 and displays all rows of data from the site database 20 in a pull-down format for the user to select.

[0097] In step S32, the reference device 80 (the service acquisition unit 811 of the service reference unit 81) acquires all of the service services registered by the service identification method (see Figure 13) as services used at the analysis target site specified by the user in step S31 from the service database 70 (see Figure 9).

[0098] In step S33, the reference device 80 (the analysis item acquisition unit (an example of a third analysis item acquisition unit) 812 of the service reference unit 81) refers to the service database 60 (see Figure 8B) and acquires cookies, web storage, or external communication URLs using the service name as the key. For example, it acquires a cookie with the Name attribute name "app1" and the domain attribute value "example.com" corresponding to the service name "InsightPulse". Details of acquiring cookies, etc., are as described above.

[0099] In step S34, the reference device 80 (the service output unit 813 of the service reference unit 81) outputs the service, along with a cookie, web storage, or external communication URL, to the display of the user terminal 90 (see Figure 12). For example, the service name "InsightPulse" and the cookie corresponding to this service, with the Name attribute name "app1" and the domain attribute value "example.com", are output on a single line (see Figure 12).

[0100] The service reference method according to this embodiment is a method executed by a computer and includes the steps of: acquiring a service used by the aforementioned service identification method as a service used at the site to be analyzed; acquiring a cookie, web storage, or external communication URL associated with the service by referring to a service database; and outputting the service used and the cookie, web storage, or external communication URL. This makes it possible to output the services used at the target site in association with the cookie, web storage, or external communication URL for accessing the service. In addition to listing the services used within the site, it becomes possible to provide users with a list of services used and analysis items linked together.

[0101] Figure 15 shows the flow of the analysis information referencing method performed by the reference device 80.

[0102] In step S41, the user specifies the site to be analyzed that they wish to refer to. In this example, the user specifies the site to be analyzed from an input screen output by the reference device 80 to the display 91 of the user terminal 90. The analysis target input screen has an input form 915 and displays all rows of data from the site database 20 in a pull-down format (see Figure 14B).

[0103] In step S42, the reference device 80 (analysis item acquisition unit 821 of the service reference unit 81) acquires all analysis items registered by the analysis method (see Figure 6) as services used at the site to be analyzed from the analysis item database 40 (see Figure 5). For example, the analysis item acquisition unit 821 acquires analysis information from the first row of the upper table of the analysis item database 40 shown in Figure 5, where the site URL is "XXX.com", the Name attribute is app1, and the domain attribute is example.com.

[0104] In step S43, the reference device 80 (analysis item output unit 822 of the service reference unit 81) outputs all analysis information, which associates the site URL acquired by the analysis item acquisition unit 821 with cookies, web storage, or external communication URLs within the site, to the display of the user terminal 90 (see Figure 13). For example, the page URL "XXX.com" and the cookie issued on this page with the Name attribute name "app1" and domain attribute value "example.com" are output on a single line.

[0105] The analysis item referencing method according to this embodiment is a method executed by a computer and includes the steps of: acquiring analysis items registered by the aforementioned analysis method as analysis information of pages within the site to be analyzed; and outputting all acquired analysis information to the user terminal 90. This makes it possible to output the analysis items of the target site. It becomes possible to provide the user with a list of what analysis items the target site has.

[0106] The service identification system 1 according to this embodiment comprises an analysis device 10, a service identification device 50, a reference device 80, and a service database 60 in which data is registered, with cookies, web storage, and external communication URLs each associated with a service name. With this, the analysis device 10 extracts analysis items, the service identification device 50 identifies the service used on the site by matching these analysis items with the service database 60, and the reference device 80 provides information on this service to the user.

[0107] Furthermore, according to the service identification system 1 of this embodiment, the system includes: an analysis device 10 that acquires the site URL of a site to be analyzed, analyzes one or more pages within the site published at the site URL, extracts cookies issued by one or more pages, web storage that is set, or external communication URLs of external communications that occur, and registers the site URL of the page that issues cookies, sets web storage, or generates an external communication URL in association with the cookies issued by that page, web storage that is set, or external communication URLs that occur; a service identification device 50 that matches analysis items, including the correspondence between the site URL registered by the analysis device 10 and the cookies, web storage, or external communication URLs, with a service database 60, identifies the services corresponding to the cookies, web storage, or external communication URLs included in the analysis items as service used on the page at the site URL, and registers the site URL and the service in association; and a service database 60 in which data is registered in which each of the cookies, web storage, and external communication URLs is associated with a service. This makes it possible to manage external services used by a site in conjunction with cookies and other data issued to access those external services.

[0108] Furthermore, the service identification system 1 according to this embodiment includes an analysis item database 40 in which the correspondence between site URLs and cookies, web storage, or external communication URLs is registered by an analysis device, and an analysis item database 40 in which analysis items including the correspondence are acquired by the analysis device 10.

[0109] Furthermore, the service usage identification system 1 according to this embodiment further includes a reference device 80 that acquires service usage registered by the service usage identification device 50 as a service used at the site to be analyzed, and outputs the service usage.

[0110] Furthermore, the service identification system 1 according to this embodiment further comprises a service identification device 50 that registers site URLs and services in association with each other, and a reference device 80 that acquires the services.

[0111] Furthermore, the service identification system 1 according to this embodiment further comprises a site database 20 in which the site URL of at least one site to be analyzed is registered, and the site URL is acquired by the analysis device 10.

[0112] Furthermore, according to the service identification method of this embodiment, the method includes the steps of: obtaining the site URL of the site to be analyzed; analyzing one or more pages within the site published at the site URL to extract cookies issued by one or more pages, web storage set, or external communication URLs of external communications that occur; registering the site URL of the page that issues cookies, sets web storage, or generates an external communication URL in association with the cookies issued by that page, web storage set, or external communication URL that occurs; and matching the analysis items, including the correspondence between the site URL and cookies, web storage, or external communication URLs registered in the registration step, with the service database 60 to identify the services corresponding to the cookies, web storage, or external communication URLs included in the analysis items as services used on the pages at the site URL, and registering the site URL and the services used in association. The service database 60 contains data in which each of the cookies, web storage, and external communication URLs is associated with a service. This makes it possible to manage external services used by a site in conjunction with cookies and other data issued to access those external services.

[0113] Furthermore, according to the program of this embodiment, the following steps are performed on one or more computers: obtaining the site URL of the site to be analyzed, analyzing one or more pages within the site published at the site URL, extracting cookies issued by one or more pages, web storage set, or external communication URLs of external communications that occur, registering the site URL of the page that issues cookies, sets web storage, or generates an external communication URL in association with the cookies issued by that page, the web storage set, or the external communication URL that occurs, and matching the analysis items, including the correspondence between the site URL and cookies, web storage, or external communication URLs registered in the registration step, with the service database 60, identifying the services corresponding to the cookies, web storage, or external communication URLs included in the analysis items as services used on the pages at the site URL, and registering the site URL and the services used in association. The service database 60 is a database in which data is registered in which each of the cookies, web storage, and external communication URLs is associated with a service. This makes it possible to manage external services used by a site in conjunction with cookies and other data issued to access those external services.

[0114] (Second Embodiment) Figure 16 shows a schematic configuration of the service utilization identification system (also simply called the system) 1A of the second embodiment. System 1A is a network system for analyzing a site while determining security risks to identify the services being used on that site, and providing information about the identified services to a user terminal 90 used by, for example, a website administrator. System 1A comprises a security risk determination system 2, a service utilization identification device 50, and a reference device 80. System 1A may further comprise a service database (service DB) 60 and a service utilization database (service utilization DB) 70. The security risk determination system 2 comprises a proxy device 100, an analysis device 10, and a status reference device 300. The security risk determination system 2 may further comprise a status database 200, a site database 20, and an analysis item database 40. These are connected to each other so as to be able to communicate with each other via a network 99. Note that devices common to or corresponding to the devices in the first embodiment (analysis device 10, analysis target server 30, service utilization identification device 50, reference device 80, user terminal 90, site database 20, analysis item database 40, service database 60, service utilization database 70, user terminal 90) are denoted by the same reference numerals, and only the differences from the first embodiment will be described in detail (content common to or similar to the first embodiment will be referenced in this embodiment to avoid repetition of explanations).

[0115] The proxy device 100 is a computer device that acts as an intermediary between the server to be analyzed 30 and the analysis device 10 (virtual browser), analyzes the response from the server to be analyzed 30 to determine security risks, and forwards the response to the analysis device 10 (virtual browser) if it is determined that there are no security risks. The proxy device 100 has a central processing unit (CPU) and a communication device (neither of which are shown). The proxy device 100 may also be implemented using a cloud (multiple distributed servers or multiple subsystems, etc.). The CPU executes a security risk determination program to activate the function of analyzing the response from the server to be analyzed 30 and determining security risks. The functional configuration of the proxy device 100 will be described later. The security risk determination program is stored in ROM (not shown), for example, and read by the CPU, or stored in a storage medium such as a CD-ROM, and the CPU reads it using a reader (not shown) and expands it into RAM to start the program. The communication device is capable of communicating with various devices, databases, and the analysis target server 30 that constitute system 1A via network 99, either via wired or wireless communication. For example, it can communicate using protocols such as TCP / IP.

[0116] Figure 17 shows the functional configuration of the proxy device 100. The proxy device 100 includes a request determination unit 105, a request forwarding unit 101, a response analysis unit 102, a response return unit 103, a request blocking unit 106, and a response blocking unit 104.

[0117] The request determination unit 105 is a functional unit that receives requests sent from the virtual browser, determines the security risk of the request URL specified in the request, and determines that request URLs with security risks are abnormal and request URLs without security risks are normal. Here, the security risk determination may be performed, for example, by inputting the request URL into an existing external security determination service such as Google® Safe Browsing and obtaining the security risk determination result.

[0118] The request forwarding unit 101 is a functional unit that receives requests sent from the virtual browser and forwards them to the analysis target server 30 that operates the analysis target site. The analysis target site is a target site whose services used on the analysis target site are identified by the system 1A according to this embodiment. The virtual browser is a virtual device that is started by the analysis device 10 to send a request to the analysis target server 30 that operates the analysis target site, specifying the site URL of the analysis target site, and to receive a response from the analysis target server 30. The analysis target server 30 sends a response back to the proxy device 100 in response to receiving the request.

[0119] The response analysis unit 102 is a functional unit that receives and analyzes responses from the server 30 to be analyzed. This analysis includes detecting known malware, viruses, cross-site scripting and other malicious scripts from the content of the response using a security signature database, executing the code in the response (see script 33 in Figure 4) in a sandbox environment, and verifying whether the response header information is appropriate. If a malicious script is detected in the content of the response, if the code in the response behaves incorrectly in the sandbox environment, or if the response header information is inappropriate, a security risk is determined. Furthermore, if the status code included in the status code information 35 of the response sent from the server 30 to be analyzed is not 200, the response analysis unit 102 determines that the page included in the response is an inaccessible page.

[0120] The response return unit 103 is a functional unit that returns a response to the virtual browser. The response return unit 103 returns a response to the virtual browser that has been determined by the response analysis unit 102 to have no security risk. For example, if the response analysis unit 102 determines that there is no security risk in the external domain "example.com", the response return unit 103 returns the data shown in Figure 4 as the response.

[0121] The request blocking unit 106 blocks requests specifying a request URL when the request determination unit 105 determines that the request URL is abnormal. When the request blocking unit 106 determines that the request URL is abnormal, it generates a new response (i.e., an error response) indicating that the request URL has a security risk and sends it back to the virtual browser.

[0122] The response blocking unit 104 blocks communication with the site being analyzed when the response analysis unit 102 determines that the response has a security risk. The response blocking unit 104 further generates a new response (i.e., an error response) indicating that the page from which the request was sent by the request forwarding unit 101 has a security risk, and sends it back to the virtual browser.

[0123] Figure 18 shows an example of data included in an error response. An HTTP / HTTPS response consists of a response line (status line), a response header, and a response body. In this example, the response line contains HTTP protocol version and status code information 1001, indicating that the version is HTTP / 1.1 and the status code is 200. The response header contains the date and time the response was generated and connection information, indicating that this response was generated at 10:18:14 on June 9, 2024. The response body contains an HTML document, which contains blocked external domain information 1002, "Blocked domain: example.com".

[0124] The proxy device 100 according to this embodiment includes a request determination unit 105 that receives a request sent from a virtual browser and determines the security risk of the request URL specified in the request, a request forwarding unit 101 that forwards requests for which the request URL has been determined to be normal by the request determination unit 105 to a server 30 that operates the site to be analyzed, the site to be analyzed is a target site for which the services used on the site to be analyzed can be identified, a response analysis unit 102 that receives and analyzes the response from the server 30, and a response return unit 103 that returns the response to the virtual browser, thereby preventing the analysis device 10 from receiving a response that has a security risk.

[0125] Figure 19 shows the flow of the security risk determination method S100 performed by the proxy device 100.

[0126] In step S101, the proxy device 100 (request determination unit 105) receives a request sent from the virtual browser launched by the analysis device 10 and determines the security risk of the request URL specified in this request. The virtual browser is a virtual device launched by the analysis device 10 to send a request to the analysis target server 30 that operates the analysis target site, specifying the site URL of the analysis target site, and to receive a response from the analysis target server 30. The method for determining the security risk is as described above.

[0127] In step S102, if the proxy device 100 (request determination unit 105) determines that the requested URL has a security risk, in other words, that the requested URL is abnormal, the process proceeds to step S103. If the proxy device 100 (request determination unit 105) determines that the requested URL does not have a security risk, in other words, that the requested URL is normal, the process proceeds to step S104.

[0128] In step S103, the proxy device 100 (request blocking unit 106) blocks the request. The request blocking unit 106 further generates a new response (i.e., an error response) indicating that the request URL has a security risk and sends it back to the virtual browser. For example, if the request determination unit 105 determines that the request URL "example.com" has a security risk, the request blocking unit 106 generates the data shown in Figure 18 and sends it back as a response.

[0129] In step S104, the proxy device 100 (request forwarding unit 101) forwards the request, for which the request URL has been determined to be valid by the request determination unit 105, to the analysis target server 30 that operates the analysis target site. The analysis target site is a target site for which the services used on the analysis target site are identified by the system 1A according to this embodiment.

[0130] In step S105, the proxy device 100 (response analysis unit 102) receives and analyzes the response from the server 30 to be analyzed. The analysis method is as described above.

[0131] In step S106, the proxy device 100 (response analysis unit 102) determines whether or not there is a security risk in the response. If a security risk is determined to exist, the process proceeds to step S107; otherwise, the process proceeds to step S108.

[0132] In step S107, the proxy device 100 (response blocking unit 104) blocks the response from the site being analyzed. The response blocking unit 104 further generates a new response (i.e., an error response) indicating that the page included in the response has a security risk and sends it back to the virtual browser.

[0133] In step S108, the proxy device 100 (response return unit 103) returns a response to the virtual browser. For example, if the request determination unit 105 determines that the request URL is normal and the response analysis unit 102 does not determine that there is a security risk in the response, the response return unit 103 returns it as a response.

[0134] The security risk determination method according to this embodiment includes the steps of: receiving a request sent from a virtual browser and determining the security risk of the request URL specified in the request; a request step of forwarding the request, for which the request URL has been determined to be normal in the determination step, to the analysis target server 30 that operates the analysis target site, wherein the analysis target site is a target site for which the services used on the analysis target site are identified; receiving and analyzing the response from the server; and sending the response back to the virtual browser. This prevents the analysis device 10 from receiving a response that has a security risk.

[0135] Figure 20 shows the functional configuration of the analysis device 10. The device configuration of the analysis device 10 is as described above. The analysis device 10 includes an analysis target acquisition unit 11, an analysis execution unit 12, an analysis item registration unit 13, and a status registration unit 14. The analysis target acquisition unit 11 and the analysis item registration unit 13 are the same as those in the first embodiment described above.

[0136] The analysis execution unit 12 is a functional unit that targets the target site (e.g., "XXX.com") acquired from the site database 20 by the analysis target acquisition unit 11, analyzes one or more pages within the site that are publicly available on the site URL, and extracts cookies issued by each page, web storage that is set, or external communication URLs of external communications that occur. The analysis execution unit 12 includes a site access unit 121, a status extraction unit 125, an analysis item extraction unit 122, a script execution unit 123, and a link extraction unit 124.

[0137] The site access unit 121 is a functional unit that uses a virtual browser to specify the site URL of the site to be analyzed, sends a request to the proxy device 100, and receives a response from the analysis target server 30 that operates the analysis target site via the proxy device 100. The site access unit 121 further determines whether there are any link URLs that have not yet been specified among the link URLs extracted by the link extraction unit 124, and if there are any link URLs that have not yet been accessed, it specifies these link URLs and sends a request to the proxy device 100, and receives a response from the analysis target server 30 that operates the analysis target site via the proxy device 100. By the site access unit 121 specifying link URLs and sending requests to the proxy device 100, and receiving responses from the analysis target server 30 that operates the analysis target site via the proxy device 100, all pages that can be accessed from the top page of the analysis target site can be recursively analyzed.

[0138] The status extraction unit 125 is a functional unit that extracts security risks from the response received by the site access unit 121. The status extraction unit 125 may also extract the status code of the response. If the response received by the site access unit 121 is an error response, the status extraction unit 125 determines that the page to which the request was sent by the site access unit 121 has a security risk. By extracting the security risk and status code from the response received by the site access unit 121, the status extraction unit 125 can obtain the security risk of the page and broken links, etc. For example, if an error response (see Figure 18) is sent from a proxy device, the information 1002 indicating that the external domain URL was determined to be invalid will reveal that the requested page has a security risk. Note that the method for extracting the status code etc. included in the response is not particularly limited, and it is possible to extract it using APIs such as JavaScript®, Python, Java®, etc.

[0139] The analysis item extraction unit 122 is a functional unit that, when the status extracted by the status extraction unit 125 is normal (status code 200), extracts cookies issued by one or more pages or external communication URLs generated from the response received by the site access unit 121, and further acquires data stored in the web storage set in the virtual browser. The details of the processing are the same as those of the analysis item extraction unit 122 in the first embodiment.

[0140] The script execution unit 123 is a functional unit that executes a script using a virtual browser if the status extracted by the status extraction unit 125 is normal (status code 200) and the response sent by the proxy device 10 contains a script. The script is generally written in an HTML document, and the HTML document is included in the response body of the HTTP response (see script tag 33 in Figure 3). The result of the script execution can be confirmed, for example, by logs output from the interface driver that operates the virtual browser. This allows confirmation of whether the script was executed successfully or not.

[0141] The link extraction unit 124 is a functional unit that extracts the page URL of the linked page from the response sent by the proxy device 100 when the status extracted by the status extraction unit 125 is normal (status code 200). The details of the processing are the same as those of the link extraction unit 124 in the first embodiment.

[0142] The status registration unit 14 registers the page URLs (which may also be site URLs) of one or more pages, along with the status codes and security risks extracted by the status extraction unit 125, in the status database 200. For example, if the site access unit 121 receives an error response (see Figure 18) to a request specifying the page URL "XXX.com", the status registration unit 14 registers the page URL "XXX.com", the status code "200", and the security risk "Present (1)" in the status database 200. If the site access unit 121 receives a response indicating successful processing to a request specifying the page URL "XXX.com / XXX", the status registration unit 14 registers the page URL "XXX.com / XXX", the status code "200" indicating success, and the security risk "None (0)" in the status database 200. When the site access unit 121 receives a response with status code "404" in response to a request specifying the page URL "XXX.com / ZZZ", it registers the page URL "XXX.com / ZZZ", the status code "404" indicating that the page could not be found, and the security risk "None (0)" in the status database 200. The status registration unit 14, which registers the page URL, the status code of the response to the request specifying the page URL, and the security risk in the status database 200, allows the security risk analysis results by the proxy device 100 to be recorded for use by other devices.

[0143] The status database 200 is a storage device in which the analysis item registration unit 13 registers (stores) status information, which associates the page URL of a page with the status code of the response to a request specifying that page URL and the presence or absence of security risks. The storage device may include a hard disk drive (HDD) or the like.

[0144] Figure 21 shows an example of status information registered in the status database 200. The status information is registered in a table format with columns for page URL (URL), status code (StatusCode), and security risk (SecurityRisk). In this example, for example, page URL "XXX.com" is associated with response code "200" indicating that a response was successfully returned from this page and "1" indicating that there is a security risk; page URL "XXX.com / XXX" is associated with response code "200" indicating that a response was successfully returned from this page and "0" indicating that there is no security risk; page URL "XXX.com / YYY" is associated with response code "200" for this page and "0" indicating that there is no security risk; and page URL "XXX.com / ZZZ" is associated with response code "404" indicating that the link to this page is broken and "0" indicating that there is no security risk. In addition to these, other information related to the status may also be registered in the status database 200. Other information includes, for example, the external domain that is causing the security risk, and the service name of the service specified by that external domain.

[0145] According to the analysis device 10 of this embodiment, the device includes an analysis target acquisition unit 11 that acquires the site URL of the site to be analyzed, and an analysis execution unit 12 that analyzes one or more pages within the site published at the site URL. The analysis execution unit 12 includes a site access unit 121 that uses a virtual browser to specify the site URL, sends a request to the proxy device 100, and receives a response from the proxy device 100. This allows the device to receive only responses that do not pose a security risk, thereby preventing infection by malware, etc. Furthermore, similar to the first embodiment, the service usage identification device 50 matches analysis items, including the correspondence between the site URL and cookies, web storage, or external communication URLs registered by the analysis device 10, with the service database 60. The service corresponding to the cookies, web storage, or external communication URL included in the analysis items is identified as a service used on the page at the site URL, and the site URL and the service usage are registered in association. Additionally, the reference device 80 can acquire the service usage registered by the service usage identification device 50 as a service used at the site to be analyzed, and output the service usage. Further details are as described in the first embodiment.

[0146] Figure 22 shows the flow of the analysis method performed by the analysis device 10.

[0147] In step S11, the analysis device 10 (analysis target acquisition unit 11) acquires the site URLs of all analysis target sites from the site database 20. As mentioned above, the site database 20 contains information on the site URLs of the analysis target sites (URL information). The URL information may also be acquired by the operator of system 1 via an input device (not shown).

[0148] In step S12, the analysis device 10 (analysis execution unit 12) analyzes the pages within the site published at the site URL and extracts all cookies issued by the page, web storage set, or external communication URLs generated. It also extracts all link URLs. First, the site access unit 121 uses a virtual browser to send a request to the proxy device 100, specifying the site URL (the URL of the site's top page) or the page URL of the linked page extracted by the link extraction unit 124. Upon receiving the request, the proxy device 100 executes the security risk determination method S100 (see Figure 19), and the site access unit 121 receives a response from the analysis target server 30 operating the analysis target site via the proxy device 100. Details of the security risk determination method S100 are as described above.

[0149] For example, if an error response (see Figure 18) is sent from the proxy device, the "200" contained in status code 1001 is obtained as the status code, and information 1002 indicating that the external domain URL was determined to be invalid is obtained to determine that the requested page has a security risk. If a normal response (see Figure 4) is sent via the proxy device, the "200" contained in status code information 35 is obtained as the status code, and since the response body does not contain information indicating that the external domain URL was determined to be invalid, it is obtained that the requested page does not have a security risk. Details are as described above.

[0150] Next, the status extraction unit 125 extracts security risks and status codes from the response received by the site access unit 121. If there are no security risks for the page to which the request was sent by the site access unit 121, the analysis item extraction unit 122 further extracts cookies issued by one or more pages or external communication URLs generated from the response received by the site access unit 121, and further retrieves data stored in the web storage set in the virtual browser. Subsequently, the script execution unit 123 executes the script using the virtual browser if the response sent by the proxy device 100 contains a script. Then, the link extraction unit 124 extracts the page URL of the linked page from the response sent by the proxy device 100.

[0151] In step S13, the analysis device 10 (site access unit 121) determines whether there are any link URLs that have not yet been specified among the link URLs extracted by the link extraction unit 124. If there are any link URLs that have not yet been specified, the device returns to step S12; otherwise, it proceeds to step S14.

[0152] In step S14, the analysis device 10 (site access unit 121) determines whether there are any site URLs that have not yet been specified among the site URLs extracted by the analysis target acquisition unit 11. If there are site URLs that have not yet been specified, for example, if the analysis of XXX.com (see Figure 3) has been completed but the analysis of YYY.com and ZZZ.com (see Figure 3) has not yet been completed, the process returns to step S12. If there are no unspecified site URLs (i.e., the analysis of all target sites has been completed), the process proceeds to step S15.

[0153] In step S15, the analysis device 10 (analysis item registration unit 13) associates the page URL of the page that issues the cookie, web storage, or external communication URL with the cookie, web storage, or external communication URL and registers it in the analysis item database 40 (see Figure 5) so that it can be acquired by the service usage identification device 50 (acquisition is possible by the service usage identification method described later). Details of the accumulation of analysis information are as described above.

[0154] In step S16, the analysis device 10 (status registration unit 14) registers the status code and security risk of the response to the request specifying the page URL of one or more pages in the status database 200. For example, if the site access unit 121 receives an error response (see Figure 18) to a request specifying the page URL "XXX.com", the status registration unit 14 registers the page URL "XXX.com", the status code "403", and the security risk "Yes (1)" in the status database 200. If the site access unit 121 receives a response indicating successful processing to a request specifying the page URL "XXX.com / XXX", the status registration unit 14 registers the page URL "XXX.com / XXX", the status code "200" indicating success, and the security risk "No (0)" in the status database 200. When the site access unit 121 receives a response with status code "404" in response to a request specifying the page URL "XXX.com / ZZZ", it registers the page URL "XXX.com / ZZZ", the status code "404" indicating that the page could not be found, and the security risk "None (0)" in the status database 200. In this way, status information is accumulated in the status database 200. Details of the accumulation of status information are as described above.

[0155] The analysis method according to this embodiment includes the steps of obtaining the site URL of the site to be analyzed, and analyzing one or more pages within the site published at the site URL. The analysis step includes the steps of specifying the site URL using a virtual browser, executing a security risk determination method, receiving a response, and extracting security risks from the response. As a result, the analysis device 10 can receive only responses without security risks, thereby preventing infection by malware, etc. Furthermore, similar to the first embodiment, the service usage identification method matches analysis items, including the correspondence between the site URL registered by the analysis method and cookies, web storage, or external communication URLs, with the service database 60. The service corresponding to the cookie, web storage, or external communication URL included in the analysis item is identified as a service used on the page at the site URL, and the site URL and the service usage can be registered in association. Additionally, the reference method can obtain the service usage registered by the service usage identification method as a service used at the site to be analyzed, and output the service usage. Details are as described in the first embodiment.

[0156] The reference device (status reference device) 300 is a computer device that outputs the page URL of a page within the target site, associated with the status of that page, such as its security risk. The reference device 300 includes a CPU and a communication device (neither of which are shown in the illustration). The reference device 300 may be implemented using a cloud (multiple distributed servers or multiple subsystems, etc.).

[0157] Figure 23 shows the functional configuration of the reference device 300. The reference device 300 includes a status acquisition unit 301 and a status output unit 302.

[0158] The status acquisition unit 301 is a functional unit that acquires the page URLs of one or more pages, the status codes of the responses to requests specifying the page URLs, and the security risks of the pages from the status database 200 registered by the analysis device 10. For example, the status acquisition unit 301 acquires data that associates the page URL "XXX.com" with the status code "200" and the security risk "Yes (1)" from the status database 200 (see Figure 21).

[0159] The status output unit 302 is a functional unit that outputs the page URLs of one or more pages, the status code of the response to a request specifying the page URLs, and the security risk of the pages to the user terminal 90. For example, the status output unit 302 outputs data that associates the page URL "XXX.com" acquired by the status acquisition unit 301 with the status code "200" and the security risk "Yes (1)". Note that the output here may be in a format that is displayed on the display 91 of the user terminal 90, a format that is sent to the user terminal 90 in file format, or any other format.

[0160] Figure 24 shows an example of the display screen of the display 91, which shows the page URL of each page acquired by the status acquisition unit 301, the status code of the response to the request specifying the page URL, and the security risk. The screen has a target site display unit 916 and a status information display unit 917. When a user specifies "XXX.com" as the target URL in the target site display unit 913, the reference device 300 displays the site URL "XXX.com" in the target site display unit 916 and displays the status code and security risk acquired by the status acquisition unit 301 from the status database 200 corresponding to the page URL "XXX.com" in the status information display unit 917. As a result, for example, it is displayed that the status code of the response to the request specifying the site "XXX.com" is "200", and that this page has a security risk.

[0161] According to the reference device 300 of this embodiment, a status acquisition unit 301 acquires the page URLs of one or more pages, the status codes of responses to requests specifying the page URLs, and the security risks of the pages from the status database 200 registered by the analysis device 10, and a status output unit outputs the page URLs of one or more pages, the status codes of responses to requests specifying the page URLs, and the security risks of the pages to the user terminal 90, thereby enabling notification of security risks of pages within the site and broken links to pages, etc., to the administrator of the site being analyzed.

[0162] Figure 25 shows the flow of the referencing method performed by the reference device 300.

[0163] In step S301, the user specifies the site to be analyzed that they wish to refer to. In this example, the user specifies the site to be analyzed from an input screen output by the reference device 301 to the display 91 of the user terminal 90. The analysis target input screen has an input form on the target site display unit 916 and displays all rows of data from the site database 20 in a pull-down format (see Figure 24). Here, let's assume the user selects the page URL of the site to be analyzed, "XXX.com".

[0164] In step S302, the reference device 300 (status acquisition unit 301) acquires the page URLs of one or more pages, the status codes of the responses to requests specifying the page URLs, and the security risks of the pages from the status database 200 registered by the analysis device 10. For example, the status acquisition unit 301 acquires data from the status database 200 (Figure 21) that associates the page URL "XXX.com" with the status code "200" and the security risk "Yes (1)". The details of the process are as described above.

[0165] In step S303, the reference device 300 (status output unit 302) outputs the page URLs of one or more pages, the status code of the response to the request specifying the page URLs, and the security risk of the pages (referred to as security risk information) to the display 91 of the user terminal 90 (see status information display unit 917 in Figure 24). For example, the status output unit 302 outputs data associating the page URL "XXX.com", the status code "200", and the security risk "Yes (1)". Note that the security risk information is not limited to being output to the display 91 of the user terminal 90; it may also be sent to the user terminal 90 in file format or in other formats. Details of the process are as described above.

[0166] According to the reference device 300 of this embodiment, the steps include obtaining the page URLs of one or more pages, the status codes of the responses to requests specifying the page URLs, and the security risks of the pages from the status database 200 registered by the analysis device 10, and outputting the page URLs of one or more pages, the status codes of the responses to requests specifying the page URLs, and the security risks of the pages to the user terminal 90, thereby enabling notification of security risks of pages within the site and broken links to pages, etc., to the administrator of the site being analyzed.

[0167] Various embodiments of the present invention may be described with reference to flowcharts and block diagrams, where a block may represent (1) a stage in a process in which an operation is performed, or (2) a section of a device having the role of performing the operation. Specific stages and sections may be implemented by dedicated circuits, programmable circuits supplied with computer-readable instructions stored on a computer-readable medium, and / or processors supplied with computer-readable instructions stored on a computer-readable medium. Dedicated circuits may include digital and / or analog hardware circuits, and may include integrated circuits (ICs) and / or discrete circuits. Programmable circuits may include reconfigurable hardware circuits, including logical AND, logical OR, logical XOR, logical NAND, logical NOR, and other logic operations, flip-flops, registers, memory elements such as field-programmable gate arrays (FPGAs), programmable logic arrays (PLAs), etc.

[0168] Computer-readable media may include any tangible device capable of storing instructions to be executed by a suitable device, and as a result, computer-readable media having instructions stored therein will comprise a product containing instructions that can be executed to create means for performing operations specified in a flowchart or block diagram. Examples of computer-readable media may include electronic storage media, magnetic storage media, optical storage media, electromagnetic storage media, semiconductor storage media, etc. More specific examples of computer-readable media may include floppy disks (registered trademark), diskettes, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), electrically erasable programmable read-only memory (EEPROM), static random access memory (SRAM), compact disk read-only memory (CD-ROM), digital multipurpose disc (DVD), Blu-ray (registered trademark) disc, memory stick, integrated circuit card, etc.

[0169] Computer-readable instructions may include assembler instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state setting data, or source code or object code written in any combination of one or more programming languages, including object-oriented programming languages ​​such as Smalltalk®, Java®, C++, and traditional procedural programming languages ​​such as the C programming language or similar programming languages.

[0170] Computer-readable instructions are provided locally or via a wide area network (WAN) such as a local area network (LAN) or the internet to the processor or programmable circuit of a programmable data processing device such as a computer, and may be executed to create means for performing operations specified in a flowchart or block diagram. Here, the computer may be a PC (personal computer), tablet computer, smartphone, workstation, server computer, general-purpose computer, or special-purpose computer, and may also be a computer system in which multiple computers are connected. Such a computer system in which multiple computers are connected is also called a distributed computing system and is a computer in a broad sense. In a distributed computing system, multiple computers execute a program collectively by each computer executing a part of the program and passing data during program execution between computers as needed.

[0171] Examples of processors include computer processors, central processing units (CPUs), processing units, microprocessors, digital signal processors, controllers, and microcontrollers. A computer may have one or more processors. In a multiprocessor system with multiple processors, each processor executes a portion of the program, and the processors collectively execute the program by passing program execution data between them as needed. For example, in the execution of multitasks, each of the multiple processors may execute a portion of each task in small chunks by switching tasks at each time slice. In this case, which part of a program each processor executes changes dynamically. Which part of a program each of the multiple processors executes may also be statically determined by multiprocessor-aware programming.

[0172] Figure 26 shows an example of a computer 1200 in which multiple aspects of the present invention may be embodied in whole or in part. A program installed on the computer 1200 can cause the computer 1200 to function as an operation or one or more sections of an apparatus according to an embodiment of the present invention, or to execute such operation or one or more sections, and / or to cause the computer 1200 to execute a process or a stage of such process according to an embodiment of the present invention. Such a program may be executed by the CPU 1212 to cause the computer 1200 to perform a particular operation associated with some or all of the blocks in the flowcharts and block diagrams described herein.

[0173] The computer 1200 according to this embodiment includes a CPU 1212, RAM 1214, a graphics controller 1216, and a display device 1218, which are interconnected by a host controller 1210. The computer 1200 also includes input / output units such as a communication interface 1222, a storage device 1224 such as a hard disk drive, a DVD-ROM drive 1226, and an IC card drive, which are connected to the host controller 1210 via an input / output controller 1220. The computer also includes legacy input / output units such as a ROM 1230 and a keyboard 1242, which are connected to the input / output controller 1220 via an input / output chip 1240.

[0174] The CPU 1212 operates according to programs stored in the ROM 1230 and RAM 1214, thereby controlling each unit. The graphics controller 1216 acquires image data generated by the CPU 1212 from the frame buffer provided in RAM 1214 or from itself, and displays the image data on the display device 1218.

[0175] The communication interface 1222 communicates with other electronic devices via a network. The storage device 1224 stores programs and data used by the CPU 1212 in the computer 1200. The DVD-ROM drive 1226 reads programs or data from the DVD-ROM 1227 and provides them to the storage device 1224 via the RAM 1214. The IC card drive reads programs and data from the IC card and / or writes programs and data to the IC card.

[0176] The ROM 1230 stores boot programs and / or programs that depend on the computer 1200's hardware, which are executed by the computer 1200 when activated. The input / output chip 1240 may also connect various input / output units to the input / output controller 1220 via parallel ports, serial ports, keyboard ports, mouse ports, etc.

[0177] The program is provided on a computer-readable medium such as a DVD-ROM 1227 or an IC card. The program is read from the computer-readable medium and installed on a storage device 1224, RAM 1214, or ROM 1230, which are examples of computer-readable mediums, and executed by the CPU 1212. The information processing described within these programs is read by the computer 1200, resulting in coordination between the program and the various types of hardware resources described above. The apparatus or method may be configured to realize the manipulation or processing of information in accordance with the use of the computer 1200.

[0178] For example, when communication is performed between a computer 1200 and an external device, the CPU 1212 may execute a communication program loaded into the RAM 1214 and, based on the processing described in the communication program, instruct the communication interface 1222 to perform communication processing. Under the control of the CPU 1212, the communication interface 1222 reads transmission data stored in a transmission buffer processing area provided in a recording medium such as the RAM 1214, storage device 1224, DVD-ROM 1227, or IC card, transmits the read transmission data to the network, or writes received data received from the network to a receive buffer processing area provided on the recording medium.

[0179] Furthermore, the CPU 1212 may read all or necessary parts of a file or database stored on an external recording medium such as a storage device 1224, a DVD-ROM drive 1226 (DVD-ROM 1227), or an IC card into the RAM 1214, and perform various types of processing on the data in the RAM 1214. The CPU 1212 then writes the processed data back to the external recording medium.

[0180] Various types of information, such as various types of programs, data, tables, and databases, may be stored on the recording medium and subjected to information processing. The CPU 1212 may perform various types of processing on the data read from the RAM 1214, including various types of operations, information processing, conditional judgments, conditional branching, unconditional branching, information retrieval / replacement, etc., as described throughout this disclosure and specified by the program instruction sequence, and write the results back to the RAM 1214. The CPU 1212 may also retrieve information in files, databases, etc., within the recording medium. For example, if a plurality of entries having attribute values ​​of a first attribute, each associated with an attribute value of a second attribute, are stored in the recording medium, the CPU 1212 may search among the plurality of entries for an entry that matches the condition for which the attribute value of the first attribute is specified, read the attribute value of the second attribute stored in that entry, and thereby obtain the attribute value of the second attribute associated with the first attribute that satisfies a predetermined condition.

[0181] The program or software module described above may be stored on or near the computer 1200 on a computer-readable medium. Alternatively, a recording medium such as a hard disk or RAM provided within a server system connected to a dedicated communication network or the Internet can be used as a computer-readable medium, thereby providing the program to the computer 1200 via the network.

[0182] Although the present invention has been described above using embodiments, the technical scope of the present invention is not limited to the scope described in the above embodiments. It will be apparent to those skilled in the art that various modifications or improvements can be made to the above embodiments. It will be clear from the claims that such modified or improved forms may also be included in the technical scope of the present invention.

[0183] It should be noted that the execution order of operations, procedures, steps, and stages in the devices, systems, programs, and methods shown in the claims, specifications, and drawings is not explicitly stated as "before," "prior to," etc., and that these can be performed in any order unless the output of a previous process is used in a later process. Even if the operation flow in the claims, specifications, and drawings is described using phrases such as "first," "next," etc. for convenience, this does not mean that it is mandatory to perform the operations in that order.

[0184] This specification also discloses the configurations described in the following items: (Item 1) A proxy device comprising: a request determination unit that receives a request sent from a virtual browser and determines the security risk of the request URL specified in the request; a request forwarding unit that forwards the request, for which the request URL has been determined to be normal by the request determination unit, to a server operating a site to be analyzed, wherein the site to be analyzed is a target site for which the services used on the site to be analyzed are identified; a response analysis unit that receives and analyzes a response from the server; and a response return unit that returns the response to the virtual browser. (Item 2) The proxy device according to Item 1, wherein the response analysis unit determines the security risk from the response sent from the server, and the response return unit returns the response, for which the response analysis unit has determined to have no security risk, to the virtual browser. (Item 3) The proxy device according to Item 1, further comprising a request blocking unit that blocks the request when the request determination unit determines the request URL to be abnormal. (Item 4) The proxy device according to Item 3, wherein the request blocking unit generates a new response indicating that the request URL has a security risk and sends it back to the virtual browser when the request blocking unit determines that the request URL is abnormal. (Item 5) The proxy device according to Item 2, further comprising a response blocking unit that blocks the return of the response when the response analysis unit determines that the response has a security risk. (Item 6) The proxy device according to Item 5, wherein the response blocking unit further generates a new response indicating that the page included in the response has a security risk and sends it back to the virtual browser when the response analysis unit determines that the response has a security risk. (Item 7) The proxy device according to Item 1, wherein the response analysis unit determines that the page included in the response is an inaccessible page when the status code of the response sent from the server is not 200.(Item 8) The proxy device described in Item 1, wherein the virtual browser is activated by the analysis device to send the request to the server operating the site to be analyzed by specifying the site URL of the site to be analyzed, and to receive the response from the server. (Item 9) The analysis device comprises: an analysis target acquisition unit that acquires the site URL of the site to be analyzed; and an analysis execution unit that analyzes one or more pages within the site published at the site URL, wherein the analysis execution unit has: a site access unit that sends the request to the proxy device described in Item 1 by specifying the site URL using the virtual browser, and receives the response from the proxy device; and a status extraction unit that extracts security risks from the response. (Item 10) The analysis device described in Item 9, wherein the analysis execution unit further has a link extraction unit that extracts the page URL of the linked page from the response, and the site access unit further sends a request to the proxy device by specifying the page URL of the linked page, and receives a response from the proxy device. (Item 11) The analysis device according to Item 9, further comprising a status registration unit that associates the page URLs of one or more pages with the status code of the response to the request specifying the page URLs and the security risk in a status database. (Item 12) A reference device comprising: a status acquisition unit that acquires the page URLs of one or more pages with the status code of the response to the request specifying the page URLs and the security risk from the status database registered by the analysis device according to Item 11; and a status output unit that outputs the page URLs of one or more pages with the status code of the response to the request specifying the page URLs and the security risk to a user terminal.(Item 13) A security risk determination method performed by a computer, comprising: a step of receiving a request sent from a virtual browser and determining the security risk of the request URL specified in the request; a request step of forwarding the request, for which the request URL has been determined to be normal by the determination step, to a server operating a site to be analyzed, wherein the site to be analyzed is a target site for which the services used on the site to be analyzed are identified; a step of receiving and analyzing a response from the server; and a step of returning the response to the virtual browser. (Item 14) An analysis method performed by a computer, comprising: a step of obtaining the site URL of a site to be analyzed; a step of analyzing one or more pages within the site published at the site URL, wherein the analysis step includes: sending the request to a proxy device equipped with a computer that executes the security risk determination method described in Item 13 by specifying the site URL using the virtual browser, and receiving the response from the proxy device; and a step of extracting security risks from the response. (Item 15) The analysis method according to Item 14, further comprising the step of registering in a status database the status code and security risk of the response to the request specifying the page URLs of the one or more pages. (Item 16) A referencing method performed by a computer, comprising the steps of: obtaining the status code and security risk of the response to the request specifying the page URLs of the one or more pages from the status database registered by the analysis method according to Item 15; and outputting the status code and security risk of the response to the request specifying the page URLs of the one or more pages to a user terminal.(Item 17) A security risk assessment program that causes a computer to execute the following steps: (Item 17) A procedure to receive a request sent from a virtual browser and determine the security risk of the request URL specified in the request; a procedure to forward the request, for which the request URL has been determined to be normal by the determination step, to a server operating a site to be analyzed, wherein the site to be analyzed is a site in which the services used on the site to be analyzed are identified; a procedure to receive and analyze a response from the server; and a procedure to return the response to the virtual browser. (Item 18) An analysis program that causes a computer to execute the following steps: (Item 18) A procedure to obtain the site URL of a site to be analyzed; a procedure to analyze one or more pages within the site published at the site URL; and the analysis procedure to cause a computer to execute the following steps: (Item 18) A procedure to obtain the site URL of a site to be analyzed; and a procedure to analyze one or more pages within the site published at the site URL. (Item 19) The analysis program described in Item 18, which causes the computer to further perform a procedure to register in a status database the status code and security risk of the response to the request specifying the page URLs of the one or more pages. (Item 20) A reference program which causes the computer to perform a procedure to obtain from the status database registered by executing the analysis program described in Item 19 the status code and security risk of the response to the request specifying the page URLs of the one or more pages, and the page URLs of the response to the request specifying the page URLs, and the security risk of the response to the request specifying the page URLs, and output the status code and security risk of the response to the request specifying the page URLs to a user terminal.(Item 21) A security risk determination system comprising: a proxy device as described in Item 1; an analysis device as described in Item 9; a reference device as described in Item 12; and a status database in which data is registered that associates the page URLs of one or more pages with the status codes and security risks of the responses to requests specifying the page URLs. (Item 22) The system comprises: an analysis device that identifies the services used on the site to be analyzed; a proxy device that mediates between the server operating the site to be analyzed and a virtual browser launched by the analysis device, wherein the site to be analyzed is a target site from which the services used on the site to be analyzed are identified; the analysis device obtains the site URL of the site to be analyzed and sends a request to the proxy device specifying the site URL using a virtual browser; the proxy device receives the request sent from the virtual browser and determines the security risk of the request URL specified in the request; the proxy device forwards the request, which has been determined to be normal, to the server operating the site to be analyzed; the proxy device receives and analyzes the response from the server; and the proxy device sends the response back to the virtual browser. A security risk determination system that performs the steps of: (Item 23) When the proxy device determines that the request URL is abnormal, it generates a new response indicating that there is a security risk in the request URL and sends it back to the virtual browser.(Item 24) The security risk determination system according to Item 22, wherein the proxy device further performs a step of blocking communication with the site to be analyzed when it determines that the response has a security risk. (Item 25) The security risk determination system according to Item 24, wherein, in the blocking step, the proxy device further determines that the response has a security risk, generates a new response indicating that the pages included in the response have a security risk and sends it back to the virtual browser. (Item 26) The security risk determination system according to Item 22, wherein the reference device further performs a step of outputting the page URLs of one or more pages, the status code of the response to the request specifying the page URLs, and the security risk to the user terminal from the status database registered in the registration step.(Item 27) A security risk determination method performed by one or more devices, comprising: a step in which an analysis device obtains the site URL of a site to be analyzed and sends a request to a proxy device specifying the site URL using a virtual browser, wherein the site to be analyzed is a target site from which the services used on the site to be analyzed are identified; a step in which the proxy device receives the request sent from the virtual browser and determines the security risk of the request URL specified in the request; a step in which the proxy device forwards the request, which has been determined to be normal, to the server operating the site to be analyzed; a step in which the proxy device receives and analyzes the response from the server; and a step in which the proxy device sends the response back to the virtual browser. A security risk determination method comprising the steps of: the analysis device receiving the response from the proxy device, extracting security risks from the response, analyzing one or more pages within the site published at the site URL based on the response, and registering the page URLs of the one or more pages, the status code of the response to the request specifying the page URL, and the security risk in a status database.(Item 28) A security risk determination program that causes one or more computers to execute the following steps: a procedure to obtain the site URL of a site to be analyzed, and to send a request to a proxy device by specifying the site URL using a virtual browser, wherein the site to be analyzed is a target site from which the services used on the site to be analyzed can be identified; a procedure to receive the request sent from the virtual browser by the proxy device and determine the security risk of the request URL specified in the request; a procedure to forward the request, which the proxy device has determined to be normal, to a server operating the site to be analyzed; a procedure to receive and analyze the response from the server by the proxy device; a procedure to return the response to the virtual browser by the proxy device; and a procedure to receive the response from the proxy device, extract security risks from the response, analyze one or more pages within the site published at the site URL based on the response, and register the page URLs of the one or more pages, the status code of the response to the request specifying the page URL, and the security risk in a status database.

[0185] 1, 1A... System (Service Specification System), 2... Security Risk Assessment System, 10... Analysis Device, 11... Analysis Target Acquisition Unit, 12... Analysis Execution Unit, 13... Analysis Item Registration Unit, 14... Status Registration Unit, 20... Site Database, 30... Analysis Target Server, 31... Cookie Settings, 32... External Communication URL Settings, 33... Script Tag, 34... Link Tag, 35... Status Code Information, 40... Analysis Item Database, 50... Service Specification Device, 51... Analysis Item Acquisition Unit, 52... Service Specification Unit, 53... Service Registration Unit, 60... Service database, 70...Service database used, 80...Reference device, 81...Service reference unit used, 82...Analysis item reference unit, 90...User terminal, 91...Display, 99...Network, 100...Proxy device, 101...Request forwarding unit, 102...Response analysis unit, 103...Response return unit, 104...Response blocking unit, 105...Request determination unit, 106...Request blocking unit, 121...Site access unit, 122...Analysis item extraction unit, 123...Script execution unit, 124...Link extraction unit, 125...Status extraction unit, 200...Status 300...Status reference device, 301...Status acquisition unit, 302...Status output unit, 521...External communication URL matching unit, 522...Cookie matching unit, 523...Web storage matching unit, 811...Usage service acquisition unit, 812...Analysis item acquisition unit (third analysis item acquisition unit), 813...Usage service output unit, 821...Analysis item acquisition unit (second analysis item acquisition unit), 822...Analysis item output unit, 911...Target site display unit, 912...Usage service display unit, 913...Target site display unit, 914...Analysis item display unit, 915...Input form, 916...Target site display unit, 917...Status information display unit, 1001...Status code information, 1002...Blocked external domain information, 1200...Computer, 1210...Host controller, 1212...CPU, 1214...RAM, 1216...Graphics controller, 1218...Display device, 1220...Input / output controller, 1222...Communication interface, 1224...Storage device, 1226...DVD-ROM drive, 1240...Input / output chip, 1242...Keyboard, S100...Security risk determination method.

Claims

1. A proxy device comprising: a request determination unit that receives a request sent from a virtual browser and determines the security risk of the request URL specified in the request; a request forwarding unit that forwards the request, for which the request URL has been determined to be normal by the request determination unit, to a server operating a site to be analyzed, wherein the site to be analyzed is a target site for which the services used on the site to be analyzed can be identified; a response analysis unit that receives and analyzes the response from the server; and a response return unit that returns the response to the virtual browser.

2. The proxy device according to claim 1, wherein the response analysis unit determines security risks from the response transmitted from the server, and the response return unit returns the response determined by the response analysis unit to have no security risks to the virtual browser.

3. The proxy device according to claim 1, further comprising a request blocking unit that blocks the request when the request determination unit determines the request URL to be abnormal.

4. The proxy device according to claim 3, wherein when the request blocking unit determines that the request URL is abnormal, it generates a new response indicating that the request URL has a security risk and sends it back to the virtual browser.

5. The proxy device according to claim 2, further comprising a response blocking unit that blocks the return of the response when the response analysis unit determines that the response has a security risk.

6. The proxy device according to claim 5, wherein the response blocking unit further generates a new response indicating that the page included in the response has a security risk when the response analysis unit determines that the response has a security risk, and sends it back to the virtual browser.

7. The proxy device according to claim 1, wherein the response analysis unit determines that a page included in the response is an inaccessible page when the status code of the response sent from the server is not 200.

8. The proxy device according to claim 1, wherein the virtual browser is activated by the analysis device to send the request to the server operating the site to be analyzed by specifying the site URL of the site to be analyzed, and to receive the response from the server.

9. An analysis device comprising: an analysis target acquisition unit that acquires the site URL of a site to be analyzed; an analysis execution unit that analyzes one or more pages within the site published at the site URL, wherein the analysis execution unit includes: a site access unit that uses the virtual browser to specify the site URL and sends the request to the proxy device described in claim 1 and receives the response from the proxy device; and a status extraction unit that extracts security risks from the response.

10. The analysis device according to claim 9, wherein the analysis execution unit further comprises a link extraction unit that extracts the page URL of the linked page from the response, and the site access unit further specifies the page URL of the linked page and sends a request to the proxy device and receives a response from the proxy device.

11. The analysis device according to claim 9, further comprising a status registration unit that associates the page URLs of one or more pages with the status code of the response to the request specifying the page URL and the security risk and registers them in a status database.

12. A reference device comprising: a status acquisition unit that acquires the page URLs of one or more pages, the status code of the response to the request specifying the page URLs, and the security risk from the status database registered by the analysis device according to claim 11; and a status output unit that outputs the page URLs of one or more pages, the status code of the response to the request specifying the page URLs, and the security risk to a user terminal.

13. A security risk determination method performed by a computer, comprising: a step of receiving a request sent from a virtual browser and determining the security risk of the request URL specified in the request; a request step of forwarding the request, for which the request URL has been determined to be normal in the determination step, to a server operating a site to be analyzed, wherein the site to be analyzed is a target site for which the services used on the site to be analyzed are identified; a step of receiving and analyzing a response from the server; and a step of returning the response to the virtual browser.

14. A computer-based analysis method comprising: obtaining the site URL of a site to be analyzed; and analyzing one or more pages within the site published at the site URL, wherein the analysis step includes: sending the request to a proxy device equipped with a computer that executes the security risk determination method described in claim 13 by specifying the site URL using the virtual browser, and receiving the response from the proxy device; and extracting security risks from the response.

15. The analysis method according to claim 14, further comprising the step of registering in a status database the status code and security risk of the response to the request specifying the page URL of the one or more pages.

16. A referencing method performed by a computer, comprising the steps of: obtaining the page URLs of one or more pages, the status code of the response to the request specifying the page URLs, and the security risk from the status database registered by the analysis method described in claim 15; and outputting the page URLs of one or more pages, the status code of the response to the request specifying the page URLs, and the security risk to a user terminal.

17. A security risk assessment program that causes a computer to execute the following steps: a step of receiving a request sent from a virtual browser and determining the security risk of the request URL specified in the request; a step of forwarding the request, for which the request URL has been determined to be normal by the determination step, to a server operating a site to be analyzed, wherein the site to be analyzed is a site in which the services used on the site to be analyzed can be identified; a step of receiving and analyzing a response from the server; and a step of sending the response back to the virtual browser.

18. An analysis program that causes a computer to perform the following steps: a step to obtain the URL of a site to be analyzed; a step to analyze one or more pages within the site published at the URL; the step to perform the analysis is to send the request to a proxy device equipped with a computer that executes the security risk determination program described in claim 17 by specifying the URL of the site using the virtual browser, receive the response from the proxy device, and extract security risks from the response.

19. The analysis program according to claim 18, further comprising causing a computer to perform a procedure to register in a status database the status code and security risk of the response to the request specifying the page URL of the one or more pages.

20. A reference program that causes a computer to execute the following steps: a procedure for obtaining the page URLs of one or more pages, the status code of the response to the request specifying the page URLs, and the security risk from the status database registered by executing the analysis program described in claim 19; and a procedure for outputting the page URLs of one or more pages, the status code of the response to the request specifying the page URLs, and the security risk to a user terminal.

21. A security risk determination system comprising: a proxy device according to claim 1; an analysis device according to claim 9; a reference device according to claim 12; and a status database in which data is registered that associates the page URLs of one or more pages with the status codes and security risks of responses to requests specifying the page URLs.

Citation Information

Patent Citations

  • Communication relay device, communication relay method, and program

    JP2004318816A

  • Information processing device, control method thereof and program

    JP2013033448A

  • Access relay device, information processing method, and program

    JP2016162278A

  • Virtual Browser Integration

    JP2019526842A