WO2016195090A1 - 検知システム、検知装置、検知方法及び検知プログラム - Google Patents
検知システム、検知装置、検知方法及び検知プログラム Download PDFInfo
- Publication number
- WO2016195090A1 WO2016195090A1 PCT/JP2016/066642 JP2016066642W WO2016195090A1 WO 2016195090 A1 WO2016195090 A1 WO 2016195090A1 JP 2016066642 W JP2016066642 W JP 2016066642W WO 2016195090 A1 WO2016195090 A1 WO 2016195090A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- account
- address
- accounts
- group
- threshold
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1441—Countermeasures against malicious traffic
- H04L63/1466—Active attacks involving interception, injection, modification, spoofing of data unit addresses, e.g. hijacking, packet injection or TCP sequence number attacks
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/30—Authentication, i.e. establishing the identity or authorisation of security principals
- G06F21/31—User authentication
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/55—Detecting local intrusion or implementing counter-measures
- G06F21/552—Detecting local intrusion or implementing counter-measures involving long-term monitoring or reporting
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/10—Network architectures or network communication protocols for network security for controlling access to devices or network resources
- H04L63/104—Grouping of entities
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1408—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
- H04L63/1416—Event detection, e.g. attack signature detection
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1408—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
- H04L63/1425—Traffic logging, e.g. anomaly detection
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F2221/00—Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F2221/21—Indexing scheme relating to G06F21/00 and subgroups addressing additional information or applications relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F2221/2135—Metering
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L43/00—Arrangements for monitoring or testing data switching networks
- H04L43/10—Active monitoring, e.g. heartbeat, ping or trace-route
- H04L43/106—Active monitoring, e.g. heartbeat, ping or trace-route using time related information in packets, e.g. by adding timestamps
Definitions
- the present invention relates to a detection system, a detection device, a detection method, and a detection program.
- account authentication is often used to confirm the identity. For example, the user attempts account authentication in order to use the service, and can log in and use the service only when the user is authenticated.
- account authentication uses an account and a password.
- the attacker prepares both a dummy account that successfully logs in and an account (target account) that attempts to perform unauthorized login, and tries to log in based on a list of mixed dummy accounts and target accounts. Then, the attacker repeats login attempts while changing the target account itself or the target account password. For this reason, in the conventional detection method in which thresholds are set for the authentication failure rate and the authentication success rate, such an account hacking has a problem that the authentication failure rate and the authentication success rate do not decrease and cannot be detected by the threshold value.
- An example of an embodiment disclosed in the present application has been made in view of the above, and aims to improve the accuracy of detecting account hacking.
- An example of an embodiment disclosed in the present application is to extract an account and an account transmission source address from authentication information acquired from an authentication device that performs user authentication, and according to the account time stamp and the transmission source address, Group accounts by slot and source address. Then, an account group that excludes duplication of the same account in the same group is extracted. Then, the number of accounts that overlap between the extracted account groups is calculated. Then, when the number of account groups with the same source address exceeding the first threshold exceeds the second threshold, it is determined that the same source address is the account attacker's address.
- the accuracy of detecting account hacking can be improved.
- FIG. 1 is a block diagram illustrating an example of a system according to the embodiment.
- FIG. 2 is a diagram illustrating an example of an account group according to the embodiment.
- FIG. 3 is a flowchart illustrating an example of detection processing according to the embodiment.
- FIG. 4 is a diagram illustrating an example of an outline of the detection process according to the first embodiment.
- FIG. 5 is a diagram illustrating an example of an outline of the detection process according to the second embodiment (third embodiment).
- FIG. 6 is a diagram illustrating an example of an outline of detection processing according to the fourth embodiment (fifth embodiment).
- FIG. 7 is a diagram illustrating an example of a computer in which the detection apparatus is realized by executing a program.
- FIG. 1 is a block diagram illustrating an example of a system according to the embodiment.
- a system 1 according to the embodiment includes a client 3 and a server 4 connected via a network 2 such as a public network.
- the detection device 10 is connected to the server 4.
- the user makes an authentication request to the server 4 via the network 2, and the server 4 returns the result to the user.
- the server 4 holds the authentication user information and the authentication result as an authentication record, and transmits the authentication record to the detection device 10.
- the client 3 is a user terminal that uses the service via the network 2.
- the client 3 also includes an attacker's terminal by account hacking.
- the server 4 is a server that performs user authentication by an account in an application server that provides a service.
- the server 4 authenticates the user using user information such as a user account and a password received from the client 3.
- the server 4 outputs an authentication record.
- the authentication record includes, for example, a user account (hereinafter referred to as an account), a password, a time stamp, an account, an IP address of the client 3 that transmitted the password, and the like.
- the authentication record may be output in a log format.
- the server 4 may be configured integrally with an application server that provides a service in terms of hardware or software.
- the server 4 may be configured integrally with a detection device 20 described later in terms of hardware or software.
- the detection device 10 detects an attack by account hacking on the server 4.
- the detection device 10 includes an account group storage unit 11, an extraction unit 12, a calculation unit 13, and a determination unit 14.
- the extraction unit 12 extracts the account for each authentication, the time stamp, and the IP address of the client 3 of the account transmission source (hereinafter referred to as the transmission source IP address) from the authentication record received from the server 4.
- the transmission source IP address As long as it is a network identifier that can identify the client 3 of the account transmission source, not only the transmission source IP address but also a MAC (Media Access Control) address or the like may be used.
- the time stamp extracted from the authentication record received by the extraction unit 12 from the server 4 is the time when the user tried to authenticate at the server 4 using the account. Alternatively, the time stamp may be the time when the authentication record arrives at the detection device 10 from the server 4 or the time when the account is extracted from the authentication record at the detection device 10.
- the extraction unit 12 groups the extracted accounts according to the time stamp of the period ⁇ and the source IP address according to the time stamp of the account and the source IP address. And the extraction part 12 excludes duplication of the same account within the same group of the grouped account.
- the above is the account group extraction performed by the extraction unit 12.
- the extraction unit 12 stores the extracted account group in the account group storage unit 11.
- FIG. 2 is a diagram illustrating an example of an account group according to the embodiment.
- FIG. 2A schematically shows a plurality of accounts with different time stamps and transmission source IP addresses as authentication record groups.
- the extraction unit 12 of the detection apparatus 10 sets the authentication record group for each predetermined period ⁇ (time slot K, K ⁇ 1) to which the time stamp belongs and the source IP address (IP address). Group accounts by A, B, C). And the extraction part 12 excludes the duplication of the account in the same account group.
- the account group AG [A] [K ⁇ 1].
- the time slot K is a period that immediately follows the time slot K-1. 2 (b) is merely an example, and the number of time slots and the number of source IP addresses are not limited to those shown in FIG. 2 (b).
- the determination unit 14 determines the account duplication number> ⁇ (first threshold) ( ⁇ is a predetermined positive number)> ⁇ (the first number of account groups) in the source IP address unit. 2 threshold) ( ⁇ is a predetermined positive number), the source IP address is determined to be the IP address of the client 3 of the attacker by account hacking. Examples of processing by the determination unit 14 will be described later based on Examples 1 to 5.
- FIG. 3 is a flowchart illustrating an example of detection processing according to the embodiment.
- the detection process according to the embodiment is executed by the detection device 10.
- the detection device 10 initializes the reference time stamp BT of the time slot with the current time.
- the detection device 10 initializes the time slot ID_K with 1.
- the detection apparatus 10 initializes an array AG for storing account groups (step S11 above).
- the detection apparatus 10 determines whether or not an end command from the system administrator is input to the system 1 from a console (not shown) (step S12). If the detection device 10 determines that an end command from the system administrator has been input (step S12: Yes), the detection device 10 ends the detection process. On the other hand, if the detection apparatus 10 determines that an end command by the system administrator has not been input (step S12: No), the process proceeds to step S13.
- step S13 the detection apparatus 10 determines whether an unprocessed authentication record R has arrived. If the detection apparatus 10 determines that an unprocessed authentication record R has arrived (step S13: Yes), the process proceeds to step S14. On the other hand, when the detection apparatus 10 determines that the unprocessed authentication record R has not arrived (step S13: No), the process proceeds to step S12.
- step S14 the detection device 10 determines whether or not the result of subtracting the reference time stamp BT of the time slot from the time stamp of the unprocessed authentication record R determined to arrive in step S13 is greater than the predetermined period ⁇ . To do. That is, in step S14, the detection device 10 determines that the time stamp of the unprocessed authentication record R determined to arrive in step S13 is the reference time stamp BT + of the time slot initialized at the current time in step S11 or step S15 described later. It is determined whether or not the time is within a predetermined period ⁇ .
- step S14: Yes When the detection device 10 determines that the result of subtracting the reference time stamp BT of the time slot from the time stamp of the unprocessed authentication record R determined to have arrived in step S13 is greater than the predetermined period ⁇ (step S14: Yes) ), And the process proceeds to step S15. On the other hand, when the detection device 10 determines that the result of subtracting the reference time stamp BT of the time slot from the time stamp of the unprocessed authentication record R determined to have arrived in step S13 is equal to or less than the predetermined period ⁇ (step S14: No). Then, the process proceeds to step S19.
- step S15 the detection apparatus 10 increments the time slot ID_K by 1, and initializes the reference time stamp BT of the time slot with the current time.
- step S16 determines whether or not time slot ID_K ⁇ N (step S16).
- N is a predetermined natural number indicating the number of time slots for calculating the account duplication number. If the detection apparatus 10 determines that the time slot ID_K ⁇ N (step S16: Yes), the process proceeds to step S17. On the other hand, when the detection apparatus 10 determines that the time slot ID_K ⁇ N (step S16: No), the process proceeds to step S12.
- step S17 the detection apparatus 10 calculates the account duplication number. Details of the calculation of the account duplication number will be described later based on Examples 1 to 5.
- step S18 attack determination. Details of the attack determination will be described later based on the first to fifth embodiments.
- step S19 the detection apparatus 10 determines whether or not the array AG has the key of the IP address of the unprocessed authentication record R that has arrived in step S13. If the detection apparatus 10 determines that the array AG has the key of the IP address of the unprocessed authentication record R that has arrived at step S13 (step S19: Yes), the process proceeds to step S21. On the other hand, if the detection apparatus 10 determines that the array AG does not have the key of the IP address of the unprocessed authentication record R that has arrived at step S13 (step S19: No), the process proceeds to step S20.
- step S20 the detection apparatus 10 initializes the array AG [IP address of the authentication record R] with an empty array.
- the array AG [source IP address] [K] is an array for storing accounts belonging to the account group determined by the source IP address and the time slot ID_K.
- step S21 the detection apparatus 10 adds an account to the array AG [IP address of authentication record R] [K] so as to maintain uniqueness. That is, in step S21, the detection apparatus 10 does not store the account already stored in the array AG [IP address of the authentication record R] [K], and adds only the account not stored. Alternatively, in step S21, the detection device 10 adds an account to the array AG [IP address of the authentication record R] [K] while excluding duplicates. When step S21 ends, the detection device 10 moves the process to step S12.
- the embodiment pays attention to the fact that the dummy accounts prepared by the attacker are finite and the dummy accounts are repeatedly used, and the attack detection is performed based on the account duplication number of login attempts made during a certain period from each source IP address. Do. Therefore, according to the embodiment, even if an attacker performs account hacking using a list in which dummy accounts are mixed in the target account, an attack can be detected.
- FIG. 4 is a diagram illustrating an example of an outline of the detection process according to the first embodiment.
- the account duplication number H [X] [X] [K] of AG [X] [K] and AG [X] [Ki] for a certain source IP address X included in the time slot ID_K. ] [Ki] is calculated by the following equation (1).
- Ki is a certain time slot ID (K ⁇ N + 1 ⁇ Ki ⁇ K (N> 0)).
- indicates the number of elements of the set *.
- the calculation unit 13 calculates the account duplication number using H [X] [X] [K] [Ki] according to the following equation (1).
- the determination unit 14 is 1 when H [X] [X] [K] [Ki]> ⁇ with respect to the predetermined positive number ⁇ , and H [X] [X] [K] [Ki ] With respect to the function TH (H [X] [X] [K] [Ki]) that becomes 0 when? ⁇ ⁇ , C [X] defined by the following equation (2) is calculated. Then, the determination unit 14 determines that the transmission source IP address X satisfying C [X]> ⁇ with respect to the predetermined positive number ⁇ is the IP address of the attacker client 3 by the following equation (3). . The determination unit 14 determines that the source IP address X satisfying C [X] ⁇ ⁇ with respect to the predetermined positive number ⁇ is not the IP address of the attacker client 3.
- the determination unit 14 determines that any source IP address is the client of the attacker using the above equation (3). It is determined that the IP address is not 3.
- FIG. 5 is a diagram illustrating an example of an outline of the detection process according to the second embodiment.
- the account duplication number H [X] [Y] [K] [Ki] is calculated by the following equation (4).
- the calculation unit 13 calculates the account duplication number using H [X] [Y] [K] [Ki] according to the following equation (4).
- the determination unit 14 determines that H [X] [Y] [K] [Ki] is 1 when H [X] [Y] [K] [Ki]> ⁇ with respect to the predetermined positive number ⁇ . ] With respect to the function TH (H [X] [Y] [K] [Ki]) that becomes 0 when? ⁇ ⁇ , C [X] defined by the following equation (5) is calculated. Then, the determination unit 14 determines that the transmission source IP address X satisfying C [X]> ⁇ with respect to the predetermined positive number ⁇ is the IP address of the attacker's client 3 according to the above equation (3). . The determination unit 14 determines that the source IP address X satisfying C [X] ⁇ ⁇ with respect to the predetermined positive number ⁇ is not the IP address of the attacker client 3.
- Embodiments 2 and 3 described above it is possible to detect unauthorized logins by a plurality of source IP addresses using a dummy account and reduce unauthorized logins by an attacker.
- FIG. 6 is a diagram illustrating an example of an outline of the detection process according to the fourth embodiment.
- the weighting factor W [Y] [Ki] is calculated for each account group AG [Y] [Ki] (K ⁇ N + 1 ⁇ Ki ⁇ N (N> 0)) as shown in the following formula (7). (K ⁇ N + 1 ⁇ Ki ⁇ N) is multiplied by TH (H [X] [Y] [K] [Ki]) (K ⁇ N + 1 ⁇ Ki ⁇ N (N> 0)) to calculate C [X]. To do.
- weighting coefficients W [Y] [Ki] corresponding to AG [Y] [Ki] are all assumed to be 1.0.
- the weighting coefficient W [Y] [Ki] of the source IP address Y with respect to the source IP address X W [Y] [K-1]> W [Y] [K-2]>...> W [Y] [Ki] is set so that W [Y] [K ⁇ N + 1]. .
- the weighting method is not limited to the rules 1 and 2, but may be a rule in which the rules 1 and 2 are combined, for example.
- the determination unit 14 determines that the transmission source IP address A is the IP address of the attacker client 3 according to the above equation (3). .
- H [C] [ C] [2] [2] 4.
- H [C] [C] [C] [2] [ 1] 3.
- the determination unit 14 determines that the transmission source IP address C is the IP address of the attacker's client 3 according to the above equation (3).
- Embodiments 4 and 5 described above it is possible to detect unauthorized logins by a plurality of source IP addresses using a dummy account with higher accuracy and reduce unauthorized logins by an attacker.
- the calculation unit 13 calculates the account duplication between account groups including the account duplication between the account groups.
- the present invention is not limited to this, and when calculating the account duplication between account groups, the calculation unit 13 excludes the account duplication between each account group itself, and calculates only the account duplication between different account groups. It may be calculated. In this case, ⁇ and ⁇ , which are the predetermined positive numbers, are also adjusted to be appropriate values.
- the embodiment disclosed in the present application does not depend on the authentication failure rate and the authentication success rate, and performs attack discrimination by detecting a dummy account used by an attacker. For this reason, the embodiment can detect attacks against unauthorized login by mass-managing the authentication failure rate and the authentication success rate from the source IP address used by the attacker. Can reduce unauthorized login.
- Each component of the detection apparatus 10 illustrated in FIG. 1 is functionally conceptual, and does not necessarily need to be physically configured as illustrated. That is, the specific form of the distribution and integration of the functions of the detection device 10 is not limited to the illustrated one, and all or a part thereof may be functionally or physically in arbitrary units according to various loads or usage conditions. It can be configured to be distributed or integrated.
- each or all of the processes performed in the detection apparatus 10 may be realized by a processing apparatus such as a CPU (Central Processing Unit) and a program that is analyzed and executed by the processing apparatus.
- each process performed in the detection apparatus 10 may be implement
- FIG. 7 is a diagram illustrating an example of a computer in which the detection apparatus is realized by executing a program.
- the computer 1000 includes a memory 1010 and a CPU 1020, for example.
- the computer 1000 also includes a hard disk drive interface 1030, a disk drive interface 1040, a serial port interface 1050, a video adapter 1060, and a network interface 1070. In the computer 1000, these units are connected by a bus 1080.
- the memory 1010 includes a ROM (Read Only Memory) 1011 and a RAM 1012.
- the ROM 1011 stores a boot program such as BIOS (Basic Input Output System).
- BIOS Basic Input Output System
- the hard disk drive interface 1030 is connected to the hard disk drive 1031.
- the disk drive interface 1040 is connected to the disk drive 1041.
- a removable storage medium such as a magnetic disk or an optical disk is inserted into the disk drive 1041.
- the serial port interface 1050 is connected to a mouse 1051 and a keyboard 1052, for example.
- the video adapter 1060 is connected to the display 1061, for example.
- the hard disk drive 1031 stores, for example, an OS 1091, an application program 1092, a program module 1093, and program data 1094. That is, a program that defines each process of the detection apparatus 10 is stored in, for example, the hard disk drive 1031 as a program module 1093 in which a command to be executed by the computer 1000 is described. For example, a program module 1093 for executing information processing similar to the functional configuration in the detection apparatus 10 is stored in the hard disk drive 1031.
- the setting data used in the processing in the above embodiment is stored as program data 1094 in, for example, the memory 1010 or the hard disk drive 1031. Then, the CPU 1020 reads the program module 1093 and the program data 1094 stored in the memory 1010 and the hard disk drive 1031 to the RAM 1012 as necessary, and executes them.
- the program module 1093 and the program data 1094 are not limited to being stored in the hard disk drive 1031, but may be stored in, for example, a removable storage medium and read out by the CPU 1020 via the disk drive 1041 or the like. Alternatively, the program module 1093 and the program data 1094 may be stored in another computer connected via a network (LAN (Local Area Network), WAN (Wide Area Network), etc.). The program module 1093 and the program data 1094 may be read by the CPU 1020 via the network interface 1070.
- LAN Local Area Network
- WAN Wide Area Network
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- General Engineering & Computer Science (AREA)
- Computing Systems (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Theoretical Computer Science (AREA)
- Software Systems (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
Abstract
Description
以下、本願が開示する検知システム、検知装置、検知方法及び検知プログラムの実施形態を説明する。なお、以下の実施形態は、一例を示すに過ぎず、本願が開示する技術を限定するものではない。また、以下に示す種々の形態及び実施例は、矛盾しない範囲で適宜組合せてもよい。
図1は、実施形態に係るシステムの一例を示すブロック図である。実施形態に係るシステム1は、公衆網等のネットワーク2を介して接続されたクライアント3及びサーバ4を含む。また、サーバ4には、検知装置10が接続される。ユーザは、ネットワーク2を介してサーバ4に対して認証要求を行い、サーバ4はその結果をユーザに返す。その際、サーバ4は、認証ユーザの情報及び認証の結果を認証レコードとして保持し、検知装置10に送信する。
図3は、実施形態に係る検知処理の一例を示すフローチャートである。実施形態に係る検知処理は、検知装置10により実行される。先ず、検知装置10は、タイムスロットの基準タイムスタンプBTを現在時刻で初期化する。そして、検知装置10は、タイムスロットID_Kを1で初期化する。そして、検知装置10は、アカウントグループを格納する配列AGを初期化する(以上、ステップS11)。
実施形態は、攻撃者が用意するダミーアカウントが有限であり、ダミーアカウントが繰り返し用いられていることに着目し、各送信元IPアドレスから一定期間中にログイン試行したアカウント重複数に基づき攻撃検知を行う。よって、実施形態によれば、攻撃者が、ターゲットアカウントにダミーアカウントを混在させたリストを用いてアカウントハッキングを行っても、攻撃を検知することができる。
図1に示す検知装置10の各構成要素は機能概念的なものであり、必ずしも物理的に図示のように構成されていることを要しない。すなわち、検知装置10の機能の分散及び統合の具体的形態は図示のものに限られず、全部又は一部を、各種の負荷や使用状況等に応じて、任意の単位で機能的又は物理的に分散又は統合して構成することができる。
図7は、プログラムが実行されることにより、検知装置が実現されるコンピュータの一例を示す図である。コンピュータ1000は、例えば、メモリ1010、CPU1020を有する。また、コンピュータ1000は、ハードディスクドライブインタフェース1030、ディスクドライブインタフェース1040、シリアルポートインタフェース1050、ビデオアダプタ1060、ネットワークインタフェース1070を有する。コンピュータ1000において、これらの各部はバス1080によって接続される。
2 ネットワーク
3 クライアント
4 サーバ
10 検知装置
11 アカウントグループ記憶部
12 抽出部
13 計算部
14 判定部
1000 コンピュータ
1010 メモリ
1020 CPU
Claims (8)
- ユーザ認証を行う認証装置と、
前記認証装置から取得した認証情報からアカウント及びアカウントの送信元アドレスを抽出し、アカウントのタイムスタンプ及び送信元アドレスに応じて、所定時間間隔のタイムスロット毎かつ送信元アドレス毎にアカウントをグループ化し、同一グループ内で同一アカウントの重複を除外したアカウントグループを抽出する抽出部と、
前記抽出部により抽出された各アカウントグループ間で重複するアカウント数を計算する計算部と、
前記計算部により計算されたアカウント数が第1閾値を越える同一送信元アドレスのアカウントグループの数が第2閾値を越える場合に、該同一送信元アドレスが攻撃者のアドレスであると判定する判定部と
を備える検知装置と
を含むことを特徴とする検知システム。 - 認証装置から取得した認証情報からアカウント及びアカウントの送信元アドレスを抽出し、アカウントのタイムスタンプ及び送信元アドレスに応じて、所定時間間隔のタイムスロット毎かつ送信元アドレス毎にアカウントをグループ化し、同一グループ内で同一アカウントの重複を除外したアカウントグループを抽出する抽出部と、
前記抽出部により抽出された各アカウントグループ間で重複するアカウント数を計算する計算部と、
前記計算部により計算されたアカウント数が第1閾値を越える同一送信元アドレスのアカウントグループの数が第2閾値を越える場合に、該同一送信元アドレスが攻撃者のアドレスであると判定する判定部と
を備えることを特徴とする検知装置。 - 前記計算部は、第1の送信元アドレスのアカウントグループのうちの最新のタイムスロットに該当するアカウントグループと、該第1の送信元アドレスのアカウントグループのうちの最新のタイムスロット以前の所定数の各タイムスロットに該当する各アカウントグループとの間で重複する第1のアカウント数をそれぞれ計算し、
前記判定部は、前記第1のアカウント数が前記第1閾値を越えるアカウントグループの数が前記第2閾値を越える場合に、該第1の送信元アドレスが攻撃者のアドレスであると判定する
ことを特徴とする請求項2に記載の検知装置。 - さらに、
前記計算部は、前記第1の送信元アドレスのアカウントグループのうちの最新のタイムスロットに該当するアカウントグループと、前記第1の送信元アドレス以外の送信元アドレスのアカウントグループのうちの最新のタイムスロット以前の所定数の各タイムスロットに該当する各アカウントグループとの間で重複する第2のアカウント数をそれぞれ計算し、
前記判定部は、前記第2のアカウント数が前記第1閾値を越えるアカウントグループの数が前記第2閾値を越える場合に、該第1の送信元アドレスが攻撃者のアドレスであると判定する
ことを特徴とする請求項3に記載の検知装置。 - さらに、
前記判定部は、前記第2のアカウント数が前記第1閾値を越えるアカウントグループが存在する場合に、前記第2のアカウント数が前記第1閾値を越えるアカウントグループに該当する前記第1の送信元アドレス以外の送信元アドレスが攻撃者のアドレスであると判定する
ことを特徴とする請求項4に記載の検知装置。 - 前記判定部は、前記計算部により計算されたアカウント数にタイムスロット又は送信元アドレスに応じた各加重係数を乗算した値をもとに攻撃者のアドレスを判定する
ことを特徴とする請求項2に記載の検知装置。 - ユーザ認証を行う認証装置及び検知装置を含む検知システムにおける検知方法であって、
前記検知装置が、
前記認証装置から取得した認証情報からアカウント及びアカウントの送信元アドレスを抽出し、アカウントのタイムスタンプ及び送信元アドレスに応じて、所定時間間隔のタイムスロット毎かつ送信元アドレス毎にアカウントをグループ化し、同一グループ内で同一アカウントの重複を除外したアカウントグループを抽出し、
抽出した各アカウントグループ間で重複するアカウント数を計算し、
計算したアカウント数が第1閾値を越える同一送信元アドレスのアカウントグループの数が第2閾値を越える場合に、該同一送信元アドレスが攻撃者のアドレスであると判定する
処理を含んだことを特徴とする検知方法。 - 請求項2に記載の検知装置としてコンピュータを機能させる検知プログラム。
Priority Applications (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| US15/578,908 US10972500B2 (en) | 2015-06-05 | 2016-06-03 | Detection system, detection apparatus, detection method, and detection program |
| JP2017522291A JP6392985B2 (ja) | 2015-06-05 | 2016-06-03 | 検知システム、検知装置、検知方法及び検知プログラム |
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| JP2015115034 | 2015-06-05 | ||
| JP2015-115034 | 2015-06-05 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2016195090A1 true WO2016195090A1 (ja) | 2016-12-08 |
Family
ID=57441344
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/JP2016/066642 Ceased WO2016195090A1 (ja) | 2015-06-05 | 2016-06-03 | 検知システム、検知装置、検知方法及び検知プログラム |
Country Status (3)
| Country | Link |
|---|---|
| US (1) | US10972500B2 (ja) |
| JP (1) | JP6392985B2 (ja) |
| WO (1) | WO2016195090A1 (ja) |
Cited By (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN114386049A (zh) * | 2020-10-20 | 2022-04-22 | Oppo广东移动通信有限公司 | 加密方法、解密方法、装置及设备 |
Families Citing this family (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2017208969A1 (ja) * | 2016-06-01 | 2017-12-07 | 日本電信電話株式会社 | 検知装置、検知方法、検知システム、および検知プログラム |
| US10671998B2 (en) * | 2016-09-27 | 2020-06-02 | Paypal, Inc. | Managing fraudulent logins at payment systems |
| US10672004B2 (en) * | 2016-09-28 | 2020-06-02 | Paypal, Inc. | Managing fraudulent sign-ups at payment systems |
| US10686833B2 (en) * | 2017-03-31 | 2020-06-16 | Samsung Electronics Co., Ltd. | System and method of detecting and countering denial-of-service (DoS) attacks on an NVMe-of-based computer storage array |
Citations (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2003100619A1 (en) * | 2002-05-28 | 2003-12-04 | Fujitsu Limited | Unauthorized access detection apparatus, unauthorized access detection program, and unauthorized access detection method |
| US20050216955A1 (en) * | 2004-03-25 | 2005-09-29 | Microsoft Corporation | Security attack detection and defense |
| JP2005341217A (ja) * | 2004-05-27 | 2005-12-08 | Fujitsu Ltd | 不正アクセス検知装置、不正アクセス検知方法、不正アクセス検知プログラムおよび分散型サービス不能化攻撃検知装置 |
| US20070220605A1 (en) * | 2006-03-15 | 2007-09-20 | Daniel Chien | Identifying unauthorized access to a network resource |
| US20110185419A1 (en) * | 2010-01-26 | 2011-07-28 | Bae Systems Information And Electronic Systems Integration Inc. | Method and apparatus for detecting ssh login attacks |
| JP2011150612A (ja) * | 2010-01-25 | 2011-08-04 | Fujitsu Ltd | アカウント不正使用判別プログラム、装置、及び方法 |
Family Cites Families (18)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US8234503B2 (en) * | 2004-05-19 | 2012-07-31 | Ca, Inc. | Method and systems for computer security |
| US7508757B2 (en) * | 2004-10-15 | 2009-03-24 | Alcatel Lucent | Network with MAC table overflow protection |
| GB2422505A (en) * | 2005-01-20 | 2006-07-26 | Agilent Technologies Inc | Sampling datagrams |
| US20060256729A1 (en) * | 2005-05-10 | 2006-11-16 | David Chen | Method and apparatus for identifying and disabling worms in communication networks |
| US7624447B1 (en) * | 2005-09-08 | 2009-11-24 | Cisco Technology, Inc. | Using threshold lists for worm detection |
| US7706263B2 (en) * | 2005-12-15 | 2010-04-27 | Yahoo! Inc. | Tracking and blocking of spam directed to clipping services |
| US7832009B2 (en) * | 2005-12-28 | 2010-11-09 | Foundry Networks, Llc | Techniques for preventing attacks on computer systems and networks |
| US20090064329A1 (en) * | 2007-06-25 | 2009-03-05 | Google Inc. | Zero-hour quarantine of suspect electronic messages |
| US8434140B2 (en) * | 2007-11-06 | 2013-04-30 | Barracuda Networks, Inc. | Port hopping and seek you peer to peer traffic control method and system |
| US20090198707A1 (en) * | 2008-02-06 | 2009-08-06 | Electronic Data Systems Corporation | System and method for managing firewall log records |
| US9866426B2 (en) * | 2009-11-17 | 2018-01-09 | Hawk Network Defense, Inc. | Methods and apparatus for analyzing system events |
| US8516585B2 (en) * | 2010-10-01 | 2013-08-20 | Alcatel Lucent | System and method for detection of domain-flux botnets and the like |
| US8984627B2 (en) * | 2010-12-30 | 2015-03-17 | Verizon Patent And Licensing Inc. | Network security management |
| US11328323B2 (en) * | 2013-10-15 | 2022-05-10 | Yahoo Ad Tech Llc | Systems and methods for matching online users across devices |
| US8832832B1 (en) * | 2014-01-03 | 2014-09-09 | Palantir Technologies Inc. | IP reputation |
| US9591008B2 (en) * | 2015-03-06 | 2017-03-07 | Imperva, Inc. | Data access verification for enterprise resources |
| US20170098067A1 (en) * | 2015-10-01 | 2017-04-06 | Facebook, Inc. | Systems and methods for user authentication |
| US10594728B2 (en) * | 2016-06-29 | 2020-03-17 | AVAST Software s.r.o. | Detection of domain name system hijacking |
-
2016
- 2016-06-03 US US15/578,908 patent/US10972500B2/en active Active
- 2016-06-03 WO PCT/JP2016/066642 patent/WO2016195090A1/ja not_active Ceased
- 2016-06-03 JP JP2017522291A patent/JP6392985B2/ja active Active
Patent Citations (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2003100619A1 (en) * | 2002-05-28 | 2003-12-04 | Fujitsu Limited | Unauthorized access detection apparatus, unauthorized access detection program, and unauthorized access detection method |
| US20050216955A1 (en) * | 2004-03-25 | 2005-09-29 | Microsoft Corporation | Security attack detection and defense |
| JP2005341217A (ja) * | 2004-05-27 | 2005-12-08 | Fujitsu Ltd | 不正アクセス検知装置、不正アクセス検知方法、不正アクセス検知プログラムおよび分散型サービス不能化攻撃検知装置 |
| US20070220605A1 (en) * | 2006-03-15 | 2007-09-20 | Daniel Chien | Identifying unauthorized access to a network resource |
| JP2011150612A (ja) * | 2010-01-25 | 2011-08-04 | Fujitsu Ltd | アカウント不正使用判別プログラム、装置、及び方法 |
| US20110185419A1 (en) * | 2010-01-26 | 2011-07-28 | Bae Systems Information And Electronic Systems Integration Inc. | Method and apparatus for detecting ssh login attacks |
Cited By (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN114386049A (zh) * | 2020-10-20 | 2022-04-22 | Oppo广东移动通信有限公司 | 加密方法、解密方法、装置及设备 |
Also Published As
| Publication number | Publication date |
|---|---|
| JP6392985B2 (ja) | 2018-09-19 |
| US20180176250A1 (en) | 2018-06-21 |
| JPWO2016195090A1 (ja) | 2017-11-09 |
| US10972500B2 (en) | 2021-04-06 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| CN109194680B (zh) | 一种网络攻击识别方法、装置及设备 | |
| US9237168B2 (en) | Transport layer security traffic control using service name identification | |
| CN102792635B (zh) | 基于行为的安全系统 | |
| JP6392985B2 (ja) | 検知システム、検知装置、検知方法及び検知プログラム | |
| US20220038442A1 (en) | Multi-party computation (mpc) based authorization | |
| US7937586B2 (en) | Defending against denial of service attacks | |
| US20170006053A1 (en) | Automatically preventing and remediating network abuse | |
| US12137080B2 (en) | Packet watermark with static salt and token validation | |
| US20150350234A1 (en) | Manipulating api requests to indicate source computer application trustworthiness | |
| WO2016006520A1 (ja) | 検知装置、検知方法及び検知プログラム | |
| JP2019021294A (ja) | DDoS攻撃判定システムおよび方法 | |
| CN109698809B (zh) | 一种账号异常登录的识别方法及装置 | |
| CN105721411A (zh) | 一种防止盗链的方法、防止盗链的服务器及客户端 | |
| WO2015043491A1 (zh) | 一种用于对互联网账号的登录进行安全验证的方法及系统 | |
| US20190166112A1 (en) | Protecting against malicious discovery of account existence | |
| US10931691B1 (en) | Methods for detecting and mitigating brute force credential stuffing attacks and devices thereof | |
| CN107046516B (zh) | 一种识别移动终端身份的风控控制方法及装置 | |
| US8572366B1 (en) | Authenticating clients | |
| CN107196972A (zh) | 一种认证方法及系统、终端和服务器 | |
| CN108600145B (zh) | 一种确定DDoS攻击设备的方法及装置 | |
| US20240080314A1 (en) | Packet watermark with dynamic token validation | |
| US20130305321A1 (en) | Methods for confirming user interaction in response to a request for a computer provided service and devices thereof | |
| CN102098285A (zh) | 一种防范钓鱼攻击的方法及装置 | |
| CN101917438A (zh) | 在网络通信系统中访问控制方法和系统 | |
| CN113678419B (zh) | 端口扫描检测 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 16803521 Country of ref document: EP Kind code of ref document: A1 |
|
| ENP | Entry into the national phase |
Ref document number: 2017522291 Country of ref document: JP Kind code of ref document: A |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 15578908 Country of ref document: US |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 16803521 Country of ref document: EP Kind code of ref document: A1 |





