WO2020003406A1 - 不審メール検知装置、不審メール検知方法および不審メール検知プログラム - Google Patents
不審メール検知装置、不審メール検知方法および不審メール検知プログラム Download PDFInfo
- Publication number
- WO2020003406A1 WO2020003406A1 PCT/JP2018/024373 JP2018024373W WO2020003406A1 WO 2020003406 A1 WO2020003406 A1 WO 2020003406A1 JP 2018024373 W JP2018024373 W JP 2018024373W WO 2020003406 A1 WO2020003406 A1 WO 2020003406A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- suspicious
- text
- target
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F13/00—Interconnection of, or transfer of information or other signals between, memories, input/output devices or central processing units
Definitions
- the present invention relates to a technology for detecting a suspicious e-mail.
- Targeted attacks are a serious threat.
- a targeted attack is an attack aimed at stealing confidential information or the like targeting a specific organization or a specific person.
- targeted email attacks remain one of the serious threats.
- Targeted email attacks are email-based attacks. According to Trend Micro research, targeted email attacks account for 76 percent of all corporate attacks. Therefore, preventing targeted email attacks is important from the viewpoint of preventing sophisticated cyber attacks that increase damage. Against this background, technologies are being studied to prevent an organization from being targeted e-mail attacks by detecting targeted e-mail attacks.
- Patent Literature 1 discloses a technique of comparing a header of a received mail with a learned regular header to determine whether the received mail is a suspicious electronic mail.
- Patent Literature 2 discloses a technology that specifies a file format for determining whether a file attached to an electronic mail is suspicious and determines whether the specified format is permitted.
- Patent Literature 3 discloses a technique for determining that a new mail is a suspicious electronic mail when the similarity between the header information of the new mail and the header information of the past mail is low.
- Patent Document 4 discloses a technique for determining that a received mail is a suspicious electronic mail when the similarity between the body of the received mail and the body of the spam message exceeds a threshold.
- Non-patent document 1 and non-patent document 2 will be referred to in the embodiments.
- the present invention aims to enable appropriate determination of whether an email is suspicious.
- the suspicious mail detection device of the present invention A sender profile generation unit that generates a sender profile of the target mail based on the target mail that is the inspection target electronic mail, From a text list file in which one or more text data of one or more suspicious emails and one or more sender profiles of the one or more suspicious emails are associated with each other, A text data extraction unit for extracting text data corresponding to the sender profile; A text inspection unit that compares the text of the target email with text data extracted from the text list file and determines whether the target email is a suspicious email based on the comparison result.
- the present invention it is possible to compare the text of an e-mail with a proper suspicious mail to be compared with the text of the e-mail, and determine whether the e-mail is suspicious based on the comparison result. Therefore, it is possible to appropriately determine whether the electronic mail is suspicious.
- FIG. 2 is a configuration diagram of a suspicious mail detection device 100 according to the first embodiment.
- FIG. 4 is a schematic diagram of a suspicious mail detection method according to the first embodiment.
- 5 is a flowchart of a suspicious mail detection method according to the first embodiment.
- FIG. 3 is a diagram showing a text list file 131A according to the first embodiment.
- FIG. 4 is a diagram showing a text list file 131B according to the first embodiment.
- 5 is a flowchart of an operation phase (S120) according to the first embodiment.
- 9 is a flowchart of a text inspection process (S126) according to the first embodiment.
- FIG. 2 is a hardware configuration diagram of the suspicious mail detection device 100 according to the first embodiment.
- Embodiment 1 FIG. A form for detecting a suspicious email will be described with reference to FIGS.
- the suspicious mail detection device 100 is a computer including hardware such as a processor 101, a memory 102, an auxiliary storage device 103, and an input / output interface 104. These hardwares are connected to each other via signal lines.
- the processor 101 is an IC (Integrated Circuit) that performs arithmetic processing, and controls other hardware.
- the processor 101 is a CPU (Central Processing Unit), a DSP (Digital Signal Processor), or a GPU (Graphics Processing Unit).
- the memory 102 is a volatile storage device.
- the memory 102 is also called a main storage device or a main memory.
- the memory 102 is a RAM (Random Access Memory).
- the data stored in the memory 102 is stored in the auxiliary storage device 103 as needed.
- the auxiliary storage device 103 is a nonvolatile storage device.
- the auxiliary storage device 103 is a ROM (Read Only Memory), a HDD (Hard Disk Drive), or a flash memory.
- the data stored in the auxiliary storage device 103 is loaded into the memory 102 as needed.
- the input / output interface 104 is a port to which an input device and an output device are connected.
- the input / output interface 104 is a USB terminal
- the input device is a keyboard and a mouse
- the output device is a display.
- USB is an abbreviation for Universal Serial Bus.
- the suspicious mail detection device 100 includes elements such as a text data registration unit 111, a mail reception unit 121, a surface analysis unit 122, a sender profile generation unit 123, a text data extraction unit 124, a text inspection unit 125, and an alert generation unit 126. These elements are realized by software.
- the auxiliary storage device 103 causes a computer to function as a text data registration unit 111, a mail reception unit 121, a surface analysis unit 122, a sender profile generation unit 123, a text data extraction unit 124, a text inspection unit 125, and an alert generation unit 126.
- Suspicious mail detection program is stored.
- the suspicious mail detection program is loaded into the memory 102 and executed by the processor 101.
- the auxiliary storage device 103 stores an OS (Operating System). At least a part of the OS is loaded into the memory 102 and executed by the processor 101. That is, the processor 101 executes the suspicious mail detection program while executing the OS.
- Data obtained by executing the suspicious mail detection program is stored in a storage device such as the memory 102, the auxiliary storage device 103, a register in the processor 101, or a cache memory in the processor 101.
- the auxiliary storage device 103 functions as the storage unit 130.
- another storage device may function as the storage unit 130 instead of the auxiliary storage device 103 or together with the auxiliary storage device 103.
- the suspicious e-mail detection device 100 may include a plurality of processors instead of the processor 101.
- the plurality of processors share the role of the processor 101.
- the suspicious mail detection program can be recorded (stored) in a computer-readable manner on a non-volatile recording medium such as an optical disk or a flash memory.
- the operation of the suspicious email detection device 100 corresponds to a suspicious email detection method.
- the procedure of the suspicious email detection method corresponds to the procedure of the suspicious email detection program.
- the mail receiving unit 121 receives an electronic mail to be inspected.
- the e-mail to be inspected is called a target e-mail.
- the surface analysis unit 122 determines whether the target mail is a suspicious mail by performing a surface analysis on the target mail.
- Suspicious e-mail is a suspicious e-mail.
- a suspicious email is an email that is presumed to be a targeted attack email.
- the targeted e-mail is an e-mail for performing a targeted e-mail attack.
- the alert generation unit 126 When the surface analysis unit 122 determines that the target mail is a suspicious mail, the alert generation unit 126 generates an alert.
- the sender profile generation unit 123 generates a sender profile of the target mail based on the target mail.
- the sender profile is data indicating information on the sender of the e-mail.
- the body data extraction unit 124 extracts body data corresponding to the sender profile of the target mail from the body list file.
- the text list file is a file in which one or more body data of one or more suspicious mails and one or more sender profiles of the one or more suspicious mails are associated with each other.
- the text data is data representing the text of the text of the suspicious email.
- the body inspection unit 125 compares the body of the target mail with the body data extracted from the body list file. Then, the body inspection unit 125 determines whether the target mail is a suspicious mail based on the comparison result. Specifically, when the target mail is not determined to be a suspicious mail by the surface analysis, the body inspection unit 125 determines whether the target mail is a suspicious mail.
- the alert generation unit 126 When the body inspection unit 125 determines that the target mail is a suspicious mail, the alert generation unit 126 generates an alert.
- Step S110 is a preparation phase.
- the user inputs a set of body data and a sender profile for each of one or more suspicious mails to the suspicious mail detection device 100.
- the body data registration unit 111 receives a set of body data and a sender profile for each of one or more suspicious mails. Then, the body data registration unit 111 registers a set of the body data and the sender profile for each of one or more suspicious mails in the body list file 131.
- the text list file 131 is stored in the storage unit 130.
- a user can create a set of text data and a sender profile by referring to a text example of a targeted attack email disclosed by an organization related to information processing.
- An organization related to information processing is the Information Processing Promotion Agency (IPA).
- Non-Patent Document 2 shows an example of a targeted attack email and how to distinguish it.
- the text list file 131 will be described with reference to FIGS.
- the text list file 131A in FIG. 4 and the text list file 131B in FIG. 5 are specific examples of the text list file 131.
- the text list file 131A and the text list file 131B include two or more pairs of text data and a transmission profile.
- the text data indicates the text of the text of the suspicious email.
- X 1 represents the company name
- X 2 represents the university name
- X 3 represents the sender's name
- Y 1 represents a company name
- Y 2 is represents the software name.
- the text data indicates the text pattern of the text of the suspicious email.
- the body data indicates one or more words used in the body of the suspicious email and the order of the one or more words.
- [XXX] is a placeholder and means a proper noun that identifies “XXX”. That is, proper nouns are replaced with placeholders in the text data.
- [organization name] means a proper noun that identifies the organization name.
- the sender profile includes profile information such as address, affiliation, industry, and attribute.
- the address in the sender profile indicates the sender's mail address.
- the affiliation in the sender profile indicates the organization to which the sender belongs.
- the industry in the sender profile indicates the industry to which the organization to which the sender belongs belongs.
- the attribute in the sender profile indicates the attribute of the sender or the attribute of the mail body.
- X 2 represents the university name.
- Y 3 represents the organization name.
- the sender's name and sender's domain are also examples of profile information.
- the profile information is of a dictionary type, and the profile information is managed in association with a key using a label such as a sender name or affiliation as a key.
- Step S120 is an operation phase.
- the suspicious email detection device 100 determines whether the target email is a suspicious email.
- step S121 the mail receiving unit 121 receives an electronic mail to be inspected.
- the received e-mail is called target e-mail.
- the mail receiving unit 121 receives a target mail from the mail system.
- a specific example of a mail system is a mail server or a mail client.
- step S122 the surface analysis unit 122 performs a surface analysis on the target mail. Specifically, the surface analysis unit 122 performs a surface analysis on the header of the target mail. Then, the surface analysis unit 122 determines whether the target mail is a suspicious mail based on the analysis result. For example, the surface analysis unit 122 determines whether the target mail is a suspicious mail by a method disclosed in any of Patent Literatures 1 to 4. If the target mail is a suspicious mail, the process proceeds to step S123. If the target mail is not a suspicious mail, the process proceeds to step S124.
- step S123 the alert generating unit 126 generates an alert.
- the alert generating unit 126 displays an alert message on a display.
- the alert message indicates that a suspicious electronic mail (target mail) has occurred.
- the operation phase (S120) ends.
- step S124 the sender profile generation unit 123 generates a sender profile of the target mail.
- the sender profile generation unit 123 acquires information to be included in the sender profile of the target mail as follows.
- the sender profile generation unit 123 extracts the mail address of the sender from the header of the target mail.
- the sender profile generation unit 123 extracts the name (affiliation name) of the organization to which the sender belongs from the body of the target mail by analyzing the body of the target mail.
- the sender profile generation unit 123 searches the Internet for the affiliation name of the sender.
- the sender profile generation unit 123 determines the name of the industry (industry name) to which the organization to which the sender belongs is based on the information obtained from the search result.
- the sender profile generation unit 123 determines the attributes of the sender based on the affiliation name of the sender.
- the sender profile generation unit 123 determines the attribute of the text of the target mail by analyzing the text of the target mail.
- step S125 the body data extracting unit 124 extracts one or more body data corresponding to the sender profile of the target mail from the body list file 131.
- the body data extraction unit 124 extracts body data corresponding to the sender profile of the target mail as follows. First, the body data extraction unit 124 selects a sender profile that matches the sender profile of the target mail from the body list file 131. For example, a sender profile that matches the sender profile of the target mail is a sender profile that includes all information included in the sender profile of the target mail. Also, for example, a sender profile that matches the sender profile of the target mail is a sender profile whose degree of matching with the sender profile of the target mail exceeds a threshold. The matching degree between the target mail and the sender profile is higher as the number of pieces of information common to the sender profile of the target mail is larger. Then, the text data extraction unit 124 extracts text data associated with the selected sender profile from the text list file 131. The extracted text data is text data corresponding to the sender profile of the target mail.
- a sender profile that matches the sender profile of the target mail is a sender profile that includes all information included
- step S126 the body inspection unit 125 inspects the body of the target mail based on one or more body data extracted from the body list file 131.
- the operation phase (S120) ends.
- step S1261 the text inspection unit 125 selects one unselected text data from one or more text data extracted from the text list file 131.
- the text data in step S1262 is the text data selected in step S1261.
- step S1262 the text inspection unit 125 calculates the similarity between the text of the target mail and the text data by comparing the text of the target mail with the text data. The more similar the text of the body of the target mail is to the text represented by the body data, the higher the similarity between the body of the target mail and the body data.
- the body inspection unit 125 calculates the similarity between the body of the target mail and the body data as follows. First, the text inspection unit 125 calculates a text feature vector (target feature vector) in the text of the target mail and a text feature vector represented by the text data (comparison feature vector) using existing technology. A specific example of the existing technology is Word2Vec.
- Non-Patent Document 1 is a document relating to Word2Vec. By applying Word2Vec, a distributed expression can be extracted from the body of an e-mail, and the extracted distributed expression can be represented by a feature vector. Then, text inspection section 125 calculates the cosine similarity between the target feature vector and the comparison feature vector. The calculated cosine similarity is the similarity between the body of the target mail and the body data.
- step S1263 the text inspection unit 125 compares the similarity calculated in step S1262 with a threshold. If the similarity is equal to or larger than the threshold, the process proceeds to step S1265. If the similarity is less than the threshold, the process proceeds to step S1264.
- step S1264 the text inspection unit 125 determines whether there is text data not selected in step S1261.
- the text data not selected in step S1261 is referred to as unselected data. If there is unselected data, the process proceeds to step S1261. If there is no unselected data, the text inspection processing (S126) ends.
- alert generating section 126 generates an alert.
- the alert generating unit 126 displays an alert message on a display.
- the alert message indicates that a suspicious electronic mail (target mail) has occurred.
- the text inspection process (S126) ends.
- Embodiment 1 *** Effect of Embodiment 1 *** Even if the surface information such as the header is natural, a suspicious e-mail can be detected when a malicious exchange is performed. As a result, it is possible to prevent a sophisticated attack by an attacker.
- the suspicious mail detection device 100 includes a processing circuit 109.
- the processing circuit 109 is hardware that implements a text data registration unit 111, a mail reception unit 121, a surface analysis unit 122, a sender profile generation unit 123, a text data extraction unit 124, a text inspection unit 125, and an alert generation unit 126. is there.
- the processing circuit 109 may be dedicated hardware or the processor 101 that executes a program stored in the memory 102.
- the processing circuit 109 is dedicated hardware, the processing circuit 109 is, for example, a single circuit, a composite circuit, a programmed processor, a parallel programmed processor, an ASIC, an FPGA, or a combination thereof.
- ASIC is an abbreviation for Application Specific Integrated Circuit
- FPGA is an abbreviation for Field Programmable Gate Array.
- the suspicious e-mail detection device 100 may include a plurality of processing circuits replacing the processing circuit 109. The plurality of processing circuits share the role of the processing circuit 109.
- processing circuit 109 some functions may be realized by dedicated hardware, and the remaining functions may be realized by software or firmware.
- the processing circuit 109 can be realized by hardware, software, firmware, or a combination thereof.
- 100 suspicious mail detection device 101 processor, 102 memory, 103 auxiliary storage device, 104 input / output interface, 109 processing circuit, 111 text data registration unit, 121 mail reception unit, 122 surface analysis unit, 123 sender profile generation unit, 124 Text data extraction unit, 125 ⁇ text inspection unit, 126 # alert generation unit, 130 # storage unit, 131 # text list file.
Landscapes
- Engineering & Computer Science (AREA)
- Theoretical Computer Science (AREA)
- Physics & Mathematics (AREA)
- General Engineering & Computer Science (AREA)
- General Physics & Mathematics (AREA)
- Information Transfer Between Computers (AREA)
Abstract
送信者プロファイル生成部(123)は、検査対象の電子メールである対象メールに基づいて前記対象メールの送信者プロファイルを生成する。本文データ抽出部(124)は、1つ以上の不審メールについての1つ以上の本文データと、前記1つ以上の不審メールについての1つ以上の送信者プロファイルと、が互いに対応付けられた本文一覧ファイルから、前記対象メールの前記送信者プロファイルに対応する本文データを抽出する。本文検査部(125)は、前記対象メールの本文を前記本文一覧ファイルから抽出された本文データと比較し、比較結果に基づいて前記対象メールが不審メールであるか判定する。
Description
本発明は、不審な電子メールを検知するための技術に関するものである。
標的型攻撃が深刻な脅威となっている。標的型攻撃は、特定の組織または特定の人を対象として、機密情報の窃取等を目的とする攻撃である。
標的型攻撃の中でも、標的型メール攻撃は、依然として重大な脅威の一つである。標的型メール攻撃は、電子メールをベースにした攻撃である。
トレンドマイクロの調査では、標的型メール攻撃によるマルウェア感染は企業に対する攻撃全体の76パーセントにも上る、との結果が出ている。そのため、標的型メール攻撃を防ぐことは、被害を増加させる巧妙なサイバー攻撃を防ぐ観点から重要である。
このような背景の元、標的型攻撃メールを検知することによって標的型メール攻撃から組織を防ぐための技術が検討されている。
標的型攻撃の中でも、標的型メール攻撃は、依然として重大な脅威の一つである。標的型メール攻撃は、電子メールをベースにした攻撃である。
トレンドマイクロの調査では、標的型メール攻撃によるマルウェア感染は企業に対する攻撃全体の76パーセントにも上る、との結果が出ている。そのため、標的型メール攻撃を防ぐことは、被害を増加させる巧妙なサイバー攻撃を防ぐ観点から重要である。
このような背景の元、標的型攻撃メールを検知することによって標的型メール攻撃から組織を防ぐための技術が検討されている。
特許文献1には、受信メールのヘッダを学習済みの正規ヘッダと比較することによって、受信メールが不審な電子メールであるか判断する技術が開示されている。
特許文献2には、電子メールに添付されるファイルが不審であるか判断するためにファイルのフォーマットを特定し、特定したフォーマットが許可されるものであるか判定する技術が開示されている。
特許文献3には、新規メールのヘッダ情報と過去メールのヘッダ情報との類似度が低い場合に新規メールが不審な電子メールであると判断する技術が開示されている。
特許文献4には、受信メールの本文とスパムメッセージの本文との類似度が閾値を超える場合に受信メールが不審な電子メールであると判断する技術が開示されている。
特許文献2には、電子メールに添付されるファイルが不審であるか判断するためにファイルのフォーマットを特定し、特定したフォーマットが許可されるものであるか判定する技術が開示されている。
特許文献3には、新規メールのヘッダ情報と過去メールのヘッダ情報との類似度が低い場合に新規メールが不審な電子メールであると判断する技術が開示されている。
特許文献4には、受信メールの本文とスパムメッセージの本文との類似度が閾値を超える場合に受信メールが不審な電子メールであると判断する技術が開示されている。
非特許文献1および非特許文献2については、実施の形態において言及する。
Mikolov, Tomas, et al. "Efficient estimation of word representations in vector space.", arXiv preprint arXiv:1301.3781 (2013)
岡野裕樹、木邑実,辻宏郷,青木眞夫,"IPAテクニカルウォッチ「標的型攻撃メールの見分け方」",独立行政法人情報処理推進機構 技術本部 セキュリティセンター,2015年1月9日
特許文献1または特許文献3に開示された技術のように電子メールのヘッダに基づいて電子メールが不審であるか判定する方法では、メールヘッダが正規のヘッダであるように偽装された電子メールを検知することができない。
特許文献2に開示された技術のように添付ファイルのフォーマットに基づいて添付ファイルが不審であるか判定する方法では、中身が不正であるがフォーマットが正しい電子メールを検知することができない。
特許文献4に開示された技術のように電子メールの本文とスパムメッセージの本文との類似度に基づいて電子メールが不審であるか判定する方法では、電子メールの本文と比較するスパムメッセージの本文が適切なものでなければ電子メールが不審であるか適切に判定することができない。また、電子メールの本文をあらゆるスパムメッセージの本文と比較しようとすると、処理負荷および処理時間が増大してしまう。
特許文献2に開示された技術のように添付ファイルのフォーマットに基づいて添付ファイルが不審であるか判定する方法では、中身が不正であるがフォーマットが正しい電子メールを検知することができない。
特許文献4に開示された技術のように電子メールの本文とスパムメッセージの本文との類似度に基づいて電子メールが不審であるか判定する方法では、電子メールの本文と比較するスパムメッセージの本文が適切なものでなければ電子メールが不審であるか適切に判定することができない。また、電子メールの本文をあらゆるスパムメッセージの本文と比較しようとすると、処理負荷および処理時間が増大してしまう。
本発明は、電子メールが不審であるか適切に判定できるようにすることを目的とする。
本発明の不審メール検知装置は、
検査対象の電子メールである対象メールに基づいて前記対象メールの送信者プロファイルを生成する送信者プロファイル生成部と、
1つ以上の不審メールについての1つ以上の本文データと、前記1つ以上の不審メールについての1つ以上の送信者プロファイルと、が互いに対応付けられた本文一覧ファイルから、前記対象メールの前記送信者プロファイルに対応する本文データを抽出する本文データ抽出部と、
前記対象メールの本文を前記本文一覧ファイルから抽出された本文データと比較し、比較結果に基づいて前記対象メールが不審メールであるか判定する本文検査部とを備える。
検査対象の電子メールである対象メールに基づいて前記対象メールの送信者プロファイルを生成する送信者プロファイル生成部と、
1つ以上の不審メールについての1つ以上の本文データと、前記1つ以上の不審メールについての1つ以上の送信者プロファイルと、が互いに対応付けられた本文一覧ファイルから、前記対象メールの前記送信者プロファイルに対応する本文データを抽出する本文データ抽出部と、
前記対象メールの本文を前記本文一覧ファイルから抽出された本文データと比較し、比較結果に基づいて前記対象メールが不審メールであるか判定する本文検査部とを備える。
本発明によれば、電子メールの本文を電子メールの本文と比較する不審メールの本文として適切なものと比較し、比較結果に基づいて電子メールが不審であるか判定することが可能となる。そのため、電子メールが不審であるか適切に判定することが可能となる。
実施の形態および図面において、同じ要素または対応する要素には同じ符号を付している。説明した要素と同じ符号が付された要素の説明は適宜に省略または簡略化する。図中の矢印はデータの流れ又は処理の流れを主に示している。
実施の形態1.
不審な電子メールを検知する形態について、図1から図7に基づいて説明する。
不審な電子メールを検知する形態について、図1から図7に基づいて説明する。
***構成の説明***
図1に基づいて、不審メール検知装置100の構成を説明する。
不審メール検知装置100は、プロセッサ101とメモリ102と補助記憶装置103と入出力インタフェース104といったハードウェアを備えるコンピュータである。これらのハードウェアは、信号線を介して互いに接続されている。
図1に基づいて、不審メール検知装置100の構成を説明する。
不審メール検知装置100は、プロセッサ101とメモリ102と補助記憶装置103と入出力インタフェース104といったハードウェアを備えるコンピュータである。これらのハードウェアは、信号線を介して互いに接続されている。
プロセッサ101は、演算処理を行うIC(Integrated Circuit)であり、他のハードウェアを制御する。例えば、プロセッサ101は、CPU(Central Processing Unit)、DSP(Digital Signal Processor)、またはGPU(Graphics Processing Unit)である。
メモリ102は揮発性の記憶装置である。メモリ102は、主記憶装置またはメインメモリとも呼ばれる。例えば、メモリ102はRAM(Random Access Memory)である。メモリ102に記憶されたデータは必要に応じて補助記憶装置103に保存される。
補助記憶装置103は不揮発性の記憶装置である。例えば、補助記憶装置103は、ROM(Read Only Memory)、HDD(Hard Disk Drive)、またはフラッシュメモリである。補助記憶装置103に記憶されたデータは必要に応じてメモリ102にロードされる。
入出力インタフェース104は入力装置および出力装置が接続されるポートである。例えば、入出力インタフェース104はUSB端子であり、入力装置はキーボードおよびマウスであり、出力装置はディスプレイである。USBはUniversal Serial Busの略称である。
メモリ102は揮発性の記憶装置である。メモリ102は、主記憶装置またはメインメモリとも呼ばれる。例えば、メモリ102はRAM(Random Access Memory)である。メモリ102に記憶されたデータは必要に応じて補助記憶装置103に保存される。
補助記憶装置103は不揮発性の記憶装置である。例えば、補助記憶装置103は、ROM(Read Only Memory)、HDD(Hard Disk Drive)、またはフラッシュメモリである。補助記憶装置103に記憶されたデータは必要に応じてメモリ102にロードされる。
入出力インタフェース104は入力装置および出力装置が接続されるポートである。例えば、入出力インタフェース104はUSB端子であり、入力装置はキーボードおよびマウスであり、出力装置はディスプレイである。USBはUniversal Serial Busの略称である。
不審メール検知装置100は、本文データ登録部111とメール受付部121と表層解析部122と送信者プロファイル生成部123と本文データ抽出部124と本文検査部125とアラート発生部126といった要素を備える。これらの要素はソフトウェアで実現される。
補助記憶装置103には、本文データ登録部111とメール受付部121と表層解析部122と送信者プロファイル生成部123と本文データ抽出部124と本文検査部125とアラート発生部126としてコンピュータを機能させるための不審メール検知プログラムが記憶されている。不審メール検知プログラムは、メモリ102にロードされて、プロセッサ101によって実行される。
さらに、補助記憶装置103にはOS(Operating System)が記憶されている。OSの少なくとも一部は、メモリ102にロードされて、プロセッサ101によって実行される。
つまり、プロセッサ101は、OSを実行しながら、不審メール検知プログラムを実行する。
不審メール検知プログラムを実行して得られるデータは、メモリ102、補助記憶装置103、プロセッサ101内のレジスタ、または、プロセッサ101内のキャッシュメモリといった記憶装置に記憶される。
さらに、補助記憶装置103にはOS(Operating System)が記憶されている。OSの少なくとも一部は、メモリ102にロードされて、プロセッサ101によって実行される。
つまり、プロセッサ101は、OSを実行しながら、不審メール検知プログラムを実行する。
不審メール検知プログラムを実行して得られるデータは、メモリ102、補助記憶装置103、プロセッサ101内のレジスタ、または、プロセッサ101内のキャッシュメモリといった記憶装置に記憶される。
補助記憶装置103は記憶部130として機能する。但し、他の記憶装置が、補助記憶装置103の代わりに、又は、補助記憶装置103と共に、記憶部130として機能してもよい。
不審メール検知装置100は、プロセッサ101を代替する複数のプロセッサを備えてもよい。複数のプロセッサは、プロセッサ101の役割を分担する。
不審メール検知プログラムは、光ディスクまたはフラッシュメモリ等の不揮発性の記録媒体にコンピュータ読み取り可能に記録(格納)することができる。
***動作の説明***
不審メール検知装置100の動作は不審メール検知方法に相当する。また、不審メール検知方法の手順は不審メール検知プログラムの手順に相当する。
不審メール検知装置100の動作は不審メール検知方法に相当する。また、不審メール検知方法の手順は不審メール検知プログラムの手順に相当する。
図2に基づいて、不審メール検知方法の概要を説明する。
メール受付部121は、検査対象の電子メールを受け取る。
検査対象の電子メールを対象メールという。
メール受付部121は、検査対象の電子メールを受け取る。
検査対象の電子メールを対象メールという。
表層解析部122は、対象メールに対する表層解析によって、対象メールが不審メールであるか判定する。
不審メールは、不審な電子メールである。例えば、不審メールは、標的型攻撃メールであると推測される電子メールである。標的型電子メールは、標的型メール攻撃を行うための電子メールである。
不審メールは、不審な電子メールである。例えば、不審メールは、標的型攻撃メールであると推測される電子メールである。標的型電子メールは、標的型メール攻撃を行うための電子メールである。
表層解析部122によって対象メールが不審メールであると判定された場合、アラート発生部126はアラートを発生させる。
送信者プロファイル生成部123は、対象メールに基づいて、対象メールの送信者プロファイルを生成する。
送信者プロファイルは、電子メールの送信者に関する情報を示すデータである。
送信者プロファイルは、電子メールの送信者に関する情報を示すデータである。
本文データ抽出部124は、本文一覧ファイルから、対象メールの送信者プロファイルに対応する本文データを抽出する。
本文一覧ファイルは、1つ以上の不審メールについての1つ以上の本文データと、前記1つ以上の不審メールについての1つ以上の送信者プロファイルと、が互いに対応付けられたファイルである。
本文データは、不審メールの本文の文面を表すデータである。
本文一覧ファイルは、1つ以上の不審メールについての1つ以上の本文データと、前記1つ以上の不審メールについての1つ以上の送信者プロファイルと、が互いに対応付けられたファイルである。
本文データは、不審メールの本文の文面を表すデータである。
本文検査部125は、対象メールの本文を本文一覧ファイルから抽出された本文データと比較する。そして、本文検査部125は、比較結果に基づいて、対象メールが不審メールであるか判定する。
具体的には、本文検査部125は、表層解析によって対象メールが不審メールであると判定されない場合に、対象メールが不審メールであるか判定する。
具体的には、本文検査部125は、表層解析によって対象メールが不審メールであると判定されない場合に、対象メールが不審メールであるか判定する。
本文検査部125によって対象メールが不審メールであると判定された場合、アラート発生部126はアラートを発生させる。
図3に基づいて、不審メール検知方法の手順を説明する。
ステップS110は準備フェーズである。
ステップS110において、利用者は、1つ以上の不審メールのそれぞれについて本文データと送信者プロファイルとの組を不審メール検知装置100に入力する。
本文データ登録部111は、1つ以上の不審メールのそれぞれについて本文データと送信者プロファイルとの組を受け付ける。そして、本文データ登録部111は、1つ以上の不審メールのそれぞれについて本文データと送信者プロファイルとの組を本文一覧ファイル131に登録する。本文一覧ファイル131は記憶部130に記憶される。
例えば、利用者は、情報処理に関する組織が公開する標的型攻撃メールの文面例を参考にすることによって、本文データと送信者プロファイルとの組を作成することが可能である。情報処理に関する組織の一例は、情報処理推進機構(IPA)である。非特許文献2は、標的型攻撃メールの例と見分け方を示している。
ステップS110は準備フェーズである。
ステップS110において、利用者は、1つ以上の不審メールのそれぞれについて本文データと送信者プロファイルとの組を不審メール検知装置100に入力する。
本文データ登録部111は、1つ以上の不審メールのそれぞれについて本文データと送信者プロファイルとの組を受け付ける。そして、本文データ登録部111は、1つ以上の不審メールのそれぞれについて本文データと送信者プロファイルとの組を本文一覧ファイル131に登録する。本文一覧ファイル131は記憶部130に記憶される。
例えば、利用者は、情報処理に関する組織が公開する標的型攻撃メールの文面例を参考にすることによって、本文データと送信者プロファイルとの組を作成することが可能である。情報処理に関する組織の一例は、情報処理推進機構(IPA)である。非特許文献2は、標的型攻撃メールの例と見分け方を示している。
図4および図5に基づいて、本文一覧ファイル131を説明する。
図4の本文一覧ファイル131Aおよび図5の本文一覧ファイル131Bは、本文一覧ファイル131の具体例である。
本文一覧ファイル131Aおよび本文一覧ファイル131Bは、本文データと送信プロファイルとの組を2つ以上含んでいる。
図4の本文一覧ファイル131Aおよび図5の本文一覧ファイル131Bは、本文一覧ファイル131の具体例である。
本文一覧ファイル131Aおよび本文一覧ファイル131Bは、本文データと送信プロファイルとの組を2つ以上含んでいる。
図4の本文一覧ファイル131Aにおいて、本文データは、不審メールの本文の文面を示している。
第1本文データにおいて、X1は法人名を表し、X2は大学名を表し、X3は送信者名を表している。
第2本文データにおいて、Y1は会社名を表し、Y2はソフトウェア名を表している。
第1本文データにおいて、X1は法人名を表し、X2は大学名を表し、X3は送信者名を表している。
第2本文データにおいて、Y1は会社名を表し、Y2はソフトウェア名を表している。
図5の本文一覧ファイル131Bにおいて、本文データは、不審メールの本文についての文面のパターンを示している。
具体的には、本文データは、不審メールの本文で使用される1つ以上の語と1つ以上の語の順序とを示している。
[XXX]は、プレースホルダであり、「XXX」を識別する固有名詞を意味する。つまり、本文データにおいて、固有名詞はプレースホルダに置き換えられている。例えば、[組織名]は、組織名を識別する固有名詞を意味する。
さらに、動詞の活用等の問題を無視するために、原型だけを本文データに含めるようにするとよい。
具体的には、本文データは、不審メールの本文で使用される1つ以上の語と1つ以上の語の順序とを示している。
[XXX]は、プレースホルダであり、「XXX」を識別する固有名詞を意味する。つまり、本文データにおいて、固有名詞はプレースホルダに置き換えられている。例えば、[組織名]は、組織名を識別する固有名詞を意味する。
さらに、動詞の活用等の問題を無視するために、原型だけを本文データに含めるようにするとよい。
図4の本文一覧ファイル131Aおよび図5の本文一覧ファイル131Bにおいて、送信者プロファイルは、アドレスと所属と業界と属性といったプロファイル情報を含んでいる。
送信者プロファイルにおけるアドレスは、送信者のメールアドレスを示す。
送信者プロファイルにおける所属は、送信者が所属する団体を示す。
送信者プロファイルにおける業界は、送信者が所属する団体が属する業界を示す。
送信者プロファイルにおける属性は、送信者の属性またはメール本文の属性を示す。
第1本文データにおいて、X2は大学名を表している。
第2本文データにおいて、Y3は団体名を表している。
送信者プロファイルにおけるアドレスは、送信者のメールアドレスを示す。
送信者プロファイルにおける所属は、送信者が所属する団体を示す。
送信者プロファイルにおける業界は、送信者が所属する団体が属する業界を示す。
送信者プロファイルにおける属性は、送信者の属性またはメール本文の属性を示す。
第1本文データにおいて、X2は大学名を表している。
第2本文データにおいて、Y3は団体名を表している。
送信者の名前および送信者のドメインもプロファイル情報の一例である。
プロファイル情報は辞書型であり、送信者名または所属などのラベルをキーとしてキーに対応付けてプロファイル情報が管理される。
プロファイル情報は辞書型であり、送信者名または所属などのラベルをキーとしてキーに対応付けてプロファイル情報が管理される。
図3に戻り、ステップS120から説明を続ける。
ステップS120は運用フェーズである。
ステップS120において、不審メール検知装置100は、対象メールが不審メールであるか判定する。
ステップS120は運用フェーズである。
ステップS120において、不審メール検知装置100は、対象メールが不審メールであるか判定する。
図6に基づいて、運用フェーズ(S120)の手順を説明する。
ステップS121において、メール受付部121は、検査対象となる電子メールを受け取る。受け取られる電子メールを対象メールという。
例えば、メール受付部121は、メールシステムから対象メールを受け取る。メールシステムの具体例は、メールサーバまたはメールクライアントである。
ステップS121において、メール受付部121は、検査対象となる電子メールを受け取る。受け取られる電子メールを対象メールという。
例えば、メール受付部121は、メールシステムから対象メールを受け取る。メールシステムの具体例は、メールサーバまたはメールクライアントである。
ステップS122において、表層解析部122は、対象メールに対する表層解析を行う。具体的には、表層解析部122は、対象メールのヘッダに対する表層解析を行う。
そして、表層解析部122は、解析結果に基づいて、対象メールが不審メールであるか判定する。
例えば、表層解析部122は、特許文献1から特許文献4のいずれかに開示されている方法で、対象メールが不審メールであるか判定する。
対象メールが不審メールである場合、処理はステップS123に進む。
対象メールが不審メールでない場合、処理はステップS124に進む。
そして、表層解析部122は、解析結果に基づいて、対象メールが不審メールであるか判定する。
例えば、表層解析部122は、特許文献1から特許文献4のいずれかに開示されている方法で、対象メールが不審メールであるか判定する。
対象メールが不審メールである場合、処理はステップS123に進む。
対象メールが不審メールでない場合、処理はステップS124に進む。
ステップS123において、アラート発生部126は、アラートを発生させる。
例えば、アラート発生部126は、アラートメッセージをディスプレイに表示する。アラートメッセージは、不審な電子メール(対象メール)が発生したことを知らせる。
ステップS123の後、運用フェーズ(S120)は終了する。
例えば、アラート発生部126は、アラートメッセージをディスプレイに表示する。アラートメッセージは、不審な電子メール(対象メール)が発生したことを知らせる。
ステップS123の後、運用フェーズ(S120)は終了する。
ステップS124において、送信者プロファイル生成部123は、対象メールの送信者プロファイルを生成する。
例えば、送信者プロファイル生成部123は、対象メールの送信者プロファイルに含める情報を以下のように取得する。
送信者プロファイル生成部123は、対象メールのヘッダから、送信者のメールアドレスを抽出する。
送信者プロファイル生成部123は、対象メールの本文を解析することによって、対象メールの本文から、送信者が所属する団体の名称(所属名)を抽出する。
送信者プロファイル生成部123は、送信者の所属名をインターネットで検索する。そして、送信者プロファイル生成部123は、検索結果から得られる情報に基づいて、送信者が所属する団体が属する業界の名称(業界名)を判定する。
送信者プロファイル生成部123は、送信者の所属名に基づいて、送信者の属性を判定する。
送信者プロファイル生成部123は、対象メールの本文を解析することによって、対象メールの本文の属性を判定する。
送信者プロファイル生成部123は、対象メールのヘッダから、送信者のメールアドレスを抽出する。
送信者プロファイル生成部123は、対象メールの本文を解析することによって、対象メールの本文から、送信者が所属する団体の名称(所属名)を抽出する。
送信者プロファイル生成部123は、送信者の所属名をインターネットで検索する。そして、送信者プロファイル生成部123は、検索結果から得られる情報に基づいて、送信者が所属する団体が属する業界の名称(業界名)を判定する。
送信者プロファイル生成部123は、送信者の所属名に基づいて、送信者の属性を判定する。
送信者プロファイル生成部123は、対象メールの本文を解析することによって、対象メールの本文の属性を判定する。
ステップS125において、本文データ抽出部124は、本文一覧ファイル131から、対象メールの送信者プロファイルに対応する1つ以上の本文データを抽出する。
具体的には、本文データ抽出部124は、対象メールの送信者プロファイルに対応する本文データを以下のように抽出する。
まず、本文データ抽出部124は、対象メールの送信者プロファイルと合致する送信者プロファイルを本文一覧ファイル131から選択する。例えば、対象メールの送信者プロファイルと合致する送信者プロファイルは、対象メールの送信者プロファイルに含まれる全ての情報を含んだ送信者プロファイルである。また例えば、対象メールの送信者プロファイルと合致する送信者プロファイルは、対象メールの送信者プロファイルとの合致度が閾値を超える送信者プロファイルである。対象メールの送信者プロファイルとの合致度は、対象メールの送信者プロファイルと共通する情報の数が多いほど高い。
そして、本文データ抽出部124は、選択した送信者プロファイルに対応付けられた本文データを本文一覧ファイル131から抽出する。抽出される本文データが、対象メールの送信者プロファイルに対応する本文データである。
まず、本文データ抽出部124は、対象メールの送信者プロファイルと合致する送信者プロファイルを本文一覧ファイル131から選択する。例えば、対象メールの送信者プロファイルと合致する送信者プロファイルは、対象メールの送信者プロファイルに含まれる全ての情報を含んだ送信者プロファイルである。また例えば、対象メールの送信者プロファイルと合致する送信者プロファイルは、対象メールの送信者プロファイルとの合致度が閾値を超える送信者プロファイルである。対象メールの送信者プロファイルとの合致度は、対象メールの送信者プロファイルと共通する情報の数が多いほど高い。
そして、本文データ抽出部124は、選択した送信者プロファイルに対応付けられた本文データを本文一覧ファイル131から抽出する。抽出される本文データが、対象メールの送信者プロファイルに対応する本文データである。
ステップS126において、本文検査部125は、本文一覧ファイル131から抽出された1つ以上の本文データに基づいて、対象メールの本文を検査する。
ステップS126の後、運用フェーズ(S120)は終了する。
ステップS126の後、運用フェーズ(S120)は終了する。
図7に基づいて、本文検査処理(S126)の手順を説明する。
ステップS1261において、本文検査部125は、本文一覧ファイル131から抽出された1つ以上の本文データの中から、未選択の本文データを1つ選択する。
ステップS1261において、本文検査部125は、本文一覧ファイル131から抽出された1つ以上の本文データの中から、未選択の本文データを1つ選択する。
ステップS1262における本文データは、ステップS1261で選択された本文データである。
ステップS1262において、本文検査部125は、対象メールの本文を本文データと比較することによって、対象メールの本文と本文データとの類似度を算出する。対象メールの本文の文面が本文データによって表される文面に似ているほど、対象メールの本文と本文データとの類似度は高い。
例えば、本文検査部125は、対象メールの本文と本文データとの類似度を以下のように算出する。
まず、本文検査部125は、対象メールの本文における文面の特徴ベクトル(対象特徴ベクトル)と、本文データによって表される文面の特徴ベクトル(比較特徴ベクトル)と、を既存技術によって算出する。既存技術の具体例はWord2Vecである。非特許文献1はWord2Vecに関する文献である。Word2Vecを応用することによって、電子メールの本文から分散表現を抽出し、抽出した分散表現を特徴ベクトルで表すことができる。
そして、本文検査部125は、対象特徴ベクトルと比較特徴ベクトルとのコサイン類似度を算出する。算出されるコサイン類似度が対象メールの本文と本文データとの類似度である。
まず、本文検査部125は、対象メールの本文における文面の特徴ベクトル(対象特徴ベクトル)と、本文データによって表される文面の特徴ベクトル(比較特徴ベクトル)と、を既存技術によって算出する。既存技術の具体例はWord2Vecである。非特許文献1はWord2Vecに関する文献である。Word2Vecを応用することによって、電子メールの本文から分散表現を抽出し、抽出した分散表現を特徴ベクトルで表すことができる。
そして、本文検査部125は、対象特徴ベクトルと比較特徴ベクトルとのコサイン類似度を算出する。算出されるコサイン類似度が対象メールの本文と本文データとの類似度である。
ステップS1263において、本文検査部125は、ステップS1262で算出した類似度を閾値と比較する。
類似度が閾値以上である場合、処理はステップS1265に進む。
類似度が閾値未満である場合、処理はステップS1264に進む。
類似度が閾値以上である場合、処理はステップS1265に進む。
類似度が閾値未満である場合、処理はステップS1264に進む。
ステップS1264において、本文検査部125は、ステップS1261で選択されていない本文データが有るか判定する。ステップS1264において、ステップS1261で選択されていない本文データを未選択データという。
未選択データが有る場合、処理はステップS1261に進む。
未選択データが無い場合、本文検査処理(S126)は終了する。
未選択データが有る場合、処理はステップS1261に進む。
未選択データが無い場合、本文検査処理(S126)は終了する。
ステップS1265において、アラート発生部126は、アラートを発生させる。
例えば、アラート発生部126は、アラートメッセージをディスプレイに表示する。アラートメッセージは、不審な電子メール(対象メール)が発生したことを知らせる。
ステップS1265の後、本文検査処理(S126)は終了する。
例えば、アラート発生部126は、アラートメッセージをディスプレイに表示する。アラートメッセージは、不審な電子メール(対象メール)が発生したことを知らせる。
ステップS1265の後、本文検査処理(S126)は終了する。
***実施の形態1の効果***
ヘッダ等の表層情報が自然であっても悪意あるやり取りが実施された際に不審な電子メールを検知することができる。その結果、攻撃者による巧妙な攻撃を防ぐことが可能となる。
ヘッダ等の表層情報が自然であっても悪意あるやり取りが実施された際に不審な電子メールを検知することができる。その結果、攻撃者による巧妙な攻撃を防ぐことが可能となる。
***実施の形態の補足***
図8に基づいて、不審メール検知装置100のハードウェア構成を説明する。
不審メール検知装置100は処理回路109を備える。
処理回路109は、本文データ登録部111とメール受付部121と表層解析部122と送信者プロファイル生成部123と本文データ抽出部124と本文検査部125とアラート発生部126とを実現するハードウェアである。
処理回路109は、専用のハードウェアであってもよいし、メモリ102に格納されるプログラムを実行するプロセッサ101であってもよい。
図8に基づいて、不審メール検知装置100のハードウェア構成を説明する。
不審メール検知装置100は処理回路109を備える。
処理回路109は、本文データ登録部111とメール受付部121と表層解析部122と送信者プロファイル生成部123と本文データ抽出部124と本文検査部125とアラート発生部126とを実現するハードウェアである。
処理回路109は、専用のハードウェアであってもよいし、メモリ102に格納されるプログラムを実行するプロセッサ101であってもよい。
処理回路109が専用のハードウェアである場合、処理回路109は、例えば、単一回路、複合回路、プログラム化したプロセッサ、並列プログラム化したプロセッサ、ASIC、FPGAまたはこれらの組み合わせである。
ASICはApplication Specific Integrated Circuitの略称であり、FPGAはField Programmable Gate Arrayの略称である。
不審メール検知装置100は、処理回路109を代替する複数の処理回路を備えてもよい。複数の処理回路は、処理回路109の役割を分担する。
ASICはApplication Specific Integrated Circuitの略称であり、FPGAはField Programmable Gate Arrayの略称である。
不審メール検知装置100は、処理回路109を代替する複数の処理回路を備えてもよい。複数の処理回路は、処理回路109の役割を分担する。
処理回路109において、一部の機能が専用のハードウェアで実現されて、残りの機能がソフトウェアまたはファームウェアで実現されてもよい。
このように、処理回路109はハードウェア、ソフトウェア、ファームウェアまたはこれらの組み合わせで実現することができる。
実施の形態は、好ましい形態の例示であり、本発明の技術的範囲を制限することを意図するものではない。実施の形態は、部分的に実施してもよいし、他の形態と組み合わせて実施してもよい。フローチャート等を用いて説明した手順は、適宜に変更してもよい。
100 不審メール検知装置、101 プロセッサ、102 メモリ、103 補助記憶装置、104 入出力インタフェース、109 処理回路、111 本文データ登録部、121 メール受付部、122 表層解析部、123 送信者プロファイル生成部、124 本文データ抽出部、125 本文検査部、126 アラート発生部、130 記憶部、131 本文一覧ファイル。
Claims (5)
- 検査対象の電子メールである対象メールに基づいて前記対象メールの送信者プロファイルを生成する送信者プロファイル生成部と、
1つ以上の不審メールについての1つ以上の本文データと、前記1つ以上の不審メールについての1つ以上の送信者プロファイルと、が互いに対応付けられた本文一覧ファイルから、前記対象メールの前記送信者プロファイルに対応する本文データを抽出する本文データ抽出部と、
前記対象メールの本文を前記本文一覧ファイルから抽出された本文データと比較し、比較結果に基づいて前記対象メールが不審メールであるか判定する本文検査部と
を備える不審メール検知装置。 - 前記不審メール検知装置は、さらに、
前記対象メールに対する表層解析によって前記対象メールが不審メールであるか判定する表層解析部
を備える請求項1に記載の不審メール検知装置。 - 前記本文検査部は、前記表層解析によって前記対象メールが不審メールであると判定されない場合に、前記対象メールが不審メールであるか判定する
請求項2に記載の不審メール検知装置。 - 送信者プロファイル生成部が、検査対象の電子メールである対象メールに基づいて前記対象メールの送信者プロファイルを生成し、
本文データ抽出部が、1つ以上の不審メールについての1つ以上の本文データと、前記1つ以上の不審メールについての1つ以上の送信者プロファイルと、が互いに対応付けられた本文一覧ファイルから、前記対象メールの前記送信者プロファイルに対応する本文データを抽出し、
本文検査部が、前記対象メールの本文を前記本文一覧ファイルから抽出された本文データと比較し、比較結果に基づいて前記対象メールが不審メールであるか判定する
不審メール検知方法。 - 検査対象の電子メールである対象メールに基づいて前記対象メールの送信者プロファイルを生成する送信者プロファイル生成処理と、
1つ以上の不審メールについての1つ以上の本文データと、前記1つ以上の不審メールについての1つ以上の送信者プロファイルと、が互いに対応付けられた本文一覧ファイルから、前記対象メールの前記送信者プロファイルに対応する本文データを抽出する本文データ抽出処理と、
前記対象メールの本文を前記本文一覧ファイルから抽出された本文データと比較し、比較結果に基づいて前記対象メールが不審メールであるか判定する本文検査処理
としてコンピュータを機能させるための不審メール検知プログラム。
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| PCT/JP2018/024373 WO2020003406A1 (ja) | 2018-06-27 | 2018-06-27 | 不審メール検知装置、不審メール検知方法および不審メール検知プログラム |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| PCT/JP2018/024373 WO2020003406A1 (ja) | 2018-06-27 | 2018-06-27 | 不審メール検知装置、不審メール検知方法および不審メール検知プログラム |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2020003406A1 true WO2020003406A1 (ja) | 2020-01-02 |
Family
ID=68986693
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/JP2018/024373 Ceased WO2020003406A1 (ja) | 2018-06-27 | 2018-06-27 | 不審メール検知装置、不審メール検知方法および不審メール検知プログラム |
Country Status (1)
| Country | Link |
|---|---|
| WO (1) | WO2020003406A1 (ja) |
Citations (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2012243146A (ja) * | 2011-05-20 | 2012-12-10 | Kddi Corp | 電子メール分類装置、電子メール分類方法及び電子メール分類プログラム |
| US8566938B1 (en) * | 2012-11-05 | 2013-10-22 | Astra Identity, Inc. | System and method for electronic message analysis for phishing detection |
-
2018
- 2018-06-27 WO PCT/JP2018/024373 patent/WO2020003406A1/ja not_active Ceased
Patent Citations (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2012243146A (ja) * | 2011-05-20 | 2012-12-10 | Kddi Corp | 電子メール分類装置、電子メール分類方法及び電子メール分類プログラム |
| US8566938B1 (en) * | 2012-11-05 | 2013-10-22 | Astra Identity, Inc. | System and method for electronic message analysis for phishing detection |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| Venkatraman et al. | Use of data visualisation for zero‐day malware detection | |
| US9953162B2 (en) | Rapid malware inspection of mobile applications | |
| US8239948B1 (en) | Selecting malware signatures to reduce false-positive detections | |
| Andronio et al. | Heldroid: Dissecting and detecting mobile ransomware | |
| US8839401B2 (en) | Malicious message detection and processing | |
| US9038186B1 (en) | Malware detection using file names | |
| US8635700B2 (en) | Detecting malware using stored patterns | |
| US20180183815A1 (en) | System and method for detecting malware | |
| AU2018217323A1 (en) | Methods and systems for identifying potential enterprise software threats based on visual and non-visual data | |
| US20110277033A1 (en) | Identifying Malicious Threads | |
| JP6697123B2 (ja) | プロファイル生成装置、攻撃検知装置、プロファイル生成方法、および、プロファイル生成プログラム | |
| JP2019505943A (ja) | サイバーセキュリティシステムおよび技術 | |
| US11809556B2 (en) | System and method for detecting a malicious file | |
| US20180285565A1 (en) | Malware detection in applications based on presence of computer generated strings | |
| US8516100B1 (en) | Method and apparatus for detecting system message misrepresentation using a keyword analysis | |
| CN107368740B (zh) | 一种针对数据文件中可执行代码的检测方法及系统 | |
| JP6169497B2 (ja) | 接続先情報判定装置、接続先情報判定方法、及びプログラム | |
| US20210021617A1 (en) | Suspicious mail detection device, suspicious mail detection method, and computer readable medium | |
| WO2020003406A1 (ja) | 不審メール検知装置、不審メール検知方法および不審メール検知プログラム | |
| CN114238974B (zh) | 恶意Office文档的检测方法、装置、电子设备及存储介质 | |
| Chen et al. | Shellcode detector for malicious document hunting | |
| US9553882B2 (en) | Correlation of advertising content to malicious software | |
| Alzahrani et al. | RanDS: A Large-Scale Open Dataset of Raw Binaries and Extracted Features for Ransomware Research | |
| Burton et al. | Wordythief: A malicious spammer | |
| Sadhu et al. | An Approach for Malware Detection by Analyzing its Functionalities |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 18924281 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 18924281 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: JP |