WO2022239162A1 - 決定方法、決定装置及び決定プログラム - Google Patents
決定方法、決定装置及び決定プログラム Download PDFInfo
- Publication number
- WO2022239162A1 WO2022239162A1 PCT/JP2021/018118 JP2021018118W WO2022239162A1 WO 2022239162 A1 WO2022239162 A1 WO 2022239162A1 JP 2021018118 W JP2021018118 W JP 2021018118W WO 2022239162 A1 WO2022239162 A1 WO 2022239162A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- label
- feature information
- ioc
- iocs
- learning
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/55—Detecting local intrusion or implementing counter-measures
- G06F21/554—Detecting local intrusion or implementing counter-measures involving event detection and direct action
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/55—Detecting local intrusion or implementing counter-measures
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/55—Detecting local intrusion or implementing counter-measures
- G06F21/552—Detecting local intrusion or implementing counter-measures involving long-term monitoring or reporting
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F2221/00—Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F2221/03—Indexing scheme relating to G06F21/50, monitoring users, programs or devices to maintain the integrity of platforms
- G06F2221/034—Test or assess a computer or a system
Definitions
- the present invention relates to a determination method, a determination device, and a determination program.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Software Systems (AREA)
- Theoretical Computer Science (AREA)
- Computer Hardware Design (AREA)
- Physics & Mathematics (AREA)
- General Engineering & Computer Science (AREA)
- General Physics & Mathematics (AREA)
- Management, Administration, Business Operations System, And Electronic Commerce (AREA)
Abstract
Description
参考文献1:S. C. Sundaramurthy, A. G. Bardas, J. Case, X. Ou, M. Wesch, J. McHugh, and S. R. Rajagopalan, “A human capital model for mitigating security analyst burnout,” Proc. SOUPS, 2015.
参考文献2:Ponemon Institute, “Improving the Effectiveness of the Security Operations Center,” 2019.
参考文献3:F. B. Kokulu, A. Soneji, T. Bao, Y. Shoshitaishvili, Z. Zhao, A. Doupe, and G.-J. Ahn, “Matched and Mismatched SOCs: A Qualitative Study on Security Operations Center Issues,” Proc. ACM CCS, 2019.
まず、図1を用いて、第1の実施形態に係る決定装置を含むセキュリティシステムについて説明する。図1は、セキュリティシステムについて説明する図である。
参考文献4:M. Vielberth, F. Bohm, I. Fichtinger, and G. Pernul, “Security Operations Center: A Systematic Study and Open Challenges,” IEEE Access, vol.8, pp.227756-227779, 2020.
図6は、学習処理の流れを示すフローチャートである。図6に示すように、まず、決定装置20は、過去のアラートの入力を受け付ける(ステップS101)。
これまで説明してきたように、特徴情報抽出部21は、サイバーセキュリティに関する情報に含まれるIOCから特徴情報を抽出する。ラベル付与部22は、IOCのそれぞれについて、関連するアラートの対応に要した稼働量の実績に応じたラベルを付与する。学習部23は、特徴情報抽出部21によって抽出された特徴情報及びラベル付与部22によって付与されたラベルを組み合わせた学習データを用いて、IOCの特徴情報からラベルを出力するモデルの学習を行う。
また、図示した各装置の各構成要素は機能概念的なものであり、必ずしも物理的に図示のように構成されていることを要しない。すなわち、各装置の分散及び統合の具体的形態は図示のものに限られず、その全部又は一部を、各種の負荷や使用状況等に応じて、任意の単位で機能的又は物理的に分散又は統合して構成することができる。さらに、各装置にて行われる各処理機能は、その全部又は任意の一部が、CPU(Central Processing Unit)及び当該CPUにて解析実行されるプログラムにて実現され、あるいは、ワイヤードロジックによるハードウェアとして実現され得る。なお、プログラムは、CPUだけでなく、GPU等の他のプロセッサによって実行されてもよい。
一実施形態として、決定装置20は、パッケージソフトウェアやオンラインソフトウェアとして上記の決定処理を実行する決定プログラムを所望のコンピュータにインストールさせることによって実装できる。例えば、上記の決定プログラムを情報処理装置に実行させることにより、情報処理装置を決定装置20として機能させることができる。ここで言う情報処理装置には、デスクトップ型又はノート型のパーソナルコンピュータが含まれる。また、その他にも、情報処理装置にはスマートフォン、携帯電話機やPHS(Personal Handyphone System)等の移動体通信端末、さらには、PDA(Personal Digital Assistant)等のスレート端末等がその範疇に含まれる。
10 分析エンジン
20 決定装置
21 特徴情報抽出部
22 ラベル付与部
23 学習部
24 予測部
25 モデル情報
30 アラートモニタ
40 IOCチェッカー
Claims (7)
- 決定装置によって実行される決定方法であって、
サイバーセキュリティに関する情報に含まれるIOC(Indicator of Compromise)から特徴情報を抽出する特徴情報抽出工程と、
前記IOCのそれぞれについて、関連するアラートの対応に要した稼働量の実績に応じたラベルを付与するラベル付与工程と、
前記特徴情報抽出工程によって抽出された特徴情報及び前記ラベル付与工程によって付与されたラベルを組み合わせた学習データを用いて、IOCの特徴情報からラベルを出力するモデルの学習を行う学習工程と、
を含むことを特徴とする決定方法。 - 前記ラベル付与工程は、前記IOCのうち、関連するアラートに対して一定期間内に発生した手動調査の回数が所定値以上であるIOCについて、優先度が高いことを示すラベルを付与し、前記手動調査の回数が前記所定値未満であるIOCについて、優先度が高くないことを示すラベルを付与することを特徴とする請求項1に記載の決定方法。
- 前記ラベル付与工程は、前記IOCのうち、関連するアラートに対して一定期間内に発生した手動調査に要した時間が所定値以上であるIOCについて、優先度が高いことを示すラベルを付与し、前記時間が前記所定値未満であるIOCについて、優先度が高くないことを示すラベルを付与することを特徴とする請求項1に記載の決定方法。
- 前記学習工程による学習が行われたモデルを用いて、IOCの特徴情報からラベルを予測する予測工程をさらに含むことを特徴とする請求項1から3のいずれか1項に記載の決定方法。
- 前記予測工程において、優先度が高いことを示すラベルが予測されたIOCに関する情報を通知する通知工程をさらに含むことを特徴とする請求項4に記載の決定方法。
- サイバーセキュリティに関する情報に含まれるIOC(Indicator of Compromise)から特徴情報を抽出する特徴情報抽出部と、
前記IOCのそれぞれについて、関連するアラートの対応に要した稼働量の実績に応じたラベルを付与するラベル付与部と、
前記特徴情報抽出部によって抽出された特徴情報及び前記ラベル付与部によって付与されたラベルを組み合わせた学習データを用いて、IOCの特徴情報からラベルを出力するモデルの学習を行う学習部と、
を有することを特徴とする決定装置。 - コンピュータに、
サイバーセキュリティに関する情報に含まれるIOC(Indicator of Compromise)から特徴情報を抽出する特徴情報抽出手順と、
前記IOCのそれぞれについて、関連するアラートの対応に要した稼働量の実績に応じたラベルを付与するラベル付与手順と、
前記特徴情報抽出手順によって抽出された特徴情報及び前記ラベル付与手順によって付与されたラベルを組み合わせた学習データを用いて、IOCの特徴情報からラベルを出力するモデルの学習を行う学習手順と、
を実行させることを特徴とする決定プログラム。
Priority Applications (3)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| US18/290,022 US20240248986A1 (en) | 2021-05-12 | 2021-05-12 | Determination method, determination device, and determination program |
| JP2023520663A JP7513205B2 (ja) | 2021-05-12 | 2021-05-12 | 決定方法、決定装置及び決定プログラム |
| PCT/JP2021/018118 WO2022239162A1 (ja) | 2021-05-12 | 2021-05-12 | 決定方法、決定装置及び決定プログラム |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| PCT/JP2021/018118 WO2022239162A1 (ja) | 2021-05-12 | 2021-05-12 | 決定方法、決定装置及び決定プログラム |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2022239162A1 true WO2022239162A1 (ja) | 2022-11-17 |
Family
ID=84028048
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/JP2021/018118 Ceased WO2022239162A1 (ja) | 2021-05-12 | 2021-05-12 | 決定方法、決定装置及び決定プログラム |
Country Status (3)
| Country | Link |
|---|---|
| US (1) | US20240248986A1 (ja) |
| JP (1) | JP7513205B2 (ja) |
| WO (1) | WO2022239162A1 (ja) |
Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2016117132A1 (ja) * | 2015-01-23 | 2016-07-28 | 株式会社Ubic | 電子メール分析システム、電子メール分析システムの制御方法、及び電子メール分析システムの制御プログラム |
| JP2018521430A (ja) * | 2015-05-04 | 2018-08-02 | ハサン・シェド・カムラン | コンピュータネットワークにおけるセキュリティを管理する方法及び装置 |
| WO2018235252A1 (ja) * | 2017-06-23 | 2018-12-27 | 日本電気株式会社 | 分析装置、ログの分析方法及び記録媒体 |
| US20190230098A1 (en) * | 2018-01-22 | 2019-07-25 | T-Mobile Usa, Inc. | Indicator of compromise calculation system |
| WO2020148934A1 (ja) * | 2019-01-16 | 2020-07-23 | 株式会社日立製作所 | 分析装置および分析方法 |
Family Cites Families (11)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US9697352B1 (en) * | 2015-02-05 | 2017-07-04 | Logically Secure Limited | Incident response management system and method |
| US10778702B1 (en) * | 2017-05-12 | 2020-09-15 | Anomali, Inc. | Predictive modeling of domain names using web-linking characteristics |
| US11562064B2 (en) * | 2018-06-29 | 2023-01-24 | Netiq Corporation | Machine learning-based security alert escalation guidance |
| US11003766B2 (en) * | 2018-08-20 | 2021-05-11 | Microsoft Technology Licensing, Llc | Enhancing cybersecurity and operational monitoring with alert confidence assignments |
| US11443515B2 (en) * | 2018-12-21 | 2022-09-13 | Ambient AI, Inc. | Systems and methods for machine learning enhanced intelligent building access endpoint security monitoring and management |
| US11637862B1 (en) * | 2019-09-30 | 2023-04-25 | Mandiant, Inc. | System and method for surfacing cyber-security threats with a self-learning recommendation engine |
| US11165815B2 (en) * | 2019-10-28 | 2021-11-02 | Capital One Services, Llc | Systems and methods for cyber security alert triage |
| US11822672B1 (en) * | 2021-02-04 | 2023-11-21 | Cisco Technology, Inc. | Systems and methods for scanning images for vulnerabilities |
| US11882130B2 (en) * | 2021-02-25 | 2024-01-23 | Palo Alto Networks, Inc. | Automated extraction and classification of malicious indicators |
| US20240152603A1 (en) * | 2021-03-16 | 2024-05-09 | Nippon Telegraph And Telephone Corporation | Device for extracting trace of act, method for extracting trace of act, and program for extracting trace of act |
| US20240289447A1 (en) * | 2023-02-28 | 2024-08-29 | State Farm Mutual Automobile Insurance Company | Systems and methods for automated cybersecurity threat testing and detection |
-
2021
- 2021-05-12 WO PCT/JP2021/018118 patent/WO2022239162A1/ja not_active Ceased
- 2021-05-12 US US18/290,022 patent/US20240248986A1/en active Pending
- 2021-05-12 JP JP2023520663A patent/JP7513205B2/ja active Active
Patent Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2016117132A1 (ja) * | 2015-01-23 | 2016-07-28 | 株式会社Ubic | 電子メール分析システム、電子メール分析システムの制御方法、及び電子メール分析システムの制御プログラム |
| JP2018521430A (ja) * | 2015-05-04 | 2018-08-02 | ハサン・シェド・カムラン | コンピュータネットワークにおけるセキュリティを管理する方法及び装置 |
| WO2018235252A1 (ja) * | 2017-06-23 | 2018-12-27 | 日本電気株式会社 | 分析装置、ログの分析方法及び記録媒体 |
| US20190230098A1 (en) * | 2018-01-22 | 2019-07-25 | T-Mobile Usa, Inc. | Indicator of compromise calculation system |
| WO2020148934A1 (ja) * | 2019-01-16 | 2020-07-23 | 株式会社日立製作所 | 分析装置および分析方法 |
Also Published As
| Publication number | Publication date |
|---|---|
| JP7513205B2 (ja) | 2024-07-09 |
| JPWO2022239162A1 (ja) | 2022-11-17 |
| US20240248986A1 (en) | 2024-07-25 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US12225042B2 (en) | System and method for user and entity behavioral analysis using network topology information | |
| US12184697B2 (en) | AI-driven defensive cybersecurity strategy analysis and recommendation system | |
| US20230412620A1 (en) | System and methods for cybersecurity analysis using ueba and network topology data and trigger - based network remediation | |
| US12206708B2 (en) | Correlating network event anomalies using active and passive external reconnaissance to identify attack information | |
| US12289335B2 (en) | Security finding categories-based prioritization | |
| US11245713B2 (en) | Enrichment and analysis of cybersecurity threat intelligence and orchestrating application of threat intelligence to selected network security events | |
| EP3938937B1 (en) | Cloud security using multidimensional hierarchical model | |
| US9411965B2 (en) | Methods and systems for improved risk scoring of vulnerabilities | |
| US9098333B1 (en) | Monitoring computer process resource usage | |
| Sharma | Behavioral analytics and zero trust | |
| US20200004957A1 (en) | Machine learning-based security alert escalation guidance | |
| WO2021216163A2 (en) | Ai-driven defensive cybersecurity strategy analysis and recommendation system | |
| WO2020019063A1 (en) | Systems and methods for cybersecurity risk assessment of users of a computer network | |
| US20240396924A1 (en) | A top-down cyber security system and method | |
| US12488107B2 (en) | Identification of variants of artificial intelligence generated malware | |
| JP2018163537A (ja) | 情報処理装置、情報処理方法、プログラム | |
| US12579269B2 (en) | Artificial intelligence (AI)-based system for detecting malware in endpoint devices using a multi-source data fusion and method thereof | |
| EP3799367B1 (en) | Generation device, generation method, and generation program | |
| JP7513205B2 (ja) | 決定方法、決定装置及び決定プログラム | |
| JP7578191B2 (ja) | 抽出方法、抽出装置及び抽出プログラム | |
| JP7563587B2 (ja) | 抽出方法、抽出装置及び抽出プログラム | |
| JP2022024277A (ja) | 分析システム、分析装置、分析方法 | |
| Paulikas et al. | Survey of Cloud Traffic Anomaly Detection Algorithms | |
| Boddy et al. | Establishing Situational Awareness for Securing Healthcare Patient Records | |
| WO2021154460A1 (en) | Cybersecurity profiling and rating using active and passive external reconnaissance |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 21941896 Country of ref document: EP Kind code of ref document: A1 |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 2023520663 Country of ref document: JP |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 18290022 Country of ref document: US |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 21941896 Country of ref document: EP Kind code of ref document: A1 |

