Access prevention apparatus, method, and program of preventing access
Abstract
[Subject] By detecting it and warning in advance, when a user accesses a link with a risk of inducing Phishing fraud, By always displaying the information of the owner of the site which prevents a user from suffering the damage of Phishing fraud, and has accessed it now, and a user enabling it to always check whether the site which he meant is accessed. It aims at reducing a risk of suffering the damage of Phishing fraud. [Solution means] The site information storage part access prevention equipment remembers the information on the site of a communication network to be, The input unit which inputs the information on the site accessed through a communication network, We decided to have a judgment part which judges relation with the information on the site which the information and site information storage part of the site which the input unit inputted memorize using a predetermined algorithm, and the output unit which outputs warning based on the judgment result of a judgment part. [Selection figure] Fig. 1
Term
No projected expiry on record.
- Priority and filed
- Published
- Today
13 claims: 5 independent, 8 dependent
- 1The site information storage unit that stores the site information of the communication network, the input unit that inputs the information of the site accessed via the communication network, the site information input by the input unit, and the site information storage unit stores the information. An access prevention device including a determination unit that determines the relationship with site information using a predetermined algorithm, and an output unit that outputs a warning based on the determination result of the determination unit. 通信ネットワークのサイトの情報を記憶するサイト情報記憶部と、 通信ネットワークを介してアクセスするサイトの情報を入力する入力部と、 前記入力部が入力したサイトの情報と前記サイト情報記憶部が記憶するサイトの情報との関連を所定のアルゴリズムを用いて判定する判定部と、 前記判定部の判定結果にもとづいて警告を出力する出力部とを備えることを特徴とするアクセス防止装置。
- 3The site information storage unit stores a URL (Uniform Resource Locator) as information on the site, the input unit inputs a URL as information on the site, and the determination unit is a URL input by the input unit. The claim is characterized in that it determines whether or not the URL stored in the site information storage unit is similar, and when the output unit determines that the determination unit is similar, it outputs a warning. The access prevention device described in 1. 前記サイト情報記憶部は、 前記サイトの情報としてURL(Uniform Resource Locator)を記憶し、 前記入力部は、 前記サイトの情報としてURLを入力し、 前記判定部は、 前記入力部が入力するURLと前記サイト情報記憶部が記憶するURLとが類似しているか否かを判定し、 前記出力部は、 前記判定部が類似していると判定した場合、警告を出力することを特徴とする請求項1に記載のアクセス防止装置。
- 9The input unit inputs the URL of the link destination (Uniform Resource Locator) as the information of the site, and the determination unit inputs the URL of the link destination input by the input unit and the URL of the link destination input by the input unit. A claim characterized in that it determines whether or not the URL of a site accessed via a communication network originally matches, and the output unit outputs a warning when it is determined that the determination unit does not match. The access prevention device described in 1. 前記入力部は、 前記サイトの情報としてリンク先のURL(Uniform Resource Locator)を入力し、 前記判定部は、 前記入力部が入力するリンク先のURLと前記入力部が入力するリンク先のURLを元に通信ネットワークを介してアクセスするサイトのURLとが一致するか否かを判定し、 前記出力部は、 前記判定部が一致しないと判定した場合、警告を出力することを特徴とする請求項1に記載のアクセス防止装置。
- 12The site information storage process for storing the site information of the communication network, the input process for inputting the information of the site accessed via the communication network, the site information input in the input process, and the site information storage process for storing the information. An access prevention method characterized by executing a determination step of determining the relationship with site information using a predetermined algorithm and an output step of outputting a warning based on the determination result of the determination step. 通信ネットワークのサイトの情報を記憶するサイト情報記憶工程と、 通信ネットワークを介してアクセスするサイトの情報を入力する入力工程と、 前記入力工程で入力したサイトの情報と前記サイト情報記憶工程で記憶したサイトの情報との関連を所定のアルゴリズムを用いて判定する判定工程と、 前記判定工程の判定結果にもとづいて警告を出力する出力工程とを実行することを特徴とするアクセス防止方法。
- 13The site information storage process for storing the site information of the communication network, the input process for inputting the information of the site accessed via the communication network, and the site information input in the input process and the site information storage process for storing. An access prevention program characterized in that a computer executes a determination process for determining the relationship with site information using a predetermined algorithm and an output process for outputting a warning based on the determination result of the determination process. 通信ネットワークのサイトの情報を記憶するサイト情報記憶処理と、 通信ネットワークを介してアクセスするサイトの情報を入力する入力処理と、 前記入力処理で入力したサイトの情報と前記サイト情報記憶処理で記憶したサイトの情報との関連を所定のアルゴリズムを用いて判定する判定処理と、 前記判定処理の判定結果にもとづいて警告を出力する出力処理とをコンピュータに実行させることを特徴とするアクセス防止プログラム。
Independent claims5
93 paragraphs, as filed
The present invention is an access prevention device that prevents fraudulent acts such as fraud performed by a fraudulent site by detecting a fraudulent site impersonating a legitimate site of a communication network and warning of the danger of access. , Access prevention methods and access prevention programs.
In recent years, a scam called Phishing has been increasing rapidly on the Internet. Phishing means the act of guiding a user to a site that looks like a real company's website, and having the user enter a credit card number or the like to steal it.
For example, Phishing's typical method is to direct victims to fake sites by sending emails that appear to be from well-known companies to victims. The email has the sender's name (From) as the company's name, and the text says, "If you do not access the link below and enter your personal information, your account will expire." .. A user who misunderstands the link in the email as that of a well-known company will enter the credit card number and password of the service on the fake site.
As a means of preventing access to such a dangerous site, there is currently a method of restricting access by an access denial list. In this method, a list of sites that are not allowed to be accessed is prepared in advance, and access to the site is prohibited when a user tries to access the site. Further, as a variant thereof, there is also a method of holding an access permission list and allowing access only to the sites included in the list.<patcit num="1"><text>Japanese Unexamined Patent Publication No. 2004-159159</text></patcit>
<p> However, from the perspective of preventing Phishing, it is easy for Phishing practitioners to build a site with any name, so if they are on the disallowed list, they will immediately build a site with a different name. It is possible. Therefore, in order to deal with this, it is necessary to keep updating the access denial list endlessly, and there is a problem that it does not function as a means to prevent Phishing fraud. In addition, access restrictions based on the access permission list hinder free browsing of the Web, so it was difficult to apply them only in an environment where there is no problem even if the usage of the Web is severely restricted.</p><p> Therefore, when a user accesses a link that may induce a Phishing scam, the purpose is to prevent the user from being victimized by the Phishing scam by detecting the link and giving a warning in advance. Furthermore, by constantly displaying the information of the owner (company) of the site you are currently accessing so that you can always check whether the user is accessing the site you intended, you will be further victimized by Phishing scams. The purpose is to reduce the risk of encountering.</p>
<p> The access prevention device includes a site information storage unit that stores information on the site of the communication network, an input unit that inputs information on the site accessed via the communication network, and a site information and site information storage unit input by the input unit. It is decided to include a determination unit that determines the relationship with the site information stored in the information using a predetermined algorithm, and an output unit that outputs a warning based on the determination result of the determination unit.</p>
<p> According to the present invention, when the determination unit determines that the site accessed via the communication network input from the input unit is related to the site information of the communication network stored in the site information storage unit, the access prevention device causes the output unit to determine. By outputting a warning, it is possible to prevent fraudulent activities such as Phishing scams performed by malicious sites.</p>
Embodiment 1. In Embodiment 1, it is determined whether the URL of the site accessed via the communication network (Uniform Resource Locator) and the URL of the famous site are similar, and the site to be accessed is the famous site. An embodiment that warns the user of the fact when it is determined that the case is not the case will be described. A "site" is an information providing base in which devices (servers) that provide information via a communication network represented by the Internet and the devices (servers) are gathered.
FIG. 1 is a diagram showing the configuration of the terminal 101 and the connection with the database 107 in the first embodiment. The terminal 101 is composed of a browser 102, a network access unit 105, a camouflage determination unit 103, and a famous site information storage unit 104.
In the first embodiment, the terminal 101 corresponds to the access prevention device described in the claims, the camouflage determination unit 103 corresponds to the determination unit, and the famous site information storage unit 104 corresponds to the site information storage unit. Further, the browser 102 realizes an input unit by inputting data from a keyboard, for example, and realizes an output unit by displaying the data on a display.
The browser 102 inputs the information of the site accessed via the communication network, and outputs a warning based on the determination result performed by the impersonation determination unit 103 (described later). In addition, the browser 102 is operated by a user to provide a user interface for viewing Web (World Wide Web) contents on a communication network and e-mails written in HTML (Hyper Text Markup Language).
The famous site information storage unit 104 stores information on the site of the communication network. Here, the URL of a famous site is assumed as "site information".
The camouflage determination unit 103 determines the relationship between the information of the site accessed via the communication network input from the browser 102 and the information of the famous site stored in the famous site information storage unit 104 by using a predetermined algorithm. Specifically, it is determined whether or not the site that the browser 102 attempts to access is a site disguised as a famous site.
The network access unit 105 provides a function of communicating with a Web server or a database in response to a request from the browser 102.
In addition, the terminal 101 can access the database 107 via the communication network 106. The database 107 stores the name of the organization that operates the site of the communication network, and responds to the inquiry from the terminal 101 using the URL or the like with the name of the organization that operates the site specified from the URL.
Next, the operation of the terminal 101 in the first embodiment will be described. The famous site information storage unit 104 of the terminal 101 stores the URL as the site information, the browser 102 inputs the URL as the site information, and the camouflage determination unit 103 stores the URL and the famous site information input by the browser 102. It is determined whether or not the URL stored in the unit 104 is similar, and the browser 102 outputs a warning when it is determined that the impersonation determination unit 103 is similar.
The operation will be specifically described. FIG. 2 is a flowchart for explaining the operation in the first embodiment. The browser 102 of the terminal 101 accepts a page access request by the user 100 for selecting a link destination or the like (step S201). The browser 102 inputs the URL for accessing the selected page into the spoofing determination unit 103, and requests a determination as to whether or not the URL is similar to that of the famous site (step S202). The camouflage determination unit 103 compares the host name portion in the input URL with the host name of a known famous site stored in the famous site information storage unit 104, and calculates the degree of similarity between them. As a result, except when an exact match is obtained, when the similarity exceeds a certain threshold value, it is determined that there is a possibility of camouflage, and the determination result is returned to the browser 102 (step S203). The browser 102 displays a warning that the access destination may be a fake site disguised as a famous site according to the judgment result received from the fake judgment unit 103, and asks the user whether to continue the access. Confirm (step S204).
Figure 3 shows an example of a screen for confirmation by the user. If the user approves the access by clicking the "OK" button on the confirmation screen (step S205), the browser 102 accesses the communication network site through the network access unit 105 as before and displays the Web content. Acquire and display it to the user (step S206).
Next, the method of calculating the degree of similarity in the camouflage determination unit 103 will be described with reference to FIGS. 4 and 5. The camouflage determination unit 103 includes a matrix that gives the similarity for each character as shown in FIG. In this matrix, the similarity between the same characters is 1, and the similarity between different characters is 0. However, for characters that are easily misidentified by the user, such as "1 (ichi)" and "I (eye)", "0 (zero)" and "O (o)", depending on the ease of misidentification. Assign similarity in the range 0 to 1.
The method of calculating the similarity between character strings will be described with reference to FIG. Let's assume that the URL of a famous site is "DOGS" and the URL of the site you are trying to access is "D0S".
As shown in FIG. 5, the camouflage determination unit 103 sets the number of characters (4) of the famous site URL DOGS in the horizontal direction and the number of characters (3) of the access destination URL D0S in the vertical direction. A grid-like directed graph is generated, and edges are also generated diagonally from the upper left to the lower right of each grid.
Next, assign a score to each side of the graph. Diagonal graphs are assigned similarities when comparing horizontal and vertical characters. Assign a value of 0 or less to each graph stretched horizontally and vertically. The assigned value is called the Gap penalty. In Figure 5, a Gap penalty of -0.1 is assigned.
Of the routes from the upper left corner to the lower right corner of the graph to which scores are assigned to each side, the route with the highest score is calculated, and the value obtained by dividing the score by the number of characters of the famous site is similar to the access destination URL. The degree. The above is the method for calculating the similarity between character strings.
The camouflage determination unit 103 uses this method between the host name of the site accessed via the communication network input from the browser 102 and the host name of each famous site stored in the famous site information storage unit 104. If the maximum similarity exceeds a certain threshold, the site accessed via the communication network is judged to be at risk of spoofing, and the browser 102 warns. Is output.
In addition, the browser 102 ignores the warning even though it outputs a warning, and for the site that the user has approved to access, by storing the site, when accessing the site again. Can also prevent the user from being warned.
According to the first embodiment, the terminal 101 has a camouflage determination unit 103 that the site accessed via the communication network input from the browser 102 is related to the information of the communication network site stored in the famous site information storage unit 104. When the determination is made, the browser 102 outputs a warning to prevent fraudulent acts such as Phishing fraud performed by a malicious site.
According to the first embodiment, when the URL of the site accessed via the communication network input from the browser 102 is similar to the URL of the famous site stored in the famous site information storage unit 104, the URL is via the communication network. By determining that the site to be accessed is disguised as a famous site and outputting a warning from the browser 102, it is possible to avoid access to the disguised site and prevent fraudulent activities such as Phishing fraud. it can.
According to the first embodiment, when the site that has been accessed by ignoring the warning is accessed again, the site can be accessed without receiving the warning, and the warning is received one by one. The annoyance can be eliminated.
According to the first embodiment, by detecting the access to the URL similar to the famous site which is the feature of the Phishing target site, the access to the Phishing site can be effectively performed without updating the access denial list. Can be prevented.
In the first embodiment, the case where the access prevention device is realized by a terminal has been described, but it is not limited to the terminal, but can be any of a personal computer, a mobile phone, a PDA (Personal Digital Assistance), and a proxy server. It can also be realized.
Embodiment 2. In Embodiment 2, the similarity between a site accessed via a communication network and a famous site is calculated via the communication network instead of the entire host name of the URL used in Embodiment 1. An embodiment using the domain name described in the URL of the site to be accessed and the character string or a part of the URL of the famous site will be described.
FIG. 6 is a diagram showing the configuration of the terminal 101 and the connection with the database 107 in the second embodiment. The configuration of the terminal in the second embodiment is the same as that in the first embodiment. Further, the function of each unit is the same as that of the first embodiment except that the camouflage determination unit 103 communicates via the network access unit 105.
Also in the second embodiment, the terminal 101 corresponds to the access prevention device described in the claims, the camouflage determination unit 103 corresponds to the determination unit, and the famous site information storage unit 104 corresponds to the site information storage unit. Further, the browser 102 realizes an input unit by inputting data from a keyboard, for example, and realizes an output unit by displaying the data on a display.
Next, the operation of the terminal 101 in the second embodiment will be described. The famous site information storage unit 104 of the terminal 101 stores at least a part of the character string used in the URL as the site information, and the browser 102 inputs the URL in which the domain name is described as the site information and determines the impersonation. Part 103 determines whether or not the domain name described in the URL input by the browser 102 is similar to at least a part of the character string used in the URL stored in the famous site information storage unit 104, and the browser 102 determines. Outputs a warning when the camouflage determination unit 103 determines that they are similar.
The famous site information storage unit 104 of the terminal 1 stores the name of the organization that operates the communication network site as the site information, the browser 102 inputs the URL as the site information, and the camouflage determination unit 103 uses the communication network. The name of the organization that operates the site specified by the URL entered from the browser 102 is acquired from the database 107 that stores the name of the organization that operates the site, and the name of the organization acquired from the database 107 and the famous site information storage unit. It is determined whether or not the name of the organization stored in 104 matches, and the browser 102 outputs a warning when it is determined that the impersonation determination unit 103 does not match.
The operation will be specifically described. FIG. 7 is a flowchart for explaining the operation in the second embodiment.
Step S801 and step S802 are the same as steps S201 and S202 in the first embodiment. Upon receiving the inquiry, the camouflage determination unit 103 determines whether the entered URL is similar to the URL of the famous site, and when it is determined that the URL is similar, the impersonation determination unit 103 further exists on the Internet via the network access unit 105. Query database 107, for example, using the Linux WHOIS command for the name of the organization that operates the site identified by the URL (step S803). The camouflage determination unit 103 acquires the name of the organization from the database 107, and confirms whether or not the acquired name of the organization matches the name of the organization that operates the famous site stored in the famous site information storage unit 104 (step S804). ). Respond to the browser if there is no risk of spoofing if they match, and if there is a risk of spoofing if they do not match (step S805). Browser 102 warns the user if there is a risk of impersonation (step S806). Subsequent steps S807 and S808 are the same as steps S205 and S206 of the first embodiment.
Next, a similar determination method in the second embodiment will be described. In the first embodiment, when determining the similarity of URLs, the entire host name of the URL is compared. However, in the second embodiment, instead of comparing the entire host name of the URL, the host name is divided into domains, and each divided domain is compared with the character string that characterizes the URL of the famous site to determine the similarity. ..
For example, as shown in Fig. 8, if the URL of the site that determines the presence or absence of impersonation is http://www.dec.def.com/ and the character string that characterizes the URL of a famous site is def, then def , Judge the presence or absence of spoofing Compare the URL domains of www, dec, def, and com, respectively.
Here, for the character string that characterizes the URL, for example, if the URL of the site of a certain company is http://www.abc-xyz.co.jp), abc-xyz in it corresponds to it.
The same method of calculating the similarity as in the first embodiment is used to determine the similarity between the character strings, but in the second embodiment, the Gap penalty is set to 0 because the determination based on the looser similarity is sufficient. Expanded the range of URLs that are considered spoofed.
As a result of comparison, when it is determined that the URLs are similar, for example, the WHOIS command is used to acquire the name of the organization that operates the site specified from the URL, and the camouflage determination unit 103 obtains the famous site information. Compare with the name of the organization that operates the famous site stored in the storage unit 104. At this time, in order to deal with the case where the Japanese corporation and the overseas corporation operate sites with different domains, register the names of multiple organizations as the names of the organizations that operate one famous site specified by the URL. Is possible. Therefore, the table as shown in FIG. 9 is stored in the famous site information storage unit in the second embodiment.
According to the second embodiment, it is not necessary to compare all the URLs of the sites accessed via the communication network with all the URLs of the famous sites stored in the famous site information storage unit 104. By comparing, it is possible to determine whether or not a site accessed via a communication network is disguised as a famous site.
According to the second embodiment, the name of the organization that operates the site is stored and managed by using the URL of the site that is accessed via the communication network. A site accessed via a communication network by inquiring about a third-party database and comparing the obtained name of the organization with the name of the organization that operates the famous site stored in the famous site information storage unit 104. You can check if the URL of is really the URL of a famous site. In addition, by performing this confirmation in combination with the above-mentioned determination of camouflage using the URL or a part thereof, it is possible to make the determination of camouflage to a famous site of the site accessed via the communication network more reliable. it can.
According to the second embodiment, even a Phishing site different from a famous site can be detected except for a key character string.
Embodiment 3. In the first embodiment and the second embodiment, the determination of impersonation is performed on a terminal equipped with a browser, but in the third embodiment, the impersonation is performed on a proxy server that is passed through when accessing the Web from the terminal. An embodiment in which a determination unit and a famous site information storage unit are arranged and a fake determination is performed based on a request from a terminal on a proxy server connected to the terminal via a communication network will be described.
FIG. 10 is a diagram showing the configuration of the proxy server 1104 and the connection with the terminal 1101 in the third embodiment. The proxy server 1104 is connected to the terminal 1101 operated by the user via the communication network 1103.
The proxy server 1104 is composed of a spoofing determination unit 1105, a famous site information storage unit 1107, and a web proxy server unit 1106. The functions of the camouflage determination unit 1105 and the famous site information storage unit 1107 are the same as those in the first embodiment. The web proxy server unit 1106 is a part that realizes the function of the proxy server 1104 as a proxy server, and includes transmission / reception via the communication network 1103.
In the third embodiment, the proxy server 1104 corresponds to the access prevention device described in the claims, the camouflage determination unit 1105 corresponds to the determination unit, and the famous site information storage unit 1107 corresponds to the site information storage unit. In addition, the web proxy server unit 1106 realizes an input unit and an output unit via a communication network.
Next, the operation of the proxy server 1104 in the third embodiment will be described. The famous site information storage unit 1107 of the proxy server 1104 stores the URL as the site information, and the web proxy server unit 1106 stores the URL as the site information from the terminal 1101 and the parameters input from the form or generated by the script language. When the judgment unit determines that the entered URL is similar to the URL stored in the famous site information storage unit 1107 after inputting, the web proxy server unit 1106 inputs from the form or generates it by a script language. Outputs a warning written in HTML that includes the parameter in a format that is not displayed on the screen.
When the web proxy server unit 1106 of the proxy server 1104 inputs information that approves access to the site that ignores the warning from the terminal, the impersonation judgment unit 1105 uses the URL entered by the web proxy server unit 1106 and the famous site. It is not determined whether or not the URL stored in the information storage unit 1107 is similar.
The browser 1102 of the terminal 1101 sends a request URL described in HTTP to the proxy server 1104 according to the settings inside the browser in order to access the website by the operation of the user 1100. The web proxy server unit 1106 of the proxy server 1104 receives the request URL from the terminal 1101 and sends it to the impersonation determination unit 1105. The camouflage determination unit 1105 determines whether the URL is disguised as a famous site by the method shown in the first embodiment. If it is determined that there is a risk of camouflage, the result is notified to the web proxy server unit 1106. The web proxy server unit 1106 generates a proxy error page for asking the user 1100 for confirmation, and sends it to the browser 1102 of the terminal 1101.
On the proxy error page, for example, the content shown in FIG. 11 is described in HTML. The request URL is described in the action attribute of the proxy error page form, and the parameter information sent from the terminal 1101 together with the URL request is described as HTML hidden element 1204 in the tag of the proxy error page form. ing.
The screen 1201 as shown in FIG. 11 is displayed on the browser 1102 according to the content described in HTML on the proxy error page. When the user presses the displayed [OK] button, the URL request is sent to the proxy server again. However, this time, the URL request is sent with the parameter described in HTML (-_- PHISHING_WARNING_CONFIRM -_- = 1 (1203 part) in Fig. 11) added to the proxy error page sent by the proxy server. To.
When the web proxy server unit 1106 of the proxy server 1104 receives the request URL to which this parameter is added, the request is sent to the web server specified by the URL without being sent to the spoofing determination unit 1105. At that time, the parameters previously added to the proxy error page by the proxy server are automatically removed.
In the third embodiment, Phishing is detected collectively by the proxy server 1104, but it is also possible to realize the function of the proxy server on the user's terminal and determine the impersonation there.
According to the third embodiment, it is not necessary to provide each terminal with a function for determining a fake site, and the fake determination can be collectively executed by the proxy server.
According to the third embodiment, even if a warning is received from the proxy server 1104, the user recognizes the warning and approves the access to access the site without executing the impersonation judgment by the proxy server. can do.
According to the third embodiment, by determining the impersonation on the proxy server 1104, it is possible to collectively protect the users of the terminal 1101 connected to the LAN in the organization from Phishing fraud. In addition, Phishing scams can be addressed without changing the existing browser of terminal 1101.
Embodiment 4. In Embodiment 4, by clicking the display of the link destination displayed on the browser and the display of this link destination, it is determined whether or not the site actually accessed matches or not. , An embodiment for preventing access to an unauthorized site will be described.
The configuration of the terminal 101 in the fourth embodiment is the same as that of the first embodiment. Next, the operation will be described. The browser 102 inputs the URL of the link destination as the site information, and the impersonation determination unit 103 uses the URL of the link destination input by the browser 102 and the URL of the link destination input by the browser 102 via the communication network. It is determined whether or not the URL of the site to be accessed matches, and the browser 102 outputs a warning when it is determined that the impersonation determination unit 103 does not match.
Further, the operation in the fourth embodiment will be described with reference to the flowchart shown in FIG. Step S301 is the same as step S201 in the first embodiment. The browser 102 sends the URL of the site to be accessed via the communication network 106 to the camouflage determination unit 103, requests access, and the character string information displayed on the anchor or button that triggered the access to the URL. (Label) is also sent and a judgment as to whether or not they match is requested (step S302). If the URL is described in the label, the impersonation determination unit 103 determines whether the URL and the URL of the actual access destination match, and if they are different, the response that there is a possibility of impersonation. Is returned to the browser 102 (step S303). Steps S304 to S306 are the same as steps S204 to S206.
According to the fourth embodiment, it is possible to prevent access to an unauthorized site by displaying a URL different from the actual access destination on the browser and deceiving the user who sees the display.
According to the fourth embodiment, it is possible to detect a Phishing technique that causes the displayed link to access a site other than the displayed link.
Embodiment 5. In Embodiment 5, the URL of the site accessed via the communication network is displayed on the browser, and the name of the organization that operates the successful site is always displayed alongside the URL so that the user can always display it. An embodiment that enables confirmation of whether or not the site that one is accessing is the target site will be described.
The configuration of the terminal 101 in the fifth embodiment is the same as that in the first embodiment. Next, the operation will be described. The impersonation determination unit 103 acquires the name of the organization that operates the site specified by the URL input from the browser 102 from the database 107 that stores the name of the organization that operates the site of the communication network, and the browser 102 determines the impersonation. The name of the organization acquired by the unit 103 is output.
The operation in the fifth embodiment will be described with reference to the flowchart shown in FIG. Step S401 is the same as step S201 in the first embodiment. The browser 102 requests the impersonation determination unit 103 to inquire about the name of the organization that operates the site together with the URL of the site that requests access (step S402). The impersonation determination unit 103 uses, for example, a WHOIS command to inquire the database 107 of the database 107 via the network access unit 105 for the name of the organization that operates the site specified by the URL (step S403). The database 107 responds to the impersonation determination unit 103 with the name of the organization (step S404), and the impersonation determination unit 103 returns the name of the organization obtained from the database 107 to the browser 102 (step S405). The browser 102 displays the name of the organization that operates the site to be accessed obtained by answering the user (step S406).
FIG. 14 shows an example in which the URL of the site requesting access according to the fifth embodiment and the name of the organization obtained from the database 107 are displayed on the browser 102.
According to the fifth embodiment, the URL of the site to be accessed and the name of the organization that operates the site can be displayed, and the user can access the site while confirming the access destination. ..
According to the fifth embodiment, the user can always check whether the site he / she is visiting belongs to the company he / she really wants to visit.
Embodiment 6. In Embodiment 6, when a forged input form is sent by e-mail, an e-mail to an unauthorized site is sent by comparing the sender and destination of the e-mail. The embodiment for preventing the transmission of the above will be described.
FIG. 15 shows the configuration of the terminal 1401 and the connection with the database 1405 in the sixth embodiment. The terminal 1401 is composed of an e-mail client with an HTML display function (hereinafter abbreviated as an e-mail client) 1402, a network access unit 1404, and a spoofing determination unit 1403.
The e-mail client 1402 can send and receive e-mails, display them, and display information written in HTML. The functions of the network access unit 1404 and the camouflage determination unit 1403 are the same as those in the first embodiment.
In the sixth embodiment, the terminal 1401 corresponds to the access prevention device described in the claims, and the camouflage determination unit 1403 corresponds to the determination unit. Further, the e-mail client 1402 realizes an input unit by writing an e-mail from a keyboard, for example, and realizes an output unit by displaying the e-mail on a display.
Next, the operation in the sixth embodiment will be described. The browser 102 inputs the source address and the destination address of the e-mail as the site information, and the spoofing determination unit 103 uses the database 107 that stores the name of the organization that operates the site on the communication network to display the e-mail. Obtained and acquired the name of the organization that operates the site specified by the sender address of the entered e-mail and the name of the organization that operates the site specified by the destination address of the e-mail entered by the browser 102. The browser 102 determines whether the name of the organization that operates the site specified by the e-mail source address matches the name of the organization that operates the site specified by the e-mail destination address. , If the camouflage determination unit 103 determines that they do not match, a warning is output.
The operation in the sixth embodiment will be specifically described with reference to the flowchart shown in FIG. The e-mail client 1402 inputs information such as a password to the form displayed in the e-mail from the user 1400 (step S501). When the e-mail client 1402 tries to send an e-mail to a website, it sends the source address of the e-mail and the destination address (URL) of the form to the spoofing determination unit 1403 (step S502). From the source address and the destination address received via the network access unit, the spoofing determination unit 1403 uses, for example, the WHOIS command to determine the source address and the destination address in the same manner as in the second embodiment. Query database 1405 for the name of the organization that operates the site (S503). The impersonation determination unit 1403 acquires the names of the organizations that operate the site of the sender address and the site of the destination address of the e-mail from the database (step S504), and compares them. As a result, if the names do not match, the email responds to the email client that it may have been sent to deceive the user (step S505). Email client 1402 displays a warning to user 1400 (step S506).
According to the sixth embodiment, a fake sender's e-mail address different from the destination e-mail address is displayed to prevent information leakage due to unknowingly sending an e-mail to a fake site. Can be done.
The embodiment has been described above. In addition to the above, as an embodiment, a terminal or browser (including a mailer capable of displaying HTML mail) provided with a famous site information storage unit and a spoofing determination unit can be realized. It is possible to realize a browser having a function of displaying a warning screen when a user accesses a site similar to a famous site. After displaying the warning, if the site approved by the user is accessed again, it is possible to realize a browser having a function of accessing the Web as usual without displaying the warning. When it is determined that the URLs are similar, it is possible to realize a camouflage determination unit having a function of inquiring the database and confirming the owner (company) of the site. A camouflage determination unit that determines the degree of similarity can be realized by comparing the character string that is the keyword of the famous site URL with the character string that represents each domain of the access target URL. It is possible to realize a famous site information storage unit that stores a character string representing the URL of a famous site and the name of the company that owns the site. A proxy server having a camouflage determination unit can be realized.
In addition, as the content of the Web page generated when issuing a warning, the parameter to be sent by the original access can be described in the <input hidden> tag. In addition, a parameter (Figure 12-1203) can be added to the original URL to determine that the user has authorized access.
It is possible to realize a spoofing determination unit that warns of spoofing when the URL displayed as a link and the URL actually accessed when the link is selected are different. It is possible to realize a browser that constantly displays the owner information of the Web page being browsed on the screen by acquiring it with WHOIS. WHOIS investigates and compares the domain name part of the sender's email address with the organization that owns the destination URL of the form in the email, and if it does not match, it has a spoofing judgment unit that determines that it is spoofed and has a function to call it. It is possible to realize a mail client with an HTML display function.
Regarding the access prevention device, the site information storage unit stores the URL (Uniform Resource Locator) as the site information, and the input unit is generated as the site information by the URL, the parameters input from the form, and the script language. When at least one of the parameters is input and the judgment unit determines that the URL input by the input unit and the URL stored by the site information storage unit are similar, the output unit is the parameter and script input from the form. You may output a warning written in HTML that includes the parameters generated by the language in a format that is not displayed on the screen.
As described above, the access prevention device which is the terminal or the proxy server described in the first to sixth embodiments can be realized by a computer. FIG. 16 is a diagram showing a hardware configuration when an access prevention device which is a terminal or a proxy server according to the first to sixth embodiments is realized by a computer. In FIG. 17, the access prevention device includes a CPU (Central Processing Unit) 911 that executes a program. CPU911 is ROM (Read Only Memory) 913, RAM (Random Access Memory) 914, communication board 915, display device 901, keyboard (K / B) 902, mouse 903, FDD (Flexible Disk Drive) 904 via bus 912. , Magnetic disk device 920, CDD (Compact Disk Drive) 905, printer device 906, scanner device 907.
RAM914 is an example of volatile memory. ROM913, FDD904, CDD905, magnetic disk device 920, and optical disk device are examples of non-volatile memory. These are examples of storage devices or storage units.
The communication board 915 is connected to a fax machine, a telephone, a LAN, and the like. The communication board 915, K / B902, FDD904, scanner device 907, etc. are examples of input units. Further, the communication board 915, the display device 901, and the like are examples of the output unit.
Here, the communication board 915 is not limited to a LAN, and may be directly connected to the Internet or a WAN (Wide Area Network) such as ISDN. When directly connected to the Internet or a WAN such as ISDN, the access prevention device is connected to the Internet or a WAN such as ISDN, and the web server becomes unnecessary.
The magnetic disk device 920 stores an operating system (OS) 921, a window system 922, a program group 923, and a file group 924. The program group 923 is executed by CPU911, OS921, and the window system 922.
In the program group 923, a program that executes the function described as "~ part" in the above-described first to sixth embodiments is stored. The program is read and executed by CPU911.
The part of the arrow in the flowchart described in the description of the first to sixth embodiments described above mainly indicates the input / output of data, and the data for the input / output of the data is the magnetic disk device 920, FD (Flexible Disk). ), Optical discs, CDs (Compact Disks), MDs (Mini Disks), DVDs (Digital Versatile Disks), and other recording media. Alternatively, it is transmitted by a signal line or other transmission medium.
What is described as "~ part" in the above-described first to sixth embodiments may be realized by the firmware stored in the ROM 913. Alternatively, it may be implemented by software only, hardware only, a combination of software and hardware, or a combination of firmware.
The programs for implementing the first to sixth embodiments described above also include a magnetic disk device 920, an FD (Flexible Disk), an optical disk, a CD (Compact Disk), an MD (Mini Disk), and a DVD (Digital Versatile Disk). It may be stored by using a recording device using other recording media such as.
<figref num="1">It is a figure which shows the structure of the terminal and the connection with a database in Embodiment 1. FIG.</figref><figref num="2">It is a flowchart for demonstrating the operation in Embodiment 1.</figref><figref num="3">It is a figure which shows the example of the screen for confirmation by the user in Embodiment 1. FIG.</figref><figref num="4">It is a figure for demonstrating the calculation method of the degree of similarity in the camouflage determination part in Embodiment 1. FIG.</figref><figref num="5">It is a figure for demonstrating the calculation method of the degree of similarity in the camouflage determination part in Embodiment 1. FIG.</figref><figref num="6">It is a figure which shows the configuration of the terminal and the connection with a database in Embodiment 2. FIG.</figref><figref num="7">It is a flowchart for demonstrating the operation in Embodiment 2.</figref><figref num="8">It is a figure which shows the example of the character string which characterizes the URL of the famous site to be compared in Embodiment 2 and the domain of the URL of the site which determines the presence or absence of spoofing.</figref><figref num="9">It is a figure which shows the example which it is possible to register the name of a plurality of organizations as the name of the organization which operates one famous site specified by the URL in Embodiment 2. FIG.</figref><figref num="10">It is a figure which shows the configuration of the proxy server and the connection with a terminal in Embodiment 3. FIG.</figref><figref num="11">It is a figure which shows the description example by HTML in the proxy error page in Embodiment 3. FIG.</figref><figref num="12">It is a flowchart for demonstrating the operation in Embodiment 4.</figref><figref num="13">It is a flowchart for demonstrating the operation in Embodiment 5.</figref><figref num="14">It is a figure which shows the example which displayed the URL of the site requesting access and the name of the organization obtained from the database in the browser in Embodiment 5.</figref><figref num="15">It is a figure which shows the configuration of the terminal and the connection with a database in Embodiment 6.</figref><figref num="16">It is a flowchart explaining the operation in Embodiment 6.</figref><figref num="17">It is a figure which shows the hardware configuration when the access prevention device which is a terminal and a proxy server in Embodiment 1 to Embodiment 6 is realized by a computer.</figref>
Code description
100 users, 101 terminals (access prevention device), 102 browsers (input / output), 103 spoofing judgment (judgment), 104 famous site information storage (site information storage), 105 network access, 106 communication Network, 107 database, 1100 user, 1101 terminal, 1102 browser, 1103 communication network, 1104 proxy server (access prevention device), 1105 spoofing judgment unit (judgment unit), 1106 web proxy server unit (input unit / output unit), 1107 Famous site information storage unit (site information storage unit), 1400 users, 1401 terminal (access prevention device), 1402 email client with HTML display function (input unit / output unit), 1403 camouflage judgment unit (judgment unit), 1404 network Access section, 1405 database, 901 display device, 902 keyboard (K / B), 903 mouse, 904 FDD, 905 CDD, 906 printer device, 907 scanner device, 911 CPU, 912 bus, 913 ROM, 914 RAM, 915 communication board, 920 magnetic disk drive, 921 OS, 922 window system, 923 programs, 924 files.
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| JP2014142942A | Cited by | Japan | Examiner |
| US9603022B2 | Cited by | United States of America | Applicant |
| JP2016026338A | Cited by | Japan | Examiner |
| KR100885634B1 | Cited by | Republic of Korea | Search report |
| US8707455B2 | Cited by | United States of America | Applicant |
| WO2020065777A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| JP2016026338A | Cited by | Japan | Search report |
| JP5595509B2 | Cited by | Japan | Examiner |
| JP2016045754A | Cited by | Japan | Search report |
| US11234128B2 | Cited by | United States of America | Applicant |
| JP2020524314A | Cited by | Japan | Search report |
| JPWO2020065777A1 | Cited by | Japan | Search report |
| JPWO2020021811A1 | Cited by | Japan | Search report |
| WO2020021811A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| JP2009230662A | Cited by | Japan | Search report |
| US9471714B2 | Cited by | United States of America | Applicant |
| JP2011237979A | Cited by | Japan | Search report |
| KR100788904B1 | Cited by | Republic of Korea | Search report |
| JP5753302B1 | Cited by | Japan | Examiner |
| WO2012043650A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| JP2008158882A | Cited by | Japan | Examiner |
| JP2014142942A | Cited by | Japan | Search report |
| JP2012521599A | Cited by | Japan | Search report |
| WO03014969A2 | Cites | World Intellectual Property Organization (WIPO) | Search report |
| JP2002157366A | Cites | Japan | Search report |
| JP2002312395A | Cites | Japan | Search report |
2 priority claims, no other members on record
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 2004289860 | Japan | A | |
| JP20040289860 | – | – | – |
12 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of no payment of annual feesLAPS | LAPS | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Certificate of patent or registration of utility modelR150 | R150 | |
| First payment of annual fees (during grant procedure)A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)A01 | A01 | |
| Written decision to grant a patent or to grant a registration (utility model)A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Written amendmentA521 | A521 | |
| Notification of reasons for refusalA131 | A131 | |
| Written amendmentA521 | A521 | |
| Notification of reasons for refusalA131 | A131 | |
| Written request for application examinationA621 | A621 |
Numbers
- Publication
- 2006106928
- Publication, DOCDB
- 2006106928
- Publication, EPODOC
- JP2006106928
- Application
- 289860
- Application, DOCDB
- 2004289860
- Application, EPODOC
- JP20040289860
Titles2
- Japanese
- アクセス防止装置、アクセス防止方法及びアクセス防止プログラム
- English
- Access prevention device, access prevention method and access prevention program
Classification
- IPC, 3
- G06F21 20
- G06F15 00
- G06F13 00