IP Library › Granted Patent US 12,645,822
Granted Patent B2
US 12,645,822 · App. 18/613,584 · Granted Jun 2, 2026

Control method, server, recording medium, and security analysis system

Inventors: Tatsumi Oba (Chiba, JP); Yuji Unagami (Osaka, JP); Naohisa Nishida (Kanagawa, JP); Takuji Hiramoto (Osaka, JP)
Assignee: PANASONIC INTELLECTUAL PROPERTY CORPORATION OF AMERICA
G06F21/6218
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,645,822
App. No.
18/613,584
Granted
Jun 2, 2026
Kind
B2
Abstract

A control method according to the present disclosure is performed by one of a plurality of servers each including a distributed ledger and includes: obtaining request transaction data including an analysis request identification (ID) uniquely identifying a request for analysis, and an access method for accessing relevant information usable for the analysis; and recording a block including the request transaction data into the distributed ledger. The control method further includes: obtaining analysis transaction data including an analysis result corresponding to the analysis request ID, log information associated with the analysis result, and threat intelligence information serving as a basis of the analysis result; obtaining a verification result for the analysis transaction data; generating a block including the analysis transaction data; and when the verification result indicates that the validity of the analysis transaction data has been verified, recording the block including the analysis transaction data into the distributed ledger.

Claims (74)

1 . A control method that is performed by one server included in a security analysis system including a plurality of servers each including a distributed ledger, the control method comprising:

obtaining request transaction data including an analysis request identification (ID) uniquely identifying a request for analysis, and access information indicating an access method for accessing relevant information usable for the analysis;

recording a block into the distributed ledger after including, in the block, the request transaction data obtained;

obtaining analysis transaction data and generating a block including the analysis transaction data obtained, the analysis transaction data including an analysis result corresponding to the analysis request ID included in the request transaction data recorded, log information used to generate the analysis result and being is a portion of the relevant information, and threat intelligence information serving as a basis of the analysis result;

obtaining a verification result that is a result of verification of validity of the analysis result included in the analysis transaction data; and

when the verification result obtained indicates that the validity of the analysis result included in the analysis transaction data has been verified, recording the block including the analysis transaction data into the distributed ledger, wherein

the result of the verification of the validity is a result obtained by performing matching between (i) a first piece of information included in the threat intelligence information included in the analysis transaction data and (ii) a second piece of information included in the log information included in the analysis transaction data.

2 . The control method according to claim 1 , wherein

the analysis is analysis of an alert issued by a security product,

the request transaction data includes information of the alert issued by the security product, the analysis request ID, and the access information,

the log information included in the analysis transaction data is log information included in the relevant information, associated with the analysis result, and actually used for the analysis, and

the threat intelligence information included in the analysis transaction data is threat intelligence information serving as the basis of the analysis result and corresponding to a cause of the alert.

3 . The control method according to claim 2 , wherein

the access information included in the request transaction data includes an access destination of and access rights to relevant information usable for the analysis and required for the analysis.

4 . The control method according to claim 1 , wherein

the analysis is threat hunting analysis,

the access information included in the request transaction data includes an access destination of and access rights to relevant information usable for the analysis and indicating an environment in which security monitoring is ongoing,

the log information included in the analysis transaction data is log information included in the relevant information, associated with the analysis result, and obtained by accessing the environment, and

the threat intelligence information included in the analysis transaction data is threat intelligence information serving as the basis of the analysis result and linked to the log information.

5 . The control method according to claim 1 , wherein

the request transaction data further includes:

information indicating an analysis fee for the request for the analysis.

6 . The control method according to claim 1 , further comprising:

canceling the request for the analysis that is specified by the analysis request ID, when (i) cancellation transaction data including the analysis request ID and information indicating cancellation of the request for the analysis is obtained before the analysis transaction data is obtained after the request transaction data is obtained and (ii) the cancellation transaction data is recorded into the distributed ledger.

7 . The control method according to claim 1 , wherein

a digital signature generated by an authorized security company is provided to the threat intelligence information included in the analysis transaction data.

8 . The control method according to claim 1 , wherein

the first piece of information is signature information of malware included in the threat intelligence information included in the analysis transaction data,

the second piece of information is a byte sequence in a trace included in the log information included in the analysis transaction data, and

the result of the verification of the validity is a result obtained by performing matching between (i) the signature information of the malware in the threat intelligence information included in the analysis transaction data and (ii) the byte sequence in the trace included in the log information included in the analysis transaction data.

9 . The control method according to claim 1 , wherein

the request transaction data further includes one or more tags each indicating a type of the analysis, and

the analysis transaction data further includes one or more tags each indicating the type of the analysis conducted to obtain the analysis result.

10 . The control method according to claim 1 , wherein

information that is included in the access information and able to identify a user who makes the request for the analysis has been anonymized.

11 . The control method according to claim 1 , wherein

the access information included in the request transaction data includes remote access rights to security information and event management (SIEM) that is used by a user who makes the request for the analysis.

12 . The control method according to claim 1 , wherein

the access information included in the request transaction data includes information indicating an operation to obtain log information required for the analysis, the information being included in the relevant information usable for the analysis.

13 . The control method according to claim 1 , wherein

when the verification result obtained indicates that the analysis transaction data has been excluded from verification, the analysis transaction data is not recorded into the distributed ledger.

14 . The control method according to claim 13 , wherein

a degree of similarity between the analysis result included in the analysis transaction data currently subject to the verification and the analysis result included in the analysis transaction data that has been generated earlier than the analysis transaction data currently subject to the verification is calculated, and when the degree of similarity calculated exceeds a predetermined threshold value, the verification of the validity of the analysis result included in the analysis transaction data currently subject to the verification is skipped, and the verification result indicates that the analysis transaction data currently subject to the verification has been excluded from the verification.

15 . The control method according to claim 1 , wherein

the first piece of information is URL information of malware included in the threat intelligence information included in the analysis transaction data,

the second piece of information is URL information included in the log information included in the analysis transaction data, and

the result of the verification of the validity is a result obtained by performing matching between (i) the URL information of the malware in the threat intelligence information included in the analysis transaction data and (ii) the URL information included in the log information included in the analysis transaction data.

16 . A server included in a security analysis system including a plurality of servers each including a distributed ledger, the server comprising:

a processor; and

memory, wherein

using the memory, the processor obtains request transaction data including an analysis request identification (ID) uniquely identifying a request for analysis, and access information indicating an access method for accessing relevant information usable for the analysis,

the processor records a block into the distributed ledger after including, in the block, the request transaction data obtained,

the processor obtains analysis transaction data and generates a block including the analysis transaction data obtained, the analysis transaction data including an analysis result corresponding to the analysis request ID included in the request transaction data recorded, log information used to generate the analysis result and being a portion of the relevant information, and threat intelligence information serving as a basis of the analysis result,

the processor obtains a verification result that is a result of verification of validity of the analysis result included in the analysis transaction data, and

when the verification result obtained indicates that the validity of the analysis result included in the analysis transaction data has been verified, the processor records the block including the analysis transaction data into the distributed ledger, wherein

the processor obtains the result of the verification of the validity by performing matching between (i) a first piece of information included in the threat intelligence information included in the analysis transaction data and (ii) a second piece of information included in the log information included in the analysis transaction data.

17 . A non-transitory computer-readable recording medium having recorded thereon a program for causing a control method to be performed in a security analysis system including a plurality of servers each including a distributed ledger, the program causing a computer to execute:

obtaining request transaction data including an analysis request identification (ID) uniquely identifying a request for analysis, and access information indicating an access method for accessing relevant information usable for the analysis;

recording a block into the distributed ledger after including, in the block, the request transaction data obtained;

obtaining analysis transaction data including an analysis result corresponding to the analysis request ID included in the request transaction data recorded, log information used to generate the analysis result and being a portion of the relevant information, and threat intelligence information serving as a basis of the analysis result;

obtaining a verification result that is a result of verification of validity of the analysis result included in the analysis transaction data, and generating a block including the analysis transaction data; and

when the verification result obtained indicates that the validity of the analysis result included in the analysis transaction data has been verified, recording the block including the analysis transaction data into the distributed ledger, wherein

the result of the verification of the validity is a result obtained by performing matching between (i) a first piece of information included in the threat intelligence information included in the analysis transaction data and (ii) a second piece of information included in the log information included in the analysis transaction data.

18 . A security analysis system comprising:

a user terminal that requests analysis;

an analyst terminal that conducts the analysis requested; and

a plurality of servers each including a distributed ledger, wherein

one server included in the plurality of servers includes a processor and memory,

using the memory, the processor obtains, from the user terminal, request transaction data including an analysis request identification (ID) uniquely identifying a request for the analysis, and access information indicating an access method for accessing relevant information usable for the analysis,

the processor records a block into the distributed ledger after including, in the block, the request transaction data obtained,

the processor obtains, from the analyst terminal, analysis transaction data including an analysis result corresponding to the analysis request ID included in the request transaction data recorded, log information used to generate the analysis result and being a portion of the relevant information, and threat intelligence information serving as a basis of the analysis result,

the processor obtains a verification result that is a result of verification of validity of the analysis result included in the analysis transaction data, and generates a block including the analysis transaction data,

when the verification result obtained indicates that the validity of the analysis result included in the analysis transaction data has been verified, the processor records the block including the analysis transaction data into the distributed ledger, and

the processor obtains the result of the verification of the validity by performing matching between (i) a first piece of information included in the threat intelligence information included in the analysis transaction data and (ii) a second piece of information included in the log information included in the analysis transaction data.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2024
From: OBA, TATSUMI; UNAGAMI, YUJI; NISHIDA, NAOHISA; HIRAMOTO, TAKUJI
To: PANASONIC INTELLECTUAL PROPERTY CORPORATION OF AMERICA
Reel/Frame 068038/0105 →
Continuity (3)
Continuation PCTJP2022038219 · Oct 13, 2022
Provisional Application 63255103 · Oct 13, 2021
Related Publication 20240232416A1 · Jul 11, 2024
References Cited (24)
US 11818120B2 · Jen · 2023 [cited by examiner]
US 20170223030A1 · Merza · 2017 [cited by examiner]
US 20190163912A1 · Kumar · 2019 [cited by examiner]
US 20200134189A1 · Carter · 2020 [cited by examiner]
US 20200358801A1 · Allouche · 2020 [cited by examiner]
US 20210014065A1 · Gourisetti · 2021 [cited by examiner]
US 20210294915A1 · In · 2021 [cited by examiner]
US 20210326786A1 · Sun · 2021 [cited by examiner]
US 20210326886A1 · Tang · 2021 [cited by examiner]
US 20220141240A1 · Sel · 2022 [cited by examiner]
US 20220270102A1 · Nishida · 2022 [cited by examiner]
US 20220351306A1 · Zemenchik · 2022 [cited by examiner]
US 20230091179A1 · Bari · 2023 [cited by examiner]
US 20230169517A1 · Garner, IV · 2023 [cited by examiner]
US 20250363505A1 · Gordon · 2025 [cited by examiner]
US 20260019342A1 · Perg · 2026 [cited by examiner]
US 20260025759A1 · Li · 2026 [cited by examiner]
JP 2022101716 · 2022 [cited by applicant]
Chatziamanetoglou et al.; “CTI Blockchain-Based Sharing using Proof-of-Quality Consensus Algorithm”, 2021, IEEE International Conference on Cyber Security and Resilience (CSR) Workshops, pp. 331-336. (Year: 2021). [cited by examiner]
Purohit et al.; “DefenseChain: Consortium Blockchain for Cyber Threat Intelligence Sharing and Defense”, 2020, IEEE, pp. 112-119 (Year: 2020). [cited by examiner]
International Search Report issued Nov. 15, 2022 in International (PCT) Application No. PCT/JP2022/038219. [cited by applicant]
Cyber Threat Intelligence Technical Committee, “Indicator for Malicious URL”, Sep. 2023 (URL: https://oasis-open.github.io/cti-documentation/examples/indicator-for-malicious-url). [cited by applicant]
BACnet Testing Laboratories, “BTL Listing of Tested Products”, 2022 (URL: https.//bacnetinternational.net/btl/). [cited by applicant]
Oasis Open, “environment”, 2023 (URL: https://stix2.readthedocs.io/en/latest/api/stix2.environment.html#stix2.environment.Environment.object_similarity). [cited by applicant]