Threatariumby もぐら総合研究所by Mogura Research Institute
ABOUT THREATARIUM

サイバー脅威を、
観測・相関・理解する。
Observe, correlate,
and understand cyber threats.

Threatarium(スレタリウム)は、 インターネット上で観測される攻撃行動を IP単体ではなくAttack Campaignとして捉え、 変化や関連性を可視化する Cyber Threat Campaign Observatoryです。

Threatarium is a Cyber Threat Campaign Observatory that treats observed Internet attack activity as Attack Campaigns rather than isolated IP addresses, making changes and relationships easier to understand.

CENTER QUESTIONWhat attack campaign is happening right now?

今この瞬間、どのような攻撃Campaignが 発生・継続・変化しているのかを 観測データから追跡します。

Threatarium follows observed data to understand which attack Campaigns are emerging, continuing, or changing right now.

HOW IT WORKS

Threatariumの観測フローThreatarium observation flow

生の通信をそのまま断定的に見せるのではなく、 段階的に整理・相関し、 根拠を追跡できる分析へ変換します。

Raw traffic is not presented as a definitive conclusion. It is organized and correlated in stages so the evidence behind each analysis can be followed.

01

観測Observe

公開Sensorが受けたHTTP/HTTPSアクセスから、スキャン、脆弱性探索、認証攻撃などの観測イベントを収集します。

Public sensors collect observed HTTP/HTTPS activity such as scans, vulnerability probes, and credential attacks.

02

分類Classify

Ruleベースの分類と統計処理で、観測された通信の特徴を整理します。AIだけを一次判定の根拠にはしません。

Rule-based classification and statistics organize observed behavior. AI is not used as the sole primary decision source.

03

相関Correlate

IPアドレス単体ではなく、URI、時間、HTTP Method、User-Agent、ASN/Geoなどの行動特徴からFingerprintとCampaignを構成します。

Threatarium correlates behavior using URI, time, HTTP method, User-Agent, ASN, Geo, and other features instead of relying on IP addresses alone.

04

説明Explain

CampaignのEvidenceを保持した上で、構造化された分析結果を人が理解しやすい形へ要約・説明します。

Campaign evidence is preserved while structured analysis is summarized into explanations that are easier for people to understand.

ANALYSIS PIPELINE
Sensor→AttackEvent→Rule / Statistics→Fingerprint→Campaign→Explanation
TRANSPARENCY

データをどう解釈するかHow to interpret the data

観測事実と推定を分けるSeparate observations from inference

「観測された事実」「分析上の関連」「AIによる説明」を区別し、特定の人物や組織への安易な帰属を行いません。

Observed facts, analytical relationships, and AI-generated explanations are kept distinct. Threatarium does not casually attribute activity to a specific person or organization.

IPを攻撃者そのものとみなさないAn IP address is not an attacker identity

送信元IPはVPN、Proxy、クラウド、NAT、侵害端末などを経由している場合があります。公開画面ではIPをマスクします。

A source IP may represent a VPN, proxy, cloud service, NAT gateway, or compromised device. Public views mask source IP addresses.

GeoIPは推定値として扱うTreat GeoIP as an estimate

国・都市・緯度経度・ASN等はGeoIPデータベースに基づく概略情報であり、実際の攻撃者所在地を示すものではありません。

Country, city, coordinates, ASN, and related values are approximate GeoIP data and do not indicate an attacker's actual physical location.

AIが停止しても観測を止めないObservation continues without AI

収集、Rule分類、基本Campaign処理はAI必須にせず、AI環境が停止しても観測基盤が継続できる構成を目指します。

Collection, rule classification, and core Campaign processing do not depend on AI so the observation platform can continue operating if AI services are unavailable.

OPERATOR

もぐら総合研究所

Threatariumは、もぐら総合研究所が 開発・運営するサイバー脅威観測プロジェクトです。

Threatarium is a cyber threat observation project developed and operated by もぐら総合研究所.