Threatarium(以下「本サービス」)は、 インターネット上で観測されるスキャン、 脆弱性探索、認証攻撃その他の通信を分析し、 サイバー攻撃の傾向を可視化する 脅威観測プラットフォームです。 本ポリシーでは、本サービスが取り扱う情報と その利用目的について説明します。
Threatarium is a cyber-threat observation platform that analyzes scans, vulnerability probing, authentication attacks, and other Internet traffic observed by its sensors. This policy explains the information handled by the service and how it is used.
2. 取得する情報
本サービスでは、サービスの提供、セキュリティ確保および攻撃傾向の分析のため、以下の情報を取得する場合があります。
- 本サービスへのアクセス日時、IPアドレス、User-Agent等の一般的なアクセス情報
- 攻撃観測用センサーで受信した通信に関する送信元IPアドレス、観測日時、HTTPメソッド、リクエスト先、通信先ポート等の技術情報
- 観測データを基に生成された攻撃分類、Fingerprint、Campaign、統計情報等の分析結果
- GeoIPデータベース等から推定した国・地域その他の概略位置情報
- 利用者がブラウザ上で明示的に許可した場合の現在地情報
攻撃観測用センサーでは、原則としてHTTPリクエスト本文の保存を目的としていません。収集対象は攻撃傾向の分析に必要な技術的メタデータを中心とします。
3. 情報の利用目的
取得した情報は、主に以下の目的で利用します。
- サイバー攻撃、スキャン、脆弱性探索等の観測および分析
- 攻撃イベントの分類、相関分析およびCampaign生成
- 統計情報、攻撃マップ、ランキング等の生成
- 本サービスの安定運用、不正利用対策および障害調査
- 機能改善、研究および脅威情報サービスの品質向上
4. IPアドレスと位置情報
IPアドレスから推定される国・地域情報は、GeoIPデータベース等を利用した概略的な推定情報であり、正確な所在地を保証するものではありません。
また、観測された送信元IPアドレスが、攻撃を実行した人物または組織そのものを示すとは限りません。VPN、Proxy、クラウドサービス、NAT、侵害された端末その他の中継環境を経由している可能性があります。
利用者のブラウザから取得する現在地情報は、利用者がブラウザの位置情報利用を明示的に許可した場合にのみ利用します。
5. 公開される情報
本サービスでは、観測結果の一部を攻撃マップ、統計情報、Campaign情報等として公開する場合があります。
公開画面では、必要に応じてIPアドレスのマスキング、集計またはその他の方法により、生の観測情報をそのまま公開しないための処理を行います。
6. 情報の保存
取得した情報は、分析、セキュリティ、障害調査およびサービス運営上必要な期間、適切な方法で保存します。
集計済みの統計情報や、個別の通信から切り離された分析結果については、攻撃傾向の長期的な比較および研究のためにより長期間保持する場合があります。
7. 第三者への提供
法令に基づく場合を除き、個人を直接識別することを目的として取得情報を第三者へ提供することはありません。
ただし、サーバー、ネットワーク、GeoIPその他の外部サービスを利用する際に、サービス提供に必要な範囲で情報が処理される場合があります。
8. Cookie等
本サービスでは、機能提供、セキュリティ確保および利用状況の把握のため、Cookieその他のブラウザ保存技術を使用する場合があります。
アクセス解析その他の外部サービスを導入する場合は、必要に応じて本ポリシーを更新します。
9. セキュリティ
本サービスは、取り扱う情報への不正アクセス、漏えい、改ざん等を防止するため、合理的な技術的および運用上の安全管理措置を講じます。
10. 本ポリシーの変更
本サービスの機能追加、運用方法の変更または法令等への対応に伴い、本ポリシーを変更する場合があります。
重要な変更がある場合は、本サービス上で適切な方法により告知します。
2. Information We Collect
Threatarium may collect the following information to provide the service, maintain security, and analyze observed attack activity.
- General access information such as access time, IP address, and User-Agent.
- Technical metadata received by attack-observation sensors, including source IP address, observation time, HTTP method, requested URI, and destination port.
- Analysis results generated from observed data, including attack classifications, Fingerprints, Campaigns, and statistics.
- Approximate country, region, and other coarse location information inferred from GeoIP databases or similar sources.
- Browser location information only when the visitor explicitly grants location permission.
Attack-observation sensors are not intended to retain HTTP request bodies as a general rule. Collection is centered on technical metadata required to analyze attack activity.
3. Purposes of Use
Collected information is primarily used for the following purposes.
- Observing and analyzing cyberattacks, scans, vulnerability probing, and related activity.
- Classifying attack events, performing correlation analysis, and generating Campaigns.
- Generating statistics, attack maps, rankings, and related visualizations.
- Operating the service reliably, preventing abuse, and investigating failures.
- Improving features, conducting research, and improving the quality of threat-intelligence functions.
4. IP Addresses and Location Information
Country and region information inferred from IP addresses is approximate GeoIP data and does not guarantee an exact physical location.
An observed source IP address does not necessarily identify the person or organization that originated an attack. Traffic may pass through VPNs, proxies, cloud services, NAT, compromised systems, or other intermediary infrastructure.
Browser location is used only when the visitor explicitly grants permission through the browser.
5. Information Shown Publicly
Threatarium may publish portions of observation results through attack maps, statistics, Campaign information, and similar views.
Public views may mask IP addresses, aggregate records, or apply other processing so that raw observation data is not exposed without appropriate controls.
6. Retention
Collected information is retained using appropriate safeguards for as long as reasonably necessary for analysis, security, incident investigation, and service operation.
Aggregated statistics and analysis results separated from individual communications may be retained for longer periods for longitudinal comparison and research.
7. Disclosure to Third Parties
Except where required by law, Threatarium does not provide collected information to third parties for the purpose of directly identifying individuals.
Information may be processed to the extent necessary by infrastructure, network, GeoIP, and other external service providers used to operate Threatarium.
8. Cookies and Browser Storage
Threatarium may use cookies and other browser-storage technologies to provide features, maintain security, and understand service usage.
If external analytics or similar services are introduced, this policy will be updated when appropriate.
9. Security
Threatarium applies reasonable technical and operational safeguards designed to prevent unauthorized access, leakage, alteration, and other inappropriate handling of information.
10. Changes to This Policy
This policy may be changed as Threatarium adds features, changes operations, or responds to legal or regulatory requirements.
Material changes will be announced through an appropriate method on the service.
11. Contact
For questions about this policy or the handling of information by Threatarium, please contact us at the address below.
Mogura Research Institute
mogurasoken@gmail.com