Market Context — Why This Technology, Why Now

The escalating cost of cyber breaches, often reaching millions per incident, fuels urgent demand for proactive security. Stricter global regulations on data protection and incident response compel enterprises to invest in advanced threat intelligence. Maintaining uninterrupted digital operations is also a competitive necessity. This technology provides a critical tool for organizations to meet these demands, protect assets, and build trust in a hostile digital environment.

Key Competitive Advantages
01

Increases malicious URL detection accuracy by ~1.5x by precisely reconstructing access paths to malicious URLs, including those hidden behind legitimate sites, which are often missed by conventional URL filtering.

02

Provides immediate response to unknown threats by estimating risk from access behavior patterns, independent of signatures, enabling rapid defense against zero-day attacks and new malware strains.

03

Reduces security operations workload by ~20% by automating malicious domain identification and risk assessment, significantly cutting manual log analysis and threat investigation efforts for security analysts.

Market Opportunity
Financial Services
$1.5B–$2.5B globally (AI est.)
This market demands strict regulatory compliance and customer asset protection, where cyber attack damages can be severe, leading to high investment intent in cutting-edge threat detection technologies.
Large investment banks Retail banking institutions Financial technology (FinTech) providers Insurance companies
Public Sector & Government
$1.5B–$2B globally (AI est.)
Protecting national infrastructure and classified information is a pressing concern. Proactive domain risk assessment is essential for safeguarding against supply chain attacks.
National defense agencies Critical infrastructure operators Government IT service providers Public utility companies
Manufacturing
$1B–$1.5B globally (AI est.)
As smart factories and IoT adoption advance, security risks in converged OT/IT environments are increasing, making factory network protection an urgent priority.
Industrial control system (ICS) vendors Automotive manufacturers Aerospace and defense contractors Smart factory solution providers
Information & Telecommunications
$2.5B–$3B globally (AI est.)
Beyond protecting their own service infrastructure, integrating this technology into customer security offerings could provide a differentiated value proposition.
Telecommunications providers Cloud service providers Managed Security Service Providers (MSSPs) Internet Service Providers (ISPs)
IP Defensibility — Why Competitors Can't Replicate This
What This Patent Covers

This patent protects a system and method for estimating domain risk by reconstructing access paths from malicious URLs. It covers the core algorithms for collecting access records, building paths, and estimating risk. The claims were refined through examination, demonstrating a clear and robust scope against prior art, making it a stable and difficult-to-invalidate right.

Competitive White Space

This patent primarily covers domain risk estimation via access path reconstruction. White space exists in real-time endpoint behavioral analytics, advanced data loss prevention (DLP) systems, and secure application development practices, where licensees could build complementary IP.

Economic Impact
~$200K/year estimated cyber damage avoidance per enterprise (est.)
estimated ROI · USD · AI analysis
ROI Calculation Logic

Assuming an average enterprise experiences ~$650K (AI est.) in annual cyber attack damages, this technology's high-precision malicious URL access prevention could avert approximately 30% of that damage, equating to ~$200K (AI est.) annually. This directly translates to reduced costs from data breach liabilities, system recovery, business interruption, and brand reputation damage.

Speed to Market
6× faster than in-house development
This technology's core algorithms, from web access record collection to access path reconstruction and risk estimation, are already patented and the technical foundation is established. This enables significantly faster market entry for licensees compared to developing a similar system from scratch. It has the potential for rapid transition from Proof of Concept (PoC) to full deployment by integrating with existing network logs and web proxy data.
Competitive Positioning

X: Threat Detection Accuracy
Y: Operational Efficiency

Business Models & Applications
☁️ SaaS-Based Threat Intelligence
A model providing real-time domain risk information and malicious URL detection capabilities to enterprises as a cloud service based on this technology, monetized through monthly subscriptions.
🔑 Licensing to Security Products
A model granting licenses to integrate this technology's module into existing security gateways, UTMs, SIEM products, and similar solutions, thereby enhancing product value.
🤝 Consulting Partnership Solution
A model integrating this technology into enterprise web security diagnostics and risk assessment services, offering advanced analysis results and countermeasure proposals as a packaged solution.
Adjacent Application Opportunities
🛡️ Security Vendors
Next-Generation DNS Filtering
Integrate this technology into DNS filtering services to proactively block access not only to known blacklisted domains but also to potentially malicious ones. This could reduce false positives and enhance security without compromising user experience, improving threat prevention by an estimated 30%.
☁️ Cloud Services
Secure Web Access Platform
Offer this technology as a PaaS/SaaS feature that analyzes web access logs in cloud environments in real-time, automatically detecting and warning users about the risk of being directed to malicious sites. This could enhance cloud user security levels, potentially reducing incident response times by 25%.
🌐 ISP・Telecommunications Carriers
Customer Threat Protection Service
Leverage vast communication logs held by ISPs to provide web threat protection services to customers, based on risk information estimated by this technology. This could reduce cyber attack risks in home and enterprise networks by an estimated 15-20%, creating a new value-added revenue stream.
Integration Roadmap — Estimated 15-Month Deployment
Phase 1: Requirements & PoC
Duration: 4 months
Define integration requirements with the licensee's existing systems (e.g., web proxies, DNS servers, SIEM) and conduct a Proof of Concept (PoC) using a small volume of access logs to validate the technology's detection accuracy and effectiveness.
Phase 2: System Development & Testing
Duration: 7 months
Based on PoC results, optimize and implement the technology's algorithms within the licensee's system environment. Conduct large-scale data testing and tuning to ensure operational stability.
Phase 3: Production & Optimization
Duration: 4 months
After deployment to the production environment, continuously evaluate and refine the risk estimation model's accuracy through ongoing feedback using real-world web access logs, advancing operational automation and optimization.
Technical Feasibility
This technology is a software-centric solution that leverages existing web access records as its analysis foundation, requiring no significant new hardware investment. The patent claims explicitly detail 'access record collection means,' 'access path construction means,' and 'risk estimation means,' all implementable on general-purpose server environments or cloud infrastructure. Integration with existing log management systems and network monitoring tools is relatively straightforward, suggesting low technical adoption barriers.
Success Scenario
Upon adopting this technology, an enterprise's security team could automatically and accurately identify potential risks leading to malicious URLs within the vast daily web access logs. This could enable proactive defense before incidents occur, potentially reducing information leakage risks by over 50%. Furthermore, resources previously spent on manual threat analysis could be reallocated to strategic security enhancement activities.
Patent Record
APPLICATION NO.
特願2020-172204
REGISTRATION NO.
7603298
FILING DATE
2020/10/12
GRANT DATE
2024/12/12
EXPIRATION DATE
2040/10/12
PATENT HOLDER
国立研究開発法人情報通信研究機構
Examination History
2023年09月28日
出願審査請求書
2024年07月23日
拒絶理由通知書
2024年08月21日
手続補正書(自発・内容)
2024年08月21日
意見書
2024年11月12日
特許査定