Information processing device and computer program product
By providing the first and second determination units in the information processing device, the integrity before and after the start of the program is monitored in real time, the problem of inability to monitor program tampering before and before the start of the monitoring program is solved in the prior art, and the monitoring efficiency and accuracy of the determination of integrity are improved.
Patent Information
- Application Number
- CN202411682448.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2024-01-11
- Filing Date
- 2024-11-22
- Publication Date
- 2025-07-11
AI Technical Summary
Existing monitoring programs cannot monitor program tampering before monitoring programs started.
The information processing device is provided with a determination unit, including a first determination unit and a second determination unit, which are respectively used to determine the integrity before and after the program is started, to judge the integrity of the program by the white list and hash value, and output a warning when tampering is detected.
Real-time monitoring before and after the program is started is realized, program integrity is ensured, and the load on judgment processing is reduced, while meeting the startup time requirements are improved.
Smart Images

Figure CN120296731A_ABST
Abstract
Description
Technical Field
[0001] Embodiments of the present invention relate to an information processing apparatus and a monitoring program. Background Art
[0002] As an anti-malware for monitoring program tampering, there is a monitoring program that uses a whitelist. The whitelist is a list of groups that store file paths and hash values for each program. When the execution of a program is detected, the monitoring program uses the whitelist to determine the integrity of the program. Summary of the Invention
[0003] Technical Problem to be Solved by the Invention
[0004] However, there are also programs that start before the monitoring program in a program. Therefore, in a monitoring program that uses a whitelist, it may not be possible to monitor the tampering of a program that starts before the monitoring program.
[0005] The technical problem to be solved by the embodiments of the present invention is to provide an information processing apparatus and a monitoring program that can monitor the tampering of a program that starts before the monitoring program.
[0006] Solution to the Technical Problem
[0007] In one embodiment, the information processing apparatus includes: a determination unit that performs a determination operation for determining the integrity of a program; and an output unit that outputs a warning related to a program that fails in the determination operation. The determination unit includes: a first determination unit that determines the integrity of a first program executed before the start of the determination unit in response to the start of the determination unit; and a second determination unit that determines the integrity of a second program executed after the start of the determination unit in response to the execution of the second program. Brief Description of the Drawings
[0008] Figure 1 It is a block diagram showing an example of the hardware configuration of the information processing apparatus according to the embodiment.
[0009] Figure 2 It is a block diagram showing an example of the functional configuration of the information processing apparatus according to the embodiment.
[0010] Figure 3 It is a diagram showing an example of the data structure of the first list according to the embodiment.
[0011] Figure 4 It is a diagram showing an example of the data structure of the second list according to the embodiment.
[0012] Figure 5 It is a flowchart showing an example of the monitoring process in the information processing apparatus according to the embodiment.
[0013] Figure 6 This is a flowchart showing an example of the first determination process in the information processing apparatus according to the embodiment.
[0014] Figure 7 This is a flowchart showing an example of the second determination process in the information processing apparatus according to the embodiment.
[0015] Figure 8 This is a block diagram showing an example of the functional configuration of the information processing apparatus according to the modification.
[0016] Figure 9 This is a diagram showing an example of the data structure of the third list according to the modification.
[0017] Figure 10 This is a flowchart showing an example of the first determination process in the information processing apparatus according to the modification.
[0018] Explanation of Reference Numerals
[0019] 1... Information processing apparatus; 11... Control circuit; 12... Memory; 13... Communication module; 14... User interface; 15... Driver; 16... Storage medium; 21... Management unit; 22... Determination unit; 23... Output unit; 24... First list; 25... Second list; 26... Third list; 31, 33... First determination unit; 32, 34... Second determination unit. Detailed Embodiment
[0020] Hereinafter, the information processing apparatus according to the embodiment will be described with reference to the drawings.
[0021] 1. Embodiment
[0022] The information processing apparatus according to the embodiment is a computer and its peripheral devices that have security requirements for the integrity of programs. Specifically, for example, the information processing apparatus according to the embodiment is an MFP (multifunction peripheral). Additionally, for example, the information processing apparatus according to the embodiment can also be an office device such as a POS (point of sale) terminal.
[0023] 1.1 Configuration
[0024] First, the configuration of the information processing apparatus according to the embodiment will be described.
[0025] 1.1.1 Hardware Configuration
[0026] Figure 1 This is a diagram showing an example of the hardware configuration of the information processing apparatus according to the embodiment. As Figure 1As shown in the figure, the information processing apparatus 1 includes a control circuit 11, a memory 12, a communication module 13, a user interface 14, a driver 15, and a storage medium 16.
[0027] The control circuit 11 is a circuit that integrally controls the respective components of the information processing apparatus 1. The control circuit 11 includes a CPU (central processing unit), a RAM (random access memory), a ROM (read only memory), and the like. The CPU of the control circuit 11 controls the entirety of the information processing apparatus 1 according to a program stored in the ROM of the control circuit 11. The RAM of the control circuit 11 has a working area for the CPU of the control circuit 11. The ROM of the control circuit 11 stores programs (monitoring programs) used by the information processing apparatus 1 in the monitoring process. The monitoring process is a process for monitoring whether there is any tampering with the program to be monitored. The monitoring process includes a first determination process and a second determination process. The detailed content of the monitoring process will be described later.
[0028] The memory 12 includes, for example, an HDD (Hard Disk Drive) or an SSD (Solid State Drive). The memory 12 stores information used in the monitoring process in the information processing apparatus 1.
[0029] The communication module 13 is a circuit used for the transmission and reception of data between the information processing apparatus 1 and a network (not shown).
[0030] The user interface 14 is a device responsible for communication between the information processing apparatus 1 and the user. The user interface 14 includes an input device and an output device. The input device includes, for example, a touch panel and operation buttons. The output device includes, for example, a printer, a speaker, and a display. When the information processing apparatus 1 is an MFP, the output device may also be, for example, an operation panel attached to the printer.
[0031] The driver 15 is a device for reading software stored in the storage medium 16. The driver 15 includes, for example, a CD (Compact Disk) drive or a DVD (Digital Versatile Disk) drive.
[0032] The storage medium 16 is a medium that stores software by means of an electrical, magnetic, optical, mechanical, or chemical action. The storage medium 16 may also store a monitoring program.
[0033] 1.1.2 Functional Configuration
[0034] Figure 2This is a block diagram showing an example of the functional configuration of the information processing device according to the embodiment.
[0035] like Figure 2 As shown, the CPU of the control circuit 11 expands the program stored in the ROM of the control circuit 11 or the storage medium 16 in the RAM of the control circuit 11. Then, the CPU of the control circuit 11 interprets and executes the program expanded in the RAM of the control circuit 11. Thus, the information processing device 1 functions as a computer including the management unit 21, the determination unit 22, and the output unit 23. In addition, the information processing device 1 stores the first list 24 and the second list 25 in the memory 12.
[0036] The management unit 21 is a functional block that manages the execution of various programs. The management unit 21 starts the startup program and the monitoring program in response to the startup of the information processing device 1 (power on). The startup program includes programs that have been executed and programs that are being executed, based on the startup of the monitoring program. In addition, the management unit 21 executes a dedicated program after the information processing device 1 is started. In the case where the information processing device 1 is an MFP, the dedicated program is, for example, a program for making the information processing device 1 function as an MFP. The dedicated program is a program that is scheduled to be executed based on the startup of the monitoring program. The number of dedicated programs can be significantly greater than the number of startup programs.
[0037] The management unit 21 notifies the determination unit 22 that the program to be monitored has started execution. When the management unit 21 receives a notification from the determination unit 22 indicating that the program being executed among the programs to be monitored may be tampered with, the program is stopped. When the management unit 21 receives a notification from the determination unit 22 indicating that the program scheduled to be executed among the programs to be monitored may be tampered with, the execution of the program is rejected.
[0038] The determination unit 22 is a functional block that performs monitoring processing. The determination unit 22 determines the integrity of the program to be monitored during the monitoring process. Specifically, the determination unit 22 includes a first determination unit 31 and a second determination unit 32.
[0039] The first determination unit 31 is a functional block that executes a first determination process based on the first list 24. The first determination process is a process for determining the integrity of a startup program among the programs to be monitored.
[0040] Figure 3 This is a diagram showing an example of the data structure of the first list according to the embodiment.
[0041] like Figure 3As shown, the first list 24 is a whitelist corresponding to the startup programs of the monitored objects. The first list 24 consists of a plurality of entries corresponding respectively to the startup programs of the monitored objects. Each of the plurality of entries stores a group of the file path and the hash value of the corresponding startup program of the monitored object.
[0042] In Figure 3 example, the entry in the first row indicates that the file path and the hash value of Program A are respectively " / bin / A" and "1234…". The entry in the second row indicates that the file path and the hash value of Program B are respectively " / bin / B" and "2345…". The entry in the third row indicates that the file path and the hash value of Program C are respectively " / bin / C" and "3456…".
[0043] When it is determined that there is a possibility of tampering with the startup program of the monitored object, the first determination unit 31 notifies the output unit 23 of a notification indicating the possibility of tampering. In addition, when it is determined that there is a possibility of tampering with the program being executed among the startup programs of the monitored object, the first determination unit 31 further notifies the management unit 21 of a notification indicating the possibility of tampering.
[0044] The second determination unit 32 is a functional block that performs a second determination process based on the second list 25. The second determination process is a process of determining whether there is a possibility of tampering with the dedicated programs in the programs of the monitored objects.
[0045] Figure 4 is a diagram showing an example of the data structure of the second list related to the embodiment.
[0046] As Figure 4 shown, the second list 25 is a whitelist corresponding to the dedicated programs of the monitored objects. The second list 25 consists of a plurality of entries corresponding respectively to the dedicated programs of the monitored objects. Each of the plurality of entries stores a group of the file path and the hash value of the corresponding dedicated program of the monitored object.
[0047] In Figure 4 example, the entry in the first row indicates that the file path and the hash value of Program AA are respectively " / bin / AA" and "abcd…". The entry in the second row indicates that the file path and the hash value of Program BB are respectively " / bin / BB" and "bcde…". The entry in the third row indicates that the file path and the hash value of Program CC are respectively " / bin / CC" and "cdef…".
[0048] When it is determined that there is a possibility of tampering with the dedicated program of the monitored object, the second determination unit 32 notifies the output unit 23 and the management unit 21 of a notification indicating the possibility of tampering.
[0049] When the output unit 23 receives, from the determination unit 22, a notification indicating the possibility of program tampering of the monitoring target (i.e., a notification indicating the failure of the determination process), a warning including information indicating the possibility of tampering is output to the user via the user interface 14. When the information processing apparatus 1 is an MFP, the output unit 23 displays the warning on the operation panel of the printer, for example. The output unit 23 may also output a warning sound together with the display of the warning.
[0050] 1.2 Operations
[0051] Next, the operations of the information processing apparatus according to the embodiment will be described.
[0052] 1.2.1 Monitoring Process
[0053] Figure 5 is a flowchart showing an example of the monitoring process in the information processing apparatus according to the embodiment. Figure 5 The figure shows an outline of the process for monitoring program tampering after the information processing apparatus 1 is powered on.
[0054] When the information processing apparatus 1 is powered on (start), the management unit 21 executes the startup program to start the information processing apparatus 1. In addition, the management unit 21 further starts the monitoring program (ACT1). After starting the monitoring program, the startup program can include either a program that has been executed or a program that is being executed.
[0055] After the process of ACT1, the first determination unit 31 executes the first determination process (ACT2). The first determination unit 31 executes the first determination process of ACT2 within a specified time. The specified time is the upper limit value of the time required for the startup of the information processing apparatus 1, and is, for example, a value specified as the specification of the information processing apparatus 1. That is, the first determination unit 31 executes the first determination process while satisfying the constraints related to the startup time of the information processing apparatus 1.
[0056] After the process of ACT2, the second determination unit 32 executes the second determination process (ACT3) as the dedicated program starts to execute. The second determination unit 32 executes the second determination process after the startup of the information processing apparatus 1 is completed.
[0057] When the second determination process of ACT3 ends, the monitoring process ends (end).
[0058] 1.2.2 First Determination Process
[0059] Figure 6 is a flowchart showing an example of the first determination process in the information processing apparatus according to the embodiment. Figure 6 The processes of ACT11 to ACT19 shown correspond to the process of ACT2 in Figure 5
[0060] When the monitoring program starts (starts), the first determination unit 31 refers to the first list 24 (ACT11).
[0061] The first determination unit 31 selects an entry from the first list 24 (ACT12).
[0062] The first determination unit 31 determines whether a program corresponding to the entry (selected entry) specified by the file path (specified path) selected in the process of ACT12 exists (ACT13).
[0063] If a program corresponding to the selected entry exists in the specified path (ACT13; yes), the first determination unit 31 calculates the hash value of the program corresponding to the selected entry (ACT14).
[0064] The first determination unit 31 determines whether the hash value calculated in the process of ACT14 is consistent with the hash value stored in the selected entry (ACT15).
[0065] If the hash value calculated in the process of ACT14 is inconsistent with the hash value stored in the selected entry (ACT15; no), the first determination unit 31 determines whether the program corresponding to the selected entry is being executed (ACT16).
[0066] If the program corresponding to the selected entry is being executed (ACT16; yes), the first determination unit 31 notifies the management unit 21 that there is a possibility of tampering with the program corresponding to the selected entry.
[0067] When receiving the notification indicating the possibility of tampering, the management unit 21 stops the execution of the program corresponding to the selected entry (ACT17).
[0068] If a program corresponding to the selected entry does not exist in the specified path (ACT13; no), if the program corresponding to the selected entry is not being executed (ACT16; no), or after the process of ACT17, the first determination unit 31 further notifies the output unit 23 that there is a possibility of tampering with the program corresponding to the selected entry.
[0069] When receiving a notification indicating a possibility of tampering, the output unit 23 outputs a warning related to the program corresponding to the selected entry to the user (ACT18). More specifically, when the program corresponding to the selected entry does not exist in the specified path (ACT13; No), the output unit 23 displays a warning screen indicating the non-existence of a start program on the display or the operation panel. When the program corresponding to the selected entry is not being executed (ACT16; No), or after the processing of ACT17 (i.e., in the case where ACT15 is No), the output unit 23 outputs a warning to the user indicating the possibility of tampering with the program corresponding to the selected entry.
[0070] When the hash value calculated in the processing of ACT14 matches the hash value stored in the selected entry (ACT15: Yes), or after the processing of ACT18, the first determination unit 31 determines whether all the entries in the first list 24 have been selected (ACT19).
[0071] When there are unselected entries in the first list 24 (ACT19; No), the first determination unit 31 selects an unselected entry from the first list 24 (ACT12). Then, the first determination unit 31, the management unit 21, and the output unit 23 perform the subsequent processing of ACT13 to ACT19. In this way, the first determination unit 31, the management unit 21, and the output unit 23 repeat the processing of ACT12 to ACT19 until all the entries in the first list 24 have been selected.
[0072] When all the entries in the first list 24 have been selected (ACT19; Yes), the first determination process ends (ends).
[0073] 1.2.3 Second determination process
[0074] Figure 7 It is a flowchart showing an example of the second determination process in the information processing apparatus according to the embodiment. Figure 7 The processing of ACT21 to ACT29 shown corresponds to Figure 5 the processing of ACT3 in
[0075] When the first determination process ends (starts), the second determination unit 32 stands by until the management unit 21 detects the start of execution of the dedicated program (ACT21).
[0076] When the management unit 21 detects the start of execution of the dedicated program, the management unit 21 notifies the second determination unit 32 of the program to be monitored as the dedicated program scheduled to start execution.
[0077] When receiving a notification related to the program to be monitored, the second determination unit 32 refers to the second list 25 (ACT22).
[0078] The second determination unit 32 selects an entry corresponding to the program of the monitored object for which the notification has been received from the second list 25 (the entry of the monitored object) (ACT23).
[0079] The second determination unit 32 determines whether the program of the monitored object exists in the file path (specified path) specified by the entry of the monitored object (ACT24).
[0080] If the program of the monitored object exists in the specified path (ACT24: Yes), the second determination unit 32 calculates the hash value of the program of the monitored object (ACT25).
[0081] The second determination unit 32 determines whether the hash value calculated in the process of ACT25 is the same as the hash value stored in the entry of the monitored object (ACT26).
[0082] If the program of the monitored object does not exist in the specified path (ACT24; No), or if the hash value calculated in the process of ACT26 is not the same as the hash value stored in the entry of the monitored object (ACT26; No), the second determination unit 32 notifies the management unit 21 that there is a possibility of tampering with the program of the monitored object.
[0083] When receiving a notification indicating a possibility of tampering, the management unit 21 rejects the execution of the program of the monitored object (ACT27).
[0084] After the process of ACT27, the second determination unit further notifies the output unit 23 that there is a possibility of tampering with the program of the monitored object.
[0085] When receiving a notification indicating a possibility of tampering, the output unit 23 outputs a warning related to the program of the monitored object to the user (ACT28). More specifically, if the program of the monitored object does not exist in the specified path (ACT24; No), the output unit 23 displays a warning screen indicating the non-existence of the dedicated program on the display or the operation panel. If the hash value calculated in the process of ACT26 is not the same as the hash value stored in the entry of the monitored object (ACT26; No), the output unit 23 outputs a warning to the user indicating that there is a possibility of tampering with the program of the monitored object.
[0086] If the hash value calculated in the process of ACT26 is the same as the hash value stored in the entry of the monitored object (ACT26: Yes), or after the process of ACT28, the second determination unit 32 determines whether to end the monitoring based on the second determination process (ACT29).
[0087] In the case where the monitoring based on the second determination process continues (ACT29; No), the second determination unit 32 stands by until the management unit 21 detects the start of execution of the dedicated program (ACT21). Then, the second determination unit 32, the management unit 21, and the output unit 23 execute the subsequent processes of ACT22 to ACT29. In this way, the second determination unit 32, the management unit 21, and the output unit 23 repeat the processes of ACT21 to ACT29 until the monitoring based on the second determination process ends.
[0088] In the case where the monitoring based on the second determination process ends (ACT29; Yes), the second determination process ends (ends).
[0089] 1.3 Effects of the Embodiment
[0090] According to the embodiment, the first determination unit 31 executes the first determination process of referring to the first list 24 to determine the integrity of the startup program executed before the start of the monitoring program in response to the start of the monitoring program. Thus, for all programs that may be executed before the start of the monitoring program, it is possible to monitor for tampering. It should be noted that the first determination unit 31 executes the first determination process within the constraints of the startup time of the information processing device 1. Therefore, it is possible to quickly determine the integrity of the startup program while satisfying the requirements related to the startup time of the information processing device 1.
[0091] In addition, the second determination unit 32 executes the second determination process of referring to the second list 25 and determining the integrity of the dedicated program each time in response to the execution of the dedicated program executed after the start of the monitoring program. Thus, for the programs executed after the start of the monitoring program, it is possible to monitor for tampering for each program at the timing of execution. Therefore, it is not necessary to determine all the programs in the second list 25 at once, and the load of the determination process can be dispersed.
[0092] 2. Modification Examples
[0093] Various modifications can be applied to the above-described embodiment.
[0094] In the above-described embodiment, the case where the determination unit 22 executes the first determination process and the second determination process based on the mutually different first list 24 and second list 25 respectively has been described, but it is not limited thereto. For example, the determination unit 22 may also execute the first determination process and the second determination process based on the same list.
[0095] Hereinafter, mainly the configurations and operations different from the embodiment will be described. The description of the configurations and operations equivalent to the embodiment will be appropriately omitted.
[0096] 2.1 Configuration
[0097] Figure 8It is a block diagram showing an example of the functional configuration of the information processing apparatus according to the modified example. Figure 8 Corresponds to that in the embodiment. Figure 2 As Figure 8 shown, the information processing apparatus 1 stores the third list 26 in the memory 12. The determination unit 22 includes a first determination unit 33 and a second determination unit 34.
[0098] The first determination unit 33 is a functional block that performs the first determination process based on the third list 26. When it is determined that there is a possibility of tampering with the startup program of the monitoring target, the first determination unit 33 notifies the output unit 23 of a notification indicating the possibility of tampering. In addition, when it is determined that there is a possibility of tampering with the program being executed in the startup program of the monitoring target, the first determination unit 33 further notifies the management unit 21 of a notification indicating the possibility of tampering.
[0099] The second determination unit 34 is a functional block that performs the second determination process based on the third list 26. When it is determined that there is a possibility of tampering with the dedicated program of the monitoring target, the second determination unit 32 notifies the output unit 23 and the management unit 21 of a notification indicating the possibility of tampering.
[0100] Figure 9 It is a diagram showing an example of the data structure of the third list according to the modified example.
[0101] As Figure 9 shown, the third list 26 is a whitelist corresponding to all programs of the monitoring target. The third list 26 is composed of a plurality of entries corresponding to the programs of the monitoring target respectively. Each of the plurality of entries stores a group of the file path and the hash value of the corresponding program of the monitoring target. It should be noted that among the plurality of entries, all the startup programs that become the monitoring target in the first determination process are configured in a specified same file path. In addition, among the plurality of entries, all the dedicated programs that become the monitoring target in the second determination process are configured in a file path different from the specified file path where the startup programs are configured.
[0102] In Figure 9In the example, the entries in the first row indicate that the file path and hash value of program A are " / bin / X" and "1234…", respectively. The entries in the second row indicate that the file path and hash value of program B are " / bin / X" and "2345…", respectively. The entries in the third row indicate that the file path and hash value of program C are " / bin / X" and "3456…", respectively. Additionally, the entries in the fourth row indicate that the file path and hash value of program AA are " / bin / AA" and "abcd…", respectively. The entries in the fifth row indicate that the file path and hash value of program BB are " / bin / BB" and "bcde…", respectively. The entries in the sixth row indicate that the file path and hash value of program CC are " / bin / CC" and "cdef…", respectively. When the file path " / bin / X" is set as the specified file path, programs A to C are startup programs to be monitored in the first determination process. Additionally, programs AA to CC are dedicated programs to be monitored in the second determination process.
[0103] 2.2 Operations
[0104] Figure 10 is a flowchart showing an example of the first determination process in the information processing apparatus according to the modified example. Figure 10 corresponds to the Figure 6 in the embodiment. That is, Figure 10 the processes of ACT31 to ACT38 shown correspond to the Figure 5 process of ACT2 in the
[0105] When the monitoring program starts (start), the first determination unit 33 refers to the third list 26 (ACT31).
[0106] The first determination unit 33 selects an entry specifying the specified file path from the third list 26 (ACT32). In the Figure 9 example, the specified file path is " / bin / X".
[0107] The first determination unit 33 calculates the hash value of the program corresponding to the entry selected in the process of ACT32 (selected entry) (ACT33).
[0108] The first determination unit 33 determines whether the hash value calculated in the process of ACT33 is the same as the hash value stored in the selected entry (ACT34).
[0109] When the hash value calculated in the process of ACT33 is not the same as the hash value stored in the selected entry (ACT34; NO), the first determination unit 33 determines whether the program corresponding to the selected entry is being executed (ACT35).
[0110] When the program corresponding to the selected entry is being executed (ACT35; Yes), the first determination unit 33 notifies the management unit 21 that there is a possibility that the program corresponding to the selected entry has been tampered with.
[0111] When receiving the notification indicating the possibility of tampering, the management unit 21 stops the execution of the program corresponding to the selected entry (ACT36).
[0112] When the program corresponding to the selected entry is not being executed (ACT35; No), or after the processing of ACT36, the first determination unit 33 further notifies the output unit 23 that there is a possibility that the program corresponding to the selected entry has been tampered with.
[0113] When receiving the notification indicating the possibility of tampering, the output unit 23 outputs a warning related to the program corresponding to the selected entry to the user (ACT37). More specifically, when the program corresponding to the selected entry is not being executed (ACT35; No), or after the processing of ACT36 (i.e., the case where ACT34 is No), the output unit 23 outputs a warning indicating that there is a possibility that the program corresponding to the selected entry has been tampered with to the user.
[0114] When the hash value calculated in the processing of ACT33 is consistent with the hash value stored in the selected entry (ACT34: Yes), or after the processing of ACT37, the first determination unit 33 determines whether all the entries corresponding to the specified file path of the third list 26 have been selected (ACT38).
[0115] When there are unselected entries corresponding to the specified file path of the third list 26 (ACT38; No), the first determination unit 33 selects an unselected entry from the third list 26 (ACT32). Then, the first determination unit 33, the management unit 21, and the output unit 23 execute the subsequent processing of ACT33 to ACT38. In this way, the first determination unit 33, the management unit 21, and the output unit 23 repeat the processing of ACT32 to ACT39 until all the entries corresponding to the specified file path of the third list 26 are selected.
[0116] When all the entries corresponding to the specified file path of the third list 26 are selected (ACT38; Yes), the first determination process ends (ends).
[0117] 2.3 Effects related to the modification example
[0118] According to the modification example, the first determination unit 33 refers to a specified path in the third list 26 and performs the first determination process on all programs within the specified path. The second determination unit 34 performs the second determination process, which determines the integrity of the dedicated program each time in response to the execution of the dedicated program executed after the monitoring program is started by referring to the third list 26. Thus, it is possible to perform the same processing as in the embodiment without having a list of sets of two or more storage file paths and hash values. Therefore, it is not necessary to manage multiple security-related data structures, and the security management cost can be reduced.
[0119] Although several embodiments of the present invention have been described, these embodiments are presented by way of example only and are not intended to limit the scope of the invention. These new embodiments can be implemented in various other ways, and various omissions, substitutions, and changes can be made without departing from the spirit of the invention. These embodiments and their modifications are included in the scope and spirit of the invention, and are similarly included in the invention described in the claims and its equivalents.
Claims
1. An information processing apparatus, comprising: A determination unit that performs a determination operation for determining the integrity of a determination program; and an output unit that outputs a warning related to a program that fails in the determination operation, the determination unit includes: a first determination unit that, in response to the start of the determination unit, determines the integrity of a first program executed before the start of the determination unit; and a second determination unit that, in response to the execution of a second program executed after the start of the determination unit, determines the integrity of the second program.
2. The information processing apparatus according to claim 1, wherein the first program is a startup program executed in response to the startup of the information processing apparatus, the first determination unit determines the integrity of the first program while satisfying a constraint related to the startup time of the information processing apparatus.
3. The information processing apparatus according to claim 1, wherein the first determination unit determines the integrity of the first program based on a first list composed of a plurality of entries each storing a different file path and a hash value group, the second determination unit determines the integrity of the second program based on a second list different from the first list and composed of a plurality of entries each storing a different file path and a hash value group.
4. The information processing apparatus according to claim 1, wherein the first determination unit and the second determination unit respectively determine the integrity of the first program and the second program based on a third list composed of a plurality of entries each storing a file path and a hash value group, the first determination unit determines the integrity of the first program based on the first entry among the plurality of entries that stores the same file path, the second determination unit determines the integrity of the second program based on the second entry among the plurality of entries that stores different file paths respectively.
5. The information processing apparatus according to claim 1, wherein the information processing apparatus further includes a control circuit that is a circuit for integrally controlling each component of the information processing apparatus.
6. The information processing apparatus according to claim 1, wherein the information processing apparatus further includes a communication module that is a circuit for transmitting and receiving data between the information processing apparatus and a network.
7. The information processing apparatus according to claim 1, wherein the information processing apparatus further includes a user interface that is a device responsible for communication between the information processing apparatus and a user.
8. The information processing apparatus according to claim 1, wherein the information processing apparatus further includes a driver that is a device for reading software stored in a storage medium.
9. The information processing apparatus according to claim 8, wherein the storage medium is a medium that stores software through electrical, magnetic, optical, mechanical, or chemical action.
10. A computer program product, including a monitoring program, the monitoring program for causing a computer to function as a determination unit and an output unit, the determination unit performs a determination operation for determining the integrity of a program, the output unit outputs a warning related to a program that fails in the determination operation, the determination unit includes: A first determination unit, in response to activation of the determination unit, determines the integrity of a first program executed before the activation of the determination unit; And A second determination unit, in response to execution of a second program executed after the activation of the determination unit, determines the integrity of the second program.