First communication device, communication system including first communication device, computer program for first communication device, and method executed by first communication device
By implementing a communication device that assesses the capabilities of other devices in the network before transmitting attack detection information, the system reduces communication load and optimizes network traffic.
Patent Information
- Application Number
- JP2023182825
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-10-24
- Publication Date
- 2025-05-09
AI Technical Summary
Existing communication systems face high communication loads between communication devices and servers when detecting external attacks, as they typically transmit attack detection information to the server regardless of the capabilities of other devices in the network.
A communication device is configured with a detection unit to identify external attacks and a determining unit to assess whether other communication devices in the network can handle the attack. If capable, the device does not transmit detection information to the server, thereby reducing communication load.
This configuration reduces the communication load between the communication device and the server by only transmitting detection information when other devices in the network are unable to handle the attack, thus optimizing network traffic.
Smart Images

Figure 2025072221000001_ABST
Abstract
Description
[Technical field]
[0001] This specification discloses a technique for dealing with attacks on a communication terminal from an external device. [Background technology]
[0002] Patent Document 1 discloses a communication system including a server, a management device, and multiple IP routers. The management device receives attack detection information from the IP router that detects an attack, and determines the type of attack according to the number of attacks detected in the entire network. The management device identifies a bit pattern related to the type of attack (destination IP address, source IP address, source port number, destination port number, protocol, etc. of the IP packet), and notifies other IP routers to defend against flows that match the bit pattern. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] JP 2006-67078 A [Patent Document 2] JP 2008-235876 A Summary of the Invention [Problem to be solved by the invention]
[0004] This specification provides a technique that can reduce the communication load between a communication device and a server. [Means for solving the problem]
[0005] This specification discloses a first communication device. The first communication device may include a first detection unit that detects a first attack from an outside, a first determination unit that determines whether a second communication device can deal with the first attack when the first attack is detected, and a first transmission unit that does not transmit first detection information indicating that the first attack has been detected to a server when it is determined that the second communication device can deal with the first attack, and transmits the first detection information to the server when it is determined that the second communication device cannot deal with the first attack.
[0006] According to the above configuration, when the second communication device is capable of dealing with the first attack, the first communication device does not transmit the first detection information to the server, thereby reducing the communication load between the first communication device and the server.
[0007] A computer program for implementing the first communication device, a computer-readable storage medium storing the computer program, and a method executed by the first communication device are also novel and useful. A communication system including the first communication device and another device (e.g., a second communication device) is also novel and useful. [Brief description of the drawings]
[0008] [Figure 1] 1 shows the configuration of a communication system. [Diagram 2] The contents of each table are shown below. [Diagram 3] 1 shows a sequence diagram of a first embodiment. [Figure 4] The sequence diagram continues from Figure 3. [Diagram 5] The sequence diagram continues from Figure 4. [Figure 6] The sequence diagram for case B is shown below. [Figure 7] 13 shows a sequence diagram of the second embodiment. [Figure 8] The sequence diagram continues from FIG. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0009] (First embodiment) (Configuration of communication system 2; Figure 1) 1, the communication system 2 includes a plurality of printers 10, 200, 300, a terminal 50, a management server 100, and an external terminal 60. Each of the printers 10, 200, 300 and the terminal 50 establishes a wireless connection with an access point 6, that is, a wireless connection according to the Wi-Fi standard (hereinafter referred to as a "Wi-Fi connection"). Hereinafter, the access point will be referred to as an "AP (short for Access Point)". The management server 100 and the external terminal 60 are connected to the Internet 4. Each of the printers 10, 200, 300 can communicate with the management server 100 via the AP6.
[0010] (Printer 10, 200, 300 configuration) Each of the printers 10, 200, and 300 is a peripheral device (for example, a peripheral device of the terminal 50) capable of executing a printing function. The printer 10 has a device ID "DV1" and an IP address "IP1". The printer 10 includes an operation unit 12, a display unit 14, a communication interface 16, a print execution unit 18, and a control unit 30. In the following, the interface is referred to as "I / F".
[0011] The operation unit 12 is an interface for inputting various information to the printer 10, and includes buttons, a touch screen, etc. The display unit 14 is a display or panel for displaying various information. The communication I / F 16 is an interface for executing communication with other devices. The communication I / F 16 is connected to the AP 6. The communication I / F 16 may be a wired I / F or a wireless I / F. The print execution unit 18 has an electrophotographic, inkjet, or thermal print engine.
[0012] The control unit 30 includes a CPU 32 and a memory 34. The memory 34 includes a main storage device and an auxiliary storage device, not shown. The CPU 32 executes various processes according to a program 40 stored in the auxiliary storage device of the memory 34. Specifically, the CPU 32 executes the above-mentioned various processes by loading the program 40 from the auxiliary storage device to the main storage device and executing the program 40. The main storage device is, for example, a RAM and a cache memory. The auxiliary storage device may be, for example, a flash memory, an SSD (short for Solid State Drive), or a ROM, or a combination thereof. The memory 34 further stores a VID list 42 and a detection list 44.
[0013] Printer 200 has a similar configuration to printer 10, except that printer 200 has a device ID "DV2" and an IP address "IP2". A memory (not shown) of printer 200 stores a VID list 202. Printer 300 has a similar configuration to printer 10, except that printer 200 has a device ID "DV3" and an IP address "IP3". A memory (not shown) of printer 300 stores a VID list 302.
[0014] (Configuration of Management Server 100) The management server 100 is installed on the Internet 4 by the vendor of the printers 10, 200, and 300. In a modified example, the management server 100 may be installed on the Internet 4 by a business entity different from the vendor. In another modified example, the vendor of the printers 10, 200, and 300 may not prepare the hardware for the management server 100 by itself, but may use an environment provided by an external cloud computing service. In this case, the vendor of the printers 10, 200, and 300 may prepare a program (i.e., software) for the management server 100 and implement the program in the above-mentioned environment to realize the management server 100.
[0015] The management server 100 includes a network I / F 116 and a control unit 130. The network I / F 116 is connected to the Internet 4. The control unit 130 includes a CPU 132 and a memory 134. The CPU 132 executes various processes in accordance with a program 140 stored in the memory 134. The memory 134 is composed of a volatile memory, a non-volatile memory, and the like. The memory 134 further stores a blacklist 142, a device list 144, and a model list 146.
[0016] (Configuration of terminal 50 and external terminal 60) The terminal 50 is an administrator terminal used by an administrator of the printers 10, 200, and 300. The external terminal 60 is a third party terminal capable of attacking the printers 10, 200, and 300 via the Internet 4. The external terminal 60 has an IP address "IP4." The terminal 50 and the external terminal 60 are, for example, portable terminal devices such as mobile phones, smartphones, PDAs, notebook PCs, and tablet PCs. In a modified example, the terminal 50 and the external terminal 60 may be stationary terminal devices such as desktop PCs.
[0017] Types of attacks that the printers 10, 200, 300 may be subjected to from an external device (e.g., the external terminal 60) via the Internet 4, i.e., types of vulnerabilities of the printers 10, 200, 300, include, for example, SQL injection, cross-site scripting, CSRF (cross-site request forgery), directory traversal, OS command injection, improper session management, HTTP header injection, and unauthorized mail relay.
[0018] (Composition of each list; Figure 2) Next, the printers 10, 200, 300 and the lists 42, 44, 142, 144, 146, 202, 302 in the management server 100 will be described with reference to FIG.
[0019] In the VID list 42 of the printer 10, a device ID (e.g., "DV1") and a VID (short for vulnerability ID) (e.g., "VID1" and "VID2") are stored in association with each other. The VID is information that identifies the vulnerability of the printer against various attacks. In other words, the VID is information that identifies various attacks. A printer identified by a device ID stored in the VID list 42 can deal with an attack identified by a VID associated with the device ID. For example, in the example of FIG. 2, the VID list 42 stores "DV1", "VID1", and "VID2" in association with each other. This means that the printer 10 identified by "DV1" can deal with an attack identified by "VID1" (e.g., SQL injection) and an attack identified by "VID2" (e.g., cross-site scripting). In this embodiment, "capable of dealing with attacks" means not only that a regular program for dealing with attacks is stored in the printer, but also that a workaround, which is a temporary program for dealing with attacks and will be described later, is stored in the printer.
[0020] The VID list 42 also stores the device ID and VID of each printer 200, 300 other than the printer 10. For example, in the example of FIG. 2, "DV3" and "VID1" are stored in association with each other in the VID list 42. This means that the printer 300 identified by "DV3" can deal with the attack identified by "VID1". However, "VID2" is not associated with "DV3". This means that the printer 300 cannot deal with the attack identified by "VID2". The device IDs and VIDs of the other printers 200, 300 are stored in the VID list 42 as a result of the printer 10 executing communication with the other printers 200, 300. The VID list 202 of the printer 200 and the VID list 302 of the printer 300 also contain similar information.
[0021] In the detection list 44 of the printer 10, an IP address (e.g., "IP4"), a port number (e.g., "PN1"), a VID (e.g., "VID2"), and a date and time (e.g., "T1") are stored in association with each other. Each piece of information in the detection list 44 is stored when the printer 10 detects an attack from an external device (e.g., the external terminal 60) with which it can communicate via the Internet 4. The IP address is the IP address of the external device that is the source of the attack. The port number is the destination port number included in the attack packet. As described above, the VID is information that identifies the attack. The date and time is the date and time when the attack was detected.
[0022] In the blacklist 142 of the management server 100, an IP address (e.g., "IP4"), a port number (e.g., "PN1"), a VID (e.g., "VID2"), a device ID (e.g., "DV1"), and a date and time (e.g., "T2") are stored in association with one another. The blacklist 142 is information that is stored when the management server 100 receives, from the printer 10 or the like, attack detection information indicating that an attack from an external device has been detected. The IP addresses, port numbers, and VIDs in the blacklist 142 are the same as the IP addresses, port numbers, and VIDs in the detection list 44 of the printer 10. The device ID is the device ID of the printer that sent the attack detection information. The date and time is information indicating the date and time when the attack detection information was received.
[0023] In the device list 144, the printer model name (e.g., "M1", "M2", "M3"), the printer firmware version (e.g., "V1", "V2", "V3"), the device ID (e.g., "DV1"), the owner ID (e.g., "OW1"), and the owner email address (e.g., "MA1") are stored in association with each other. The device list 144 is information showing a list of the printers managed by the management server 100, and is stored, for example, by the owner of each printer accessing the management server 100. The owner ID is user identification information designated by the user of the printer (e.g., the administrator of the terminal 50). The owner email address is the email address of the user (i.e., the administrator of the terminal 50).
[0024] In the model list 146, the printer model name (e.g., "M2"), the printer firmware version (e.g., "V2"), the VID "VID2", and workarounds (e.g., "WA1", "WA2", "WA3") are stored in association with each other. The model list 146 is information stored by the printer vendor, and for printers having specific vulnerabilities, the model name, firmware version, VID, and workaround are associated with each other. The workaround is information indicating how to deal with an attack (i.e., a printer vulnerability).
[0025] (Specific cases: Figures 3 to 6) Specific cases A and B will be described with reference to Figures 3 to 6. First, case A in which the attack detection information is notified to the server will be described with reference to Figures 3 to 5, and then case B in which the attack detection information is not notified to the server will be described with reference to Figure 6.
[0026] In the initial state of FIG. 3, each of the printers 10, 200, and 300 has established a Wi-Fi connection with the AP 6. In addition, the VID list 42 of the printer 10 stores the device ID "DV1" of the printer 10 itself and a VID that identifies attacks that the printer 10 itself can currently handle. However, the VID list 42 does not yet store information about the other printers 200 and 300. The VID lists 202 and 302 of the printers 200 and 300 do not yet store information about the other printers. The process of FIG. 3 is started at a predetermined timing. The predetermined timing is, for example, when the power of each printer 10 is turned on, a predetermined date and time, etc. In the following, the process executed by each CPU of each device (for example, the CPU 32 of the printer 10, etc.) is described as the subject of each device itself (for example, the printer 10, etc.) rather than the subject of each CPU, in order to facilitate understanding.
[0027] In T10, the printer 10 transmits a broadcast search signal to the AP 6 via the communication I / F 16. This causes the search signal to be transmitted to all child stations (i.e., the printers 200 and 300) that have established a Wi-Fi connection with the AP 6. When the printer 200 receives the search signal from the AP 6 in T10, the printer 200 transmits a response signal to the AP 6 in T12. The response signal includes the device ID "DV2" of the printer 200 and a VID ("VID1" and "VID2" in the example of FIG. 3) that identifies an attack that the printer 200 can handle. In addition, when the printer 300 receives a search signal from the AP 6 in T10, the printer 300 transmits a response signal to the AP 6 in T14. The response signal includes the device ID "DV3" of the printer 300 and a VID (only "VID1" in the example of FIG. 3) that identifies an attack that the printer 300 can handle.
[0028] At T12, printer 10 receives a response signal from printer 200 via AP 6. Also, at T14, printer 10 receives a response signal from printer 300 via AP 6. Upon receiving each response signal, printer 10 associates "DV2", "VID1", and "VID2" contained in the response signal already received from printer 200 with each other in the VID list 42 at T16. Also, printer 10 associates "DV3" and "VID1" contained in the response signal already received from printer 300 with each other in the VID list 42.
[0029] Printer 200 executes processing similar to that from T10 to T14 at a predetermined timing, and at T20, associates "DV1", "VID1", and "VID2" contained in the response signal received from printer 10 and stores them in VID list 202, and associates "DV3" and "VID1" contained in the response signal received from printer 300 and stores them in VID list 202.
[0030] Printer 300 executes processing similar to that from T10 to T14 at a predetermined timing, and at T30, associates "DV1" with "VID1" and "VID2" contained in the response signal received from printer 10 and stores them in VID list 302, and associates "DV2" with "VID1" and "VID2" contained in the response signal received from printer 200 and stores them in VID list 302.
[0031] 4, the external terminal 60 executes an attack on the printer 10. The attack packet includes the IP address "IP4" of the external terminal 60 and the destination port number "PN1."
[0032] When the printer 10 receives an attack packet from the external terminal 60 in T50, the printer 10 detects the attack in T52. When the printer 10 detects that the packet is an external attack, it does not execute the process according to the command contained in the packet. The printer 10 identifies the type of attack in T54 and executes a normal countermeasure against the attack. As an example, if the type of attack corresponds to a directory traversal vulnerability of the printer 10, the printer 10 prohibits the specification of a path having a predetermined directory structure as a normal countermeasure.
[0033] Next, in T56, the printer 10 specifies the VID "VID2" that identifies the attack detected in T52, and in T58, associates the IP address "IP4" of the external terminal 60, the destination port number "PN1" included in the attack packet, the specified VID "VID2", and the reception date and time "T1" of the attack packet, and stores them in the detection list 44. Next, in T60, the printer 10 uses the VID list 42 to determine whether the other printers 200 and 300 are capable of dealing with the above attack. Since "VID2" is associated with the printer ID "DV2", the printer 10 determines that the printer 200 is capable of dealing with the above attack. On the other hand, since "VID2" is not associated with the printer ID "DV3", the printer 10 determines that the printer 300 is not capable of dealing with the above attack.
[0034] If printer 10 determines that at least one other printer is not capable of dealing with the above attack, at T70, printer 10 transmits attack detection information to management server 100, the attack detection information including IP address "IP4", port number "PN1", VID "VID2", and device ID "DV1" of printer 10.
[0035] When the management server 100 receives the attack detection information from the printer 10 in T70, in T72, the management server 100 associates the IP address "IP4", the port number "PN1", the VID "VID2", and the device ID "DV1" of the printer 10 included in the received attack detection information with the reception date and time "T2" of the attack detection information, and stores them in the blacklist 142. Next, in T74, the management server 100 identifies the owner ID "OW1" associated with the received device ID "DV1" from the device list 144. Then, in T76, the management server 100 identifies the device IDs "DV2" and "DV3" associated with the identified owner ID "OW1" from the device list 144, which are different from the received device ID "DV1". This allows the management server 100 to identify the printer (i.e., the printer 300 in this case) to which the attack response information described below is to be sent.
[0036] Next, in T78, the management server 100 identifies, from the model list 146, the model "M2" and the version "V2" associated with the received VID "VID2." Then, in T80, the management server 100 identifies, from the device list 144, the model "M1" and the version "V1" associated with the device ID "DV2" identified in T76, and also identifies the model "M2" and the version "V2" associated with the device ID "DV3" identified in T76.
[0037] Next, in T82 of FIG. 5, the management server 100 determines that the model "M2" and version "V2" identified in T78 do not match the model "M1" and version "V1" identified from "DV2" in T80. This means that the printer 200 having the model "M1" and version "V1" already has firmware that can deal with the above attack, and therefore does not need to obtain a workaround from the management server 100. Furthermore, in T84, the management server 100 determines that the model "M2" and version "V2" identified in T78 match the model "M2" and version "V2" identified from "DV3" in T80. This means that the printer 300 having the model "M2" and version "V2" does not have firmware that can deal with the above attack, and therefore needs to obtain a workaround from the management server 100. For this reason, the management server 100 determines that a workaround should be sent to the printer 300.
[0038] In T90, the management server 100 performs name resolution using a DNS server to identify the IP address "IP3" of the printer 300. Next, in T92, the management server 100 identifies from the model list 146 a plurality of workarounds "WA1", "WA2", and "WA3" that are associated with the model "M2", the version "V2", and the VID "VID2".
[0039] In T94, the management server 100 assigns priorities to the multiple identified workarounds "WA1", "WA2", and "WA3" and stores them. In this case, the higher the model list, the higher the priority. Therefore, "WA1" has the highest priority, and "WA3" has the lowest priority. The priority is information for determining which workaround the printer should execute when there are two or more workarounds for one VID (e.g., "VID1").
[0040] In T96, the management server 100 transmits attack response information including the IP address "IP4" already received in T70, the VID "VID2" already received in T70, the port number "PN1" already received in T70, and multiple workarounds "1-WA1", "2-WA2", and "3-WA3" with priorities assigned. In the attack response information, the IP address "IP3" already identified in T90 is specified as the destination IP address. Therefore, the management server 100 can transmit the attack response information to the printer 300.
[0041] When the printer 300 receives the attack response information from the management server 100 in T96, in T98, the printer 300 associates and stores the IP address "IP4", the port number "PN1", the VID "VID2", the multiple workarounds "1-WA1", "2-WA2", and "3-WA3", and the reception date and time "T3" of the attack response information, all of which are included in the received attack response information. The printer 300 also adds "VID2" to the VID list 302 as a VID associated with the printer 300's own device ID "DV3". As a result, the VID associated with the device ID "DV3" is changed from only "VID1" to "VID1" and "VID2".
[0042] According to the above configuration, the management server 100 includes a model list 146 that stores a VID and a workaround for each of a plurality of types of vulnerabilities (in other words, attacks) in association with each other. For this reason, the management server 100 can transmit the workarounds "WA1", "WA2", and "WA3" associated with the VID "VID2" included in the attack detection information to the printer 300 (T96 in FIG. 5). Therefore, even in a situation where the printer 10 is unable to execute a normal method of dealing with an attack that has been received by the printer 10, the printer 300 can appropriately deal with the attack according to the workarounds "WA1", "WA2", and "WA3" (T114 in FIG. 5).
[0043] In T100, the management server 100 notifies the administrator identified by the owner ID "OW1" already specified in T74 of a warning. Specifically, the device list 144 stores an email address "MA1" in association with the owner ID "OW1". The management server 100 sends a warning email indicating that an attack has occurred on the printer 10, with the email address "MA1" as the destination address. This allows the terminal 50 to receive and display the warning email. The administrators of the printers 10, 200, and 300 to know that an attack has occurred on the printers by viewing the warning email.
[0044] After that, in T110, the external terminal 60 executes an attack on the printer 300. The attack packet includes the IP address "IP4" of the external terminal 60 and the destination port number "PN1."
[0045] When the printer 300 receives an attack packet from the external terminal 60 in T110, the printer 300 detects the attack in T112. The printer 300 identifies a plurality of workarounds "1-WA1", "2-WA2", and "3-WA3" associated with the IP address "IP4" and the port number "PN1" based on the information stored in T98. Next, the printer 200 identifies the workaround that is executable by the printer 300 and has the highest priority from the plurality of workarounds. In this case, the printer 300 identifies the workaround "WA1". Then, the printer 300 uses the workaround "WA1" to deal with the attack in T114. In this way, the printer 300 can use the workaround with the highest priority from among the plurality of workarounds.
[0046] A workaround is information indicating a temporary method of dealing with a vulnerability. As an example, a certain workaround may be to prohibit all access to a specific destination port number. For example, in the above embodiment, all access to port number "PN1" is prohibited in T114. This method of dealing with the vulnerability corresponds to, for example, workaround WA1. In this way, even in a situation where the printer 10 is unable to execute a normal method of dealing with an attack, the printer 300 can appropriately deal with the attack by executing a workaround.
[0047] As another example, in T50 of Fig. 4 in this embodiment, if the type of attack that the printer 10 receives from the external terminal 60 corresponds to a vulnerability in directory traversal, and in T110 of Fig. 5, the printer 300 receives a similar attack from the external terminal 60, the printer 300 blocks access to the protected assets, i.e., a part of the memory area, as a workaround. This method of dealing with the problem corresponds to, for example, workaround WA2.
[0048] As another example, a certain workaround may be to transmit header information included in a packet from an external terminal to the management server 100. For example, in the above embodiment, at T114, the printer 300 transmits header information included in an attack packet to the management server 100. The management server 100 verifies the received header information and transmits the verification result to the printer 300. The verification includes, for example, determining whether the header information includes information indicating an attack (for example, an IP address of a device known as an attacking terminal). The verification result includes, for example, information indicating a countermeasure against the attack. The printer 300 counters the attack from the external terminal 60 according to the received verification result. Note that the workaround is, for example, a provisional countermeasure against the vulnerability of HTTP header injection.
[0049] As another example, a workaround may be to block access to a database, e.g., as a temporary measure to address a SQL injection vulnerability.
[0050] As another example, a workaround may be to block script execution, e.g., as a temporary measure to address a cross-site scripting vulnerability.
[0051] As another example, a workaround may be to block OS commands, e.g., as a temporary measure to address an OS command injection vulnerability.
[0052] As another example, a workaround may be to use another means for generating a session ID, which is, for example, a temporary measure to address the vulnerability of improper session management.
[0053] As another example, a workaround may be to block email relaying, for example, as a temporary measure to address an email relay vulnerability.
[0054] As another example, a workaround may be to block connections to the IP address of the external terminal 60 and the destination port number included in the attack packet.
[0055] Although not shown in the figure, if the management server 100 does not receive attack detection information including the IP address "IP4", destination port number "PN1", and VID "VID2" of the external terminal 60 from another communication device (e.g., printer 10) for a relatively long predetermined time (e.g., one month) after transmitting the attack response information to the printer 300 in T96, the management server 100 transmits attack end information including the IP address "IP4" and destination port number "PN1" to the printer 300. When the printer 300 receives the attack end information, it erases all workarounds associated with the IP address "IP4" and destination port number "PN1". This erases unnecessary information from the memory (not shown) of the printer 300.
[0056] After that, when a predetermined timing arrives in each of the printers 10, 200, and 300, the same processes as T10 to T30 in FIG. 3 are executed. As a result, the printer 10 receives not only "VID1" but also "VID2" from the printer 300 at T14. In this case, the printer 10 stores "VID1" and "VID2" in the VID list 42 in association with the device ID "DV3" of the printer 300 at T16. That is, the VID associated with the device ID "DV3" is updated from "VID1" to "VID1" and "VID2". The printer 200 also updates the VID list 202 in the same manner. In this way, the latest status of each of the printers 10, 200, and 300 is reflected in each of the VID lists 42, 202, and 302. As a result, even if the printer 10 subsequently receives an attack T50 in FIG. 4 from the external terminal 60, the printer 10 determines that both the printers 200 and 300 are capable of dealing with the attack identified by "VID2". Therefore, the printer 10 does not transmit the attack detection information to the management server 100.
[0057] (Case B processing; Figure 6) Next, a case B in which the attack detection information is not notified to the management server 100 will be described with reference to Fig. 6. The initial state of Fig. 6 is the same as the initial state of Fig. 3, and the printer 10 is a continuation of Fig. 3.
[0058] At T130, the external terminal 60 executes an attack on the printer 10. This attack is the same as T50 in FIG. 4, except that the attack packets contain the port number "PN2" instead of the port number "PN1".
[0059] When the printer 10 receives an attack packet from the external terminal 60 in T130, the printer 10 detects the attack in T132. When the printer 10 detects that the packet is an external attack, the printer 10 does not execute the process according to the command contained in the packet. In T134, the printer 10 identifies the type of attack and executes a proper countermeasure against the attack.
[0060] Next, in T136, the printer 10 specifies the VID "VID1" that identifies the attack detected in T132, and in T138, associates the IP address "IP4" of the external terminal 60, the destination port number "PN2" included in the attack packet, the specified VID "VID1", and the reception date and time "T4" of the attack packet, and stores them in the detection list 44. Next, in T140, the printer 10 uses the VID list 42 to determine whether the other printers 200 and 300 are capable of dealing with the above attack. Since "VID1" is associated with each of the printer IDs "DV2" and "DV3", the printer 10 determines that each of the printers 200 and 300 is capable of dealing with the above attack. In this case, the printer 10 does not transmit the attack detection information including the IP address "IP4", the port number "PN2", the VID "VID1", and the device ID "DV1" of the printer 10 to the management server 100.
[0061] (Effects of this embodiment) According to the above configuration, if the printer 200, 300 is capable of dealing with an attack, that is, if it is determined that the printer 200, 300 has "VID1" which is a VID corresponding to the attack, the printer 10 does not transmit the attack detection information to the management server 100 (Case B in FIG. 6). Therefore, the communication load between the printer 10 and the management server 100 can be reduced.
[0062] (Correspondence) Printer 10, printer 300, and printer 200 are examples of a "first communication device," a "second communication device," and a "third communication device," respectively. The attack T50 in FIG. 4 and the attack T130 in FIG. 6 are examples of a "first attack," and a "second attack," respectively. The attack detection information T70 is an example of a "first detection information" and a "second detection information." A workaround is an example of "handling information." A device ID is an example of a "first attribute-related information." For example, "VID1" and "VID2" of T12 in FIG. 3 are an example of a "first relationship information." For example, "VID1" and "VID2" of T12 in FIG. 3 cited in FIG. 5 are an example of a "second relationship information."
[0063] The correspondence of the "first communication device" is as follows: T52 in FIG. 4 and T132 in FIG. 6 are examples of processing executed by the "first detection unit". T60 in FIG. 4 and T140 in FIG. 6 are examples of processing executed by the "first determination unit". T70 in FIG. 4 is an example of processing executed by the "first transmission unit". For example, T12 in FIG. 3 is an example of processing executed by the "reception unit". For example, T16 in FIG. 3 is an example of processing executed by the "storage control unit".
[0064] In this embodiment, printers 200 and 300 can also execute the same processes as printer 10. For example, printer 200 can execute processes T50 to T70 in Fig. 4. In this way, when printer 200 executes processes T50 to T70 in Fig. 4, T52, T60, and T70 in Fig. 4 are examples of processes executed by a "second detection unit," a "second determination unit," and a "second transmission unit," respectively.
[0065] (Second embodiment; Figs. 7 and 8) Next, cases C and D of the second embodiment will be described. In the first embodiment, the printers 10, 200, and 300 do not have a parent-child relationship, whereas in this embodiment, the printers 10, 200, and 300 do. In this embodiment, a "parent" is a device that sends attack detection information to the management server 100 when any printer in the same network is attacked. A "child" is a device that notifies the parent of an attack when the child itself is attacked. As shown in FIG. 1, the memory of each of the printers 10, 200, and 300 stores a parent-child flag. The parent-child flag indicates either the parent device or the child device.
[0066] The process in Fig. 7 starts at a predetermined timing similar to that in the first embodiment. The initial state in Fig. 7 is similar to the initial state in Fig. 3. In the initial state in Fig. 7, each of the printers 10, 200, and 300 is provisionally a parent device, and therefore the parent-child flag of each of the printers 10, 200, and 300 indicates the parent device.
[0067] (Case C) At T160, the printer 10 transmits a broadcast search signal to the AP 6 via the communication I / F 16. This causes the search signal to be transmitted to all child stations (i.e., the printers 200 and 300) that have established a Wi-Fi connection with the AP 6. The search signal includes the IP address of the printer 10, “IP1”, as the source IP address.
[0068] When the printer 200 receives a search signal from the AP 6 in T160, the printer 200 transmits a response signal to the AP 6 in T162. The response signal includes the IP address "IP1" of the printer 10 as a destination IP address, the IP address "IP2" of the printer 200 as a source IP address, the device ID "DV2" of the printer 200, a VID ("VID1" and "VID2" in the example of FIG. 7) that identifies an attack that the printer 200 can handle, and "parent" information indicating that the printer 200 is a parent device. The response signal further includes "150 MHz" which is the clock frequency of the CPU (not shown) of the printer 200, and "150 MB" which is the memory capacity of the memory (not shown) of the printer 200. That is, the response signal includes the specifications (i.e., processing capacity) of the printer 200, such as the clock frequency and memory capacity.
[0069] When the printer 300 receives a search signal from the AP 6 in T160, the printer 300 transmits a response signal to the AP 6 in T164. The response signal includes the IP address "IP1" of the printer 10 as the destination IP address, the IP address "IP3" of the printer 300 as the source IP address, the device ID "DV3" of the printer 300, a VID ("VID1" in the example of FIG. 7) that identifies attacks that the printer 300 can handle, and "parent" information indicating that the printer 300 is a parent device. The response signal further includes a clock frequency of "50 MHz" and a memory capacity of "50 MB".
[0070] At T162, printer 10 receives a response signal from printer 200 via AP 6, and at T164, printer 10 receives a response signal from printer 300 via AP 6. Upon receiving each response signal, printer 10 determines that each of printers 200, 300 is a parent device based on the “parent” information included in each previously received response signal.
[0071] Next, the printer 10 judges the parent-child relationship with each of the printers 200 and 300. Specifically, the printer 10 arranges the printers 10, 200, and 300 in order of high specs based on the clock frequency and memory capacity of each of the parent devices. For example, a method of judging the specs is to calculate an evaluation value by weighting the clock frequency and memory capacity. It can be judged that the higher the evaluation value, the higher the specs. In this embodiment, the printer 10 determines the printer 200 having a clock frequency of "150 MHz" and a memory capacity of "150 MB" as the first (i.e., the highest) printer. The printer 10 determines the printer 10 corresponding to the clock frequency of "100 MHz" and the memory capacity of "100 MB" as the second printer. The printer 10 determines the printer 300 corresponding to the clock frequency of "50 MHz" and the memory capacity of "50 MB" as the third printer.
[0072] Printer 10 determines that printer 200, which is ranked first, is the parent device. However, since printer 200 is already a parent device, printer 10 does not send information to printer 200 instructing it to become a parent device. Printer 10 identifies the IP address "IP3" of printer 300, which has lower specifications than printer 10 itself, according to the sorted order, and sends a child request including the IP address "IP3" as the destination address at T166. Note that printer 10 should become a child device because it has lower specifications than printer 200, but since it has not yet received a child request from printer 200, it does not become a child device at this point.
[0073] When the printer 300 receives a child request from the printer 10 in T166, the printer 300 changes the parent-child flag to child device in T168, thereby transitioning to a child device. The printer 300 further stores the IP address of the printer 10, “IP1”, included in the received child request, in memory (not shown) in T170 as the IP address of the parent device.
[0074] After that, printer 200 executes the process of T180 at a predetermined timing. T180 is the same as T160, except that the source IP address includes the IP address of printer 200, "IP2", instead of the IP address of printer 10, "IP1".
[0075] When the printer 10 receives a search signal from the AP 6 in T180, the printer 10 transmits a response signal to the AP 6 in T182. The response signal includes the IP address "IP3" as the destination IP address, the IP address "IP1" as the source IP address, the device ID "DV1", information "VID1" and "VID2" that identify vulnerabilities corresponding to attacks that the printer 10 can handle, and "parent" information indicating that it is a parent device. The response signal further includes the clock frequency "100 MHz" and the memory capacity "100 MB".
[0076] When the printer 300 receives a search signal from the AP 6 in T180, the printer 300 transmits a response signal to the AP 6 in T184. This response signal is similar to the response signal of T164, except that it contains the IP address "IP2" instead of the IP address "IP1" as the destination IP address, and contains "child" information indicating that it is a child device instead of "parent" information.
[0077] At T182, printer 200 receives a response signal from printer 10 via AP 6, and at T184, printer 200 receives a response signal from printer 300 via AP 6. Upon receiving each response signal, printer 200 determines that printer 10 is the parent device and printer 300 is the child device based on the "parent" information and "child" information contained in each previously received response signal.
[0078] Printer 200 then determines the parent-child relationship with each of printers 10 and 300. This process is similar to the parent-child relationship determination performed by printer 10.
[0079] Printer 200 identifies, in accordance with the sorted order, the IP address "IP1" of printer 10, which has a lower specification than printer 200 itself, and transmits a child request including the IP address "IP1" as a destination address in T186. Printer 200 also identifies the IP address "IP3" of printer 300, which has a lower specification than printer 200 itself, and transmits a child request including the IP address "IP3" as a destination address in T200.
[0080] When the printer 10 receives a child request from the printer 200 in T186, the printer 10 transitions to a child device by changing the parent-child flag from parent device to child device in T188. The printer 10 further stores the IP address "IP2" of the printer 200 included in the child request in memory (not shown) in T190 as the IP address of the parent device.
[0081] When printer 300 receives a child request from printer 200 in T200, printer 300 stores in memory (not shown) the IP address "IP2" of printer 200 included in the received child request as the IP address of the parent device in place of the IP address "IP1" stored in T170 in T202. This forms a parent-child relationship in which printer 200 is the parent device and printers 10, 300 are the child devices.
[0082] When printer 200 determines that printer 200 itself is the parent device, it stores the information in VID list 202. Specifically, printer 200 associates device ID "DV1" with VIDs "VID1" and "VID2" in VID list 202 based on the response signal already received from printer 10 in T210. Also, printer 200 associates device ID "DV3" with VID "VID1" in VID list 202 based on the response signal already received from printer 300. Note that printer 200's own device ID "DV2" and VIDs "VID1" and "VID2" are prestored in VID list 202.
[0083] According to the above configuration, a parent-child relationship is formed between the printers 10, 200, and 300, in which the printer 200 having a relatively high specification is the parent device and the printers 10 and 300 having a relatively low specification are the child devices. The child devices do not need to store a VID list and do not need to transmit attack detection information to the management server 100. This reduces the load on the child devices.
[0084] (Continuation of Figure 7; Figure 8) At T250, the external terminal 60 executes an attack on the printer 10. The attack is the same as T50 in Fig. 4. The processes from T252 to T258 are the same as T52 to T58 in Fig. 4.
[0085] In T260, the printer 10 transmits attack detection information including the IP address "IP4", the port number "PN1", the VID "VID2", and the device ID "DV1" of the printer 10 to the parent device, the printer 200. The attack detection information includes the IP address "IP2" of the printer 200 as the destination address.
[0086] When printer 200 receives the attack detection information from printer 10 in T260, printer 200 uses VID list 202 to determine in T262 whether or not each of the child devices, printers 10 and 300, can handle the above attack. Because printer ID "DV1" is associated with "VID2," printer 200 determines that printer 10 can handle the above attack. On the other hand, because printer ID "DV3" is not associated with "VID2," printer 200 determines that printer 300 cannot handle the above attack.
[0087] If printer 200 determines that at least one other printer is not capable of dealing with the above attack, in T264, printer 200 transmits attack detection information to management server 100, the information including the IP address "IP4", port number "PN1", VID "VID2", and device ID "DV1" of printer 10 that detected the attack.
[0088] Thereafter, the same processes as those in T74 in Fig. 4 to T114 in Fig. 5 are executed. In this case, since the printer 300 does not store the VID list 302, the VID list 302 is not updated in the cited T98.
[0089] Next, the same processes as T180 to T210 in FIG. 7 are executed. However, each response signal transmitted from the printers 10 and 300 includes "child" information instead of "parent" information. Also, the response signal transmitted from the printer 300 includes not only "VID1" but also "VID2". This is because the printer 300 has already received a workaround corresponding to "VID2" from the management server 100. Therefore, when the printer 200 receives a response signal from the printer 300, it stores "VID1" and "VID2" in the VID list 202 in association with the device ID "DV3". In other words, the VID associated with the device ID "DV3" is updated from "VID1" to "VID1" and "VID2". In this way, the latest status of each printer 10, 200, and 300 is reflected in the VID list 202.
[0090] (Case D) Next, a description will be given of Case D in which the attack detection information is not notified to the management server 100. This case is a continuation of T210 in FIG.
[0091] In T280, the external terminal 60 executes an attack on the printer 10. This attack is the same as T250, except that the attack packets are port number "PN2" instead of port number "PN1". After that, in T256, "VID1" is identified instead of "VID2", in T258, "VID1" is stored in memory instead of "VID2", and in T260, "VID1" is included in the attack detection information instead of "VID2". Other points are the same as T252 to T260.
[0092] When the printer 200 receives the attack detection information from the printer 10, in T290, the printer 200 uses the VID list 202 to determine whether or not each of the child devices, the printers 10 and 300, can deal with the above attack. Since "VID1" is associated with each of the printer IDs "DV1" and "DV3," the printer 200 determines that each of the printers 10 and 300 can deal with the above attack. In this case, the printer 200 does not transmit the attack detection information to the management server 100.
[0093] According to the above configuration, if both the child devices, the printer 10 and the printer 300, are capable of dealing with an attack, the parent device, the printer 200, does not transmit attack detection information to the management server 100. Therefore, the communication load between the printer 200 and the management server 100 can be reduced.
[0094] (Correspondence) Printer 200, printer 10, and printer 300 are examples of a “first communication device,” a “second communication device,” and a “third communication device,” respectively. The parent device and the child device are examples of a “first type of device,” and a “second type of device,” respectively.
[0095] Although specific examples of the present invention have been described above in detail, these are merely examples and do not limit the scope of the claims. The technology described in the claims includes various modifications and alterations of the specific examples exemplified above. Modifications of the above-mentioned embodiments are listed below.
[0096] (Variation 1) The method of determining the specifications for forming a parent-child relationship in the second embodiment is not limited to the method in FIG. 7, and other methods may be used. For example, the specifications may be determined based on only the clock frequency, or only the memory capacity. In other examples, the specifications may be determined based on an index other than the clock frequency and memory capacity. For example, the number of CPU threads may be used. Generally speaking, the first type of device only needs to have higher specifications than the second type of device, and the specifications may be compared based on any criteria.
[0097] (Modification 2) T76 in FIG. 4 to T98 in FIG. 5 may be omitted. That is, the management server 100 may not transmit a workaround to the printer 300. In this case, the management server 100 transmits a warning email indicating that an attack has occurred on the printer 10, with the email address "MA1" corresponding to the owner ID "OW1" identified in T74 in FIG. 4 as the destination address in T100. This allows the administrators of the printers 10, 200, and 300 to know that an attack has occurred on the printer 10 by viewing the warning email. In another modification, the management server 100 may not transmit a warning email, and may store log information indicating that an attack has occurred on the printer 10. In this case, the administrator can know that an attack has occurred on the printer 10 by accessing the management server 100 and viewing the log information. Generally speaking, the "server" may not transmit the "handling information" to the second communication device.
[0098] (Variation 3) The "first attribute-related information" does not have to be a device ID, and may be, for example, an owner ID. In this case, the process of T74 in FIG. 4 is not executed. The "first attribute-related information" may also be a group ID for identifying a group of printers 10. In this case, the processes of T74 and 76 are not executed. Instead of these processes, the management server 100 may identify the device IDs "DV2" and "DV3" of devices having the same group ID from the group ID that has already been received.
[0099] (Variation 4) A parent device does not have to have higher specifications than a child device. For example, among the three printers 10, 200, and 300, the printer that is turned on first may become the parent device. Generally speaking, a "first type device" does not have to have higher specifications than a "second type device."
[0100] (Modification 5) Only two of the three printers 10, 200, and 300 may belong to the same network. In this modification, the "third communication device" can be omitted.
[0101] (Variation 6) T10 to T30 in Fig. 3 may be omitted. In this case, after detecting an attack from the external terminal 60, the printer 10 may inquire of each of the printers 200, 300 as to whether or not the printers 200, 300 are capable of dealing with the attack. In this case, the printer 10 can determine whether or not each of the printers 200, 300 is capable of dealing with the attack, depending on the inquiry result. In this variation, the "receiving unit" and the "storage control unit" may be omitted.
[0102] (Variation 7) In the above embodiment, the processing of each step in Figures 3 to 8 is realized by software (e.g., program 40 of printer 10, program 140 of management server 100), but at least one of these processes may be realized by hardware such as a logic circuit.
[0103] In addition, the technical elements described in this specification or drawings have technical utility either alone or in various combinations, and are not limited to the combinations described in the claims at the time of filing. In addition, the technologies illustrated in this specification or drawings can achieve multiple objectives simultaneously, and achieving one of those objectives is itself technically useful.
[0104] In the scope of the claims at the time of filing of this patent application, even if each claim is dependent on only some of the claims, it is not limited to the fact that each claim can be dependent on only those some of the claims. Each claim can also be dependent on other claims that are not dependent on it at the time of filing to the extent that there is no technical contradiction. In other words, the technology of each claim can be combined in various ways as follows: (Item 1) A first communication device, a first detection unit that detects a first attack from the outside; a first determination unit that determines whether or not the second communication device is capable of dealing with the first attack when the first attack is detected; a first transmission unit that, when it is determined that the second communication device is capable of dealing with the first attack, does not transmit first detection information indicating that the first attack has been detected to a server, and, when it is determined that the second communication device is not capable of dealing with the first attack, transmits the first detection information to the server; A first communication device comprising: (Item 2) A first communication device as described in item 1, wherein when the first detection information is transmitted from the first communication device to the server, response information indicating a method of responding to the first attack is transmitted from the server to the second communication device. (Item 3) 3. The first communication device according to item 2, wherein the countermeasure method indicated by the countermeasure information includes restricting access to a destination port number included in packets of the first attack. (Item 4) the first detection information includes first attribute-related information related to an attribute of the first communication device; The first communication device according to item 2 or 3, wherein the second communication device has attributes that match the attributes of the first communication device identified by the first attribute-related information. (Item 5) When the first attack is detected and the first communication device is a first type of device that is a device that should transmit the first detection information to the server, the first determination unit determines whether the second communication device is capable of dealing with the first attack; the first transmission unit transmits the first detection information to the server when it is determined that the second communication device is not capable of dealing with the first attack; The first communication device further comprises: 5. The first communication device according to any one of claims 1 to 4, further comprising a second transmission unit that transmits the first detection information to a first type of device when the first attack is detected and the first communication device is a second type of device that is not a device that should transmit the first detection information to the server. (Item 6) 6. The first communication apparatus according to item 5, wherein the first type of device has higher specifications than the second type of device. (Item 7) the first determination unit, when the first attack is detected, determines whether or not the second communication device is capable of dealing with the first attack, and determines whether or not the third communication device is capable of dealing with the first attack; The first transmission unit is when it is determined that the second communication device is capable of dealing with the first attack and when it is determined that the third communication device is capable of dealing with the first attack, the first detection information is not transmitted to the server; 5. The first communication device according to any one of claims 1 to 4, wherein the first detection information is transmitted to the server when it is determined that at least one of the second communication device and the third communication device is not capable of dealing with the first attack. (Item 8) The first communication device further comprises: Memory, a receiving unit that receives, from the second communication device, first related information related to an attack that the second communication device can currently handle; a storage control unit that stores the first relationship information in the memory, The first communication device according to any one of claims 1 to 7, wherein, when the first attack is detected, the first judgment unit uses the first relationship information in the memory to determine whether the second communication device is capable of dealing with the first attack. (Item 9) the receiving unit receives, when a predetermined time has elapsed since receiving the first relationship information from the second communication device, second relationship information from the second communication device, the second relationship information being related to an attack that the second communication device can currently handle; 9. The first communication device according to item 8, wherein the memory control unit stores the second relationship information in the memory instead of the first relationship information when the second relationship information is different from the first relationship information. (Item 10) 1. A communication system comprising: The first communication device according to any one of items 1 to 9, the second communication device, The second communication device is a second detection unit that detects a second attack from the outside; a second determination unit that determines whether or not the first communication device is capable of dealing with the second attack when the second attack is detected; a second transmission unit that, when it is determined that the first communication device is capable of dealing with the second attack, does not transmit second detection information indicating that the second attack has been detected to the server, and transmits the second detection information to the server when it is determined that the first communication device is not capable of dealing with the second attack; A communication system comprising: [Explanation of symbols]
[0105] 2: communication system, 4: Internet, 6: access point, 10: printer, 12: operation unit, 14: display unit, 16: communication interface, 18: print execution unit, 30: control unit, 32: CPU, 34: memory, 40: program, 42: VID list, 44: detection list, 50: terminal, 60: external terminal, 100: management server, 116: network I / F, 130: control unit, 132: CPU, 134: memory, 140: program, 142: blacklist, 144: device list, 146: VID list, 146: model list, 200: printer, 202: VID list, 300: printer, 302: VID list
Claims
1. A first communication device, a first detection unit that detects a first attack from outside; a first determination unit that determines whether or not the second communication device is capable of dealing with the first attack when the first attack is detected; a first transmission unit that, when it is determined that the second communication device is capable of dealing with the first attack, does not transmit first detection information indicating that the first attack has been detected to a server, and that, when it is determined that the second communication device is not capable of dealing with the first attack, transmits the first detection information to the server; A first communication device comprising:
2. The first communication device according to claim 1 , wherein when the first detection information is transmitted from the first communication device to the server, response information indicating a method of responding to the first attack is transmitted from the server to the second communication device.
3. The first communication device according to claim 2 , wherein the countermeasure method indicated by the countermeasure information includes restricting access to a destination port number included in a packet of the first attack.
4. the first detection information includes first attribute-related information related to an attribute of the first communication device; The first communication device of claim 2 , wherein the second communication device has attributes that match the attributes of the first communication device identified by the first attribute-related information.
5. When the first attack is detected and the first communication device is a first type of device that is a device that should transmit the first detection information to the server, the first determination unit determines whether or not the second communication device is capable of dealing with the first attack; the first transmission unit transmits the first detection information to the server when it is determined that the second communication device is not capable of dealing with the first attack; The first communication device further comprises: The first communication device according to claim 1, further comprising a second transmitting unit that transmits the first detection information to a first type of device when the first attack is detected and the first communication device is a second type of device that is not a device that should transmit the first detection information to the server.
6. The first communication apparatus according to claim 5 , wherein the first type of device has a higher specification than the second type of device.
7. the first determination unit, when the first attack is detected, determines whether or not the second communication device is capable of dealing with the first attack, and determines whether or not the third communication device is capable of dealing with the first attack; The first transmission unit is when it is determined that the second communication device is capable of dealing with the first attack and when it is determined that the third communication device is capable of dealing with the first attack, the first detection information is not transmitted to the server; The first communication device according to claim 1 , further comprising: a first communication device configured to transmit the first detection information to the server when it is determined that at least one of the second communication device and the third communication device is not capable of dealing with the first attack.
8. The first communication device further comprises: Memory, a receiving unit that receives, from the second communication device, first related information related to an attack that the second communication device can currently handle; a storage control unit that stores the first relationship information in the memory, 2. The first communication device according to claim 1, wherein when the first attack is detected, the first determination unit uses the first relationship information in the memory to determine whether the second communication device is capable of dealing with the first attack.
9. the receiving unit receives, when a predetermined time has elapsed since receiving the first relationship information from the second communication device, second relationship information related to an attack that the second communication device can currently handle, from the second communication device; The first communication device according to claim 8 , wherein the storage control unit stores the second relationship information in the memory instead of the first relationship information when the second relationship information is different from the first relationship information.
10. 1. A communication system comprising: The first communication device according to claim 1 ; the second communication device, The second communication device is a second detection unit that detects a second attack from the outside; a second determination unit that determines whether or not the first communication device is capable of dealing with the second attack when the second attack is detected; a second transmission unit that, when it is determined that the first communication device is capable of dealing with the second attack, does not transmit second detection information indicating that the second attack has been detected to the server, and transmits the second detection information to the server when it is determined that the first communication device is not capable of dealing with the second attack; A communication system comprising:
11. A computer program for a first communication device, comprising: The computer of the first communication device comprises the following units: a first detection unit that detects a first attack from outside; a first determination unit that determines whether or not the second communication device is capable of dealing with the first attack when the first attack is detected; a first transmission unit that, when it is determined that the second communication device is capable of dealing with the first attack, does not transmit first detection information indicating that the first attack has been detected to a server, and that, when it is determined that the second communication device is not capable of dealing with the first attack, transmits the first detection information to the server; A computer program that functions as a
12. 1. A method performed by a first communication device, comprising: a first detection step of detecting a first attack from outside; a first determination step of determining whether or not a second communication device is capable of dealing with the first attack when the first attack is detected; a first transmission step of not transmitting first detection information indicating that the first attack has been detected to a server when it is determined that the second communication device is capable of dealing with the first attack, and transmitting the first detection information to the server when it is determined that the second communication device is not capable of dealing with the first attack; A method comprising:
Citation Information
Patent Citations
Network system and attack defense method
JP2006067078A
Semiconductor device
JP2008235876A