Communication device, computer program for communication device, and method executed by communication device
By designing an attack detection information receiving unit, a program update unit and a response processing execution unit in the communication device, the problem of difficulty in effectively dealing with external device attacks in the prior art is solved, and the safe response of the device under different program states is realized.
Patent Information
- Application Number
- JP2023185830
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-10-30
- Publication Date
- 2025-05-14
AI Technical Summary
The prior art is difficult to effectively handle specific attacks from external devices, especially if program updates or responses do not exist.
A communication device is designed, including an attack detection information receiving unit, a program update unit, and a response processing execution unit. When receiving attack detection information, the device will update or perform response processing based on whether the corresponding program exists to ensure that the attack can be effectively responded to.
The device can effectively handle specific attacks in the event of program updates or responses, ensuring the security and stability of communication devices.
Smart Images

Figure 2025074791000001_ABST
Abstract
Description
[Technical field]
[0001] This specification discloses a technique for dealing with attacks from external devices. [Background technology]
[0002] Patent Document 1 discloses a virtual network configured with a plurality of information processing devices and communication lines. When another information processing device is subjected to a DoS attack, the information processing device changes the port number to be used. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] JP 2008-48198 A Summary of the Invention [Problem to be solved by the invention]
[0004] Provided herein are novel techniques for addressing specific attacks. [Means for solving the problem]
[0005] This specification discloses a communication device. The communication device may include an attack detection information receiving unit that receives, from a first external device, attack detection information indicating that a specific attack has been detected, a first updating unit that updates a second program stored in the communication device by using the first program when the attack detection information is received from the first external device and a first program for dealing with the specific attack is present, and a first countermeasure processing execution unit that executes a first countermeasure processing for dealing with the specific attack, the first countermeasure processing being indicated by specific countermeasure information received from a first server, when the attack detection information is received from the first external device and the first program is not present.
[0006] According to the above configuration, the communication device receives attack detection information from the first external device, and if the first program is present, updates the second program using the first program. Also, the communication device receives attack detection information from the first external device, and if the first program is not present, executes a first response process. Therefore, the communication device can appropriately respond to a specific attack whether the first program is present or not.
[0007] A computer program for implementing the above-mentioned communication device, a computer-readable storage medium for storing the computer program, and a method executed by the communication device are also novel and useful. Also, a communication system including the above-mentioned communication device, a first external device, and a first server is novel and useful. [Brief description of the drawings]
[0008] [Figure 1] 1 shows the configuration of a communication system. [Diagram 2] An example of each table is shown below. [Diagram 3] 4 shows a flowchart of a printer process executed by the printer. [Figure 4] 1 shows a flowchart of a workaround process executed by a printer. [Diagram 5] 1 shows a sequence diagram of case A in which the firmware for update is registered in the firmware management server at the time an attack is detected. [Figure 6] FIG. 11 shows a sequence diagram of Case B in which the firmware to be updated is not registered in the firmware management server at the time the attack is detected. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0009] (Example) (Configuration of communication system 2; Figure 1) 1, the communication system 2 includes a plurality of printers 10, 100, a terminal 50, a firmware management server 200, and a workaround management server 300. The printers 10, 100, and the terminal 50 are connected to a local area network (LAN) 4 and can communicate with each other via the LAN 4. The LAN 4 may be either a wired LAN or a wireless LAN. The LAN 4 is connected to the Internet 6. The devices 10, 50, 100, 200, and 300 can communicate with each other via the Internet 6. In this embodiment, it is assumed that a third party's terminal 60 belongs to the LAN 4.
[0010] (Printer 10, 100 configuration) Each of the printers 10, 100 is a peripheral device (for example, a peripheral device of the terminal 50) capable of executing a printing function. The printer 10 has a device ID "DV1" and a model name "MN1". The device name is a name given by a printer administrator. The model name is a name indicating the model of the printer. The printer 10 includes an operation unit 12, a display unit 14, a communication interface 16, a print execution unit 18, and a control unit 30. In the following, the interface is referred to as "I / F".
[0011] The operation unit 12 is an interface for inputting various information to the printer 10, and includes buttons, a touch screen, etc. The display unit 14 is a display or panel for displaying various information. The communication I / F 16 is an interface for executing communication with other devices. The communication I / F 16 is connected to the LAN 4. The communication I / F 16 may be a wired I / F or a wireless I / F. The print execution unit 18 has an electrophotographic, inkjet, or thermal print engine.
[0012] The control unit 30 includes a CPU 32 and a memory 34. The memory 34 includes a main storage device and an auxiliary storage device. The CPU 32 executes various processes according to a program 40 stored in the auxiliary storage device of the memory 34. Specifically, the CPU 32 executes the above-mentioned various processes by loading the program 40 from the auxiliary storage device to the main storage device and executing the program 40. The main storage device is, for example, a RAM and a cache memory. The auxiliary storage device may be, for example, a flash memory, a solid state drive (SSD), or a ROM, or a combination thereof. The program 40 includes firmware 41 for implementing specific operations of the printer 10 (for example, operations of the print execution unit 18, etc.). The memory 34 further stores firmware information 42, general handling information 44, and an email address MA. The firmware information 42 includes version information of the firmware 41 installed in the printer 10 and a vulnerability ID (VID) corresponding to attacks that the firmware 41 can handle. The general-purpose countermeasure information 44 is general-purpose information for dealing with various attacks against the printer. In this embodiment, the general-purpose countermeasure information 44 is information that indicates a process for disabling a port that cannot use user authentication. The email address MA is the email address of the administrator of the printer 10, 100.
[0013] The printer 100 has a device ID "DV2" and a model name "MN2". The printer 100 includes an operation unit (not shown), a display unit (not shown), a communication I / F (not shown), a print execution unit (not shown), and a control unit 130. The control unit 130 includes a CPU 132 and a memory 134. The memory 134 includes a main storage device and an auxiliary storage device. The CPU 132 executes various processes according to a program 140 stored in the auxiliary storage device of the memory 134. Specifically, the CPU 132 executes the above-mentioned various processes by loading the program 140 from the auxiliary storage device to the main storage device and executing the program 140. The program 140 includes firmware 141 for implementing specific operations of the printer 100. The memory 134 further stores firmware information 142, general handling information 144, and an email address MA. The firmware information 142 includes version information of the firmware 141 installed in the printer 100, and a VID that identifies vulnerabilities against attacks that the firmware 141 can deal with. The generic handling information 144 is generic information for dealing with various attacks against the printer. In this embodiment, the generic handling information 144 is the same as the generic handling information 44 stored in the printer 10. In a modified example, the generic handling information 144 may be different from the generic handling information 44 stored in the printer 10.
[0014] (Configuration of firmware management server 200) The firmware management server 200 is installed on the Internet 6 by the vendor of the printers 10, 100 (hereinafter simply referred to as the "vendor"). In a modified example, the firmware management server 200 may be installed on the Internet 6 by a business entity other than the vendor. In another modified example, the vendor may not prepare the hardware for the firmware management server 200 on its own, but may use an environment provided by an external cloud computing service. In this case, the vendor may prepare a program (i.e., software) for the firmware management server 200 and implement it into the above-mentioned environment to realize the firmware management server 200.
[0015] The firmware management server 200 manages firmware for each of the multiple types of printers provided by the above vendor. The firmware management server 200 includes a communication I / F 216 and a control unit 230. The communication I / F 216 is connected to the Internet 6. The control unit 230 includes a CPU 232 and a memory 234. The memory 234 includes a main storage device and an auxiliary storage device. The CPU 232 executes various processes according to a program 240 stored in the auxiliary storage device of the memory 234. Specifically, the CPU 232 executes the various processes by loading the program 240 from the auxiliary storage device to the main storage device and executing the program 240. The memory 234 further stores a firmware table 242.
[0016] (Configuration of Workaround Management Server 300) The workaround management server 300 is installed on the Internet 6 by the vendor. In a modified example, the workaround management server 300 may be installed on the Internet 6 by a business entity other than the vendor. In another modified example, the vendor may not prepare the hardware of the workaround management server 300 by itself, but may use an environment provided by an external cloud computing service. In this case, the vendor may prepare a program (i.e., software) for the workaround management server 300 and implement it into the above-mentioned environment to realize the workaround management server 300.
[0017] The workaround management server 300 manages workarounds for each of the multiple types of printers provided by the above vendor. A workaround is information indicating a method of dealing with a vulnerability. The workaround management server 300 includes a communication I / F 316 and a control unit 330. The communication I / F 316 is connected to the Internet 6. The control unit 330 includes a CPU 332 and a memory 334. The memory 334 includes a main storage device and an auxiliary storage device. The CPU 332 executes various processes according to a program 340 stored in the auxiliary storage device of the memory 334. Specifically, the CPU 332 executes the above various processes by loading the program 340 from the auxiliary storage device to the main storage device and executing the program 340. The memory 334 further stores a workaround table 342.
[0018] (Configuration of terminals 50 and 60) The terminal 50 is an administrator terminal used by an administrator of the printers 10 and 100. The terminal 60 is a terminal used by a third party capable of attacking the printers 10 and 100. The terminals 50 and 60 are, for example, portable terminal devices such as mobile phones, smartphones, PDAs, notebook PCs, and tablet PCs. In a modified example, the terminal 50 may be a stationary terminal device such as a desktop PC.
[0019] Here, types of attacks that the printers 10, 100 may be subjected to from external devices (e.g., terminal 60), i.e., types of vulnerabilities of the printers 10, 100, include, for example, SQL injection, cross-site scripting, CSRF (cross-site request forgery), directory traversal, OS command injection, session management flaws, HTTP header injection, and unauthorized mail relay.
[0020] (Table composition; Fig. 2) The firmware table 242 in the firmware management server 200 and the workaround table 342 in the workaround management server 300 will be described with reference to FIG.
[0021] In the firmware table 242, a model name, a VID, version information, and firmware are stored in association with each other. The version information is information that indicates the version of the firmware. Each piece of information in the firmware table 242 is registered by the administrator of the firmware management server 200.
[0022] In the workaround table 342, a model name, a VID, and a workaround are stored in association with each other. A workaround in the workaround table 342 is information indicating a method of dealing with a vulnerability identified by a VID stored in association with the workaround. Each piece of information in the workaround table 342 is registered by the administrator of the workaround management server 300.
[0023] (Printer processing; Figure 3) The printer processing executed by the CPU 32 of the printer 10 will be described with reference to Fig. 3. The CPU 32 starts the processing of Fig. 3 when the power of the printer 10 is turned on. In the following, communication between each device is executed via the communication I / Fs 16, 216, and 316. Therefore, when describing communication between each device, the descriptions "via communication I / F 16", "via communication I / F 216", and "via communication I / F 316" will be omitted.
[0024] In S10, the CPU 32 monitors whether attack detection information is received from another printer. The attack detection information is information indicating that the other printer has detected an attack from an external device. The attack detection information includes a VID. If the CPU 32 receives attack detection information from another printer, it determines YES in S10 and proceeds to S12.
[0025] In S12, CPU 32 identifies a VID (hereinafter, referred to as a "target VID") in the received attack detection information, and determines whether or not the vulnerability corresponding to the target VID has been addressed. Specifically, CPU 32 determines whether or not firmware information 42 in memory 34 includes the target VID. If firmware information 42 includes the target VID, CPU 32 determines YES in S12 and ends the processing in Fig. 3. On the other hand, if firmware information 42 does not include the target VID, CPU 32 determines NO in S12 and proceeds to S14.
[0026] In S14, the CPU 32 executes a general-purpose countermeasure process using the general-purpose countermeasure information 44 in the memory 34. Specifically, the CPU 32 changes the port that cannot use user authentication from an enabled state to an disabled state. This causes the printer 10 to transition from the normal state to a first attack countermeasure state that can handle various attacks from third parties.
[0027] In S20, the CPU 32 transmits a firmware request including the model name "MN1" and the target VID to the firmware management server 200. The firmware request is a signal requesting the firmware management server 200 to transmit firmware (hereinafter, referred to as "update firmware") corresponding to the model name "MN1" and the target VID in the request. The firmware request is also a signal for confirming whether or not the update firmware exists. When the firmware management server 200 receives a firmware request from the printer 10, the firmware management server 200 judges whether or not the update firmware associated with the model name "MN1" and the target VID in the request is stored in the firmware table 242. If the update firmware is stored in the firmware table 242, the firmware management server 200 identifies the version information associated with the update firmware in the firmware table 242, and transmits the identified version information and the update firmware to the printer 10. On the other hand, if the update firmware is not stored in the firmware table 242, the firmware management server 200 transmits an error notification to the printer 10.
[0028] In S22, the CPU 32 determines whether or not updating firmware has been received from the firmware management server 200. If updating firmware has been received from the firmware management server 200 (YES in S22), the CPU 32 proceeds to S24. On the other hand, if updating firmware has not been received from the firmware management server 200 (NO in S22), the CPU 32 proceeds to S30.
[0029] In S24, the CPU 32 executes an update process to update the firmware 41 in the memory 34 using the update firmware received in S22. This updates the firmware 41 in the memory 34 to firmware that can deal with the vulnerability corresponding to the target VID. The CPU 32 also stores the target VID and version information in the firmware information 42 in the memory 34.
[0030] In S26, the CPU 32 executes a first release process for releasing the general-purpose countermeasure applied in S14. Specifically, the CPU 32 changes the port that cannot use user authentication from an invalid state to an valid state. This causes the state of the printer 10 to transition from the first attack response state to the normal state. In the first attack response state, there is a high possibility that the functions of the printer 10 are restricted compared to when the state of the printer 10 is the normal state. Therefore, by transitioning the state of the printer 10 from the first attack response state to the normal state, the state in which the functions of the printer 10 are restricted can be released.
[0031] In S28, the CPU 32 sends an e-mail including an update notification, a first recovery notification, the target VID, and the device name "DV1" to the e-mail address MA in the memory 34 as the destination. The update notification indicates that the firmware 41 of the printer 10 has been updated. The first recovery notification indicates that the state of the printer 10 has transitioned from the first attack response state to the normal state. This allows the administrator of the printer 10 to know that the firmware 41 has been updated. The administrator of the printer 10 can also know that the state of the printer 10 has transitioned from the first attack response state to the normal state. When S28 ends, the CPU 32 ends the processing of FIG. 3.
[0032] Also, in S30, the CPU 32 transmits a workaround request including the model name "MN1" and the target VID to the workaround management server 300. When the workaround management server 300 receives the workaround request from the printer 10, it determines whether or not a workaround (hereinafter, referred to as "target firmware") associated with the model name "MN1" and the target VID in the request is stored in the workaround table 342. If the target workaround is stored in the workaround table 342, the workaround management server 300 transmits the target workaround to the printer 10. On the other hand, if the target workaround is not stored in the workaround table 342, the workaround management server 300 transmits an error notification to the printer 10.
[0033] In S32, the CPU 32 judges whether or not a target workaround has been received from the workaround management server 300. If the CPU 32 has received a target workaround from the workaround management server 300 (YES in S32), the CPU 32 proceeds to S34. On the other hand, if the CPU 32 has not received a target workaround from the workaround management server 300 (NO in S32), the CPU 32 proceeds to S40.
[0034] In S34, the CPU 32 executes a workaround process (see FIG. 4). The workaround process is a process for applying the target workaround to the printer 10.
[0035] Also, in S40, the CPU 32 sends an e-mail including the first application notification, the target VID, the device ID "DV1", and the general-purpose handling information 44 to the e-mail address MA in the memory 34 as the destination. The first application notification indicates that the state of the printer 10 has transitioned from the normal state to the first attack handling state.
[0036] In S42, the CPU 32 monitors whether a first predetermined time (for example, 12 hours) has elapsed since the first application notification was transmitted. If the first predetermined time has elapsed, the CPU 32 determines YES in S42 and returns to S20.
[0037] (Workaround; Figure 4) The workaround process executed in S34 of FIG. 3 will be described with reference to FIG.
[0038] In S60, the CPU 32 executes a workaround process to apply the target workaround to the printer 10. As an example, the target workaround is to block access to a protected asset, that is, a portion of an area in a memory.
[0039] As another example, the target workaround is to transmit header information included in a packet from an external terminal to the workaround management server 300. Note that the workaround is, for example, a provisional countermeasure against the vulnerability of HTTP header injection.
[0040] As another example, the target workaround may be to block access to a database, for example, as a temporary measure to address a SQL injection vulnerability.
[0041] In another example, a target workaround is to block script execution. The workaround is, for example, a temporary measure to address a cross-site scripting vulnerability.
[0042] As another example, the target workaround is to block OS commands. The workaround is, for example, a temporary measure to address an OS command injection vulnerability.
[0043] As another example, the target workaround is to use a different means for generating session IDs. The workaround is, for example, a temporary measure to address a vulnerability due to improper session management.
[0044] As another example, the target workaround is to block email relaying, which is, for example, a temporary measure to address the vulnerability of email relaying.
[0045] As another example, the target workaround is to block connections to the IP address of the terminal 60 and the destination port number included in the attack packet.
[0046] In S62, the CPU 32 executes a first release process for releasing the general-purpose countermeasure applied in S14. This causes the state of the printer 10 to transition from the first attack countermeasure state to a second attack countermeasure state in which the target workaround is applied and the vulnerability corresponding to the target VID can be dealt with. In the first attack countermeasure state, the functions of the printer 10 are more likely to be restricted than when the state of the printer 10 is the second attack countermeasure state. For this reason, by transitioning the state of the printer 10 from the first attack countermeasure state to the second attack countermeasure state, the state in which the functions of the printer 10 are more restricted can be released.
[0047] In S64, the CPU 32 sends an email including a second application notification, a transition notification, the target VID, and the device name "DV1" to the email address MA in the memory 34 as the destination. The second application notification indicates that the workaround has been applied. The transition notification indicates that the state of the printer 10 has transitioned from the first attack response state to the second attack response state. This allows the administrator of the printer 10 to know that the workaround processing has been executed. In addition, the administrator of the printer 10 can know that the state of the printer 10 has transitioned from the first attack response state to the second attack response state.
[0048] In S66, the CPU 32 monitors whether a second predetermined time (e.g., 12 hours) has elapsed since the second application notification and transition notification were sent. If the second predetermined time has elapsed, the CPU 32 determines YES in S66 and proceeds to S70. The second predetermined time may be the same as or different from the first predetermined time in FIG.
[0049] S70 and S72 are the same as S20 and S22 in Fig. 3, respectively. If the CPU 32 judges YES in S72, it proceeds to S74, and if the CPU 32 judges NO in S72, it returns to S66. Note that in S66 after NO in S72, the CPU 32 monitors whether a second predetermined time has elapsed since transmitting the firmware request. S74 is the same as S24 in Fig. 3.
[0050] In S76, the CPU 32 executes a second release process for releasing the target workaround. This causes the state of the printer 10 to transition from the second attack response state to the normal state. In this way, the CPU 32 executes the update process and the second release process when the state of the printer 10 changes from a state in which there is no update program to a state in which there is firmware for updating after the workaround response process is executed. In the second attack response state, the printer 10 is more likely to have its functions restricted than when the printer 10 is in the normal state. For this reason, by shifting the state of the printer 10 from the second attack response state to the normal state, the state in which the printer 10 has its functions restricted can be released. The firmware is updated after the workaround response process is executed because the workaround is information (program) for executing a provisional process for dealing with an external attack before the firmware is provided.
[0051] In S78, the CPU 32 sends an e-mail including an update notification, a second recovery notification, the target VID, and the device name "DV1" to the e-mail address MA in the memory 34 as the destination. The second recovery notification indicates that the state of the printer 10 has transitioned from the second attack response state to the normal state. When S78 ends, the CPU 32 ends the processing of FIG. 4. This allows the administrator of the printer 10 to know that the state of the printer 10 has transitioned from the second attack response state to the normal state.
[0052] In this embodiment, the CPU 132 of the printer 100 is also configured to be able to execute the printer process of Fig. 3 and the workaround process of Fig. 4. In the printer process and workaround process executed by the CPU 132, the firmware request (see S20 in Fig. 3 and S70 in Fig. 4) and the workaround request (see S30 in Fig. 3) include the model name "MN2".
[0053] (Specific cases: Figures 5 and 6) 5 and 6, a specific case realized by the communication system 2 of the present embodiment will be described. Note that, in the following, the contents of the processing will be described mainly with respect to each device (e.g., the printer 10, etc.) instead of the CPU of each device (e.g., the CPU 32).
[0054] (Case A; Figure 5) 5, a case A in which the printer 100 is attacked by the terminal 60 will be described. In the initial state of case A, the printer 100 is in a state capable of dealing with an attack from the terminal 60. On the other hand, the firmware of the printer 10 is not in a state capable of dealing with an attack from the terminal 60. Also, the firmware table 242 of the firmware management server 200 stores the model name "MN1", the VID "VID1", the version information "VE11", and the firmware 41' in association with each other.
[0055] At T10, the terminal 60 executes an attack on the printer 100. The attack packet includes the IP address of the terminal 60, "IP1," and the destination port number, "PN1."
[0056] When the printer 100 receives an attack packet from the terminal 60 in T10, the printer 100 detects the attack in T12. When the printer 100 detects that the packet is an external attack, the printer 100 does not execute the process according to the command included in the packet. The printer 100 identifies the type of attack in T14 and executes a normal countermeasure against the attack. As an example, if the type of attack corresponds to a directory traversal vulnerability of the printer 100, the printer 100 prohibits the specification of a path having a predetermined directory structure as a normal countermeasure. Next, the printer 100 identifies the VID "VID1" that identifies the vulnerability corresponding to the attack detected in T12 in T16, and transmits attack detection information including the identified VID "VID1" to the LAN4 by broadcast in T18. As a result, the attack detection information is transmitted to devices belonging to the LAN4.
[0057] When the printer 10 receives the attack detection information from the printer 100 in T18 (YES in S10 of FIG. 3), it identifies the VID "VID1" in the information. The printer 10 determines in T20 that the firmware information 42 in the memory 34 does not include the VID "VID1" and therefore that the vulnerability corresponding to the VID "VID1" has not been addressed (NO in S12), and in T22 executes a general-purpose handling process using the general-purpose handling information 44 in the memory 34 (S14). Next, the printer 10 sends a firmware request including the model name "MN1" and the VID "VID1" to the firmware management server 200 in T30.
[0058] When the firmware management server 200 receives a firmware request from the printer 10 at T30, it identifies the model name "MN1" and VID "VID1" in the request, and determines that firmware 41' (i.e., firmware for update) associated with the identified model name "MN1" and VID "VID1" is stored in the firmware table 242. In this case, the firmware management server 200 identifies version information "VE11" associated with the firmware 41' in the firmware table 242, and transmits the identified version information "VE11" and firmware 41' to the printer 10 at T32.
[0059] When the printer 10 receives the version information "VE11" and the firmware 41' from the firmware management server 200 in T32 (YES in S22), in T40, the printer 10 executes an update process to update the firmware 41 in the memory 34 using the received firmware 41' (S24). Next, in T42, the printer 10 executes a first release process to transition the state of the printer 10 from the first attack response state to a normal state (S26), and in T44, sends an e-mail including an update notification, a first recovery notification, the VID "VID1", and the device name "DV1" to the e-mail address MA in the memory 34 as the destination. In this way, the firmware 41 of the printer 10 is updated to firmware capable of dealing with the vulnerability corresponding to the VID "VID1". Therefore, even if the printer 10 is subsequently attacked by the terminal 60, the printer 10 can deal with the attack.
[0060] (Effect of Case A) As described above, the printer 10 receives attack detection information from the printer 100 belonging to the LAN4 (T10 in FIG. 5). The printer 10 belonging to the same LAN is likely to be subjected to an attack similar to that suffered by the printer 100. By receiving the attack detection information from the printer 100, the printer 10 can be put into a state in which it can handle the attack.
[0061] Furthermore, the printer 10 executes a general-purpose handling process (T22) when attack detection information is received from the printer 100. This allows the printer 10 to handle the attack even if the printer 10 is attacked by the terminal 60 before the update process is executed or before the workaround handling process is executed.
[0062] (Case B) 6, a case B in which the printer 100 is attacked by the terminal 60 will be described. The initial state of case B is similar to the initial state of case A in FIG. 5, except that the firmware 41′ is not stored in the firmware table 242 of the firmware management server 200.
[0063] T110 to T122 are the same as T10 to T122 in FIG.
[0064] When the firmware management server 200 receives a firmware request from the printer 10 in T130, it identifies the model name "MN1" and VID "VID1" in the request, and determines that firmware associated with the identified model name "MN1" and VID "VID1" is not stored in the firmware table 242. In this case, the firmware management server 200 sends an error notification to the printer 10 in T132.
[0065] When the printer 10 receives an error notification from the firmware management server 200 in T132, it determines that it has not received the update firmware from the firmware management server 200 (NO in S22). In this case, the printer 10 transmits a workaround request including the model name "MN1" and the VID "VID1" to the workaround management server 300 in T140 (S30).
[0066] When the workaround management server 300 receives a workaround request from the printer 10 in T140, it identifies the model name "MN1" and the VID "VID1" in the request, and determines that a workaround associated with the identified model name "MN1" and VID "VID1" is not stored in the workaround table 342. In this case, the workaround management server 300 transmits an error notification to the printer 10 in T142.
[0067] When the printer 10 receives an error notification from the workaround management server 300 in T142, it determines that it has not received the target workaround from the workaround management server 300 (NO in S32). In this case, the printer 10 sends an e-mail including the first application notification, the VID "VID1", the device ID "DV1", and the general-purpose handling information 44 to the e-mail address MA in the memory 34 as the destination. This allows the administrator to know by using the terminal 50 that the general-purpose handling information 44 has been applied to the printer 10.
[0068] Thereafter, at T150, the administrator of the firmware management server 200 executes a firmware addition operation to add the firmware 41' to the firmware table 242. As a result, the model name "MN1", the VID "VID1", the version information "VE11", and the firmware 41' are stored in the firmware table 242 in association with each other.
[0069] In T160, the printer 10 determines that a first predetermined time has elapsed since the first application notification was sent (YES in S42), and in T170, sends a firmware request including the model name "MN1" and VID "VID1" to the firmware management server 200. T172, T180 to T184 are similar to T32, T40 to T44 in Fig. 3, respectively. In this way, the firmware 41 of the printer 10 is updated to firmware that can address the vulnerability corresponding to VID "VID1".
[0070] (Effects of this embodiment) According to the above configuration, when the printer 10 receives the attack detection information from the printer 100 and the firmware for update is present (YES in S22 in FIG. 3), the printer 10 uses the firmware for update to update the firmware 41 in the memory 34 (S24). When the printer 10 receives the attack detection information from the printer 100 and the firmware for update is not present (NO in S22), the printer 10 executes a workaround process (S60 in FIG. 4). Therefore, the printer 10 can appropriately deal with a specific attack whether or not the firmware for update is present.
[0071] (Correspondence) The printer 10 is an example of a "communication device". The printer 100 is an example of a "first external device". The attack of T10 in FIG. 5 is an example of a "specific attack". The firmware 41 is an example of a "first program". The firmware 41' is an example of a "second program". The firmware management server 200 is an example of a "first server". The workaround in the workaround table 342 of the workaround management server 300 is an example of a "specific handling information". The workaround handling process of S60 in FIG. 4 is an example of a "first handling process". The VID is an example of an "identification information". The firmware request is an example of a "program request". The firmware management server 200 is an example of a "second server". The LAN4 is an example of a "same network". The update notification of S28 in FIG. 3 is an example of a "first notification". The second application notification of S64 in FIG. 4 is an example of a "second notification". The second attack handling state is an example of a "first handling state". The second recovery notification of S78 in FIG. 4 is an example of a "third notification." The general-purpose response process of S14 in FIG. 3 is an example of a "second response process." A port that cannot utilize user authentication is an example of a "specific port." The first attack response state is an example of a "second response state." The first recovery notification of S28 in FIG. 3 is an example of a "fourth notification." The transition notification of S64 in FIG. 4 is an example of a "fifth notification."
[0072] S10 in Fig. 3 is an example of a process executed by an "attack detection information receiving unit." S24 in Fig. 3 is an example of a process executed by a "first updating unit." S60 in Fig. 4 is an example of a process executed by a "first handling process executing unit."
[0073] Although specific examples of the technology disclosed in this specification have been described in detail above, these are merely examples and do not limit the scope of the claims. The technology described in the claims includes various modifications and variations of the specific examples exemplified above. Modifications of the above embodiments are listed below.
[0074] (First Modification) When the printer 100 is subjected to an attack that the printer 100 can handle, the printer 100 may transmit a VID corresponding to the attack from the terminal 60 to the workaround management server 300. Then, when the workaround management server 300 receives a VID from the printer 100 and a workaround corresponding to the VID is stored in the workaround table 342, the printer 10 may transmit attack detection information including the VID and the workaround to the printer 10. Also, when the workaround management server 300 receives a VID from the printer 100 and a workaround corresponding to the VID is not stored in the workaround table 342, the printer 10 may transmit attack detection information including the VID to the printer 10. In this modification, the workaround management server 300 is an example of a "first external device."
[0075] (Second Modification) The communication system 2 may include a honeypot connected to the LAN 4. A honeypot is a device that is installed to receive external attacks in place of other devices in the LAN 4. In this case, when the honeypot is attacked, it specifies a VID that identifies the vulnerability corresponding to the attack, and transmits attack detection information including the VID to the LAN 4 by broadcast. In this modification, the honeypot is an example of a "first external device."
[0076] (Third Modification) In S28 of Fig. 3, the CPU 32 of the printer 10 may not transmit the update notification. In addition, in S64 of Fig. 4, the CPU 32 may not transmit the second application notification. In this modification, the "first notification transmission unit" and the "second notification transmission unit" may be omitted.
[0077] (Fourth Modification) It is possible to omit S66 to S76 in Fig. 4. In this modification, it is possible to omit the "second update section" and the "first transition section".
[0078] (Fifth Modification) In S78 of Fig. 4, the CPU 32 of the printer 10 does not have to transmit the second recovery notification. In this modification, the "third notification transmission unit" can be omitted.
[0079] (Sixth Modification) S14 and S26 in FIG. 3 and S76 in FIG. 4 can be omitted. In this modification, the general handling information 44 does not have to be stored in the memory 34 of the printer 10. Also, in this modification, the CPU 32 of the printer 10 does not have to send the first recovery notification (see S28 in FIG. 3), the transition notification (see S64 in FIG. 4), and the second recovery notification (see S78 in FIG. 4). In this modification, the "second handling process execution unit," "second transition unit," "third transition unit," "fourth notification transmission unit," and "fifth notification transmission unit" can be omitted.
[0080] (Seventh Modification) The general handling information 44 may be information indicating a process to block inbound communication, information indicating a process to block inbound communication from devices other than those previously accessed, etc. In another modification, the memory 34 of the printer 10 may store a list of devices that have previously accessed the printer 10. In this case, the general handling information 44 may be information indicating a process to block inbound communication from devices other than those in the list. In yet another modification, the general handling information 44 may be information indicating a process to discard or encrypt document data stored in the printer 10.
[0081] (Eighth Modification) S26 in Fig. 3 and S62 and S76 in Fig. 4 can be omitted. For example, when printer 10 receives an operation from an administrator to cancel the general-purpose countermeasure indicated in general-purpose countermeasure information 44, printer 10 may execute processing to cancel the general-purpose countermeasure. In this modification, the "second transition unit," "third transition unit," "fourth notification transmission unit," and "fifth notification transmission unit" can be omitted.
[0082] (Ninth Modification) In S28 of Fig. 3, the CPU 32 of the printer 10 does not have to transmit the first recovery notification. In this modification, the "fourth notification transmission unit" can be omitted.
[0083] (Tenth Modification) In S64 of Fig. 4, the CPU 32 of the printer 10 does not have to transmit the transition notification. In this modification, the "fifth notification transmission unit" can be omitted.
[0084] (Eleventh Modification) The firmware management server 200 and the workaround management server 300 may be configured as a single server.
[0085] (Twelfth Modification) In each of the above embodiments, the processes in FIGS. 3 to 6 are realized by software (for example, programs 40, 140, 240, 340), but at least one of these processes may be realized by hardware such as a logic circuit.
[0086] The technical elements described in this specification or drawings have technical utility either alone or in various combinations, and are not limited to the combinations described in the claims at the time of filing. In addition, the technologies illustrated in this specification or drawings can achieve multiple objectives simultaneously, and achieving one of these objectives is itself technically useful.
[0087] In the scope of the claims at the time of filing of this patent application, even if each claim is dependent on only some of the claims, it is not limited to the fact that each claim can be dependent on only those some of the claims. Each claim can also be dependent on other claims that are not dependent on it at the time of filing to the extent that there is no technical contradiction. In other words, the technology of each claim can be combined in various ways as follows: (Item 1) 1. A communication device, comprising: an attack detection information receiving unit that receives, from a first external device, attack detection information indicating that a specific attack has been detected; a first update unit that, when the attack detection information is received from the first external device and a first program for dealing with the specific attack is present, updates a second program stored in the communication device by using the first program; a first countermeasure processing execution unit that executes a first countermeasure processing indicated by specific countermeasure information received from a first server when the attack detection information is received from the first external device and the first program is not present, the first countermeasure processing being for countering the specific attack; A communication device comprising: (Item 2) the attack detection information includes identification information for identifying the specific attack, The communication device further comprises: a program request sending unit that sends a program request including the identification information to a second server when the attack detection information is received from the first external device; and a determination unit that determines that the first program exists when the first program is received from the second server in response to the program request being sent to the second server, and that determines that the first program does not exist when the first program is not received from the second server in response to the program request being sent to the second server. (Item 3) the first external device belongs to the same network as the communication device; 3. The communication device according to item 1 or 2, wherein the attack detection information is information indicating that the first external device has detected the specific attack. (Item 4) The communication device further comprises: a first notification transmission unit that, when the second program is updated, transmits to an outside a first notification indicating that the second program has been updated; a second notification transmission unit that, when the first handling process is executed, transmits to an outside a second notification indicating that the first handling process has been executed; 4. The communication device according to any one of claims 1 to 3, comprising: (Item 5) a state of the communication device transitions from a normal state in which the communication device does not respond to the specific attack to a first response state in which the communication device is able to respond to the specific attack in response to the first response process being executed; The communication device further comprises: a second update unit that updates the second program by using the first program when a state in which the first program does not exist changes to a state in which the first program exists after the first handling process is executed; a first transition unit that transitions a state of the communication device from the first handling state to the normal state when a state in which the first program is not present changes to a state in which the first program is present after the first handling process is executed; 5. The communication device according to any one of claims 1 to 4, comprising: (Item 6) The communication device further comprises: 6. The communication device according to item 5, further comprising a third notification sending unit that, when the state of the communication device transitions from the first handling state to the normal state, sends a third notification to the outside indicating that the state of the communication device has transitioned from the first handling state to the normal state. (Item 7) The communication device further comprises: a memory that stores general-purpose countermeasure information indicating a second countermeasure process that is a general-purpose countermeasure process for dealing with an attack; A communication device described in any one of items 1 to 6, comprising a second response processing execution unit that executes the second response processing indicated by the general response information in the memory when the attack detection information is received from the first external device. (Item 8) 8. The communication device according to item 7, wherein the second handling process is a process of changing a specific port of the communication device from an enabled state to an disabled state. (Item 9) a state of the communication device transitions from a normal state in which the communication device does not respond to the specific attack to a second response state in which the communication device is able to respond to the specific attack in response to the second response process being executed; The communication device further comprises: a second transition unit that transitions a state of the communication device from the second handling state to the normal state when the second program is updated after the second handling process is executed; a third transition unit that transitions a state of the communication device from the second response state to a first response state capable of responding to the specific attack when the first response process is executed after the second response process is executed; 9. The communication device according to item 7 or 8, comprising: (Item 10) The communication device further comprises: 10. The communication device according to item 9, further comprising a fourth notification sending unit that, when the state of the communication device transitions from the second handling state to the normal state, sends a fourth notification to the outside indicating that the state of the communication device has transitioned from the second handling state to the normal state. (Item 11) The communication device further comprises: Item 9 or 10. The communication device according to item 9 or 10, further comprising a fifth notification sending unit that, when the state of the communication device transitions from the second handling state to the first handling state, sends a fifth notification to the outside indicating that the state of the communication device has transitioned from the second handling state to the first handling state. (Item 12) A computer program for a communication device, comprising: A computer of the communication device, an attack detection information receiving unit that receives, from a first external device, attack detection information indicating that a specific attack has been detected; a first update unit that, when the attack detection information is received from the first external device and a first program for dealing with the specific attack is present, updates a second program stored in the communication device by using the first program; a first countermeasure processing execution unit that executes a first countermeasure processing indicated by specific countermeasure information received from a first server when the attack detection information is received from the first external device and the first program is not present, the first countermeasure processing being for countering the specific attack; A computer program that functions as a (Item 13) 1. A method performed by a communication device, comprising: an attack detection information receiving step of receiving, from a first external device, attack detection information indicating that a specific attack has been detected; a first update step of updating a second program stored in the communication device by using a first program when the attack detection information is received from the first external device and a first program for dealing with the specific attack is present; a first countermeasure processing execution step of executing a first countermeasure processing indicated by specific countermeasure information received from a first server when the attack detection information is received from the first external device and the first program does not exist, the first countermeasure processing being for countering the specific attack; A method comprising: [Explanation of symbols]
[0088] 2: communication system, 4: LAN, 6: Internet, 10: printer, 12: operation unit, 14: display unit, 16: communication I / F, 18: print execution unit, 30: control unit, 32: CPU, 34: memory, 40: program, 41: firmware, 41´: firmware, 42: firmware information, 44: general handling information, 50: terminal, 60: terminal, 100: printer, 130: control unit, 132: CPU, 134: memory, 140: program, 142: firmware information, 144: general handling information, 200: firmware management server, 216: communication I / F, 230: control unit, 232: CPU, 234: memory, 240: program, 242: firmware table, 300: workaround management server, 316: communication I / F, 330: control unit, 332: CPU, 334: memory, 340: program, 342: workaround table
Claims
1. 1. A communication device, comprising: an attack detection information receiving unit that receives, from a first external device, attack detection information indicating that a specific attack has been detected; a first update unit that updates a second program stored in the communication device by using a first program when the attack detection information is received from the first external device and a first program for dealing with the specific attack is present; a first countermeasure processing execution unit that executes a first countermeasure processing indicated by specific countermeasure information received from a first server when the attack detection information is received from the first external device and the first program is not present, the first countermeasure processing being for countering the specific attack; A communication device comprising:
2. the attack detection information includes identification information for identifying the specific attack, The communication device further comprises: a program request sending unit that sends a program request including the identification information to a second server when the attack detection information is received from the first external device; 2. The communication device according to claim 1, further comprising: a determination unit that determines that the first program exists when the first program is received from the second server in response to the program request being sent to the second server, and that determines that the first program does not exist when the first program is not received from the second server in response to the program request being sent to the second server.
3. the first external device belongs to the same network as the communication device, The communication device according to claim 1 , wherein the attack detection information is information indicating that the first external device has detected the specific attack.
4. The communication device further comprises: a first notification transmission unit that, when the second program is updated, transmits to an outside a first notification indicating that the second program has been updated; a second notification transmission unit that, when the first handling process is executed, transmits to an outside a second notification indicating that the first handling process has been executed; The communication device of claim 1 .
5. a state of the communication device transitions from a normal state in which the communication device does not respond to the specific attack to a first response state in which the communication device is able to respond to the specific attack in response to the first response process being executed; The communication device further comprises: a second update unit that updates the second program by using the first program when a state in which the first program is not present changes to a state in which the first program is present after the first handling process is executed; a first transition unit that transitions a state of the communication device from the first handling state to the normal state when a state in which the first program is not present changes to a state in which the first program is present after the first handling process is executed; The communication device of claim 1 .
6. The communication device further comprises:
6. The communication device according to claim 5, further comprising a third notification sending unit that, when the state of the communication device transitions from the first handling state to the normal state, sends a third notification to an external device indicating that the state of the communication device has transitioned from the first handling state to the normal state.
7. The communication device further comprises: a memory for storing general-purpose countermeasure information indicating a second countermeasure process which is a general-purpose countermeasure process for dealing with an attack; The communication device according to claim 1 , further comprising: a second countermeasure processing execution unit that executes the second countermeasure processing indicated by the general countermeasure information in the memory when the attack detection information is received from the first external device.
8. The communication device according to claim 7 , wherein the second handling process is a process of changing a specific port of the communication device from an enabled state to an disabled state.
9. a state of the communication device transitions from a normal state in which the communication device does not respond to the specific attack to a second response state in which the communication device is able to respond to the specific attack in response to the second response process being executed; The communication device further comprises: a second transition unit that transitions a state of the communication device from the second handling state to the normal state when the second program is updated after the second handling process is executed; a third transition unit that transitions a state of the communication device from the second response state to a first response state capable of responding to the specific attack when the first response process is executed after the second response process is executed; The communication device of claim 7 , comprising:
10. The communication device further comprises:
10. The communication device according to claim 9, further comprising: a fourth notification sending unit that, when the state of the communication device transitions from the second handling state to the normal state, sends a fourth notification to an external device indicating that the state of the communication device has transitioned from the second handling state to the normal state.
11. The communication device further comprises:
10. The communication device according to claim 9, further comprising: a fifth notification sending unit that, when the state of the communication device transitions from the second handling state to the first handling state, transmits a fifth notification to an external device indicating that the state of the communication device has transitioned from the second handling state to the first handling state.
12. A computer program for a communication device, comprising: A computer of the communication device, an attack detection information receiving unit that receives, from a first external device, attack detection information indicating that a specific attack has been detected; a first update unit that updates a second program stored in the communication device by using a first program when the attack detection information is received from the first external device and a first program for dealing with the specific attack is present; a first countermeasure processing execution unit that executes a first countermeasure processing indicated by specific countermeasure information received from a first server when the attack detection information is received from the first external device and the first program is not present, the first countermeasure processing being for countering the specific attack; A computer program that functions as a
13. 1. A method performed by a communication device, comprising: an attack detection information receiving step of receiving, from a first external device, attack detection information indicating that a specific attack has been detected; a first update step of updating a second program stored in the communication device by using a first program when the attack detection information is received from the first external device and a first program for dealing with the specific attack is present; a first countermeasure processing execution step of executing a first countermeasure processing indicated by specific countermeasure information received from a first server when the attack detection information is received from the first external device and the first program is not present, the first countermeasure processing being for countering the specific attack; A method comprising:
Citation Information
Patent Citations
Port number management method, information processing apparatus, and computer program
JP2008048198A