Information processing device, vulnerability information utilization method, and vulnerability information utilization program

The information processing apparatus effectively addresses the inefficiencies in selecting vulnerability information for image forming apparatuses by acquiring and validating vulnerability information based on the apparatus's functions, resulting in improved security and relevance of the information processed.

JP2025083891APending Publication Date: 2025-06-02KONICA MINOLTA INC
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2023197547
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-11-21
Publication Date
2025-06-02

AI Technical Summary

Technical Problem

Existing methods for selecting vulnerability information for image forming apparatuses are inefficient, as they require pre-registration of reliability and danger levels for information sources, and may include unnecessary security information.

Method used

An information processing apparatus that manages image forming apparatuses, equipped with a vulnerability information acquisition module, a function information acquisition module, and a determination module, which acquires and determines the validity of vulnerability information based on the functions executable by the image forming apparatus.

Benefits of technology

This solution enables the extraction of relevant vulnerability information suitable for image forming apparatuses, reducing unnecessary information and enhancing security by determining the validity of vulnerability information based on the apparatus's capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025083891000001_ABST
    Figure 2025083891000001_ABST
Patent Text Reader

Abstract

To extract vulnerability information suitable for an image forming apparatus.SOLUTION: An information processing device that manages an image forming apparatus includes a vulnerability information acquiring unit 51 that acquires vulnerability information related to vulnerabilities, a function information acquiring unit 53 that acquires function information related to functions that can be executed by the image forming apparatus, and a determining unit 57 that determines the validity of the vulnerability information on the basis of the function information.SELECTED DRAWING: Figure 4
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an information processing apparatus, a method for using vulnerability information, and a program for using vulnerability information. In particular, the present invention relates to an information processing apparatus that manages an image forming apparatus that executes a program, a method for using vulnerability information executed by the information processing apparatus, and a program for using vulnerability information that causes a computer to execute the method for using vulnerability information.

[0002] In recent years, image forming apparatuses installed in workplaces are connected to the Internet. Therefore, it is necessary to prevent attacks such as computer viruses that are expected to invade from the Internet. Security information indicating vulnerabilities is publicly available on the Internet. Since there is a vast amount of this security information, it is difficult to select the necessary security information from among them.

[0003] For example, Japanese Patent Application Laid-Open No. 2003-256370 discloses a security information distribution method including steps of searching an information providing site to obtain security information, referring to user information to select, for each user, security information to be notified from the obtained security information, and transmitting the selected security information to a notification destination, wherein the step of selecting security information selects security information to be notified based on the reliability of the information providing site assigned to each information providing site and the degree of danger of the security information itself.

[0004] However, in the security information distribution method described in Japanese Patent Application Laid-Open No. 2003-256370, in order to select security information, it is necessary to previously register the reliability of each information providing site and the degree of danger of the security information itself for each information providing site. In addition, in an apparatus targeted for security enhancement, unnecessary security information may be selected, and in this case, it is necessary to deal with the unnecessary security information.

Prior Art Documents

Patent Documents

[0005] [Patent Document 1] Japanese Patent Application Laid-Open No. 2003-256370 [Summary of the Invention] [Problems to be Solved by the Invention]

[0006] This invention has been made to solve the above-described problems, and one of the objects of this invention is to provide an information processing apparatus capable of extracting vulnerability information suitable for an image forming apparatus.

[0007] Another object of this invention is to provide a method for using vulnerability information capable of extracting vulnerability information suitable for an image forming apparatus.

[0008] Still another object of this invention is to provide a program for using vulnerability information capable of extracting vulnerability information suitable for an image forming apparatus. [Means for Solving the Problems]

[0009] According to an aspect of this invention for achieving the above-described object, an information processing apparatus is an information processing apparatus that manages an image forming apparatus, and includes a vulnerability information acquisition means for acquiring vulnerability information regarding vulnerability, a function information acquisition means for acquiring function information regarding functions executable by the image forming apparatus, and a determination means for determining the validity of the vulnerability information based on the function information.

[0010] According to another aspect of this invention, a method for using vulnerability information is a method for using vulnerability information executed by an information processing apparatus that manages an image forming apparatus, and includes a vulnerability information acquisition step for acquiring vulnerability information regarding vulnerability, a function information acquisition step for acquiring function information regarding functions executable by the image forming apparatus, a determination step for determining the validity of the vulnerability information based on the function information, and is executed by the information processing apparatus.

[0011] According to still another aspect of the present invention, the vulnerability information utilization program is a vulnerability information utilization program executed on a computer that manages an image forming apparatus, and includes a vulnerability information acquisition step of acquiring vulnerability information regarding vulnerabilities, a function information acquisition step of acquiring function information regarding functions executable by the image forming apparatus, a determination step of determining the validity of the vulnerability information based on the function information, and causing the computer to execute it.

Brief Description of the Drawings

[0012]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Embodiments of the Invention

[0013] Hereinafter, embodiments of the present invention will be described with reference to the drawings. In the following description, the same parts are denoted by the same reference numerals. Their names and functions are also the same. Therefore, detailed descriptions thereof will not be repeated.

[0014] FIG. 1 is a diagram showing an example of the overall outline of an image forming system according to one embodiment of the present invention. Referring to FIG. 1, the image forming system 1 includes one or more MFPs (Multi Function Peripherals) 100 and a personal computer (hereinafter referred to as "PC") 200. Here, a case where the image forming system 1 includes five MFPs 100, 100A to 100D will be described as an example. The MFPs 100, 100A to 100D are common in that they have the same hardware configuration, but the installed programs may be the same or different. The programs installed in each of the MFPs 100, 100A to 100D include a program for controlling the hardware provided therein, a program for processing image data, and other application programs. Note that the hardware configurations of the MFPs 100, 100A to 100D may be different.

[0015] The PC 200 is an example of an information processing device and is a general computer. The MFPs 100, 100A to 100D are examples of image forming devices. Each of the MFPs 100, 100A to 100D and the PC 200 is connected to the network 3. Therefore, the MFPs 100, 100A and the PC 200 can communicate with each other.

[0016] The network 3 is a local area network (LAN). Note that the network 3 is not limited to a LAN and may be a WAN (Wide Area Network) or the Internet. The network 3 is connected to the Internet 5 via the G / W 7. A server 300 is connected to the Internet 5. Therefore, the MFPs 100, 100A and the PC 200 can communicate with the server 300 connected to the Internet 5 via the G / W 7.

[0017] Figure 2 is a block diagram showing an example of the outline of the hardware configuration of a PC in the present embodiment. Referring to FIG. 2, the PC 200 includes a CPU 201 for controlling the entire PC 200, a ROM 202, a RAM 203, a hard disk drive (HDD) 204, a communication unit 205, a display unit 206, an operation unit 207, and an external storage device 209.

[0018] The ROM 202 stores programs to be executed by the CPU 201. The RAM 203 is used as a working area for the CPU 201. The HDD 204 is a large-capacity storage device that stores data non-volatilely. A solid state drive (SSD) may be used instead of the HDD 204. The communication unit 205 connects the CPU 201 to the network 3. The operation unit 207 receives operations input by the user. The display unit 206 is, but not limited to, a liquid crystal display device. Note that an organic EL (electroluminescence) display may be used instead of the liquid crystal display device.

[0019] The external storage device 209 has a CD-ROM (Compact Disk Read Only Memory) 209A mounted thereon. In the present embodiment, an example in which the CPU 201 executes a program stored in the ROM 202 will be described. However, the CPU 201 may control the external storage device 209 to read out a program for the CPU 201 to execute from the CD-ROM 209A, store the read program in the RAM 203, and execute it.

[0020] Note that the recording medium for storing the program to be executed by the CPU 201 is not limited to the CD-ROM 209A, and media such as flexible disks, cassette tapes, optical disks (MO (Magnetic Optical Disc) / MD (Mini Disc) / DVD (Digital Versatile Disc)), IC cards, optical cards, mask ROMs, and semiconductor memories such as EPROM (Erasable Programmable ROM) may also be used. Further, the CPU 201 may load the program stored in the HDD 204 into the RAM 203 and execute it on the CPU 201. The program stored in the HDD 204 includes a program downloaded by the CPU 201 from a computer connected to the Internet, or a program written by a computer connected to the Internet to the HDD 204. The program referred to here includes not only a program directly executable by the CPU 201, but also a source program, a compressed program, an encrypted program, and the like.

[0021] In the present embodiment, the MFPs 100, 100A to 100D have the same hardware configuration. Here, the hardware configuration of the MFP 100 will be described as an example.

[0022] FIG. 3 is a block diagram showing an outline of the hardware configuration of the MFP in the present embodiment. Referring to FIG. 3, the MFP 100 includes a main circuit 110, a document reading unit 130, an automatic document feeder 120, an image forming unit 140, a paper feeding unit 150, and an operation panel 160. The document reading unit 130 reads a document. The automatic document feeder 120 conveys the document to the document reading unit 130. The image forming unit 140 forms an image on a sheet or the like based on the image data output by the document reading unit 130 reading the document. The paper feeding unit 150 supplies paper to the image forming unit 140. The operation panel 160 is a user interface.

[0023] The automatic document feeder 120 automatically conveys a plurality of documents set on the document tray one by one to a predetermined document reading position set on the platen glass of the document reading unit 130. The automatic document feeder 120 discharges the document on which the image formed on the document has been read by the document reading unit 130 to the document output tray. The document reading unit 130 includes a light source that irradiates light onto the document conveyed to the document reading position, and a photoelectric conversion element that receives the light reflected by the document, and scans a document image according to the size of the document. The photoelectric conversion element converts the received light into image data, which is an electrical signal, and outputs it to the image forming unit 140. The paper feeding unit 150 conveys the paper stored in the paper feed tray to the image forming unit 140.

[0024] The image forming unit 140 forms an image by a well-known electrophotographic method. The image forming unit 140 performs various data processes such as shading correction on the image data input from the document reading unit 130. The image forming unit 140 forms an image on the paper conveyed by the paper feeding unit 150 based on the image data after data processing or the image data received from the outside, and discharges the paper on which the image has been formed to the output tray. The image forming unit 140 is provided with a paper reversal path and can form images on both sides of the paper. The paper reversal path is a path that reverses the front and back of the paper on which an image has been formed on one side (front side) of the paper in the image forming unit 140 and guides it to the image forming unit 140. Thereby, the image forming unit 140 forms an image on the other side (back side) of the paper supplied from the paper reversal path.

[0025] The main circuit 110 includes a CPU 111, a communication interface (I / F) unit 112, a ROM 113, a RAM 114, an HDD 115, a facsimile unit 116, and an external storage device 117. The HDD 115 is a large-capacity storage device. A solid state drive (SSD) may be used instead of the HDD 115. The CPU 111 is connected to the automatic document feeder 120, the document reading unit 130, the image forming unit 140, the paper feeding unit 150, and the operation panel 160, and controls the entire MFP 100.

[0026] The facsimile unit 116 is connected to the public switched telephone network (PSTN) and transmits facsimile data to the PSTN. Also, the facsimile unit 116 receives facsimile data from the PSTN. The facsimile unit 116 stores the received facsimile data in the HDD 115 and converts it into printable print data by the image forming unit 140 and outputs it to the image forming unit 140. Thereby, the image forming unit 140 forms an image on paper using the facsimile data received by the facsimile unit 116. Also, the facsimile unit 116 converts the data stored in the HDD 115 into facsimile data and transmits it to a facsimile apparatus connected to the PSTN.

[0027] The communication I / F unit 112 is an interface for connecting the MFP 100 to the network 3. The communication I / F unit 112 communicates with the PC 200 connected to the network 3 using a communication protocol such as TCP (Transmission Control Protocol) or FTP (File Transfer Protocol).

[0028] The ROM 113 stores a program executed by the CPU 111 or data necessary for executing the program. The RAM 114 is used as a work area when the CPU 111 executes a program. Also, the RAM 114 temporarily stores the read images continuously sent from the document reading unit 130.

[0029] The operation panel 160 is provided on the upper surface of the MFP 100. The operation panel 160 includes a display unit 161 and an operation unit 163. The display unit 161 is, for example, a liquid crystal display device (LCD) and displays an instruction menu for the user, information on the acquired image data, etc. Note that instead of the LCD, an organic EL display or the like may be used as long as it is a device for displaying an image.

[0030] The operation unit 163 includes a touch panel 165 and a hard key unit 167. The touch panel 165 is a capacitance type. Note that the touch panel 165 is not limited to the capacitance type, and for example, other types such as a resistive film type, a surface acoustic wave type, an infrared type, and an electromagnetic induction type can be used. The hard key unit 167 includes a plurality of hard keys. The hard keys are, for example, contact switches.

[0031] The CPU 111 executes a printing job. When the CPU 111 executes a printing job, it generates image data. The CPU 111 executes image processing on the image data. The CPU 111 outputs the image data after the image processing to the image forming unit 140, and causes the image forming unit 140 to form the image of the image data on paper. The image data is, for example, raster data. The printing job includes data to be printed and printing conditions. The data to be printed may be data in bitmap format or application data. The data to be printed includes data for each of one or more pages. The printing conditions include an accumulation condition, an aggregation condition, and a forming surface condition. The accumulation condition is a condition for determining whether to accumulate the printing job without executing it or to execute the printing job without accumulating it. The aggregation condition is a condition for determining the number of pages to form an image on one sheet of paper. The forming surface condition is a condition for determining whether to use both the front and back sides or only the front side as the surface on which to form an image on the paper. The CPU 111 generates image data from the data to be printed included in the printing job according to the printing conditions included in the printing job, and outputs the image data to the image forming unit 140.

[0032] The external storage device 117 is controlled by the CPU 111, and a CD-ROM 118 is mounted thereon. In the present embodiment, an example in which the CPU 111 executes a program stored in the ROM 113 will be described. Note that the CPU 111 may control the external storage device 117 to read out a program for the CPU 111 to execute from the CD-ROM 118, store the read program in the RAM 102, and execute it.

[0033] FIG. 4 is a block diagram showing an example of functions of the CPU included in the PC according to the present embodiment. The functions shown in FIG. 4 may be realized by hardware. Further, the CPU 201 included in the PC 200 may execute a vulnerability information utilization program stored in the ROM 202, the HDD 204, or the CD-ROM 209A, and the functions may be realized by the CPU 201.

[0034] Referring to FIG. 4, the CPU 201 included in the PC 200 includes a vulnerability information acquisition unit 51, a function information acquisition unit 53, a keyword registration unit 54, an extraction unit 55, a determination unit 57, a notification unit 59, and a prohibition unit 61. The vulnerability information acquisition unit 51 acquires vulnerability information from the outside and outputs the acquired vulnerability information to the extraction unit 55. The vulnerability information is information including information security defects caused by defects or design mistakes in the programs installed in each of the MFPs 100, 100A to 100D. The programs installed in each of the MFPs 100, 100A to 100D include application programs such as an operating system, a control program, and an image processing program. When a program pointed out as vulnerable is executed on the MFP 100 due to the vulnerability information, there is a risk that the program may be used for unauthorized access or infected with a computer virus. The vulnerability information is information for notifying the risk, and is provided from a vendor who created the program, a vendor of antivirus software, etc. Generally, the vulnerability information is often publicly available on the Internet 5 by the vendor. Also, it may be transmitted from the vendor by e-mail or the like.

[0035] The vulnerability information acquisition unit 51 includes an information reception unit 71 and an information receiving unit 73. The information reception unit 71 controls the operation unit 207 and receives the operations input by the user to the operation unit 207. Based on the operations received by the operation unit 207, the information reception unit 71 acquires vulnerability information. The user's operation may indicate the location where the vulnerability information is stored. The information reception unit 71 acquires the vulnerability information based on the location. The location where the vulnerability information is stored includes a URL which is a network address and a file name indicating a location in the HDD 204. The vulnerability information stored in the HDD 204 includes information directly input by the user from the operation unit 207 and information downloaded from a server 300 connected to the Internet 5. The data format of the vulnerability information is not limited, and it may be a web page such as HTML, text data, or PDF (Portable Document Format) data.

[0036] When the information reception unit 71 receives a URL, it controls the communication unit 205 to download the vulnerability information specified by the URL. The downloaded vulnerability information is stored in the HDD 204. When the information reception unit 71 receives a file name, it reads out the vulnerability information stored in the HDD 204.

[0037] The information receiving unit 73 receives vulnerability information from the outside. For example, when vulnerability information is transferred as a file from the outside, the information receiving unit 73 controls the communication unit 205 to receive the vulnerability information transmitted from the outside and stores the received vulnerability information in the HDD 204. Also, when the vulnerability information is transmitted by email, the information receiving unit 73 controls the communication unit 205 to receive the email and stores the vulnerability information included in the received email in the HDD 204.

[0038] The function information acquisition unit 53 acquires function information from each of the MFPs 100, 100A to 100D. The function information acquisition unit 53 outputs the function information of each of the MFPs 100, 100A to 100D to the determination unit 57. The function information acquisition unit 53 includes a set function acquisition unit 81 and a program information acquisition unit 83. The set function acquisition unit 81 acquires function information from each of the MFPs 100, 100A to 100D.

[0039] Function information is information indicating the functions that the device has and that those functions can be executed. Here, the function information includes function identification information for identifying the functions that each of the MFPs 100, 100A to 100D has, and setting information indicating that those functions can be executed. The functions are determined by the programs installed in each of the MFPs 100, 100A to 100D. For example, there is a program for sending and receiving emails, and by executing that program, there are functions for receiving emails, encrypting the received data, sending emails, and encrypting the sent emails. Also, there is a program for sending and receiving data according to the S / MIME (Secure / Multipurpose Internet Mail Extensions) standard, and by executing that program, there are functions for sending and receiving data, digitally signing, specifying the digital signature format, and encrypting the data.

[0040] The setting information includes setting values indicating that the function is to be executed and setting values set for executing the function for the function.

[0041] The program information acquisition unit 83 acquires program information regarding the programs installed in each of the MFPs 100, 100A to 100D. The program information is part of the function information. The program information includes program identification information for identifying the program and function information regarding the functions realized by executing that program.

[0042] FIG. 5 is a diagram showing an example of function information. The function information shown in FIG. 5 shows an example of function information acquired from the MFP 100. Referring to FIG. 5, for each function name, function identification information and setting values are shown in association with each other.

[0043] For the function name "E-mail reception (POP)", the function identification information "E-mail reception settings (POP)" and "SSL usage settings" are associated. The setting value "enabled" is associated with the function identification information "E-mail reception settings (POP)". This association indicates that the function of receiving e-mails according to the standards defined by POP is enabled. The setting value "enabled" is associated with the function identification information "SSL usage settings". This association indicates that it corresponds to data encrypted by the SSL protocol when receiving e-mails according to the protocol defined by POP (Post Office Protocol).

[0044] For the function name "E-mail transmission (SMTP)", the function identification information "E-mail transmission settings (SMTP)" and "SSL usage settings" are associated. The setting value "enabled" is associated with the function identification information "E-mail transmission settings (SMTP)". This association indicates that the function of transmitting e-mails according to the protocol defined by SMTP is enabled. The setting value "enabled" is associated with the function identification information "SSL usage settings". This association indicates that it corresponds to encryption by SSL when transmitting e-mails according to the protocol defined by SMTP.

[0045] For the function name "S / MIME", the function identification information "S / MIME communication settings", "Digital signature", "Digital signature format", and "Encryption type of email body" are associated. The setting value "Enabled" is associated with the function identification information "S / MIME communication settings". This association indicates that the function of sending and receiving emails using the protocol defined in S / MIME (Secure / Multipurpose Internet Mail Extensions) is enabled. The setting value "Enabled" is associated with the function identification information "Digital signature". This association indicates that it conforms to the standard for attaching digital signatures to emails. The setting value "SH-1" is associated with the function identification information "Digital signature format". This association indicates that the digital signature on the email is attached in the "SH-1" format. The setting value "3DES" is associated with the function identification information "Encryption type of email body". This association indicates that the body of the email is encrypted according to the 3DES (Data Encryption Standard) standard.

[0046] For the function name "LDAP", the function identification information "LDAP usage settings" and "SSL usage" are associated. The setting value "Disabled" is associated with the function identification information "LDAP usage settings". This association indicates that the function of accessing the directory service using LDAP (Lightweight Directory Access Protocol) is disabled. The setting value "Disabled" is associated with the function identification information "SSL usage settings". This association indicates that the data is not encrypted when accessing the directory service using LDAP.

[0047] For the function name "WebDAV Client", the function identification information "WebDAV Client Settings" and "SSL / TLS Settings" are associated. The setting value "Enabled" is associated with the function identification information "WebDAV Client Settings". This association indicates that it functions as a client for the Web server with respect to the WebDAV (Web-based Distributed Authoring and Versioning) function. The setting value "Enabled" is associated with the function identification information "SSL / TLS Settings". This association indicates that data is encrypted in accordance with the SSL / TSL (Secure Sockets Layer / Transport Layer Security) standard when sending and receiving data as a client in WebDAV.

[0048] For the function name "WebDAV Server", the function identification information "WebDAV Server Settings" and "SSL / TLS Settings" are associated. The setting value "Enabled" is associated with the function identification information "WebDAV Server Settings". This association indicates that it functions as a Web server with respect to the WebDAV function. The setting value "Enabled" is associated with the function identification information "SSL / TLS Settings". This association indicates that data is encrypted in accordance with the SSL / TSL standard when sending and receiving data as a server in WebDAV.

[0049] FIG. 6 is a diagram showing an example of program information. The program information shown in FIG. 6 shows an example of program information acquired from the MFP 100. Referring to FIG. 6, for each program identification information, function identification information and setting values are shown in association. The program identification information includes a program name and a version. For the program identification information with the program name "Program 1" and the version "1.1.1", the function identification information "WebDAV client", "WebDAV server", and "S / MIME" are associated. The setting value "enabled" is associated with the function identification information "WebDAV client". This association indicates that the WebDAV function functions as a client for the Web server. The setting value "enabled" is associated with the function identification information "WebDAV server". This association indicates that the WebDAV function functions as a Web server. The setting value "enabled" is associated with the function identification information "S / MIME". This association indicates that the function of sending and receiving data according to the protocol defined by S / MIME is enabled.

[0050] For the program identification information with the program name "Program 2" and the version "2.2.2", the function identification information "LDAP" is associated. The setting value "disabled" is associated with the function identification information "LDAP". This association indicates that the function of accessing the directory service with LDAP is disabled.

[0051] For the program identification information with the program name "Program 3" and the version "3.3.3", the setting value "disabled" is associated with the function identification information "SSL / TLS". This association indicates that data is not encrypted according to the SSL / TLS standard when sending and receiving data.

[0052] Returning to Fig. 4, the keyword registration unit 54 registers common keywords. The common keywords are keywords common to MFPs 100, 100A to 100D. The keyword registration unit 54 accepts common keywords registered by the user and registers the accepted common keywords. The keyword registration unit 54 stores the accepted common keywords in the HDD 204. The keyword registration unit 54 accepts common keywords input by the user to the operation unit 207. Also, when the user designates data in which common keywords are stored, the keyword registration unit 54 accepts the common keywords stored in the designated data. For example, the data in which common keywords are stored is stored in, for example, the CD-ROM 209A, and the keyword registration unit 54 controls the external storage device 209 to read the data stored in the CD-ROM 209A.

[0053] Fig. 7 is a diagram showing an example of common keywords. Referring to Fig. 7, the common keywords include names of attacks such as hacking, malware, or unauthorized access, and names of those attack methods. Also, the keywords are terms related to functions possessed by any of MFPs 100, 100A to 100D. Among attacks such as hacking, malware, or unauthorized access, they are names of attacks and attack methods that may be subject to attacks on functions possessed by any of MFPs 100, 100A to 100D. Note that the common keywords do not have to be common to MFPs 100, 100A to 100D, and there may be a plurality corresponding to each of MFPs 100, 100A to 100D.

[0054] Returning to FIG. 4, a plurality of vulnerability information is input to the extraction unit 55 from the vulnerability information acquisition unit 51. The extraction unit 55 extracts one or more pieces of vulnerability information that are common and related to the MFPs 100, 100A to 100D from among the plurality of pieces of vulnerability information input from the vulnerability information acquisition unit 51 as the processing target. The extraction unit 55 receives a common keyword input from the keyword registration unit 54. The extraction unit 55 extracts, as the processing target, the vulnerability information including the common keyword from among the plurality of pieces of vulnerability information. The common keyword may be a character string formed by combining a plurality of words. When the common keyword stored in the HDD 204 consists of a plurality of words, the extraction unit 55 generates each of the plurality of words as a new common keyword. Then, the extraction unit 55 extracts the vulnerability information to be processed from among the plurality of pieces of vulnerability information using the plurality of new common keywords. Thereby, the number of common keywords registered in the HDD 204 can be reduced, and appropriate vulnerability information can be extracted as the processing target from among the plurality of pieces of vulnerability information.

[0055] The determination unit 57 receives the vulnerability information selected as the processing target from the extraction unit 55 and the function information from the function information acquisition unit 53. The determination unit 57 determines whether the vulnerability information is related to the function information.

[0056] The determination unit 57 receives the function information corresponding to each of the MFPs 100, 100A to 100D from the function information acquisition unit 53. The determination unit 57 determines whether the vulnerability information is related for each of the MFPs 100, 100A to 100D. Since the determination by the determination unit 57 is the same for each of the MFPs 100, 100A to 100D, here, taking the MFP 100 as an example, the determination as to whether the vulnerability information is related to the MFP 100 will be described.

[0057] The determination unit 57 determines that the vulnerability information includes the function information of the MFP 100. The determination unit 57 identifies, from the setting information among the function information of the MFP 100, the function information for which a setting value indicating that the corresponding function is executed is set. The determination unit 57 determines the function identification information of the identified function information as a function keyword. Further, the determination unit 57 determines the setting value set in the setting information of the identified function information as a function keyword. Furthermore, when the function keyword is composed of a plurality of words, the determination unit 57 determines each of the plurality of words as a new function keyword. The determination unit 57 determines that the vulnerability information is related to the MFP 100 when the determined function keyword is included in the vulnerability information at least once.

[0058] When a plurality of function information is input from the MFP 100, the determination unit 57 determines whether the vulnerability information is related to each of the plurality of function information. Therefore, the determination unit 57 determines whether the vulnerability information is related to each device and each one or more functions.

[0059] When the determination unit 57 determines that the vulnerability information is related to the MFP 100, it determines warning information including the device identification information, function identification information, and vulnerability information of the MFP 100. The determination unit 57 outputs the warning information to the notification unit 59 and the prohibition unit 61.

[0060] In response to the input of the warning information, the notification unit 59 notifies the user. The notification unit 59 causes a warning message to be displayed on the device specified by the device identification information included in the warning information. Specifically, the notification unit 59 transmits the function identification information and the vulnerability information included in the warning information to the MFP 100 specified by the device identification information included in the warning information, and causes the MFP 100 to display the function identification information and the vulnerability information on the display unit 206. Further, the notification unit 59 transmits an e-mail describing a warning message including the function identification information and the vulnerability information to the administrator who manages the MFP 100.

[0061] The prohibition unit 61 stops the functions of the apparatus in response to the input of warning information. The prohibition unit 61 causes the apparatus specified by the apparatus identification information included in the warning information to be set so that the function specified by the function identification information included in the warning information is not executed. Specifically, the prohibition unit 61 transmits a stop command including the function identification information to the MFP 100 specified by the apparatus identification information included in the warning information, and causes the MFP 100 to be set so as not to execute the function specified by the function identification information.

[0062] FIG. 8 is a flowchart showing an example of the flow of the vulnerability information utilization process. The vulnerability information utilization process is a process executed by the CPU 201 provided in the PC 200 by executing a vulnerability information utilization program stored in the ROM 202, the HDD 204, or the CD-ROM 209A. Referring to FIG. 8, the CPU 201 provided in the PC 200 determines whether or not vulnerability information has been received (step S01). Based on an operation input to the operation unit 207 by the user, the vulnerability information is received. The vulnerability information itself may be input, or a URL that is the location information of the vulnerability information on the network may be received. The CPU 201 downloads the vulnerability information using the URL and acquires the vulnerability information. If the vulnerability information has been received, the process proceeds to step S03, otherwise the process proceeds to step S02.

[0063] In step S02, it is determined whether or not vulnerability information has been received. When the vulnerability information is transmitted by e-mail from the outside, the vulnerability information attached to the e-mail is received. When an external computer stores the vulnerability information in the HDD 204, the vulnerability information is received from the external computer. If the vulnerability information has been received, the process proceeds to step S03, otherwise the process returns to step S01.

[0064] In step S03, a common keyword is acquired, and the process proceeds to step S04. The CPU 201 reads out the common keyword stored in the HDD 204. In step S04, a processing target is extracted from the vulnerability information received in step S01 or the vulnerability information received in step S02, and the process proceeds to step S05. When the vulnerability information contains the common keyword, that vulnerability information is extracted. When there are multiple common keywords, if the vulnerability information contains at least one of the multiple common keywords, that vulnerability information is selected as the processing target. Note that there may be cases where the vulnerability information is not extracted as the processing target. In that case, the process returns to step S01.

[0065] In step S05, a device to be processed is selected, and the process proceeds to step S06. In the present embodiment, the PC 200 manages the MFPs 100, 100A to 100D. The CPU 201 selects one of the MFPs 100, 100A to 100D as the processing target. Hereinafter, the case where the MFP 100 is selected as the processing target will be described as an example.

[0066] In step S06, a function keyword generation process is executed, and the process proceeds to step S07. Although the details of the function keyword generation process will be described later, it is a process of generating one or more function keywords corresponding to the MFP 100 selected as the processing target. The function keywords correspond to the functions that the MFP 100 has.

[0067] In step S07, a function keyword to be processed is selected, and the process proceeds to step S08. One of the one or more function keywords generated in step S06 is selected as the processing target. In step S08, it is determined whether the vulnerability information contains the function keyword. It is determined whether the vulnerability information extracted as the processing target in step S04 contains the function keyword selected as the processing target in step S07. If the vulnerability information contains the function keyword, the process proceeds to step S09; otherwise, the process proceeds to step S11.

[0068] In step S09, the administrator of the device selected as the processing target is notified, and the process proceeds to step S10. To the administrator who manages the MFP100 selected as the processing target in step S05, function identification information for identifying the function corresponding to the function keyword selected as the processing target and vulnerability information are notified. For example, the CPU 201 causes the MFP 100 to display the function identification information and the vulnerability information on the display unit 161. Further, the CPU 201 transmits a warning message including the function identification information and the vulnerability information to the administrator of the MFP 100.

[0069] In step S10, it is set to prohibit the execution of the corresponding function, and the process proceeds to step S11. The function corresponding to the function keyword selected in step S07 is specified, and it is set so that the function is not executed on the MFP 100 selected as the processing target. The CPU 201 transmits a command including the function identification information for identifying the function to the MFP 100 and prohibiting the execution. Thereby, in the MFP 100, it is possible to prevent the function vulnerable due to the vulnerability information from being executed.

[0070] In step S11, it is determined whether there is a function keyword that was not selected as the processing target in step S07. If there is an unselected function keyword, the process returns to step S07, otherwise the process proceeds to step S12. In step S12, it is determined whether there is an unselected device. If there is a device that was not selected as the processing target in step S05 among the MFP 100, 100A to 100D, the process returns to step S05, otherwise the process ends.

[0071] FIG. 9 is a flowchart showing an example of the flow of the function keyword generation process. The function keyword generation process is a process executed in step S06 of the vulnerability information utilization process. Before the function keyword generation process is executed, the MFP 100 is selected as the device to be processed.

[0072] Referring to FIG. 9, the CPU 201 provided in the PC 200 acquires function information from the MFP 100 and proceeds with the process to step S22. The function information acquired here includes program information. In step S22, the function information to be processed is selected, and the process proceeds to step S23.

[0073] In step S23, it is determined whether the selected function is set to be executable. If the function is set to be executable, the process proceeds to step S24; otherwise, the process proceeds to step S25. The CPU 201 determines, based on the setting information of the function information, whether the function specified by the function identification information of the function information is set to an executable state in the MFP 100.

[0074] In step S24, a function keyword is generated, and the process proceeds to step S25. The function identification information of the function information is determined as the function keyword. Also, the set value set in the setting information of the function information is determined as the function keyword. When the function keyword is composed of a plurality of words, each of the plurality of words is determined as the function keyword. The function keyword is associated with the function information selected in step S22.

[0075] In step S25, it is determined whether there is unselected function information. It is determined whether there is function information that has not been selected as the processing target in step S22 among the function information acquired from the MFP 100 in step S21. If there is unselected function information, the process returns to step S22; otherwise, the process returns to the vulnerable information utilization process.

[0076] As described above, the PC200 in the present embodiment functions as an information processing device that manages the MFPs 100, 100A to 100D. The CPU 111 included in the PC200 acquires vulnerability information regarding vulnerabilities, acquires function information regarding functions executable by each of the MFPs 100, 100A to 100D, and determines the validity of the vulnerability information based on the function information. For this reason, it is possible to eliminate vulnerability information related to functions that any of the MFPs 100, 100A to 100D cannot execute, and for each of the MFPs 100, 100A to 100D, the validity of the vulnerability information related to the functions that it can execute is determined. For this reason, it is possible to extract vulnerability information suitable for each of the MFPs 100, 100A to 100D.

[0077] Since the PC200 notifies the determination result, it is possible to notify valid vulnerability information suitable for each of the MFPs 100, 100A to 100D.

[0078] When the determination result for the device is valid in each of the MFPs 100, 100A to 100D, the PC200 causes the device to set a set value at which the function specified by the function information corresponding to the device becomes inexecutable. For this reason, the security of each of the MFPs 100, 100A to 100D can be enhanced.

[0079] The PC200 acquires vulnerability information input by the user or identification information for specifying the vulnerability information. For this reason, it becomes easy to acquire vulnerability information.

[0080] Further, the function information includes function identification information for identifying the functions possessed by each of the MFPs 100, 100A to 100D, and the PC200 determines whether at least a part of the keywords of the function identification information included in the function information is included in the vulnerability information. For this reason, for each of the MFPs 100, 100A to 100D, it is possible to extract vulnerability information related to the functions that it has.

[0081] In addition, the function information includes a setting value indicating whether the function specified by the function identification information is executable, and the PC 200 determines whether the setting value corresponding to the function identification information included in the vulnerability information indicates executability. Therefore, it is possible to extract vulnerability information related to the functions of each of the MFPs 100, 100A to 100D that are set to be executable.

[0082] In addition, the function information includes program identification information for identifying a program that executes the function, and the PC 200 determines whether at least a part of the keywords of the function identification information for identifying the function realized by the program is included in the vulnerability information. Therefore, it is possible to extract vulnerability information related to the programs installed in each of the MFPs 100, 100A to 100D.

[0083] In addition, the function information includes a setting value indicating whether the function realized by the program is executable, and the PC 200 determines whether the setting value corresponding to the function realized by the program indicates executability. Therefore, it is possible to extract vulnerability information related to the functions realized by the programs installed in each of the MFPs 100, 100A to 100D that are set to be executable.

[0084] The PC 200 extracts a determination target including a predetermined keyword among the acquired vulnerability information, and determines the validity of the vulnerability information extracted for the determination target. Therefore, since the vulnerability information to be the determination target is extracted from among a plurality of pieces of vulnerability information, it is possible to exclude unnecessary vulnerability information that is not related to the MFPs 100, 100A to 100D to be managed. Therefore, the load on the PC 200 can be reduced.

[0085] <Summary of the Embodiment> (Item 1) An information processing apparatus for managing an image forming apparatus, a vulnerability information acquisition means for acquiring vulnerability information regarding vulnerabilities, a function information acquisition means for acquiring function information regarding functions executable by the image forming apparatus, An information processing apparatus comprising: determination means for determining the validity of the vulnerability information based on the function information.

[0086] According to this aspect, function information regarding functions executable by the image forming apparatus is acquired, and based on the function information, the validity of the vulnerability information is determined. Therefore, vulnerability information related to functions that the image forming apparatus cannot execute can be excluded, and the validity of the vulnerability information related to functions that the image forming apparatus can execute is determined. As a result, an information processing apparatus capable of extracting vulnerability information suitable for the image forming apparatus can be provided.

[0087] (Item 2) The information processing apparatus according to Item 1, further comprising notification means for notifying the determination result by the determination means.

[0088] According to this aspect, valid vulnerability information suitable for the image forming apparatus can be notified.

[0089] (Item 3) The information processing apparatus according to Item 1, further comprising prohibition means for causing the image forming apparatus to set a set value that makes the function specified by the function information inexecutable when the determination result by the determination means indicates that it is valid.

[0090] According to this aspect, the security of the image forming apparatus can be enhanced.

[0091] (Item 4) The information processing apparatus according to Item 1, wherein the vulnerability information acquisition means acquires the vulnerability information input by the user or identification information for specifying the vulnerability information.

[0092] According to this aspect, acquisition of vulnerability information becomes easy.

[0093] (Item 5) The function information includes function identification information for identifying functions of the image forming apparatus. The information processing apparatus according to item 1, wherein the determination means determines whether or not at least a part of keyword of the function identification information included in the function information is included in the vulnerability information.

[0094] According to this aspect, vulnerability information related to functions of the image forming apparatus can be extracted.

[0095] (Item 6) The function information further includes a setting value indicating whether or not the function specified by the function identification information is executable. The information processing apparatus according to item 5, wherein the determination means determines whether or not the setting value corresponding to the function identification information included in the vulnerability information indicates executable.

[0096] According to this aspect, vulnerability information related to functions of the image forming apparatus that are set to be executable can be extracted.

[0097] (Item 7) The function information includes program identification information for identifying a program that executes the function. The information processing apparatus according to item 1, wherein the determination means determines whether or not at least a part of keyword of the function identification information for identifying the function realized by the program is included in the vulnerability information.

[0098] According to this aspect, vulnerability information related to programs installed in the image forming apparatus can be extracted.

[0099] (Item 8) The function information further includes a setting value indicating whether or not the function realized by the program specified by the program identification information is executable. The information processing apparatus according to item 7, wherein the determination means determines whether or not the setting value corresponding to the function realized by the program specified by the program identification information indicates executable.

[0100] According to this aspect, it is possible to extract vulnerability information related to functions that are executable and realized by a program installed in an image forming apparatus.

[0101] (Item 9) The information processing apparatus further includes extraction means for extracting a determination target including a predetermined keyword among the vulnerability information acquired by the vulnerability information acquisition means. The determination means determines the validity of the vulnerability information extracted as a determination target by the extraction means. The information processing apparatus according to Item 1.

[0102] According to this aspect, a determination target including a predetermined keyword among the vulnerability information is extracted, and the validity of the vulnerability information extracted as the determination target is determined. For this reason, since the vulnerability information to be a determination target is extracted from among a plurality of pieces of vulnerability information, unnecessary vulnerability information can be excluded. For this reason, the load of determination can be reduced.

[0103] (Item 10) The information processing apparatus according to any one of Items 1 to 9, An image forming apparatus including image forming means for forming an image on a recording medium.

[0104] According to this aspect, it is possible to provide an image forming apparatus capable of extracting valid vulnerability information.

[0105] (Item 11) A method for using vulnerability information executed by an information processing apparatus for managing an image forming apparatus, A vulnerability information acquisition step of acquiring vulnerability information regarding a vulnerability, A function information acquisition step of acquiring function information regarding functions executable by the image forming apparatus, A determination step of determining the validity of the vulnerability information based on the function information, and a method for using vulnerability information to be executed by the information processing apparatus.

[0106] According to this aspect, it is possible to provide a method for using vulnerability information capable of extracting vulnerability information suitable for an image forming apparatus.

[0107] (Item 12) A vulnerability information utilization program executed by a computer that manages an image forming apparatus, a vulnerability information acquisition step of acquiring vulnerability information regarding vulnerabilities, a function information acquisition step of acquiring function information regarding functions executable by the image forming apparatus, a determination step of determining the validity of the vulnerability information based on the function information, and a vulnerability information utilization program to be executed by the computer.

[0108] According to this aspect, it is possible to provide a vulnerability information utilization program capable of extracting vulnerability information suitable for an image forming apparatus.

[0109] (13) The information processing apparatus according to item 1, wherein the identification information accepts a network address indicating a position where the vulnerability information is stored.

[0110] (14) The vulnerability information is in PDF (Portable Document Format) or text data format.

[0111] The embodiments disclosed this time should be considered to be illustrative in all respects and not restrictive. The scope of the present invention is shown not by the above description but by the scope of the claims, and it is intended that all modifications within the meaning and scope equivalent to the scope of the claims be included.

Explanation of Reference Numerals

[0112] 1 Image forming system, 100, 100A, 100B, 100C, 100D MFP, 200 PC 200, 300 Server, 3 Network, 5 Internet, 51 Vulnerable information acquisition unit, 53 Function information acquisition unit, 54 Keyword registration unit, 55 Extraction unit, 57 Judgment unit, 59 Notification unit, 61 Prohibition unit, 71 Information reception unit, 73 Information receiving unit, 81 Setting function acquisition unit, 83 Program information acquisition unit, 102 RAM, 111 CPU, 112 Communication I / F unit, 113 ROM, 114 RAM, 115 HDD, 116 Facsimile unit, 117 External storage device, 118 CD-ROM, 120 Automatic document feeder, 130 Document reading unit, 140 Image forming unit, 150 Paper feeding unit, 160 Operation panel, 161 Display unit, 163 Operation unit, 165 Touch panel, 167 Hard key unit, 201 CPU, 202 ROM, 203 RAM, 204 HDD, 205 Communication unit, 206 Display unit, 207 Operation unit, 209 External storage device, 209A CD-ROM.

Claims

1. An information processing apparatus for managing an image forming apparatus, comprising: a vulnerability information acquisition means for acquiring vulnerability information regarding vulnerabilities; a function information acquisition means for acquiring function information regarding functions executable by the image forming apparatus; a determination means for determining the validity of the vulnerability information based on the function information.

2. The information processing apparatus according to claim 1, further comprising a notification means for notifying a determination result by the determination means.

3. The information processing apparatus according to claim 1, further comprising a prohibition means for causing the image forming apparatus to set a set value at which a function specified by the function information becomes non-executable when a determination result by the determination means indicates that it is valid.

4. The information processing apparatus according to claim 1, wherein the vulnerability information acquisition means acquires the vulnerability information input by a user or identification information for specifying the vulnerability information.

5. The function information includes function identification information for identifying functions of the image forming apparatus, and the determination means determines whether at least a part of keyword of the function identification information included in the function information is included in the vulnerability information.

6. The function information further includes a set value indicating whether the function specified by the function identification information is executable, and the determination means determines whether the set value corresponding to the function identification information included in the vulnerability information indicates executable.

7. The function information includes program identification information for identifying a program for executing the function, and the determination means determines whether at least a part of keyword of the function identification information for identifying the function realized by the program is included in the vulnerability information.

8. The function information further includes a set value indicating whether the function realized by the program specified by the program identification information is executable, and the determination means determines whether the set value corresponding to the function realized by the program specified by the program identification information indicates executable.

9. further comprising an extraction means for extracting a determination target including a predetermined keyword among the vulnerability information acquired by the vulnerability information acquisition means The information processing apparatus according to claim 1, wherein the determination means determines the validity of the vulnerability information extracted for the determination target by the extraction means.

10. An image forming apparatus comprising: the information processing apparatus according to any one of claims 1 to 9; and image forming means for forming an image on a recording medium.

11. A method for using vulnerability information executed by an information processing apparatus that manages an image forming apparatus, the method comprising: a vulnerability information acquisition step of acquiring vulnerability information regarding a vulnerability; a function information acquisition step of acquiring function information regarding functions executable by the image forming apparatus; a determination step of determining the validity of the vulnerability information based on the function information; and a method for using vulnerability information to be executed by the information processing apparatus.

12. A vulnerability information utilization program executed by a computer that manages an image forming apparatus, the program comprising: a vulnerability information acquisition step of acquiring vulnerability information regarding a vulnerability; a function information acquisition step of acquiring function information regarding functions executable by the image forming apparatus; a determination step of determining the validity of the vulnerability information based on the function information; and a vulnerability information utilization program to be executed by the computer.

Citation Information

Patent Citations

  • Security information distribution method and security information distribution server

    JP2003256370A