Information processing system, information processing device, management server, method, and program
The information processing system intercepts and modifies DNS query messages to include user or group identification, allowing for policy-based access control within the system, addressing the challenge of detailed control in existing technologies.
Patent Information
- Application Number
- JP2023207613
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-12-08
- Publication Date
- 2025-06-19
AI Technical Summary
Existing access control technologies struggle to perform detailed control, such as applying different security policies for each user or group, especially in office and remote environments, requiring the introduction of security devices or VPNs.
An information processing system that intercepts DNS query messages before they reach the destination server, modifies them to include user or group identification information, and routes them through a management server for policy-based processing.
Enables easy introduction of access control by allowing security policies to be applied based on user or group identification, enhancing security without the need for extensive network modifications or device installations.
Smart Images

Figure 2025092000000001_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to communication control in an IP network.
Background Art
[0002] Conventionally, for a WWW site accessed by a PC, it is confirmed whether a combination of a domain name and an IP address is registered in an access permission DB or an access prohibition DB, and for a WWW site accessed by a PC, it is confirmed whether a combination of a domain name and an IP address is registered in a secure DNS server registered in a secure DNS·DB. A security server has been proposed that controls access to a WWW site by a PC using these confirmation results (see, for example, Patent Document 1).
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] Conventionally, various security technologies have been proposed that determine whether a site is a site where access is permitted by referring to a domain name or an IP address shown in a DNS (Domain Name System) query message and control access to the site. However, access control starting from a DNS query message is difficult to perform detailed control such as applying different security policies for each user or group, and when attempting to perform detailed control such as applying different security policies for each user or group, in an office environment, work involving the introduction of a security device into the network and in a remote environment, work involving the introduction of a VPN, etc. is required.
[0005] In view of the above problems, an object of the present disclosure is to provide access control that can be introduced relatively easily.
Means for Solving the Problems
[0006] An example of the present disclosure is an information processing system for managing user terminals, including a management server for managing the user terminals, a message acquisition means for acquiring a first DNS query message created by the user terminal before the first DNS query message reaches a destination DNS server set in the first DNS query message, a message creation means for creating a second DNS query message by adding identification information capable of identifying an account related to the user terminal to the acquired first DNS query message, and a message transmission means for transmitting the DNS query message to the management server, the message transmission means transmitting the second DNS query message to the management server instead of the first DNS query message when the second DNS query message is created. The management server includes an information management means for managing a correspondence relationship between the identification information and a security policy applied to the account related to the identification information, a message reception means for receiving the second DNS query message transmitted from any of the user terminals, an identification information extraction means for extracting the identification information from the received second DNS query message, and a security policy application means for specifying a security policy corresponding to the extracted identification information by referring to the information management means and processing the second DNS query message according to the specification result.
[0007] The present disclosure can be understood as an information processing apparatus, a system, a method executed by a computer, or a program to be executed by a computer. Further, the present disclosure can also be understood as a recording medium in which such a program is recorded and can be read by a computer or other devices, machines, etc. Here, the recording medium readable by a computer or the like refers to a recording medium that accumulates information such as data and programs by an electrical, magnetic, optical, mechanical, or chemical action and can be read by a computer or the like.
Advantages of the Invention
[0008] According to the present disclosure, it becomes possible to provide access control that can be introduced relatively easily.
Brief Description of the Drawings
[0009]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Modes for Carrying Out the Invention
[0010] Hereinafter, embodiments of an information processing apparatus, method, and program according to the present disclosure will be described with reference to the drawings. However, the embodiments described below are merely illustrative of the embodiments, and do not limit the information processing apparatus, method, and program according to the present disclosure to the specific configurations described below. In practice, specific configurations according to the implementation mode may be appropriately adopted, and various improvements and modifications may be made.
[0011] In this embodiment, embodiments of an information processing apparatus, method, and program according to the present disclosure when implemented in an information processing system that provides connection to a server on the Internet in an office environment or a remote environment will be described. However, the information processing apparatus, method, and program according to the present disclosure can be widely used for technologies for access control, and the application target of the present disclosure is not limited to the examples shown in this embodiment.
[0012] <Configuration of the system> FIG. 1 is a schematic diagram showing the configuration of a system 1 according to this embodiment. The system 1 according to this embodiment includes one or a plurality of information processing terminals 80 (hereinafter referred to as "user terminals 80") connected to each other via a network, and a management server 10 having a security function for managing these user terminals 80.
[0013] The management server 10 is a computer including a CPU (Central Processing Unit) 11, a ROM (Read Only Memory) 12, a RAM (Random Access Memory) 13, a storage device 14 such as an EEPROM (Electrically Erasable and Programmable Read Only Memory) or an HDD (Hard Disk Drive), a communication unit 15 such as a NIC (Network Interface Card), etc. However, regarding the specific hardware configuration of the management server 10, appropriate omissions, replacements, or additions can be made according to the implementation mode. Also, the management server 10 is not limited to a single device. The management server 10 may be realized by a plurality of devices using so-called cloud or distributed computing technologies, etc.
[0014] The user terminal 80 is a computer including a CPU 81, a ROM 82, a RAM 83, a storage device 84, a communication unit 85, etc. However, regarding the specific hardware configuration of the user terminal 80, appropriate omissions, replacements, or additions can be made according to the implementation mode. Also, the user terminal 80 is not limited to a single device. The user terminal 80 may be realized by a plurality of devices using so-called cloud or distributed computing technologies, etc. Further, an agent program for setting the management server 10 as a specified DNS server and capturing a packet before it is sent from the user terminal 80 is installed in the user terminal 80, and the functions described later provided by the user terminal 80 are mainly realized by the agent program being executed by the user terminal 80.
[0015] FIG. 2 is a diagram showing an outline of the functional configuration of the user terminal 80 and the management server 10 according to the present embodiment. The user terminal 80 functions as an information processing apparatus including a message acquisition unit 91, a message creation unit 92, a message transmission unit 93, and a message reception unit 94 when a program recorded in the storage device 84 is read into the RAM 83 and executed by the CPU 81. In the present embodiment, each function provided in the user terminal 80 is executed by the CPU 81 which is a general-purpose processor, but a part or all of these functions may be executed by one or a plurality of dedicated processors. Further, a part or all of these functions may be executed by a device installed remotely or a plurality of devices installed dispersedly using cloud technology or the like.
[0016] The message acquisition unit 91 acquires the first DNS query message created by the user terminal 80 before the first DNS query message reaches the destination DNS server set in the first DNS query message, thereby preventing the first DNS query message from reaching the destination DNS server set in the first DNS query message. In the present embodiment, an example of capturing the first DNS query message within the user terminal 80 will be described. For this reason, in the present embodiment, the message acquisition unit 91 acquires the first DNS query message before the first DNS query message is transmitted from the user terminal 80, thereby preventing the transmission of the first DNS query message.
[0017] The message creation unit 92 creates a second DNS query message by adding identification information (hereinafter referred to as "account information") that can identify the account related to the user terminal 80 to the acquired first DNS query message. The account information added here is the account information preset in the message creation unit 92, which is user account information linked to the user terminal 80 (account information assigned to each user) or group account information to which the user terminal 80 belongs (account information assigned in group units). Also, the account information can be added, for example, by using an option resource record of EDNS0 (Extension Mechanisms for DNS version 0). Here, when the first DNS query message is not a message having an option resource record such as EDNS0, the message creation unit 92 creates a second DNS query message based on the first DNS query message as a message having an option resource record such as EDNS0, and sets the account information in the option resource record of the created message. In this embodiment, an example of adding account information using the option resource record of EDNS0 has been described, but other fields or methods may be adopted for adding account information according to the protocol adopted according to the embodiment.
[0018] The message transmission unit 93 transmits the DNS query message to the management server 10. Here, when the second DNS query message is created by the message creation unit 92, the message transmission unit 93 transmits the second DNS query message to the management server 10 instead of the first DNS query message.
[0019] When the name resolution result is obtained, the message receiving unit 94 delivers the name resolution result to the upper-layer application side (more specifically, the resolver of the DNS client). Also, when there is no response to the query transmitted by the message transmitting unit 93 for a certain number of times, or when a message indicating that the name resolution has failed or an error regarding the format is returned, the message receiving unit 94 stops the additional processing (packet capture processing) of the account information by the message creation unit 92. As a result, for example, when there is a possibility that the second DNS query message has been discarded by a relay device on the network, the packet capture processing is aborted, and the first DNS query message can be directly sent to the network for name resolution.
[0020] When the program recorded in the storage device 14 is read into the RAM 13 and executed by the CPU 11, the management server 10 functions as an information processing apparatus including an information management unit 21, a message receiving unit 22, an identification information extraction unit 23, a security policy application unit 24, and a name resolution unit 25. In this embodiment, each function provided in the management server 10 is executed by the CPU 11 which is a general-purpose processor, but some or all of these functions may be executed by one or more dedicated processors. Also, some or all of these functions may be executed by a device installed remotely or a plurality of devices installed distributively using cloud technology or the like.
[0021] The information management unit 21 manages the correspondence relationship between the account information and the security policy applied to the account related to the account information. As described above, the account information may be the account information assigned to each user, or the account information assigned in units of groups. Therefore, in this embodiment, the security policy can be set in units of users or groups. More specifically, it is possible to set the detection conditions for security risks and the operations after the detection of security risks in the security policy. For example, as the detection conditions for security risks related to DNS queries, it is possible to set the level of the score detected as a risk and the category of the operation detected as a risk for both or either the domain name to be resolved and the IP address after name resolution. Also, for example, as the operation after the detection of security risks related to DNS queries, it is possible to set operations such as not answering the name resolution result IP address to the user terminal 80 (answering with no answer. In this case, since the user terminal 80 fails to resolve the name, the process related to the target DNS query ends here), and answering a specific IP address as the name resolution result IP address to the user terminal 80. Here, the specific IP address is, for example, the IP address of a server that returns a page indicating the reason for denying access (the determination reason based on the security policy) when accessed via HTTP or HTTPS (it may be the IP address of the management server 10). Note that at the stage of DNS queries, since the protocol by which the user terminal 80 will use the name resolution result is unknown later, if the access from the user terminal 80 to the specific IP address is performed using a protocol other than HTTP / HTTPS, the server at the IP address may deny the access from the user terminal 80.
[0022] The message reception unit 22 receives various packets including the second DNS query message transmitted from any of the user terminals 80.
[0023] When the received packet is a packet related to the second DNS query message, the identification information extraction unit 23 extracts account information from the second DNS query message.
[0024] By referring to the information management unit 21, the security policy application unit 24 identifies the security policy corresponding to the extracted account information and processes the second DNS query message according to the identification result. In addition, when the account information is not extracted by the identification information extraction unit 23, or when the domain name or IP address related to the second DNS query message is a domain name or IP address whose access is prohibited by the security policy application unit 24, the security policy application unit 24 does not give the correct name resolution result related to the second DNS query message to the user terminal 80, so as to prevent the source user terminal 80 of the DNS query message from accessing the prohibited domain name or IP address.
[0025] In addition, the entity that executes the security service according to the applied security policy is not limited to the management server 10. For example, the packet may be transferred to a security service provided by a server other than the management server 10, and the security service may be received at the transfer destination. Here, the security service at the transfer destination may be a security service provided by a virtual environment such as a container.
[0026] The name resolution unit 25 obtains the IP address of the domain name requested in the DNS query message from the user terminal 80 according to the applied security policy. In addition, the name resolution unit 25 transmits a DNS response message including the obtained IP address to the source user terminal 80 of the DNS query message.
[0027] <Processing flow> Next, the flow of the process executed by the system 1 according to the present embodiment will be described using a flowchart. Note that the specific content and order of the processes shown in the flowchart described below are examples for implementing the present disclosure. The specific process content and order may be appropriately selected according to the embodiments of the present disclosure.
[0028] FIG. 3 is a flowchart showing an outline of the flow of the packet capture process according to the present embodiment. The process shown in this flowchart is executed when a DNS query message is created by the user terminal 80 and is about to be sent to the network.
[0029] In steps S101 and S102, the DNS query message is captured. The message acquisition unit 91 captures a packet created by the user terminal 80 and about to be sent to the network before the packet is sent from the user terminal 80 (step S101), and determines whether the packet is a packet of a DNS query message (the first DNS query message) (step S102). Here, the determination of the type of the packet may be made by referring to the protocol information and port number included in the packet. If it is determined that the packet is not a packet of a DNS query message (NO in step S102), the process proceeds to step S104. On the other hand, if it is determined that the packet is a packet of a DNS query message (YES in step S102), the process proceeds to step S103.
[0030] In step S103, a packet of a DNS query message with account information inserted is created. The message creation unit 92 creates a packet of a second DNS query message by adding identification information (account information) that can identify the account related to the user terminal 80 to the first DNS query message acquired in step S101. Then, the process proceeds to step S104.
[0031] In step S104, the packet is transmitted. If it is determined in step S102 that the packet captured in step S101 is not a packet of a DNS query message (NO in step S102), the message transmission unit 93 transmits the captured packet to the network as it is. Note that since the creation process of the second DNS query message (the process of step S103) is stopped in the DNS packet process (see FIG. 5) described later, even if the packet of the second DNS query message is not created, the message transmission unit 93 transmits the captured packet to the network as it is. On the other hand, if it is determined in step S102 that the packet captured in step S101 is a packet of a DNS query message (YES in step S102) and the packet of the second DNS query message is created in step S103, the message transmission unit 93 transmits the packet of the second DNS query message to the management server 10 instead of the packet of the first DNS query message. Then, the processing shown in this flowchart ends.
[0032] FIG. 4 is a flowchart showing an outline of the flow of DNS query response processing according to the present embodiment. The processing shown in this flowchart is executed when a DNS query message transmitted from the user terminal 80 is received.
[0033] From step S201 to step S203, account information is extracted from the received DNS query message. The message reception unit 22 receives a packet of a DNS query message transmitted from any of the user terminals 80 (step S201), and the identification information extraction unit 23 extracts the account information inserted in step S103 of the packet capture process described with reference to FIG. 3 from the received packet (step S202). If the account information can be obtained (YES in step S203), the process proceeds to step S205. On the other hand, if the account information cannot be obtained (NO in step S203), the process proceeds to step S204.
[0034] In step S204, processing corresponding to a DNS query message without account information set is executed. The security policy application unit 24 applies a prescribed security policy for processing a DNS query message for which account information has not been extracted to the packet for which account information has not been extracted, and processes the DNS query message according to the security policy. Although the specific method of processing is not limited, for example, any of the following processing may be adopted. In the present embodiment, the flow in the case of adopting the following processing (1) is shown in a flowchart.
[0035] (1) Apply the default policy (guest policy). ··· Here, the default policy is not a security policy set by an administrator for a user or group, but a policy applied to a terminal that does not belong to any registered user or group. For example, it is a policy that prohibits access only to a server or the like that has been determined to be particularly harmful. When the packet capture process is stopped by the message receiving unit 94 and the first DNS query message is directly sent to the network for name resolution, since no account information is added to the first DNS query message, the identification information extraction unit 23 cannot extract the account information for determining the source of the DNS query message. Therefore, in the present embodiment, by applying the default policy to the source from which account information has not been extracted, security can be ensured even in a case where the packet capture process has been stopped.
[0036] However, the specific processing method for a DNS query message without account information set is not limited to the above-mentioned "(1) Application of default policy", and for example, any of the following processing may be adopted. (2) As a result of name resolution, by replying with a specific IP address to the user terminal 80 and causing access to the IP address, a process of notifying that name resolution for the user terminal 80 without an account will not be performed. (3) Not reply with the name resolution result to the user terminal 80 (send a reply message with an empty IP address as the name resolution result), or by replying that name resolution has failed, a process of not providing the name resolution result related to the DNS query message. Or (4) The same process as for a normal DNS query message (i.e., the name resolution unit 25 makes a query to the upper DNS server for name resolution and replies with the result to the user terminal 80).
[0037] By executing a process according to the specified security policy for a DNS query message without account information set, the information processing system according to this embodiment can apply the specified security policy to the user terminal 80 that sends a DNS query message without account information set. After that, the process shown in this flowchart ends.
[0038] In step S205, the security policy corresponding to the account information is applied. The security policy application unit 24 refers to the information management unit 21 to identify the security policy corresponding to the extracted account information, and then executes the process for the second DNS query message received in step S201 according to the identified security policy. After that, the process proceeds to step S206.
[0039] From step S206 to step S208, when the request by the second DNS query message is an address reference, a domain name check is performed. When the request by the second DNS query message is an address reference (YES in step S206. For example, in the case of an IPv4 address query, an IPv6 address query, and an HTTPS service query, that is, any of type numbers 1, 28, and 65), and a domain name check is set in the security policy applied in step S205, the security policy application unit 24 extracts the domain name being queried from the second DNS query message, and determines whether the domain name is a domain name that may answer the name resolution result for the user terminal 80 (step S207). If the domain name check is not set in the applied security policy, the check may be omitted. The specific method of this check is not limited. For example, a determination using a whitelist or a blacklist may be performed, or a determination using AI may be performed, etc.
[0040] As a result of the check, if it is determined that the domain name is a domain name that should not answer the name resolution result for the user terminal 80 (for example, the domain name of a host with security problems or a host whose use is prohibited for business reasons) (NO in step S208), the security policy application unit 24 records the domain name and the check result in the storage device 14, and the process proceeds to step S213. On the other hand, as a result of the check, if it is determined that the domain name is a domain name that may answer the name resolution result for the user terminal 80 (YES in step S208), or if the request by the second DNS query message is not an address reference (NO in step S206. For example, in the case of not being any of an IPv4 address query, an IPv6 address query, and an HTTPS service query, that is, not any of type numbers 1, 28, and 65), the process proceeds to step S209.
[0041] In step S209, name resolution for the DNS query is performed. The name resolution unit 25 acquires the IP address of the requested domain name according to the applied security policy. At this time, the acquisition of the IP address may be performed by the management server 10 making an inquiry to an upper-level DNS server (root server or authoritative server) as a full-service resolver, or by referring to the cache stored in the management server 10 as a cache server, or by referring to a preset IP address according to the security policy. When the IP address corresponding to the domain name is acquired, the process proceeds to step S210.
[0042] In steps S210 and S211, the IP address obtained as the name resolution result is inspected. The security policy application unit 24 inspects the IP address obtained in step S209 and determines whether it is an IP address that can be answered as the name resolution result to the user terminal 80 when the inspection of the IP address is set in the security policy applied in step S205 (step S210). Note that when the inspection of the IP address is not set in the applied security policy, the inspection may be omitted. The specific method of the inspection is not limited. For example, determination using a white list or a black list may be performed, or determination using AI or the like may be performed.
[0043] As a result of the inspection, if it is determined that the IP address is one that should not be answered as the name resolution result to the user terminal 80 (for example, an IP address with security problems or an IP address whose use is prohibited for business reasons) (NO in step S211), the security policy application unit 24 records the IP address and the inspection result in the storage device 14, and the process proceeds to step S213. On the other hand, if it is determined as a result of the inspection that the IP address is one that can be answered as the name resolution result to the user terminal 80 (YES in step S211), the process proceeds to step S212.
[0044] In step S212, the DNS name resolution result is notified to the user terminal 80. The name resolution unit 25 transmits a DNS response message including the IP address obtained in step S209 as a response to the DNS query message received in step S201 to the source user terminal 80 of the DNS query message received in step S201. Then, the processing shown in this flowchart ends.
[0045] In step S213, processing corresponding to a DNS query message not permitted by the security policy is executed. Processing is executed when the original IP address is not answered for the DNS query message. When it is determined that the security policy is violated as a result of the inspection (NO in step S208 or NO in step S211), the security policy application unit 24 processes the DNS query message according to the security policy corresponding to the account information (or the default policy if the default policy is applied in step S204). The specific method of processing is not limited, but for example, any of the following processing may be adopted. (1) As a result of name resolution, by answering a specific IP address to the user terminal 80 and allowing access to the IP address, a process of notifying that name resolution is not performed for the user terminal 80 without an account. (2) A process of not answering the name resolution result to the user terminal 80 (transmitting a response message with an empty IP address as the name resolution result) or answering that name resolution has failed, thereby not providing the name resolution result related to the DNS query message. Then, the processing shown in this flowchart ends.
[0046] In addition, when the process of "responding with a specific IP address to the user terminal 80 as a result of name resolution" in steps S204 and S213 of the flowchart described above is adopted, the specific IP address to be responded may be the IP address of the management server 10 or the IP address of other servers. Also, the IP address to be responded may vary according to the type of security policy violated (such as prohibited domain names, prohibited IP addresses, etc.). By doing so, the user terminal 80 can access the specified IP address using a higher-level protocol such as HTTP / HTTPS and receive a notification about the details of the security policy violation, such as that the site is one that should not be accessed according to the security policy.
[0047] FIG. 5 is a flowchart showing an outline of the flow of DNS packet processing according to the present embodiment. The process shown in this flowchart is executed when a DNS packet transmitted from the management server 10 is received by the user terminal 80, or when a response packet to the packet transmitted in step S104 of the packet capture process described with reference to FIG. 3 times out.
[0048] The message receiving unit 94 determines whether an error has occurred in name resolution (step S301). Specifically, when a packet transmitted from the management server 10 is received by the user terminal 80, the message receiving unit 94 determines whether the received DNS packet is a packet including a message indicating that name resolution for the packet transmitted in step S104 has failed. Also, when a response packet to the packet transmitted in step S104 times out, the message receiving unit 94 determines whether the number of timeouts has reached a predetermined standard.
[0049] Here, when it is determined that the received DNS packet is a packet indicating that name resolution has failed, or when it is determined that the number of timeouts of the response packet has reached a predetermined standard (YES in step S301), the message receiving unit 94 stops the creation process of the second DNS inquiry message (a process corresponding to step S103 of the packet capture process described with reference to FIG. 3) for the target user terminal 80 (step S302). By doing so, even if there is a problem in the transmission and reception of the second DNS inquiry message (for example, when the second DNS inquiry message is discarded by a relay device on the network, etc.), the process of step S103 in FIG. 3 is skipped, and the first DNS inquiry message captured by packet capture can be directly transferred to the network for name resolution. On the other hand, when there is no error in name resolution and a name resolution result corresponding to the packet transmitted in step S104 is obtained, the message receiving unit 94 delivers the name resolution result to the upper layer (step S303). Thereafter, the process shown in this flowchart ends.
[0050] Note that the creation process of the second DNS inquiry message stopped in step S302 may be restarted when a predetermined condition is satisfied. For example, when a predetermined time has elapsed since the stop of the creation process of the second DNS inquiry message, or when it is detected that the network environment (for example, IP address, etc.) of the user terminal 80 or the network device 50 described later has changed, the creation process of the second DNS inquiry message may be restarted.
[0051] According to the above-described embodiment, it is possible to provide access control starting from a DNS inquiry message that can be relatively easily introduced. More specifically, according to the information processing system according to the present embodiment, by applying a security policy corresponding to the account information, it is possible to apply a security policy corresponding to the account information related to the user of the user terminal 80 to the user terminal 80.
[0052] <Variation> In the above-described embodiment, an example of capturing the first DNS query message within the user terminal 80 has been described. However, the first DNS query message may be captured at a timing that can prevent the first DNS query message from reaching the destination DNS server set in the first DNS query message, and the location where it is captured is not limited to the user terminal 80. Hereinafter, a variation in which the first DNS query message is captured in the network device 50 (for example, a device such as a router, an L3 switch, or a gateway that acquires passing packets and processes the packets according to the set policy and / or routing table) after the message is sent from the user terminal 80 will be described.
[0053] FIG. 6 is a schematic diagram showing the configuration of the system 1b according to this variation. The system 1b according to this variation includes one or a plurality of user terminals 80 connected to each other via a network, a management server 10 having a security function for managing these user terminals 80, and a network device 50 that relays messages transmitted and received by the user terminals 80 by being connected between the user terminals 80 and the Internet. Here, since the hardware configurations of the management server 10 and the user terminals 80 are substantially the same as those described with reference to FIG. 1 in the above embodiment, the description thereof will be omitted.
[0054] The network device 50 is a computer including a CPU (Central Processing Unit) 51, a ROM (Read Only Memory) 52, a RAM (Random Access Memory) 53, a storage device 54 such as an EEPROM (Electrically Erasable and Programmable Read Only Memory) or an HDD (Hard Disk Drive), a communication unit 55 such as a NIC (Network Interface Card), and the like. However, regarding the specific hardware configuration of the network device 50, appropriate omissions, replacements, and additions are possible according to the implementation mode. Also, the network device 50 is not limited to a single device. The network device 50 may be realized by a plurality of devices using so-called cloud or distributed computing technologies and the like.
[0055] FIG. 7 is a diagram showing an outline of the functional configurations of the network device 50 and the management server 10 according to this variation. The network device 50 functions as an information processing device including a message acquisition unit 61, a message creation unit 62, a message transmission unit 63, and a message reception unit 64 when a program recorded in the storage device 54 is read into the RAM 53 and executed by the CPU 51. In this variation, each function provided in the network device 50 is executed by the CPU 51 which is a general-purpose processor, but a part or all of these functions may be executed by one or a plurality of dedicated processors. Also, a part or all of these functions may be executed by a device installed remotely or a plurality of distributed devices using cloud technology or the like.
[0056] The message acquisition unit 61 acquires the first DNS query message transmitted from the user terminal 80 before the first DNS query message reaches the destination DNS server set in the first DNS query message, thereby preventing the first DNS query message from reaching the destination DNS server set in the first DNS query message. In this variation, the message acquisition unit 61 captures the packet related to the message regardless of the destination of the DNS query message (DNS query), and sets the destination to the management server 10. For an encrypted DNS query, it can be decrypted by installing a certificate and corresponding to it.
[0057] The message creation unit 62 creates a second DNS query message by adding identification information (account information) that can identify the account related to the user terminal 80 to the acquired first DNS query message. The account information added here is the user account information linked to the user terminal 80 or the group account information to which the user terminal 80 belongs. The network device 50 searches for the association data between the communication ID (for example, source IP address) of the source user terminal 80 that can be extracted from the packet and the account information of the pre-registered user terminal 80 (for example, IP address) to identify the account information related to the source user terminal 80 of the packet, and adds the identified account information. When the added account information is group account information and all user terminals 80 under the network device 50 belong to the same group, the network device 50 identifies the common account information related to the group and adds this. Since the specific method of creating the second DNS query message and the specific method of adding the account information are substantially the same as those described in the above embodiment, the description is omitted.
[0058] The message sending unit 63 sends the DNS query message to the management server 10. Here, when the second DNS query message is created by the message creation unit 62, the message sending unit 63 sends the second DNS query message to the management server 10 instead of the first DNS query message.
[0059] When the message receiving unit 64 obtains the name resolution result, it delivers the name resolution result to the user terminal 80 (more specifically, the resolver of the DNS client of the user terminal). Also, when there is no response to the query sent by the message sending unit 63 for a certain number of times, or when a message indicating that the name resolution has failed or an error regarding the format is returned, the message receiving unit 64 stops the additional processing of the account information (packet capture processing described later) by the message creation unit 62. As a result, for example, when there is a possibility that the second DNS query message has been discarded by a relay device on the network, the packet capture processing is aborted, and the first DNS query message can be directly sent to the network for name resolution.
[0060] When the program recorded in the storage device 14 of the management server 10 is read into the RAM 13 and executed by the CPU 11, the management server 10 functions as an information processing device including an information management unit 21, a message receiving unit 22, an identification information extraction unit 23, a security policy application unit 24, and a name resolution unit 25. In this variation, each function provided in the management server 10 is executed by the CPU 11 which is a general-purpose processor, but a part or all of these functions may be executed by one or more dedicated processors. Also, a part or all of these functions may be executed by a device installed remotely or a plurality of devices installed distributively using cloud technology or the like.
[0061] The functions of the information management unit 21, message reception unit 22, identification information extraction unit 23, security policy application unit 24, and name resolution unit 25 provided in the management server 10 are substantially the same as those described in the above embodiment, and thus the description thereof is omitted.
[0062] Also, regarding the processing flow, except that the execution entity of the packet capture processing described with reference to FIG. 3 is the network device 50, it is substantially the same as that described with reference to FIGS. 3 and 4 in the above embodiment, and thus the description thereof is omitted.
Description of Reference Numerals
[0063] 1, 1b Information Processing System 10 Management Server 50 Network Device 80 User Terminal
Claims
1. An information processing system for managing user terminals, a management server for managing the user terminals, message acquisition means for acquiring a first DNS query message created by the user terminal before the first DNS query message reaches a destination DNS server set in the first DNS query message, message creation means for creating a second DNS query message by adding identification information capable of identifying an account related to the user terminal to the acquired first DNS query message, message transmission means for transmitting a DNS query message to the management server, which, when the second DNS query message is created, transmits the second DNS query message to the management server instead of the first DNS query message, The management server includes information management means for managing a correspondence relationship between the identification information and a security policy applied to the account related to the identification information, message reception means for receiving the second DNS query message transmitted from any of the user terminals, identification information extraction means for extracting the identification information from the received second DNS query message, security policy application means for specifying a security policy corresponding to the extracted identification information by referring to the information management means and processing the second DNS query message according to the specification result, Information processing system.
2. When the security policy application means fails to extract the identification information by the identification information extraction means, or when the domain name or IP address related to the second DNS query message is a domain name or IP address whose access is prohibited by the security policy application means, the security policy application means does not provide the correct name resolution result related to the second DNS query message to the user terminal. The information processing system according to claim 1.
3. Further comprising the user terminal, The user terminal includes the message acquisition means, the message creation means, and the message transmission means. The message acquisition means acquires the first DNS query message before the first DNS query message is transmitted from the user terminal. The information processing system according to claim 1.
4. Further comprising a network device that relays messages transmitted and received by the user terminal, The network device includes the message acquisition means, the message creation means, and the message transmission means. The message acquisition means acquires the first DNS query message transmitted from the user terminal before the first DNS query message reaches the destination DNS server set in the first DNS query message. The information processing system according to claim 1.
5. Message acquisition means for acquiring the first DNS query message before the first DNS query message reaches the destination DNS server set in the first DNS query message; Message creation means for creating a second DNS query message by adding identification information capable of identifying an account related to the source user terminal of the first DNS query message to the acquired first DNS query message; Message sending means for sending a DNS query message to the management server, which, when the second DNS query message has been created, sends the second DNS query message to the management server instead of the first DNS query message. An information processing apparatus comprising the same.
6. The message acquisition means acquires the first DNS query message before the first DNS query message is sent from the user terminal. The information processing apparatus according to claim 5.
7. The message acquisition means acquires the first DNS query message sent from the user terminal before the first DNS query message reaches the destination DNS server set in the first DNS query message. The information processing apparatus according to claim 5.
8. A management server for managing user terminals, comprising: Information management means for managing the correspondence between identification information capable of identifying an account related to the user terminal and a security policy applied to the account; Message receiving means for receiving a second DNS query message created by adding the identification information to a first DNS query message created by the user terminal; Identification information extraction means for extracting the identification information from the received second DNS query message; Security policy application means for identifying a security policy corresponding to the extracted identification information by referring to the information management means and processing the second DNS query message according to the identification result; A management server comprising the same.
9. A computer, A message acquisition step of acquiring a first DNS query message before the first DNS query message reaches a destination DNS server set in the first DNS query message, A message creation step of creating a second DNS query message by adding identification information capable of identifying an account related to a source user terminal of the acquired first DNS query message, A message transmission step of transmitting a DNS query message to the management server, and when the second DNS query message is created, transmitting the second DNS query message to the management server instead of the first DNS query message, A method of executing.
10. A management server for managing user terminals, wherein a computer having information management means for managing a correspondence relationship between identification information capable of identifying an account related to the user terminal and a security policy applied to the account, A message reception step of receiving a second DNS query message created by adding the identification information to a first DNS query message created by the user terminal, An identification information extraction step of extracting the identification information from the received second DNS query message, A security policy application step of specifying a security policy corresponding to the extracted identification information by referring to the information management means and processing the second DNS query message according to the specification result, A method of executing.
11. A computer, A message acquisition means for acquiring a first DNS query message before the first DNS query message reaches a destination DNS server set in the first DNS query message, Message creation means for creating a second DNS query message by adding identification information capable of identifying an account related to the source user terminal of the obtained first DNS query message to the first DNS query message. Message transmission means for transmitting a DNS query message to the management server. When the second DNS query message has been created, the message transmission means transmits the second DNS query message to the management server instead of the first DNS query message. A program for causing the above to function.
12. The computer of a management server that manages user terminals Information management means for managing the correspondence relationship between identification information capable of identifying an account related to the user terminal and the security policy applied to the account. Message reception means for receiving a second DNS query message created by adding the identification information to a first DNS query message created by the user terminal. Identification information extraction means for extracting the identification information from the received second DNS query message. Security policy application means for specifying the security policy corresponding to the extracted identification information by referring to the information management means and processing the second DNS query message according to the specification result. A program for causing the above to function.
Citation Information
Patent Citations
Security management device, communication system and access control method
JP2012108947A