Diagnostic device, circuit switch, diagnostic method, and program

A diagnostic apparatus and method address the issue of non-compliant security settings by diagnosing and updating configurations to prevent unauthorized access and use, ensuring secure operation of line exchangers.

JP2025093522AActive Publication Date: 2025-06-24NEC PLATFROMS LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2023209225
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-12-12
Publication Date
2025-06-24
Estimated Expiration
2043-12-12

AI Technical Summary

Technical Problem

Existing systems fail to timely apply recommended security settings to prevent unauthorized use and access to line exchangers, despite the disclosure of such settings, leading to potential damage.

Method used

A diagnostic apparatus and method that acquires and diagnoses setting information using diagnostic rules to determine security, notifying and updating settings to ensure compliance with secure configurations.

Benefits of technology

Enables quick and effective prevention of unauthorized use and access by diagnosing and updating settings to secure configurations, thereby protecting devices from external threats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025093522000001_ABST
    Figure 2025093522000001_ABST
Patent Text Reader

Abstract

To provide a diagnostic device, a circuit switch, a diagnostic method, and a program that can prevent damage by easily and speedily taking measures against illegal use of and illegal access to a device from outside.SOLUTION: There is provided a diagnostic device etc., having: a setting information acquisition part which acquires setting information as setting details of object equipment; a diagnostic rule holding part which holds a diagnostic rule for diagnosing the setting information; a diagnostic part which diagnoses the object equipment according to the diagnostic rule; and a diagnostic result notification part which reports the result of the diagnosis, wherein the diagnostic rule holding part holds the diagnostic rule for diagnosing whether the setting information is safe in terms of security.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention provides a diagnostic apparatus, a line exchanger, a diagnostic method, and a program that can prevent damage by easily and quickly taking measures against unauthorized use and unauthorized access from the outside to devices and the like.

Background Art

[0002] Unauthorized use and unauthorized access from the outside to line exchangers on communication networks are increasing. Vendors and the like disclose recommended settings for preventing such attacks to users, and it is common to set according to these recommended settings when constructing a new system. However, due to non-application to existing systems or overlooking risks, damage still occurs even after the disclosure of the recommended setting information.

[0003] Patent Document 1 discloses the following invention. In this invention, an IP (Internet Protocol) telephone terminal adapter automatically acquires its own unique and unique number from an in-house optical device that is its upper device at the time of authentication, and uses the automatically acquired number as an IP telephone password. Therefore, compared with the configuration in which a conventional end user sets an IP telephone password in an IP telephone terminal adapter, it is possible to suppress the theft of the password. As a result, in an IP telephone connection using FTTH (Fiber To The Home), impersonation by an end user can be regulated. In addition, since the IP telephone password of an arbitrary user is associated with an optical device on the line (communication path) of that user, a mechanism that can be used only on the line of that user can be realized.

Prior Art Documents

Patent Documents

[0004]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0005] Note that the disclosures of the above prior art documents are incorporated herein by reference. The following analysis is made by the present inventors.

[0006] As described above, in the invention disclosed in Patent Document 1, it is possible to prevent unauthorized use by forgery and unauthorized use by an authentication method. On the other hand, although considerable effects can be expected by applying the recommended settings to the switch, the recommended settings are often not applied at an appropriate timing in switches that are already in operation, and this point becomes a problem of the present invention.

[0007] Therefore, in one aspect of the present invention, an object is to provide a diagnostic apparatus, a line switch, a diagnostic method, and a program that can prevent damage by easily and quickly taking measures against unauthorized use and unauthorized access from the outside to devices and the like.

Means for Solving the Problems

[0008] According to a first aspect of the present invention, there is provided a diagnostic apparatus including a setting information acquisition unit that acquires setting information that is setting contents of a target device, a diagnostic rule holding unit that holds a diagnostic rule for diagnosing the setting information, a diagnostic unit that diagnoses the target device based on the diagnostic rule, and a diagnostic result notification unit that notifies a result of the diagnosis, wherein the diagnostic rule holding unit holds a diagnostic rule for diagnosing whether or not the setting information is a secure setting in terms of security.

[0009] According to a second aspect of the present invention, there is provided a line switch including the diagnostic apparatus according to the first aspect.

[0010] According to a third aspect of the present invention, there is provided a diagnostic method for a computer to execute the following steps: a step of obtaining setting information which is the setting content of a target device; a step of obtaining a diagnostic rule for diagnosing the setting information, the diagnostic rule being for diagnosing whether the setting information is a secure setting in terms of security; a step of diagnosing the target device based on the diagnostic rule; and a step of notifying the result of the diagnosis.

[0011] According to a fourth aspect of the present invention, there is provided a program for causing a computer to execute a process of obtaining setting information which is the setting content of a target device, a process of obtaining a diagnostic rule for diagnosing the setting information, the diagnostic rule being for diagnosing whether the setting information is a secure setting in terms of security, a process of diagnosing the target device based on the diagnostic rule, and a process of notifying the result of the diagnosis.

[0012] Note that this program can be recorded on a computer-readable storage medium. The storage medium can be a non-transient one such as a semiconductor memory, a hard disk, a magnetic recording medium, an optical recording medium, etc. The present invention can also be embodied as a computer program product.

Advantages of the Invention

[0013] According to each aspect of the present invention, it is possible to provide a diagnostic device, a line switch, a diagnostic method, and a program that can easily and quickly prevent damage by taking measures against unauthorized use and unauthorized access from the outside to devices and the like.

Brief Description of the Drawings

[0014]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Figure 12

Mode for Carrying Out the Invention

[0015] First, an outline of an embodiment will be described. Note that the reference numerals in the drawings appended to this outline are for convenience of each element as an example for assisting understanding, and the description of this outline is not intended to be limiting in any way. In the present disclosure, the drawings are associated with one or more embodiments.

[0016] [Configuration] FIG. 1 shows a block diagram showing an example of the configuration of the diagnostic apparatus 100 of the present disclosure. The diagnostic apparatus 100 of the present disclosure includes a setting information acquisition unit 101, a diagnostic rule holding unit 102, a diagnostic unit 103, and a diagnostic result notification unit 104.

[0017] The setting information acquisition unit 101 acquires setting information that is the setting content of the target device. The diagnostic rule holding unit 102 holds diagnostic rules for diagnosing the setting information. The diagnostic unit 103 diagnoses the target device based on the diagnostic rules. The diagnostic result notification unit 104 notifies the result of the diagnosis. And the diagnostic rule holding unit 102 holds a diagnostic rule for diagnosing whether the setting information is a secure setting in terms of security.

[0018] In this way, the diagnostic apparatus 100 of the present disclosure can obtain a diagnostic result by diagnosing the setting information of the target device with the held diagnostic rules. By setting the held diagnostic rules as rules for diagnosing whether the setting information is secure in terms of security, the user can know whether the setting information is safe from unauthorized access and unauthorized use.

[0019] [First Embodiment] [Outline of Processing] FIG. 2 is a diagram for showing an example of the outline of processing in the diagnostic apparatus of the present disclosure. As shown in this figure, there are a diagnostic apparatus 100, a target device 200, and a terminal device 300. These are connected via a network. The diagnostic apparatus 100 has a CPU (Central Processing Unit) and a memory area, and a diagnostic rule DB in which diagnostic rules are stored may be held in the memory area. This diagnostic rule DB may be built into the diagnostic apparatus 100 as shown in FIG. 2, or may be held in another server connected to the network.

[0020] The diagnostic apparatus 100 acquires setting information from the target device 200. The diagnostic apparatus 100 executes diagnosis using the diagnostic rules held in the diagnostic rule DB for the acquired setting information. Here, the setting information set in the target device 200 may be recommended settings for generally being secure in terms of security in the target device. The result of the diagnosis is sent as a notification to the terminal device 300.

[0021] Further, the diagnostic apparatus 100 may execute processing for updating settings for the target device 200 based on the diagnostic result and the diagnostic rules.

[0022] [Configuration] FIG. 3 is a diagram for showing an example of the configuration of the diagnostic apparatus 100 according to the first embodiment. The diagnostic apparatus 100 according to the first embodiment includes a setting information acquisition unit 101, a diagnostic rule holding unit 102, a diagnostic unit 103, a diagnostic result notification unit 104, and an update unit 105.

[0023] The setting information acquisition unit 101 acquires setting information that is the setting content of the target device. The "target device" is a device to be diagnosed, and examples thereof include communication server devices such as a Web server. The "setting information that is the setting content" is information that mainly includes settings related to the communication network among the target devices 200. This setting information may be, for example, a setting related to a port for service provision, a setting related to DNS (Domain Name System), or a recommended setting recommended for security as the setting content of the target device. This recommended setting is a general setting for connecting to the communication network, and may not be a setting after adjustment according to the usage situation.

[0024] The diagnostic rule holding unit 102 holds diagnostic rules for diagnosing the setting information. The "diagnostic rules" are rules for deriving individual and specific settings according to the network environment in which the target device 200 is arranged, which are different from the recommended settings.

[0025] FIG. 4 is a diagram for explaining the outline of the diagnostic rules used by the diagnostic apparatus 100 of the present disclosure. As shown in this figure, this rule may be, for example, a checkpoint method. The same method refers to a method of diagnosing some or all of a list of checkpoints in order. The diagnosis obtains a diagnostic result of the operation of the system under the set conditions, which are the current settings that have received the recommended settings, and derives the necessary update operations from a security perspective. For example, the checkpoint (rule ID: 0x00001) is the setting of port X of server A, and in the recommended setting, it is recommended to stop service S1 for port X (checkpoint) for security reasons (recommended setting), and the target device 200 is set not to use port X (set conditions). However, if the diagnostic result shows that port X is in use (status), it is a rule for performing a series of diagnoses → updates, such as setting port X to be unused (update operation). At least a series of this checkpoint, recommended setting, set conditions, status, and update operation may be regarded as one rule element, and the set thereof may be referred to as a "diagnostic rule".

[0026] For example, when the checkpoint is application A1 (rule ID: 0x00003) of server A, the recommended setting is to provide service S3. For this reason, in the situation where the server directly starts A1, the diagnostic result is that service S3 is in service. In the example of FIG. 4, here, due to security reasons, instead of directly starting A1, an operation is derived to update the startup mode of the application so that it is started indirectly from wrapper software or the like.

[0027] The diagnostic unit 103 diagnoses the target device based on the diagnostic rules. The target device is diagnosed for each checkpoint using the diagnostic rules as described above, and a diagnostic result is output.

[0028] The diagnostic result notification unit 104 notifies the result of the diagnosis. Specifically, it refers to notifying the diagnostic result output by the diagnostic apparatus 100 to the terminal device 300 or the like via the network. The notified diagnostic result is output by a display device or the like included in the input / output interface of the terminal device 300.

[0029] The update unit 105 updates the settings of the target device 200 based on the diagnosis result and the diagnosis rules held in the diagnosis rule holding unit 102. Specifically, it executes the update operation derived by the diagnosis rule as described above to update the settings of the target device 200.

[0030] The update unit 105 may update the settings of the target device in response to an update of the diagnosis rules held in the diagnosis rule holding unit 102. For example, in FIG. 4, when the "recommended settings" in the diagnosis rule are changed according to the situation, the "update operation" may be changed in response to the change, and a process of updating the setting information may be performed.

[0031] The diagnostic apparatus 100 may further have a diagnostic rule editing reception unit (not shown) for editing the diagnostic rules in the diagnostic rule holding unit. When the diagnostic rules are changed by editing, a process of immediately updating the setting information as in the process of the above update unit 105 may be executed.

[0032] [Description of Operations] FIG. 5 is a flowchart for explaining an example of the operation of the diagnostic apparatus 100 of the present disclosure. As shown in this figure, when the diagnostic apparatus 100 starts operating, it first acquires setting information (step S51). Next, it acquires the diagnostic rules for diagnosing the setting information (step S52). Then, it diagnoses the target device based on the diagnostic rules (step S53). After the diagnosis, it updates the settings of the target device based on the diagnosis result and the diagnostic rules (step S54), and a series of processes ends.

[0033] [Hardware Configuration] FIG. 6 is a block diagram showing an example of the hardware configuration of the diagnostic apparatus 100 according to the present disclosure. The diagnostic apparatus 100 can be configured by an information processing apparatus (computer) and includes the configuration illustrated in FIG. 6. For example, the diagnostic apparatus 100 includes a CPU (Central Processing Unit) 161, a memory 162, an input / output interface 163, and a NIC (Network Interface Card) 164 which is a communication means, each of which is interconnected by an internal bus 165.

[0034] However, the configuration shown in FIG. 6 is not intended to limit the hardware configuration of the devices constituting the diagnostic apparatus 100. The diagnostic apparatus 100 may each include hardware not shown, or may not include the input / output interface 163 as necessary. Also, the number of CPUs etc. included in the diagnostic apparatus 100 is not intended to be limited to the example of FIG. 6, and for example, a plurality of CPUs may be included in each device.

[0035] The memory 162 is a RAM (Random Access Memory), a ROM (Read Only Memory), and an auxiliary storage device (such as a hard disk).

[0036] The input / output interface 163 is a means serving as an interface for a display device and an input device (not shown). The display device is, for example, a liquid crystal display or the like. The input device is a device that receives user operations such as a keyboard and a mouse.

[0037] The functions of the diagnostic apparatus 100 are realized by a setting information acquisition program which is a processing module, a diagnostic rule acquisition program, a diagnostic program, a diagnostic result notification program, and an update program. Also, examples of the data used by the above modules include diagnostic rule data etc.

[0038] The above processing module is realized, for example, by the CPU 161 executing programs stored in the memory 162 respectively. Also, the program can be downloaded via a network or updated using a storage medium storing the program. The above processing module may be realized by a semiconductor chip. That is, any means for executing the functions performed by the above processing module using some hardware and / or software may be sufficient.

[0039] [Operation of Hardware] When the diagnostic device 100 starts operating, first, the setting information acquisition program is called from the memory 162 to the CPU 161 and enters the execution state. This program connects to the target device 200 via the NIC 164 and acquires setting information. Examples of the acquisition method include directly downloading a setting file, scanning ports, etc. to obtain the device setting status, and writing out the setting information from the setting status. The setting information is temporarily stored in the memory 162.

[0040] Next, the diagnostic rule acquisition program is called from the memory 162 to the CPU 161 and enters the execution state. This program accesses the diagnostic rule DB held by the memory 162 and reads the diagnostic rules into another area on the memory 162.

[0041] Next, the diagnostic program is called from the memory 162 to the CPU 161 and enters the execution state. This program reads the acquired setting information temporarily stored in the memory 162 and the diagnostic rules also stored on the memory 162. It collates the read setting information with the "conditions" (the "checkpoint", "setting conditions", "status" in FIG. 4) part of the diagnostic rule to determine whether there is a match. If there is a match, it reads the "update operation" of the corresponding rule and stores it in another area of the memory 162.

[0042] Next, the update program is called from the memory 162 to the CPU 161 and enters the execution state. This program reads the "update operation" stored in another area of the memory 162, accesses the target device 200 via the NIC 164 or the like, and then executes the update process.

[0043] [Description of the Effect] As described above, the diagnostic apparatus 100 of the present disclosure diagnoses the setting information of the target device according to the diagnostic rule, and diagnoses whether it is secure in terms of security, so that it is possible to easily and quickly prevent unauthorized use and unauthorized access from the outside to the device or the like, thereby preventing damage. It is possible to provide a diagnostic apparatus, a line switch, a diagnostic method, and a program.

[0044] [Embodiment] [Outline of Processing] In the embodiment, an example in which the diagnostic apparatus 100 of the present disclosure is mounted on a line switch such as a telephone line will be described.

[0045] [Configuration of the Apparatus] FIG. 7 is a block diagram showing an example of the configuration of a line switch in an embodiment of the present disclosure. As shown in this figure, this embodiment is composed of a switch 30, an input / output device 20, and a management service 10. The switch 30 has a call processing unit 40 and a setting diagnosis unit 50 newly added in the present invention. The call processing unit 40 is a part that operates various services of a telephone, and has station data 41 which is setting data therefor.

[0046] The setting diagnosis unit 50 is composed of a detection unit 51, a determination unit 52, a notification unit 53, a setting update unit 54, and a recommended setting database 55. The determination unit 52 compares and risk-diagnoses the station data 41 read by the detection unit 51 and the recommended setting database 55, and the diagnostic result is notified from the notification unit 53 to the input / output device 20. After the diagnosis, the setting update unit 54 can also update the station data 41 to the recommended setting.

[0047] Regarding the recommended setting database 55, since the recommended settings vary depending on the system configuration and services used, etc., it has information on recommended settings tailored to each condition. Also, not only the station data 41, but also the settings of the equipment accommodated in the switch such as telephones and telephone lines, and external devices such as routers connected to the switch 30 are data necessary for security measures, so it also has the recommended setting information for those. In order for the user to be able to determine whether there is no problem even if the settings are changed to the recommended settings, it also has information serving as criteria for the meaning of the set values of each data and the reasons for making such settings.

[0048] Figure 8 is an image diagram showing a part of the recommended setting database 55 as an example. From No.1 to No.4 where the conditions in Figure 8 are "common" are items that need to be checked in all systems. For example, for the conditions of No.1 and 2, the recommended settings vary depending on whether to perform an internal line connection of SIP (Session Initiation Protocol) from the outside, but this condition needs to be selected by the user rather than being a station data setting. Also, since the settings of the router which is an external device are also necessary, the recommended settings are described in the "Settings other than station data, matters to be confirmed with the user" column.

[0049] For No.5 in Figure 8, since the condition is "accommodate IP internal lines in NAT (Network Address Translation)", when the NAT mode is set to be effective in the station data, it is necessary to perform a process of comparing the station data with the recommended settings. Also, since it is necessary to confirm whether an internal line is actually connected, that fact is described in the "Settings other than station data, matters to be confirmed with the user" column.

[0050] Figure 9 is a diagram for explaining the diagnostic process of the determination unit 52 in Figure 7. In the "Confirmation of Condition 1" in Figure 9, the "Condition" and "Station data to be checked" of "No.1" in Figure 8 are confirmed. If they match, the process after "Compare the set station data with the recommended settings" is executed to record the diagnostic result for Condition 1. In this way, the diagnosis is carried out for each condition, and the diagnostic results of all conditions are notified.

[0051] [Explanation of the operation of the embodiment] The operation of an embodiment of the present invention will be described with reference to FIG. 10. When the user requests the switch 30 to start diagnosis from the input / output device 20, the setting diagnosis unit 50 of the switch 30 reads the local data 41 and the recommended setting database 55 by the detection unit 51, performs a comparison diagnosis in the determination unit 52, and returns the diagnosis result from the notification unit 53 to the input / output device 20. The user checks the diagnosis result on the input / output device 20, makes changes as recommended, and if there are no problems, issues a local data update request. The determination unit 52 that has received the local data update request requests the setting update unit 54 to set the recommended data. When the setting update is completed, the result is notified from the notification unit 53 to the input / output device 20. The "diagnosis" of the determination unit 52 corresponds to the process of FIG. 9.

[0052] [Description of Other Embodiments] When receiving the diagnosis result notification in the above embodiment, if more detailed conditional setting is required, as shown in FIG. 11, after the user checks the diagnosis result notification, the user can select / add diagnosis conditions and the determination unit 52 can perform re-diagnosis. This re-diagnosis process may be performed multiple times as needed. For example, when "performing an external SIP extension connection" in No. 1 and 2 of FIG. 8 matches the user's operation conditions, if the conditions are added and a re-diagnosis is requested, No. 2 is selected as the recommended data.

[0053] It is also possible to automatically update the recommended setting database in the switch and perform diagnosis when the recommended setting information is updated. This will be described with reference to FIG. 12. The recommended setting information is managed by the management service 10 connected via the Internet to manage one or more switches 30. When a new risk is found, the recommended setting information held by the management service 10 is updated. At this time, the management service 10 downloads the recommended setting information to all the connected switches 30 and updates the recommended setting database 55.

[0054] When the recommended setting database 55 is updated, the switch 30 automatically performs diagnosis using the updated recommended setting database 55. The input / output device 20 is also notified that the recommended setting database 55 has been updated. The processing after diagnosis is the same as in the case of manual diagnosis in FIG. 9. At this time, it is also possible to perform centralized management by setting the notification destination to the management service 10 instead of the input / output device 20. Further, even without a diagnosis start request from the input / output device 20, it is possible to automatically start diagnosis due to triggers such as a system version upgrade or a change in the station data settings.

[0055] Part or all of the above disclosure may be described as follows, but is not limited thereto. [Appendix 1] It is as described in the diagnostic device according to the first aspect above. [Appendix 2] The setting information acquisition unit acquires recommended settings that are recommended for security as the setting content of the target device, preferably the diagnostic device of Appendix 1. [Appendix 3] Further comprising an update unit that updates the settings of the target device based on the result of the diagnosis and the diagnosis rule held in the diagnosis rule holding unit, preferably the diagnostic device of Appendix 1 or 2. [Appendix 4] The diagnosis rule holding unit holds a diagnosis rule consisting of a list of checkpoints. Preferably, the diagnostic device according to any one of Appendices 1 to 3. [Appendix 5] The update unit updates the settings of the target device in response to an update of the diagnosis rule held in the diagnosis rule holding unit, preferably the diagnostic device according to any one of Appendices 1 to 4. [Appendix 6] Further comprising a diagnosis rule editing reception unit for editing the diagnosis rule in the diagnosis rule holding unit, preferably the diagnostic device according to any one of Appendices 1 to 5. [Appendix 7] It is as described in the line switch according to the second aspect above. [Appendix 8] The diagnostic rule holding unit including the diagnostic device holds diagnostic rules related to unauthorized extension registration, preferably the circuit switch of Appendix 7. [Appendix 9] It is as the diagnostic method according to the above-described third perspective. [Appendix 10] It is as the program according to the above-described fourth perspective. Note that Appendix 9 and 10 can be expanded to Appendix 2 to Appendix 6 in the same manner as Appendix 1.

[0056] Each disclosure of the above-cited patent documents and the like shall be incorporated herein by reference. Within the scope of the entire disclosure of the present invention (including the claims), further modifications and adjustments of the embodiments or examples can be made based on the basic technical idea. Also, within the scope of the entire disclosure of the present invention, various combinations or selections of various disclosure elements (including each element of each claim, each element of each embodiment or example, each element of each drawing, etc.) are possible. That is, the present invention naturally includes all various deformations and modifications that could be made by those skilled in the art according to the entire disclosure including the claims and the technical idea. In particular, for the numerical ranges described in this document, any numerical value or small range included within the range should be construed as specifically described even in the absence of separate description.

Explanation of Reference Numerals

[0057] 10: Management service 20: Input / output device 30: Switch 40: Call processing unit 41: Station data 50: Setting diagnosis unit 51: Detection unit 52: Judgment unit 53: Notification unit 54: Setting update unit 55: Recommended setting database 100: Diagnostic device 101: Setting information acquisition unit 102: Diagnostic rule holding unit 103: Diagnostic unit 104: Diagnosis result notification unit 105: Update unit 161: CPU 162: Memory 163: Input / output interface 164: NIC 165: Internal bus 200: Target device 300: Terminal device

Claims

1. A setting information acquisition unit that acquires setting information which is the setting content of a target device; A diagnostic rule holding unit that holds diagnostic rules for diagnosing the setting information; A diagnostic unit that diagnoses the target device based on the diagnostic rules; A diagnostic result notification unit that notifies the result of the diagnosis, and has: The diagnostic rule holding unit holds a diagnostic rule for diagnosing whether the setting information is a secure setting in terms of security. Diagnostic device.

2. The diagnostic device according to claim 1, wherein the setting information acquisition unit acquires recommended settings recommended in terms of security as the default setting content of the target device.

3. The diagnostic device according to claim 2, further comprising an update unit that updates the settings of the target device based on the result of the diagnosis and the diagnostic rules held in the diagnostic rule holding unit. The diagnostic device according to claim 2.

4. The diagnostic device according to claim 3, wherein the diagnostic rule holding unit holds a diagnostic rule consisting of a list of checkpoints. The diagnostic device according to claim 3.

5. The diagnostic device according to claim 4, wherein the update unit updates the settings of the target device in response to an update of the diagnostic rules held in the diagnostic rule holding unit. The diagnostic device according to claim 4.

6. The diagnostic device according to claim 5, further comprising a diagnostic rule editing reception unit for editing the diagnostic rules in the diagnostic rule holding unit. The diagnostic device according to claim 5.

7. A circuit switch including the diagnostic device according to any one of claims 1 to 6.

8. The circuit switch according to claim 7, wherein the diagnostic rule holding unit included in the diagnostic device holds a diagnostic rule regarding unauthorized extension registration. The circuit switch according to claim 7.

9. A diagnostic method in which the following steps are executed by a computer, A step of acquiring setting information which is the setting content of a target device; A step of acquiring a diagnostic rule for diagnosing the setting information, the diagnostic rule for diagnosing whether the setting information is a secure setting in terms of security; A step of diagnosing the target device based on the diagnostic rule; A step of notifying the result of the diagnosis; Including a diagnostic method.

10. A process of acquiring setting information which is the setting content of a target device; A process of acquiring a diagnostic rule for diagnosing the setting information, the diagnostic rule for diagnosing whether the setting information is a secure setting in terms of security; A process of diagnosing the target device based on the diagnostic rule; A process of notifying the result of the diagnosis; A program for causing a computer to execute.

Citation Information

Patent Citations

  • Security management system, relay device, and program

    JP2007272396A

  • Information processing system, information processing device, setting determination method and program

    JP2016081270A

  • Information management device, information management system, information management method, program and information equipment

    JP2016119037A

  • Analysis system, method, and program

    WO2021192587A1

  • IP phone system, its authentication method, and IP phone terminal adapter

    JP2005341374A