Message distribution device, message distribution method, and message distribution program
The message distribution device uses the anchoring effect and C-HIP model to calculate personalized anchor values for tailored security updates, addressing habituation and improving user awareness and implementation rates.
Patent Information
- Application Number
- JP2023214801
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-12-20
- Publication Date
- 2025-07-02
AI Technical Summary
Existing security measure notification systems fail to effectively promote user awareness and habituation to security updates due to habituation of warnings and lack of personalized user consideration, as shown in Non-Patent Documents 1-5.
A message distribution device and method utilizing the anchoring effect and C-HIP model to calculate and distribute personalized anchor values based on user-specific security information, terminal status, and behavior change stages, creating tailored messages to prompt security measures.
Enhances user awareness and habituation to security measures by using the anchoring effect, reducing habituation and improving the implementation rate of security updates.
Smart Images

Figure 2025098575000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a message distribution device, a message distribution method, and a message distribution program for distributing notification messages regarding the security of a terminal.
Background Art
[0002] In recent years, cyberattacks using malware have become sophisticated, and many damages have occurred due to spam emails or unauthorized access. In such a situation, it has become even more important to implement security measures on the terminals used by users.
[0003] In Patent Document 1, a device has been proposed that notifies a user of necessary information from among security information collected from reliable sites, based on the current patch application status and the like. As a result, the user can obtain security information in a timely manner, and by applying patches according to the patch information, the host can always be used safely.
[0004] In Patent Document 2, when notifying a user of software updates, a device has been proposed that determines the presence or absence of a failure on the server side and notifies the user at a timing when no failure has occurred. As a result, the user's update timing does not overlap with the time of a server failure, and the update can be performed.
[0005] On the other hand, generally, when updating an OS or other software, even if it is an automatic update setting, it is often necessary to restart the terminal, so the user himself / herself needs to take measures. Therefore, a measure for prompting the user's actions (taking measures) is important.
[0006] In Non-Patent Document 1, it has been shown that by observing the user's brain using functional magnetic resonance imaging (fMRI), the user's visual processing center in the brain is dramatically reduced and domesticated by repeatedly displaying the same security warning.
[0007] In Non-Patent Document 2, since the interfaces of notifications not related to security and security warnings are similar, it is shown that habituation to notifications also affects security warnings and habituation occurs.
[0008] In Non-Patent Document 3, it is shown that by presenting an image of a dog to the user and attracting "cuteness", the user's attention can be directed to a security warning. Here, "cuteness" serves as a reward and promotes attention arousal.
[0009] In Non-Patent Document 4, how humans process visual warnings is modeled (Communication-Human Information Processing (C-HIP) model), and warnings switch a person's attention and cause actions by maintaining attention. And it is shown that warnings should be prominent, easy to notice, and easy to attract attention. However, humans do not act when the following bottlenecks occur midway. 1) When a familiar stimulus is given, attention does not switch. 2) When specialized knowledge / prior knowledge is required, attention switches to other things. 3) When the knowledge or beliefs based on experience are different from the warning content, humans do not act if the warning does not have the persuasive power to override the knowledge or beliefs based on the person's experience.
[0010] In Non-Patent Document 5, in the context of the C-HIP model and its relevance to software updates, it is shown that many users have insufficient understanding, hesitation, annoyance, and confusion regarding software updates.
Prior Art Documents
Patent Documents
[0011]
Patent Document 1
Patent Document 2
Non-Patent Documents
[0012] [Non-Patent Document 1] Anderson, Bonnie Brinton, et al. "How polymorphic warnings reduce habituation in the brain: Insights from an fMRI study." Proceedings of the 33rd annual ACM conference on human factors in computing systems. 2015. [Non-Patent Document 2] Vance, Anthony, et al. "The fog of warnings: how non-essential notifications blur with security warnings." Fifteenth Symposium on Usable Privacy and Security (SOUPS 2019)., 2019. [Non-Patent Document 3] Minagawa, Ryo, Tetsuji Takada: Can "cute" improve the effect of security warnings? (Second Report) - An attempt to induce safe behavior by psychological effects -, CSS2018, pp278-285, 2018. [Non-Patent Document 4] Wogalter, Michael S. "Communication-human information processing (C-HIP) model." Forensic Human Factors and Ergonomics. CRC Press, 2018. 33-49. [Non-Patent Document 5] Fagan, Michael, Mohammad Maifi Hasan Khan, and Ross Buck. "A study of users’ experiences and beliefs about software update messages." Computers in Human Behavior, pp504-519, 2015.
Summary of the Invention
Problems to be Solved by the Invention
[0013] In Patent Document 1, it is a technology for judging the reliability of an information providing site and the risk level of security information and notifying appropriate information. However, since the provided information is the same message for any user, there may be a case where the user's awareness of implementing security measures does not improve. Similarly to Patent Document 1, in Patent Document 2, the state on the server side is considered. However, since it is not the notification timing considering the user's awareness and work content, there is a problem that the effect of improving the update rate is small. In Non-Patent Document 1 and Non-Patent Document 2, it is shown that habituation occurs when a security warning is presented multiple times, and there is a problem that the effect of the security warning does not last. The method cited in Non-Patent Document 3 has a problem that since the image of the dog presented is the same every time, habituation to the warning occurs in the user and the effect does not last. Non-Patent Document 4 proposes a C-HIP model for suppressing habituation, but there is no case where it is utilized for promoting security measures. Non-Patent Document 5 only describes the relevance to software updates based on the C-HIP model shown in Non-Patent Document 4, and does not show a case where the C-HIP model is utilized.
[0014] An object of the present invention is to provide a message distribution device, a message distribution method, and a message distribution program for promoting security measures based on the C-HIP model by using the anchoring effect.
Means for Solving the Problem
[0015] The message distribution device according to the present invention includes an anchor setting unit that acquires and sets security information related to security in advance and calculates a plurality of anchor values based on the set security information, a terminal information acquisition unit that acquires terminal information including the implementation status of security measures in a user terminal, a questionnaire distribution unit that creates a questionnaire regarding the plurality of anchor values and distributes the created questionnaire to the user terminal, a questionnaire result acquisition unit that acquires an answer to the questionnaire from the user terminal and determines a graph of the anchor values to be presented to the user terminal among the plurality of anchor values based on the answer to the questionnaire, an anchor distribution unit that distributes the determined graph of the anchor values to the user terminal, a message creation unit that creates a message for requesting implementation of items of unimplemented security measures including a graph in which the anchor values of the determined graph are set to a predetermined value or more based on the terminal information, a message distribution unit that distributes the created message to the user terminal, and a message answer acquisition unit that acquires an answer including whether or not the items have been implemented for the distributed message.
[0016] The message distribution unit may set the anchor value to a predetermined value or more at the timing of distributing the message.
[0017] It includes a stage determination unit that determines the behavior change stage of the user of the user terminal with respect to security measures based on the answer to the questionnaire and the terminal information, and the questionnaire result acquisition unit may determine the graph of the anchor values based on the behavior change stage of the user.
[0018] When the graph of the anchor value determined based on the answer to the questionnaire and the graph of the anchor value determined based on the user's behavior change stage are different, the graph of the anchor value determined based on the answer to the questionnaire may be prioritized.
[0019] The plurality of anchor values may be at least any one of security risk, number of incidents, patch application rate, or update recommendation degree.
[0020] The message distribution method according to the present invention includes an anchor setting step of acquiring and setting security information related to security in advance and calculating a plurality of anchor values based on the set security information; a terminal information acquisition step of acquiring terminal information including the implementation status of security measures in a user terminal; a questionnaire distribution step of creating a questionnaire regarding the plurality of anchor values and distributing the created questionnaire to the user terminal; a questionnaire result acquisition step of acquiring an answer to the questionnaire from the user terminal and determining a graph of the anchor value to be presented to the user terminal among the plurality of anchor values based on the answer to the questionnaire; an anchor distribution step of distributing the determined graph of the anchor value to the user terminal; a message creation step of creating a message for requesting implementation of an item of an unimplemented security measure including a graph in which the anchor value of the determined graph is set to a predetermined value or more based on the terminal information; a message distribution step of distributing the created message to the user terminal; and a message answer acquisition step of acquiring an answer including whether or not the item has been implemented for the distributed message, which is executed by a computer.
[0021] The message distribution program according to the present invention is for causing a computer to function as the message distribution device.
Effect of the Invention
[0022] According to the present invention, by using the anchoring effect and based on the C-HIP model, security measures can be promoted.
Brief Description of the Drawings
[0023]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Mode for Carrying Out the Invention
[0024] Hereinafter, an example of an embodiment of the present invention will be described. The message distribution device of the present embodiment uses the anchoring effect and based on the C-HIP model, and promotes the implementation of security measures such as updating the OS or other software in the usage device (terminal) by notifying a message. The anchoring effect is a psychological effect in which subsequent decision-making is affected by the first given number (see, for example, Amos Tversky and Daniel Kahneman: Judgement under Uncertainty: Heuristics and Biases: Biases in judgement reveal some heuristics of thinking under uncertainty, Science, Vol.185, No.4157. (Sep. 27, 1974), pp. 1124-1131, etc.). In addition, this embodiment can be applied to various security measures such as OS updates (applying patches) or updates of other software. Hereinafter, mainly the case of OS updates will be exemplified and described.
[0025] FIG. 1 is a diagram showing the configuration of the management system 1 in this embodiment. The management system 1 includes an information management server 10 (message distribution device) having a database and a user terminal 20. Management software is distributed to the user terminal 20.
[0026] The management system 1 operates in cooperation with the software of the information management server 10 and the user terminal 20, thereby executing an anchor setting process (1), a terminal information acquisition process (2), a questionnaire distribution process (3), a questionnaire result acquisition process (4), an anchor distribution process (5), a behavior change stage determination process (6), a message creation process (7), a message distribution process (8), and a message response acquisition process (9).
[0027] Thereby, the information management server 10 uses the anchoring effect to distribute a graph of anchor values such as security risks, the number of incidents, and patch application rates to the user terminal 20 based on the C-HIP model. Then, at the timing of distributing a message for prompting an OS update, the information management server 10 includes a graph in which the anchor value is set to a large value equal to or greater than a normal value (predetermined value) in the message, thereby promoting the OS update by the anchoring effect.
[0028] FIG. 2 is a diagram showing the functional configuration of the information management server 10 in this embodiment. The information management server 10 is an information processing device (computer) including an input / output device and a communication device for various data, in addition to a control unit 11 and a storage unit 13.
[0029] The control unit 11 controls the entire information management server 10 and realizes each function in the present embodiment by appropriately reading and executing various programs stored in the storage unit 13. The control unit 11 may be a CPU.
[0030] The storage unit 13 is a storage area for various programs and various data for causing the hardware group to function as the information management server 10, and may be a ROM, a RAM, a flash memory, a hard disk drive (HDD), or the like. Specifically, the storage unit 13 stores various databases in addition to a program (message distribution program) for causing the control unit 11 to execute each function of the present embodiment.
[0031] The control unit 11 includes an anchor setting unit 111, a terminal information acquisition unit 112, a questionnaire distribution unit 113, a questionnaire result acquisition unit 114, an anchor distribution unit 115, a stage determination unit 116, a message creation unit 117, a message distribution unit 118, and a message response acquisition unit 119.
[0032] The anchor setting unit 111 is a functional unit responsible for the anchor setting process (1), acquires and sets security information related to security in advance, and calculates a plurality of anchor values based on the set security information. Specifically, for example, the anchor setting unit 111 automatically collects security information (reference information) such as past security risks, the number of incidents, and patch application rates from a website via the network and registers it as graph reference information 139 in the database of the storage unit 13. In addition, the anchor setting unit 111 registers the transition (the slope of the graph) of the anchor values such as security risks in the database of the storage unit 13 as graph generation information 138 in advance. The anchor setting unit 111 uses a known method (for example, Japanese Patent Application Laid-Open No. 2023-167858) to refer to the transition and slope of the graph of past anchor values based on the graph generation information 138 or graph reference information 139, which is the set security information, and calculates each of the plurality of anchor values. Here, as multiple anchor values, there are anchor values based on security risks (such as the presence or absence of vulnerabilities when patches, etc., are not applied), anchor values based on the number of incidents (such as the security damage occurrence rate in the country), anchor values based on the patch application rate (such as the application rate of OS users, the application rate within the company), anchor values based on the update recommendation level (such as the recommendation level in the OS providing company), etc. The anchor setting unit 111 sets each of the calculated multiple anchor values as the first value of the graph of the anchor value determined by the questionnaire result acquisition unit 114 described later. Note that the anchor value may be recorded in the anchor value 140 of the database in the storage unit 13.
[0033] Note that the anchor setting unit 111, based on findings obtained from, for example, questionnaire results obtained by the questionnaire result acquisition unit 114 described later, as a distribution rule, accepts in advance directly from the system administrator or via the system administrator's terminal the terminal distribution conditions 131 of the message for promoting the distribution of the anchor value by the anchor distribution unit 115 described later and the implementation of unimplemented security measures by the message distribution unit 118 described later, and registers them in the database of the storage unit 13. Also, the anchor setting unit 111 may register, as the message 132, the text to be notified according to the type of security measure and the attributes of the user such as the action change stage in the database of the storage unit 13. And when the terminal distribution conditions 131 and the message 132 are registered, the anchor setting unit 111 may automatically perform initial setting of the distribution rule 133 suitable for the attribute information including the action change stage of each user and the type of security measure.
[0034] Furthermore, the anchor setting unit 111 determines a plurality of elements (such as the text of the message, UI design, distribution timing, etc.) that define the characteristics of the anchor value and the message to be distributed individually based on the attribute information of each user (user terminal 20), and records them in the database of the storage unit 13 as the terminal distribution setting log 134. After that, each time the anchor setting unit 111 newly determines the terminal distribution setting according to a predetermined rule based on the status of each user terminal 20 obtained by the terminal information acquisition process (2) or the message response acquisition process (9) described later, it may be recorded as the terminal distribution setting log 134.
[0035] The terminal information acquisition unit 112 is a functional unit responsible for the terminal information acquisition process (2). In order to grasp the implementation status of security measures by the user, it regularly acquires terminal information such as the version of the OS of the user terminal 20 and the application status of the patch through the software of the user terminal 20. The acquired terminal information is recorded as the terminal information log 135 in the database of the storage unit 13.
[0036] The questionnaire distribution unit 113 is a functional unit responsible for the questionnaire distribution process (3). It creates a questionnaire regarding a plurality of anchor values and distributes the created questionnaire to the user terminal 20. Specifically, the questionnaire distribution unit 113 creates, for example, a questionnaire including items for asking about the anchor values that the user usually cares about among a plurality of anchor values such as security risk, number of incidents, patch application rate, and update recommendation degree. The questionnaire distribution unit 113 distributes the created questionnaire to the user terminal 20. Note that the questionnaire distribution unit 113 may distribute to the user terminal 20 a questionnaire including items for asking about the implementation status of security measures or the degree of interest by the user, together with the items for asking about the anchor values.
[0037] The questionnaire result acquisition unit 114 is a functional unit responsible for the questionnaire result acquisition process (4). It acquires the responses to the questionnaire from the user terminal 20. The acquired information is recorded as the questionnaire log 136 in the database of the storage unit 13. The questionnaire result acquisition unit 114 determines a graph of the anchor values to be presented to the user terminal 20 among a plurality of anchor values based on the answers to the questionnaire. Specifically, the questionnaire result acquisition unit 114 may randomly determine a graph of one of the plurality of anchor values. Alternatively, the questionnaire result acquisition unit 114 may determine a graph of one anchor value based on the user's behavior change stage determined by the stage determination unit 116 described later.
[0038] The anchor distribution unit 115 is a functional unit responsible for the anchor distribution process (5). For example, it takes the graph of the anchor value determined by the questionnaire result acquisition unit 114, uses the anchor value calculated by the anchor setting unit 111 as the first value of the graph, and based on the graph generation information 138 or the graph reference information 139, distributes a graph showing the transition of the anchor value to the user terminal 20 at predetermined intervals such as every day. FIG. 3 is a diagram showing an example of the graph of the anchor values to be distributed in the present embodiment. In FIG. 3, as an example of the anchor value, a graph of the patch application rate, which is the application rate of OS users, is shown. As shown in FIG. 3, the graph of the patch application rate indicates that it transitions between 10% and 20% during the period from July 1 to August 19, for example.
[0039] The stage determination unit 116 is a functional unit responsible for the behavior change stage determination process (6). It determines the user's behavior change stage regarding security measures based on the answers to the questionnaire obtained by the questionnaire result acquisition unit 114 and the terminal information. Note that the findings obtained from answers to the questionnaire, etc. include, for example, the user's interest, concern, awareness of security measures, and the behavior change stage determined according to the implementation status of the measures, or the appropriate distribution timing based on personality, risk awareness, and the working status on the user terminal 20.
[0040] Here, the behavior change stage represents a stage from a state of being uninterested in the implementation of security measures to continuously implementing them. For example, the stages are defined as follows, and it is determined for each user which stage they are in. Indifferent stage: Having no interest or concern in security measures and not being aware of the security measures that can be taken currently. Interest stage: Having an interest or concern in security measures, or being aware of the security measures that can be taken currently, but not wanting to take them. Preparation stage: Wanting to take the security measures that can be taken currently, but not implementing the security measures that should be taken by oneself. Execution stage: Sometimes implementing the security measures that should be taken by oneself, but not continuously. Maintenance stage: Continuously implementing the security measures that should be taken by oneself.
[0041] Note that the questionnaire result acquisition unit 114 may determine a graph of anchor values to be presented to the user terminal 20 according to the action change stage of the user determined by the stage determination unit 116. That is, when the user of the user terminal 20 is determined by the stage determination unit 116 to be in the execution stage or the maintenance stage with high security awareness, the questionnaire result acquisition unit 114 may determine a graph of anchor values of specialized content such as security risks and the number of incidents. On the other hand, when the user of the user terminal 20 is determined by the stage determination unit 116 to be in the indifferent stage or the interest stage with low security awareness, the questionnaire result acquisition unit 114 may determine a graph of anchor values that do not require specialized knowledge such as patch application rate and update recommendation degree. By doing so, the information management server 10 can improve the user's update intention rate by changing the graph of anchor values according to the literacy.
[0042] The message creation unit 117 is a functional unit responsible for the message creation process (7), and creates a message based on the terminal information, requesting the implementation of the items of unimplemented security measures including a graph in which the anchor values of the graph determined by the questionnaire result acquisition unit 114 are set to a predetermined value or more. Specifically, for example, as shown by the dashed line in the graph of FIG. 3, the message creation unit 117 creates a message based on message 132 at the timing of creating a message requesting implementation of unimplemented security measure items after August 19, and includes a graph in which the anchor value of the patch application rate is set to a value equal to or greater than a value (predetermined value) between the normal 10% and 20%. It is preferable that the system administrator pre-sets how much larger than the normal value (predetermined value) the anchor value should be set.
[0043] The message distribution unit 118 is a functional unit responsible for the message distribution process (8), and distributes the message created by the message creation unit 117 to the user terminal 20. By doing so, the information management server 10 can stimulate the user to take security measures by distributing a message including a graph with an anchor value larger than the normal value (predetermined value), and can suppress the habituation to security measures.
[0044] The message response acquisition unit 119 is a functional unit responsible for the message response acquisition process (9), and acquires, from the user terminal 20, a response including whether or not an unimplemented security measure item has been implemented for the message distributed by the message distribution unit 118. The content of the message distributed to the user terminal 20 and the response result are recorded in the database of the storage unit 13 as the message distribution log 137.
[0045] FIG. 4 is a first flowchart showing a process of determining a graph of the anchor value according to the response to the questionnaire by the questionnaire result acquisition unit 114 in the present embodiment. Here, a graph of the anchor value is determined according to the response to the questionnaire by the target user.
[0046] In step S1, the questionnaire result acquisition unit 114 determines whether there is a response to the questionnaire distributed by the questionnaire distribution unit 113. If this determination is YES, the process proceeds to step S2, and if the determination is NO, the process proceeds to step S3.
[0047] In step S2, the questionnaire result acquisition unit 114 determines the graph of the corresponding anchor value according to the acquired response.
[0048] In step S3, the questionnaire result acquisition unit 114 randomly determines one graph from among the graphs of a plurality of anchor values.
[0049] FIG. 5 is a second flowchart showing the process of determining the graph of the anchor value according to the response to the questionnaire by the questionnaire result acquisition unit 114 in the present embodiment. Here, the graph of the anchor value is determined according to the response to the questionnaire by the target user and the user's behavior variation stage.
[0050] In step S11, the questionnaire result acquisition unit 114 determines whether there is a response to the questionnaire distributed by the questionnaire distribution unit 113. If this determination is YES, the process proceeds to step S12, and if the determination is NO, the process proceeds to step S15.
[0051] In step S12, the questionnaire result acquisition unit 114 determines whether the graph of the anchor value determined from the answers obtained in step S11 matches the graph of the anchor value determined from the user's behavior change stage. For example, when the user's behavior change stage is the execution or maintenance stage with high security awareness, the questionnaire result acquisition unit 114 determines a graph of specialized anchor values for security risks and the number of incidents. When the questionnaire result acquisition unit 114 determines a graph of anchor values for security risks and the number of incidents from the user's questionnaire answers, if the graph of the anchor value determined from the answers matches the graph of the anchor value determined from the user's behavior change stage, it is determined that the match is successful. In this case, the determination is YES, and the process proceeds to step S13. On the other hand, when the questionnaire result acquisition unit 114 determines a graph of anchor values for patch application rate and update recommendation degree as the graph of the anchor value from the user's questionnaire answers, if the graph of the anchor value determined from the answers does not match the graph of the anchor value determined from the user's behavior change stage, it is determined that the match fails. In this case, the determination is NO, and the process proceeds to step S14. Also, when the user's behavior change stage is the unconcerned or interested stage with low security awareness, the questionnaire result acquisition unit 114 determines a graph of anchor values that does not require expertise in patch application rate and update recommendation degree. When the questionnaire result acquisition unit 114 determines a graph of anchor values for patch application rate and update recommendation degree from the user's questionnaire answers, if the graph of the anchor value determined from the answers matches the graph of the anchor value recommended from the user's behavior change stage, it is determined that the match is successful. In this case, the determination is YES, and the process proceeds to step S13. On the other hand, when the questionnaire result acquisition unit 114 determines a graph of anchor values for security risks and the number of incidents from the user's questionnaire answers, if the graph of the anchor value determined from the answers does not match the graph of the anchor value recommended from the user's behavior change stage, it is determined that the match fails. In this case, the determination is NO, and the process proceeds to step S14.
[0052] In step S13, since the graph of the anchor value determined from the answer matches the graph of the anchor value recommended from the user's behavior change stage, the questionnaire result acquisition unit 114 determines the graph of the corresponding anchor value.
[0053] In step S14, since the graph of the anchor value determined from the answer does not match the graph of the anchor value recommended from the user's behavior change stage, the questionnaire result acquisition unit 114 determines the graph of the anchor value based on the user's questionnaire answer. That is, when it does not match the graph of the anchor value determined from the user's behavior change stage, the questionnaire result acquisition unit 114 gives priority to the graph of the anchor value based on the user's questionnaire answer.
[0054] In step S15, the questionnaire result acquisition unit 114 determines the graph of the anchor value based on the user's behavior change stage.
[0055] According to the present embodiment, the information management server 10 distributes the graph of the anchor value to the user terminal 20 at a predetermined interval such as every day, and creates and distributes a message including a graph in which the anchor value is set to a value larger than a predetermined value at the timing of distributing a message for prompting the implementation of unimplemented security measures to the user terminal 20. Thereby, the information management server 10 can promote security measures based on the C-HIP model by using the anchoring effect, solve habituation, and improve and maintain the implementation rate. In addition, by distributing a message including a graph in which the anchor value is a value larger than a predetermined value, the information management server 10 can give a stimulus to the user to take security measures, and can suppress habituation to security measures.
[0056] <Modification Example 1> In one embodiment, the information management server 10 is connected to one user terminal 20, but is not limited thereto. For example, the information management server 10 may be connected to two or more user terminals 20.
[0057] <Modification Example 2> Also, for example, in the above-described embodiment, the four anchor values are the security risk, the number of incidents, the patch application rate, and the update recommendation level, but it is not limited thereto. For example, as the anchor value, a risk evaluation value such as the damage amount of security damage may be included.
[0058] <Modification Example 3> Also, for example, in the above-described embodiment, the information management server 10 creates a message for promoting the implementation of unimplemented security measures including a graph of anchor values, but it is not limited thereto. For example, the information management server 10 may create a message for promoting the implementation of unimplemented security measures with a text according to the user's behavior change stage, including a graph of anchor values. By doing so, the information management server 10 can further improve the acclimation of the user to updates and maintain the update rate.
[0059] <Modification Example 4> Also, for example, in the above-described embodiment, the information management server 10 creates and distributes to the user terminal 20 a message including a graph in which the anchor value is set to a value equal to or greater than a normal value (predetermined value) at the timing of creating a message for requesting the implementation of an item of unimplemented security measures, but it is not limited thereto. For example, when the user implements unimplemented security measures, the information management server 10 may distribute to the user terminal 20 a graph of the anchor value returned to the normal value (predetermined value).
[0060] Note that according to the present embodiment, for example, since the implementation rate of security measures by the user himself / herself can be improved, it is possible to contribute to Goal 9 of the Sustainable Development Goals (SDGs) led by the United Nations, "Build resilient infrastructure, promote sustainable industrialization and foster innovation."
[0061] Although the embodiments of the present invention have been described above, the present invention is not limited to the above-described embodiments. Also, the effects described in the above embodiments are merely an enumeration of the most preferable effects resulting from the present invention, and the effects of the present invention are not limited to those described in the embodiments.
[0062] The message distribution method by the management system 1 is realized by software. When realized by software, the program constituting this software is installed in an information processing apparatus (computer). Further, these programs may be recorded on a removable medium such as a CD-ROM and distributed to users, or may be distributed by being downloaded to the user's computer via a network. Furthermore, these programs may be provided to the user's computer as a Web service via a network without being downloaded.
Explanation of Reference Numerals
[0063] 1 Management system 10 Information management server (message distribution device) 11 Control unit 13 Storage unit 20 User terminal 111 Anchor setting unit 112 Terminal information acquisition unit 113 Questionnaire distribution unit 114 Questionnaire result acquisition unit 115 Anchor distribution unit 116 Stage determination unit 117 Message creation unit 118 Message distribution unit 119 Message response acquisition unit 131 Terminal distribution condition 132 Message 133 Distribution rule 134 Terminal distribution setting log 135 Terminal information log 136 Questionnaire log 137 Message distribution log 138 Graph generation information 139 Graph reference information 140 Anchor value
Claims
1. An anchor setting unit that acquires and sets security information related to security in advance and calculates a plurality of anchor values based on the set security information; A terminal information acquisition unit that acquires terminal information including the implementation status of security measures in the user terminal; A questionnaire distribution unit that creates a questionnaire regarding the plurality of anchor values and distributes the created questionnaire to the user terminal; A questionnaire result acquisition unit that acquires an answer to the questionnaire from the user terminal and determines a graph of anchor values to be presented to the user terminal among the plurality of anchor values based on the answer to the questionnaire; An anchor distribution unit that distributes the determined graph of anchor values to the user terminal; A message creation unit that creates a message for requesting implementation of items of unimplemented security measures including a graph in which the anchor values of the determined graph are set to a predetermined value or more based on the terminal information; A message distribution unit that distributes the created message to the user terminal; A message answer acquisition unit that acquires an answer including whether or not the item has been implemented in response to the distributed message; A message distribution device comprising the above.
2. The message distribution unit sets the anchor value to a predetermined value or more at the timing of distributing the message. The message distribution device according to claim 1.
3. A stage determination unit that determines the stage of change in the user's behavior of the user terminal with respect to security measures based on the answer to the questionnaire and the terminal information is provided, The questionnaire result acquisition unit determines the graph of anchor values based on the stage of change in the user's behavior. The message distribution device according to claim 1 or claim 2.
4. When the graph of anchor values determined based on the answer to the questionnaire and the graph of anchor values determined based on the stage of change in the user's behavior are different, the questionnaire result acquisition unit prioritizes the graph of anchor values determined based on the answer to the questionnaire. The message distribution device according to claim 3.
5. The plurality of anchor values are at least any one of security risk, number of incidents, patch application rate, or update recommendation degree. The message distribution device according to claim 1 or claim 2.
6. An anchor setting step of acquiring and setting security information related to security in advance, and calculating a plurality of anchor values based on the set security information; A terminal information acquisition step of acquiring terminal information including the implementation status of security measures in a user terminal; A questionnaire distribution step of creating a questionnaire regarding the plurality of anchor values and distributing the created questionnaire to the user terminal; A questionnaire result acquisition step of acquiring an answer to the questionnaire from the user terminal and determining a graph of the anchor values to be presented to the user terminal among the plurality of anchor values based on the answer to the questionnaire; An anchor distribution step of distributing the determined graph of the anchor values to the user terminal; A message creation step of creating a message for requesting implementation of items of unimplemented security measures including a graph in which the anchor values of the determined graph are set to a predetermined value or more based on the terminal information; A message distribution step of distributing the created message to the user terminal; A message answer acquisition step of acquiring an answer including whether or not the item has been implemented with respect to the distributed message; A message distribution method executed by a computer.
7. A message distribution program for causing a computer to function as the message distribution device according to Claim 1 or Claim 2.
Citation Information
Patent Citations
JP1975006941A
Security information distribution method and security information distribution server
JP2003256370A