Information processing apparatus and information processing method, and security program
The information processing apparatus addresses the challenge of managing multiple personal computers with identical terminal information by using configuration files to assign unique identifiers, ensuring secure and efficient operation log tracking.
Patent Information
- Application Number
- JP2023219923
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-12-26
- Publication Date
- 2025-07-08
AI Technical Summary
In companies with multiple sites, personal computers with the same terminal information (such as computer names and account names) are managed as a single entity, leading to confusion and difficulty in distinguishing between them.
An information processing apparatus that determines the existence of a configuration file, acquires setting information from it, and creates an operation log with unique terminal information, such as a domain name, to distinguish between personal computers with the same terminal information.
Enables effective management of multiple personal computers with the same terminal information by assigning unique identifiers, allowing for secure and convenient operation log tracking without affecting other computers.
Smart Images

Figure 2025102463000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to an information processing apparatus, an information processing method, and a security program.
Background Art
[0002] Recently, digitization of information has advanced, and employees have increased their work using personal computers. Therefore, in order to verify productivity in personal computer work, a system has been proposed that can obtain the operation history of a personal computer such as file generation and network access, and visualize the work. Patent Document 1 describes an information analysis system that inputs the operation history of a user on each of a plurality of terminal devices, obtains the file creation time and the file usage time from the operation history, and analyzes and outputs the utilization status of the file based on them.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] In these systems, when managing employees' personal computers, PC terminal information such as computer names, account names, and domain names is used to generate and manage unique management information. However, in a company with multiple sites, it is conceivable that the computer name and account name are the same across all sites and the computer does not participate in the domain. In such a case, there is a problem that a plurality of personal computers with the same terminal information exist at multiple sites, and the personal computers at multiple sites are managed as the same personal computer.
[0005] The present invention has been made in view of the above problems, and an object thereof is to provide a technique capable of managing a plurality of personal computers having the same terminal information.
Means for Solving the Problem
[0006] To achieve the above object, an information processing apparatus according to an aspect of the present invention has the following configuration. That is, An information processing apparatus, a determination means for determining whether a predetermined file exists or not, an acquisition means for acquiring setting information stored in the predetermined file determined to exist by the determination means, a creation means for creating an operation log in which at least a part of terminal information included in an operation history that is a history of operations executed in the information processing apparatus is used as the setting information acquired by the acquisition means, characterized by comprising.
Advantages of the Invention
[0007] According to the present invention, there is an effect that a plurality of personal computers with the same terminal information can be managed at a plurality of bases.
[0008] Other features and advantages of the present invention will become apparent from the following description with reference to the accompanying drawings. In the accompanying drawings, the same or similar components are denoted by the same reference numerals.
Brief Description of the Drawings
[0009] The accompanying drawings are included in the specification, form a part thereof, show embodiments of the present invention, and are used to explain the principles of the present invention together with the description.
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
Figure 11
Figure 12
Figure 13
Mode for Carrying Out the Invention
[0010] Hereinafter, embodiments of the present invention will be described in detail with reference to the accompanying drawings. Note that the following embodiments do not limit the invention according to the claims. Although a plurality of features are described in the embodiments, not all of these plurality of features are essential for the invention, and the plurality of features may be arbitrarily combined. Further, in the accompanying drawings, the same or similar configurations are denoted by the same reference numerals, and duplicate explanations are omitted.
[0011] [Embodiment 1] First, the configuration of the information processing system according to Embodiment 1 will be described with reference to the system configuration diagram of FIG. 1.
[0012] FIG. 1 is a diagram showing the configuration of the information processing system according to Embodiment 1 of the present invention.
[0013] This information processing system has computers, that is, information processing apparatuses 110 and 120, and each information processing apparatus is connected to a network 130 such as a LAN or the Internet. Hereinafter, the information processing apparatus 110 will be referred to as a client terminal apparatus, and the information processing apparatus 120 will be referred to as a server apparatus. Note that there may be a plurality of client terminal apparatuses 110 and server apparatuses 120. Also, the client terminal apparatus 110 and the server apparatus 120 may be any apparatuses as long as they can execute each process described later that an information processing apparatus performs, such as a PC or a mobile terminal apparatus. Further, although the client terminal apparatus 110 is connected via the network 130, it may be a stand-alone type without using the network 130.
[0014] Also, the information processing system may be configured to use a thin client (for example, terminal service, etc.). A thin client is a system that enables an information processing apparatus to remotely connect to a server apparatus and execute an application program on the server apparatus using a virtual desktop environment generated on the server apparatus. Also, the network 130 may be either wired or wireless.
[0015] FIG. 2 is a block diagram for explaining the hardware configuration of the client terminal apparatus 110 according to Embodiment 1.
[0016] The CPU (Central Processing Unit) 201 controls the operation of the entire apparatus by executing various processes using computer programs and data stored in the RAM 202 and the ROM 203, and also executes each process described later.
[0017] The RAM (Random Access Memory) 202 has an area for temporarily storing a computer program and data loaded and expanded from the storage device 206, and an area for temporarily storing various data received from external devices via the I / F (Interface) 207. Furthermore, the RAM 202 also has a work area used when the CPU 201 executes various processes. In this way, the RAM 202 can appropriately provide various storage areas.
[0018] The ROM (Read Only Memory) 203 stores the setting data of this device, the boot program, and the like.
[0019] The operation unit 204 includes a pointing device, a keyboard, and the like, and various instructions can be input to the CPU 201 by the operator of this device operating it.
[0020] The display unit 205 is, for example, an organic EL or a liquid crystal display, and displays the processing result by the CPU 201 as an image, characters, or the like. The storage device 206 is a large-capacity storage device represented by, for example, a hard disk drive (HDD) device. The operating system (OS) and computer programs and data for causing the CPU 201 to execute each process described later as what this device does are stored in this storage device 206. This computer program includes security software (security program) 211. The security software 211 is a program for security management to ensure the security of the data and programs of the client terminal 110. The security software 211 has functions such as acquiring the history of the user's personal computer operations, restricting the connection of the device according to the setting of whether the device can be connected, and restricting communication according to the setting of whether communication is possible.
[0021] The computer programs and data stored in the memory device 206 are appropriately expanded into the RAM 202 according to the control by the CPU 201 and become the processing targets by the CPU 201.
[0022] The I / F 207 is for connecting this device to the above-mentioned network 130, and this device can perform data communication with an external device connected to the network 130 via this I / F 207.
[0023] Each of the above units is connected to the bus 208.
[0024] FIG. 3 is a block diagram for explaining the hardware configuration of the server device 120 according to Embodiment 1. It is assumed that this hardware configuration is the same as the hardware configuration of the client terminal device 110 described with reference to FIG. 2. That is, the CPU 301 of the server device 120 uses the computer programs and data stored in the memory device 306 of the server device 120 to perform data communication with an external device via the I / F 307 of the server device 120 and execute each process described later as being performed by the server device 120.
[0025] The CPU 301 executes various processes using the computer programs and data expanded in the RAM 302, thereby controlling the operation of the entire device and executing each process described later as what the device does. The RAM 302 has an area for temporarily storing computer programs and data loaded from the storage device 306, and an area for temporarily storing various data received from external devices via the I / F (interface) 307. Furthermore, the RAM 302 also has a work area used when the CPU 301 executes various processes. In this way, the RAM 302 can appropriately provide various areas. The ROM 303 stores setting data, boot programs, etc. of the device. The operation unit 304 includes a pointing device, a keyboard, etc., and various instructions can be input to the CPU 301 by the operator of the device operating it. The display unit 305 can display the processing results by the CPU 301 as images, characters, etc. The storage device 306 is a large-capacity storage device typified by, for example, a hard disk drive device. The I / F 307 is for connecting the device to the above network 130, and the device can perform data communication with external devices connected to the network 130 via this I / F 307. Each of the above units is connected to the bus 308.
[0026] Incidentally, instead of the storage device 306 of the server device 120 collectively processing and storing the operation logs of the personal computers transmitted from the client terminal device 110, each client terminal device 110 may hold its own operation log in its own storage device 206. However, in such a case, the server device 120 is not essential.
[0027] <Processing by Security Software 211> Next, the security software 211 stored in the storage device 206 of the client terminal device 110 will be described using the flowchart of FIG. 4. Here, an example will be described in which the domain name, which is information indicating at least a part of the terminal information included in the personal computer operation log, is replaced with arbitrary information.
[0028] The setting file described later stores setting information that is the domain information of the client terminal device 110, including affiliation information of a company or the like, and is stored at an arbitrary location of the client terminal device 110 at the time of installation or at an arbitrary timing after installation.
[0029] FIG. 4 is a flowchart for explaining the processing performed by the client terminal device 110 according to Embodiment 1 when executing the security software 211. The processing shown in this flowchart is realized by the CPU 201 of the client terminal device 110 executing the security software 211.
[0030] First, when the security software 211 is started in S401, the process proceeds to S402, and it is determined whether a setting file (a predetermined file) is stored, for example, in the installation folder of the security software 211 or an arbitrary location. If it is determined that it is not stored here, the process proceeds to S403, and the CPU 201 acquires a domain name using, for example, the Windows (registered trademark) standard API (Application Programming Interface). Then, the process proceeds to S404, and the CPU 201 creates a personal computer operation history based on a user operation or the like. Then, the process proceeds to S405, and the CPU 201 assigns the domain name acquired in S403 to the personal computer operation history. Then, the process proceeds to S406, and the CPU 201 writes the operation log (operation history with the domain name assigned) created in this way to a log file, and ends this process.
[0031] On the other hand, when it is determined in S402 that there is a configuration file, the process proceeds to S407, and the CPU 201 reads the configuration information in the configuration file using a Windows standard API such as GetPrivateProfileString. Then, the process proceeds to S408, and the CPU 201 creates a personal computer operation history in the same manner as in S404. Then, the process proceeds to S409, and the CPU 201 creates a personal computer operation log with the configuration information obtained in S407 added as the domain name. Then, the process proceeds to S406, and the CPU 201 writes the operation log thus created to a log file and ends this process. Note that in S409, regardless of the information included in the operation history, the operation log may be configured to be rewritten based on the configuration information in the configuration file.
[0032] FIG. 5 is a diagram showing an example of a configuration file stored in the client terminal device 110 according to Embodiment 1.
[0033] Here, the format of the configuration file is shown in the form of an INI file having a file name with the extension ini. However, for example, a config file or the like may be used as long as the format is specified. Also, the string to be replaced may be written in only one line. Here, "Tokyo01" is described as the domain name.
[0034] FIG. 6 is a diagram showing an example of a personal computer operation log when there is no configuration file in S403 of FIG. 4 and the domain name is set by default.
[0035] In FIG. 6, the case where the user does not participate in the domain is shown, and "WorkGr" indicating the initial value (default value) "WORKGROUP" is set as the domain name. Therefore, in this case, this operation log cannot be distinguished from the operation logs of other personal computers having the same terminal information as the terminal information (account name, PC name, domain name, etc.) of this operation log. Also, when not participating in the domain, for example, "PC name" may be set as the domain name, or any arbitrary string may be used.
[0036] FIG. 7 is a diagram showing an example of a personal computer operation log when the domain name is set as the setting information of the setting file in S409 of FIG. 4.
[0037] In FIG. 7, the domain name “WorkGr” in FIG. 6 has become “Tokyo01” read from the setting file in the personal computer operation log. Therefore, in this case, this operation log can be identified from the operation logs of at least other PCs with different domain names.
[0038] In addition, in the above Embodiment 1, it is assumed that the setting file is stored in the installation folder, but the present invention is not limited to this, and it may be stored in any storage device (storage unit) accessible by the CPU 201.
[0039] The domain name may be a character string that can identify the terminal, for example, set as the name of the business office.
[0040] Furthermore, there may be a configuration in which a plurality of LANs to which the client terminal device 110 is connected are connected to the server device 120 via the network 130. FIG. 13 is a diagram showing an example in which a LAN used in the Tokyo area (hereinafter referred to as Tokyo LAN) and a LAN used in the Kyushu area (hereinafter referred to as Kyushu LAN) are connected to a server device through the network 130. A setting file is stored in the client terminal device 110 connected to the Tokyo LAN such that the domain name assigned to the operation history is “Tokyo01”. A setting file is stored in the client terminal device 110 connected to the Kyushu LAN such that the domain name is “Kyushu01”. With such a configuration, even when there are a plurality of LANs, the operation logs of other PCs connected to different LANs can be identified.
[0041] As described above, according to Embodiment 1, even if there are multiple personal computers, such as a personal computer name, an account name, and a personal computer that cannot be uniquely managed without participating in a domain, they can be managed as separate personal computers by placing a configuration file. Furthermore, while achieving both security and user convenience, operation logs can be obtained without affecting other personal computers. Specifically, by setting the domain name of the operation log according to the content of the configuration file when the security software starts, there is an effect that operation logs with the same account name and PC name can be distinguished.
[0042] In the above Embodiment 1, as operation logs, operation history (including the operation type of the file, the operation date and time, the file name or program name, and the operation content including the operation content) and terminal information (user's account name, domain name, PC name) are stored, but the present invention is not limited to this. In addition to this, for example, information such as email sending and receiving, PC shutdown, and PC startup may also be included. Also, the terminal information of the PC may be, for example, the IP address or MAC address of the PC.
[0043] Also, the domain name, PC name, user name (user account), etc. included in the above operation log are terminal information unique to the client terminal device.
[0044] [Embodiment 2] In Embodiment 2, the case where the management information of the client terminal device 110 is transmitted to the server device 120 will be described. In such a case, a series of processes performed by the client terminal device 110 to start communication with the server device 120 will be described with reference to the flowchart of FIG. 8. Note that the configuration of the system according to Embodiment 2 and the hardware configurations of the client terminal device 110 and the server device 120 are the same as those in the aforementioned Embodiment 1, so the description thereof will be omitted. Here, the management information is information used by the server device for log management of the client terminal device, including, in addition to the terminal information unique to the client terminal device according to Embodiment 1, version information of the security software, etc.
[0045] FIG. 8 is a flowchart for explaining the processing performed by the client terminal device 110 according to Embodiment 2 when executing the security software 211. The processing shown in this flowchart is realized by the CPU 201 of the client terminal device 110 executing the security software 211. In FIG. 8, the same processing steps as those shown in the flowchart of FIG. 4 described above are assigned the same step numbers, and the explanations related to these same processing steps are omitted.
[0046] If the configuration file (predetermined file) is not saved in S402, in S801, the CPU 201 generates a communication command (command information) including management information including the computer name, account name, and domain name acquired in S403 to be sent to the server device 120. Then, it proceeds to S802, and the CPU 201 transmits the communication command generated in S801 to the server device 120.
[0047] On the other hand, when it is determined in S402 that there is a configuration file, it proceeds to S407, and the CPU 201 acquires the configuration information in the configuration file. Then, it proceeds to S803, and the CPU 201 generates a communication command including management information to which the configuration information acquired from the configuration file is assigned as the domain name. Then, it proceeds to S802, and the CPU 201 transmits the communication command generated in S803 to the server device 120. In other words, in S803, a communication command that should be generated by the same processing as in S801 is generated by rewriting with the configuration information in the configuration file.
[0048] This makes it possible to change the management information of the computers managed by the server device 120 to unique information.
[0049] Also, since the management information of the computers is made unique, it becomes possible to restrict the connection of the devices connected to the client terminal device 110 according to the setting of whether the device can be connected, or to restrict the communication according to the setting of whether communication is possible. Note that the management information of the client terminal device 110 includes information such as the PC name, domain name, and version.
[0050] As described above, according to Embodiment 2, it is possible to change the management information of the personal computer managed by the server terminal into unique information. Further, since the management information of the personal computer has become unique, it is possible to restrict the connection of the device connected to the client terminal device according to the setting of whether or not the device can be connected, or to restrict the communication according to the setting of whether or not communication is possible.
[0051] [Embodiment 3] In this Embodiment 3, the case where a plurality of accounts are created in the client terminal device 110 will be described with reference to the flowchart of FIG. 9. Note that since the configuration of the system according to Embodiment 3 and the hardware configurations of the client terminal device 110 and the server device 120 are the same as those in the aforementioned Embodiment 1, the description thereof will be omitted.
[0052] FIG. 9 is a flowchart for explaining the processing performed by the client terminal device 110 according to Embodiment 3 when executing the security software 211. Note that the processing shown in this flowchart is realized by the CPU 201 of the client terminal device 110 executing the security software 211. In the flowchart of FIG. 9, the same processing as that in FIG. 4 described above is denoted by the same reference numerals, and the description of those processes will be omitted.
[0053] In S901, the CPU 201 acquires the content of the setting file in FIG. 10. Then, in S408, an operation history of the personal computer is created in the same manner as S404 and S408 in FIG. 4 described above. Then, the process proceeds to S902, and the CPU 201 determines the domain name corresponding to the account name of the logged-in user according to the content of the setting file acquired in S901, creates an operation log storing the domain name, and proceeds to S406.
[0054] FIG. 10 is a diagram showing an example of the setting file stored in the client terminal device 110 according to Embodiment 3.
[0055] Here, the login account name for the client terminal device 110 is described on the left side of the equal sign (=), and the domain name of the user is described on the right side.
[0056] FIG. 11 is a diagram showing an example of a personal computer operation log in Embodiment 3 where there is no configuration file and the domain name remains as it is when the user does not participate in the domain or does not have a domain name.
[0057] In the example of FIG. 11, the domain name of the logged-in user's account name (admin2) remains (WorkGr) when the user does not participate in the domain or does not have a domain name.
[0058] FIG. 12 is a diagram showing an example of a personal computer operation log in Embodiment 3 where there is a configuration file and the domain name is changed according to the content of the configuration file.
[0059] In the example of FIG. 12, the domain name of the logged-in user's account name (admin2) is changed from "WorkGr" to "Kyushu01" according to the content of the configuration file in FIG. 10.
[0060] In addition, in Embodiment 3, the case where multiple accounts are created on the client terminal device 110 has been described, but the same processing can also be executed in an environment where multiple people can log in to the client terminal device 110 simultaneously.
[0061] As described above, according to the third embodiment, even when a plurality of users who cannot be uniquely managed, such as account names and non-participating domains, use a personal computer, they can be managed as separate users by placing a configuration file. Furthermore, while achieving both security and user convenience, operation logs can be obtained without affecting other users. Specifically, when the security software starts, by setting the domain name of the operation log of the logged-in user according to the content of the configuration file, there is an effect that the operation logs of users with the same account name can be distinguished.
[0062] (Other embodiments) The present invention can also be realized by supplying a program that realizes one or more functions of the above-described embodiments to a system or device via a network or a storage medium, and having one or more processors in the computer of the system or device read and execute the program. It can also be realized by a circuit (for example, ASIC) that realizes one or more functions.
[0063] This specification and drawings disclose the following information processing apparatus, information processing method, and security program.
[0064] [Item 1] An information processing apparatus, Determination means for determining whether a predetermined file exists in the information processing apparatus; Acquisition means for acquiring information stored in the predetermined file determined to exist by the determination means; Creation means for creating an operation history in which at least a part of the terminal information included in the operation history, which is a history of operations executed in the information processing apparatus, is the information acquired by the acquisition means; An information processing apparatus characterized by having the above.
[0065] [Item 2] An information processing apparatus, Determination means for determining whether a predetermined file exists in the information processing apparatus; An acquisition means for acquiring information stored in the predetermined file determined to exist by the determination means; A creation means for creating command information in which the information acquired by the acquisition means is added to command information to be transmitted to a server device that manages the information processing device; A transmission means for transmitting the created command information to the server device; An information processing device characterized by comprising:
[0066] [Item 3] The information processing device according to item 1 or 2, wherein the determination means determines based on whether a file with a predetermined file name exists in a predetermined folder.
[0067] [Item 4] The information processing device according to any one of items 1 to 3, wherein the predetermined file has a file name with an.ini extension.
[0068] [Item 5] The information processing device according to any one of items 1 to 4, wherein the information stored in the predetermined file includes the affiliation information of the information processing device.
[0069] [Item 6] The information processing device according to item 5, wherein the affiliation information is a domain name.
[0070] [Item 7] The information processing device according to any one of items 1 to 6, wherein the operation history includes terminal information of the information processing device, a user account name, an operation date and time, and operation details.
[0071] [Item 8] An information processing device, a determination means for determining whether a predetermined file exists in the information processing device; an acquisition means for acquiring information corresponding to a logged-in user stored in the predetermined file determined to exist by the determination means; Creating means for creating an operation history in which at least a part of the terminal information included in the operation history, which is a history of operations executed in the information processing apparatus, is used as the information acquired by the acquisition means; An information processing apparatus, characterized by comprising the above.
[0072] [Item 9] The information processing apparatus according to item 8, wherein the determination means determines based on whether a file with a predetermined file name exists in a predetermined folder.
[0073] [Item 10] The information processing apparatus according to item 8 or 9, wherein the predetermined file has a file name with an.ini extension.
[0074] [Item 11] The information processing apparatus according to any one of items 8 to 10, wherein the predetermined file includes a user account and affiliation information corresponding to the account.
[0075] [Item 12] The information processing apparatus according to item 11, wherein the affiliation information is a domain name.
[0076] [Item 13] The information processing apparatus according to any one of items 8 to 12, wherein the operation history includes terminal information of the information processing apparatus, a user account name, an operation date and time, and operation content.
[0077] [Item 14] An information processing method in an information processing apparatus, comprising: A determination step of determining whether a predetermined file exists in the information processing apparatus; An acquisition step of acquiring information stored in the predetermined file determined to exist in the determination step; A creating step of creating an operation log in which at least a part of the terminal information included in the operation log, which is a history of operations executed in the information processing apparatus, is used as the information acquired in the acquiring step; An information processing method characterized by comprising the steps of:
[0078] [Item 15] An information processing method in an information processing apparatus, comprising: A determining step of determining whether a predetermined file exists in the information processing apparatus; An acquiring step of acquiring information stored in the predetermined file determined to exist in the determining step; A creating step of creating command information in which the information acquired in the acquiring step is added to command information to be transmitted to a server apparatus that manages the information processing apparatus; A transmitting step of transmitting the created command information to the server apparatus; An information processing method characterized by comprising the steps of:
[0079] [Item 16] An information processing method in an information processing apparatus, comprising: A determining step of determining whether a predetermined file exists in the information processing apparatus; An acquiring step of acquiring information corresponding to a logged-in user stored in the predetermined file determined to exist in the determining step; A creating step of creating an operation log in which at least a part of the terminal information included in the operation log, which is a history of operations executed in the information processing apparatus, is used as the information acquired in the acquiring step; An information processing method characterized by comprising the steps of:
[0080] [Item 17] A security program executed by an information processing apparatus, the information processing apparatus performing: A determining step of determining whether a predetermined file exists in the information processing apparatus; An acquiring step of acquiring information stored in the predetermined file determined to exist in the determining step; A creating step of creating an operation log in which at least a part of the terminal information included in the operation log, which is a history of operations executed in the information processing apparatus, is used as the information acquired in the acquiring step; A security program characterized by causing the above to be executed.
[0081] [Item 18] A security program executed by an information processing apparatus, the information processing apparatus being caused to: A determining step of determining whether a predetermined file exists in the information processing apparatus; An acquiring step of acquiring information stored in the predetermined file determined to exist by the determining step; A creating step of creating command information in which the information acquired in the acquiring step is added to command information to be transmitted to a server apparatus that manages the information processing apparatus; A transmitting step of transmitting the created command information to the server apparatus; A security program characterized by causing the above to be executed.
[0082] [Item 19] A security program executed by an information processing apparatus, the information processing apparatus being caused to: A determining step of determining whether a predetermined file exists in the information processing apparatus; An acquiring step of acquiring information corresponding to a logged-in user stored in the predetermined file determined to exist by the determining step; A creating step of creating an operation log in which at least a part of the terminal information included in the operation log, which is a history of operations executed in the information processing apparatus, is used as the information acquired in the acquiring step; A security program characterized by causing the above to be executed.
[0083] The present invention is not limited to the above-described embodiments, and various changes and modifications can be made without departing from the spirit and scope of the present invention. Therefore, the following claims are appended to disclose the scope of the present invention.
Explanation of Reference Numerals
[0084] 110… Client terminal device, 120… Server device, 130… Network, 211… Security software
Claims
1. An information processing apparatus, a determination means for determining whether a predetermined file exists or not; an acquisition means for acquiring setting information stored in the predetermined file determined to exist by the determination means; a creation means for creating an operation log in which at least a part of terminal information included in an operation history that is a history of operations executed in the information processing apparatus is used as the setting information acquired by the acquisition means; An information processing apparatus, characterized by comprising the above.
2. An information processing apparatus, a determination means for determining whether a predetermined file exists in the information processing apparatus or not; an acquisition means for acquiring setting information stored in the predetermined file determined to exist by the determination means; a creation means for creating command information in which the setting information acquired by the acquisition means is added to command information to be transmitted to a server apparatus that manages the information processing apparatus; a transmission means for transmitting the created command information to the server apparatus; An information processing apparatus, characterized by comprising the above.
3. The information processing apparatus according to claim 1 or 2, wherein the setting information is information on a domain name.
4. The information processing apparatus according to claim 1, wherein the terminal information is a domain name.
5. An information processing apparatus, a determination means for determining whether a predetermined file exists in the information processing apparatus or not; an acquisition means for acquiring information corresponding to a logged-in user stored in the predetermined file determined to exist by the determination means; a creation means for creating an operation history in which at least a part of terminal information included in an operation history that is a history of operations executed in the information processing apparatus is used as the information acquired by the acquisition means; An information processing apparatus, characterized by comprising the above.
6. The information processing apparatus according to claim 5, wherein the determination means determines based on whether a file with a predetermined file name exists in a predetermined folder.
7. The information processing apparatus according to claim 5, wherein the predetermined file includes a user's account and affiliation information corresponding to the account.
8. The information processing apparatus according to claim 7, wherein the affiliation information is a domain name.
9. An information processing method in an information processing apparatus, a determination step for determining whether a predetermined file exists in the information processing apparatus or not; An acquisition step of acquiring setting information stored in the predetermined file determined to exist by the determination step; A creation step of creating an operation history in which at least a part of the terminal information included in the operation history that is a history of operations executed in the information processing apparatus is set as the setting information acquired by the acquisition step; An information processing method characterized by comprising the above.
10. A security program executed by an information processing apparatus, the information processing apparatus being caused to: A determination step of determining whether or not a predetermined file exists in the information processing apparatus; An acquisition step of acquiring setting information stored in the predetermined file determined to exist by the determination step; A creation step of creating an operation history in which at least a part of the terminal information included in the operation history that is a history of operations executed in the information processing apparatus is set as the setting information acquired in the acquisition step; A security program characterized by causing the above to be executed.
Citation Information
Patent Citations
Information analysis apparatus, information analysis method, program, and information analysis system
JP2020181429A