Communication system and aggregation device

The communication system automates the aggregation and provision of IP addresses for web filtering, addressing the inefficiencies in managing relay device whitelists by reducing administrative effort and ensuring secure, efficient whitelist management.

JP2025103262APending Publication Date: 2025-07-09SAXA
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2023220537
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-12-27
Publication Date
2025-07-09

AI Technical Summary

Technical Problem

Existing relay devices require significant administrative effort to manage whitelists for web filtering, especially when using IP addresses, as network administrators must manually investigate and register IP addresses corresponding to URLs, which is cumbersome and inefficient.

Method used

A communication system comprising relay devices and an aggregation device that collects and aggregates connection destination information, including IP addresses, to provide it for use in whitelists, reducing the administrative workload by automating the process.

Benefits of technology

The system significantly reduces the workload for network administrators by automating the aggregation and provision of IP addresses for web filtering, ensuring efficient and secure whitelist management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025103262000001_ABST
    Figure 2025103262000001_ABST
Patent Text Reader

Abstract

To aggregate and provide connection destination information including a connection destination IP address as connection destination information to be used in a whitelist for web filtering.SOLUTION: Each of relay devices 20 acquires connection destination information including a connection destination IP address of a subordinate information terminal 21 by name resolution at a DNS server 30 on a communication network NW. An aggregation device 10 aggregates the connection destination information acquired by the respective relay devices 20, registers the connection destination information including the connection destination IP address in an aggregation list 14A, and provides the connection destination information including the IP address to be used in a whitelist for web filtering based on the aggregation list 14A.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a technique for aggregating and providing destination information used when performing Web filtering on access from an information terminal to a destination on a communication network.

Background Art

[0002] In relay devices such as Unified Threat Management devices and Gateway devices that relay-connect information terminals connected to a LAN to the Internet, Web filtering using a whitelist may be applied as a security measure when accessing a destination (website) on the Internet from a subordinate information terminal. A whitelist is a list in which destination information indicating a destination with recognized security is registered. The relay device collates the destination information of the destination included in the HTTP request transmitted from the subordinate information terminal with the whitelist, and transmits the HTTP request to the Internet side only when the destination information is registered in the whitelist, and cancels the HTTP request when it is not registered.

[0003] By such Web filtering using a whitelist in a relay device, it becomes possible to prevent access from a subordinate information terminal to a dangerous destination. At this time, generally, the Web filtering of the relay device is always applied to all information terminals connected to the subordinate, so the destinations accessible from the information terminal are restricted, and some users may find it difficult to use. Conventionally, in order to solve such problems, Patent Document 1 has proposed a technique of applying Web filtering only during a time zone preset for each user, or notifying the user of an alarm before the time zone arrives.

Prior Art Documents

Patent Documents

[0004]

Patent Document 1

[0005] Since setting a whitelist for a relay device requires high expertise, for example, in a company, a dedicated network administrator is responsible for setting it. When permitting access to a new connection destination, the network administrator logs in to the relay device from the administrator terminal and additionally registers the connection destination information of the new connection destination in the whitelist. In recent years, as connection destination information to be registered in a whitelist, a URL (Uniform Resource Locator) has been used, and relay devices that can use wildcards in URLs are becoming common. If wildcards can be used in URLs, a plurality of subdomains following the parent domain of the URL or a plurality of similar parent domains can be collectively registered in the whitelist with a single connection destination information. This can not only significantly reduce the size of the whitelist but also greatly reduce the workload of the network administrator required for whitelist registration.

[0006] However, there are still relay devices that can register only connection destination information using an IP address in the whitelist. Also, when performing web filtering on an information terminal such as a PC, there are cases where only a whitelist based on an IP address can be used. In such cases, it is necessary for the network administrator to investigate in advance the IP address corresponding to the URL, but depending on the connection destination, only a URL with a wildcard may be publicly available. For this reason, it is necessary to investigate the IP address in advance with a specific tool, and there is a problem that the workload on the network administrator is large.

[0007] The present invention is for solving such problems, and an object of the present invention is to provide an aggregation providing technique that can aggregate connection destination information including the IP address of a connection destination and provide it as connection destination information to be used in a whitelist for web filtering.

Means for Solving the Problem

[0008] To achieve such an object, a communication system according to the present invention includes a plurality of relay devices and an aggregation device connected to the plurality of relay devices via a communication network. Each of the plurality of relay devices is configured to obtain connection destination information including the IP address of the connection destination of the subordinate information terminals by name resolution in the DNS server of the communication network. The aggregation device registers connection destination information including the IP address of the connection destination in an aggregation list by aggregating the connection destination information obtained in each of the relay devices, and is configured to provide connection destination information including the IP address for use in a white list for Web filtering based on the aggregation list.

[0009] In one configuration example of the communication system according to the present invention, when the aggregation device provides the connection destination information registered in the aggregation list, for the connection destination information obtained by the first relay device to which Web filtering is applied with a white list among the plurality of relay devices, only the connection destination information that is obtained repeatedly by the first relay devices in a number equal to or greater than a first threshold is provided.

[0010] In one configuration example of the communication system according to the present invention, when the aggregation device provides the connection destination information registered in the aggregation list, for the connection destination information obtained by the second relay device to which Web filtering is not applied with a white list among the plurality of relay devices, only the connection destination information that is obtained repeatedly by the second relay devices in a number equal to or greater than a second threshold and for which access to the connection destination is not determined to be dangerous by the second relay device is provided.

[0011] The aggregation device according to the present invention includes a plurality of relay devices and an aggregation device connected to the plurality of relay devices via a communication network. Each of the plurality of relay devices is configured to obtain connection destination information including the IP address of the connection destination of the subordinate information terminals by name resolution in the DNS server of the communication network. The aggregation device used in the communication system is configured to register the connection destination information including the IP address of the connection destination in an aggregation list by aggregating the connection destination information obtained in each of the relay devices, and includes a control unit configured to provide the connection destination information including the IP address for use in a white list for Web filtering based on the aggregation list.

Effect of the Invention

[0012] According to the present invention, it is possible to provide connection destination information including an IP address as connection destination information used in a white list for Web filtering.

Brief Description of the Drawings

[0013]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Embodiments for Carrying Out the Invention

[0014] Next, an embodiment of the present invention will be described with reference to the drawings. [Communication System] First, with reference to the block diagram of FIG. 1, the communication system 1 according to the first embodiment of the present invention will be described. This communication system 1 is composed of a plurality of relay devices 20 installed at different sites and an aggregation device 10 connected to these relay devices 20 via a communication network NW such as the Internet. The communication network NW is connected to a DNS (Domain Name System) server for name resolution that converts the URL of the connection destination into an IP address and servers 40 such as server A and server B that are the connection destinations.

[0015] The relay devices 20 (20A, 20B) as a whole consist of communication control devices such as a unified threat management device (Unified Threat Management, hereinafter referred to as UTM device) and a gateway device (Gateway). As shown in FIG. 1, the relay devices 20A and 20B are installed at sites A and B respectively, relay-connect the information terminals 21 connected below to the communication network NW, and are configured to implement security measures such as Web filtering using a white list and virus checking for data communication on the information terminals 21 via the communication network NW.

[0016] The aggregation device 10 as a whole consists of a server device such as a Web server and is connected to these relay devices 20A and 20B via the communication network NW. The aggregation device 10 is configured to aggregate the connection destination information regarding the connection destinations of the subordinate information terminals 21 obtained by the relay devices 20A and 20B and provide the connection destination information including the IP address used in the white list for Web filtering.

[0017] As shown in FIG. 1, at base B, there is an information terminal 22 connected to the communication network NW in parallel with the relay device 20B. However, such an information terminal 22 often uses a whitelist that uses an IP address instead of a URL as connection destination information. Also, at base C, as a relay device not included in the communication system 1, a relay device 20C is installed with an information terminal 21 connected thereunder, and there are cases where a whitelist that uses an IP address instead of a URL is used as connection destination information. The connection destination information including the IP address provided by the aggregation device 10 can be directly registered in the whitelist by such an information terminal 22 or relay device 20C.

[0018] [Principle of the present invention] The relay device 20 is configured to transfer a DNS request transmitted from the browser of the subordinate information terminal 21 to the DNS server 30 on the communication network NW, and transfer the DNS response returned from the DNS server 30 in response thereto to the requesting information terminal 21. The present invention focuses on the fact that the DNS response relayed by the relay device 20 includes an IP address as connection destination information indicating the connection destination, and the aggregation device 10 aggregates the connection destination information obtained from name resolution messages such as DNS requests and DNS responses at each relay device 20 via the communication network NW, and provides connection destination information including the IP address of the connection destination as connection destination information to be used in the whitelist for web filtering.

[0019] [Aggregation device] With reference to the block diagram of FIG. 2, the configuration of the aggregation device 10 will be described in detail. The aggregation device 10 is provided with a communication I / F 11, an operation input unit 12, a display unit 13, a storage unit 14, and a control unit 15 as main circuit parts.

[0020] [Communication I / F] The communication I / F 11 is connected to the communication network NW via the communication line L, performs data communication with the relay devices 20A and 20B, receives the destination information from the relay devices 20A and 20B, outputs it to the control unit 15, and is configured to provide the destination information obtained by the control unit 15 to the administrator terminal 25 of the network administrator.

[0021] [Operation input unit] The operation input unit 12 consists of an operation input device such as a keyboard or a mouse, and is configured to detect the operator's operation and output it to the control unit 15. [Display unit] The display unit 13 consists of a screen display device such as an LCD, and is configured to display the operation menu and various data output from the control unit 15 on the screen.

[0022] [Storage unit] The storage unit 14 consists of a storage device such as a semiconductor memory or a hard disk, and is configured to store the program 14P used by the control unit 15 and various processing data. The program 14P, by cooperating with the CPU of the control unit 15, realizes various processing units for executing processing such as collection, aggregation, and provision of destination information in the control unit 15. The program 14P is read from an external device or a recording medium (both not shown) and stored in advance in the storage unit 14.

[0023] The main processing data stored in the storage unit 14 includes an aggregation list 14A and a permission list 14B. [Aggregation list] As shown in FIG. 3, the aggregation list 14A is a data list in which destination information is registered for each destination of the information terminal 21. In the example of FIG. 3, for each destination, connection destination information such as a WURL which is a URL corresponding to a wildcard indicating the destination, the URL transmitted in a DNS request at the time of name resolution of the destination, the IP address returned in a DNS response at the time of name resolution of the destination, and the number of acquisition times for each relay device that acquired the destination is registered respectively.

[0024] For example, if the URLs of servers A and B(40) are "aaa.windowsupdate.com" and "bbb.windowsupdate.com", and the IP addresses are "192.168.1.1" and "192.168.1.2", the URLs notified in the DNS requests for servers A and B will be "aaa.windowsupdate.com" and "bbb.windowsupdate.com" respectively, and the IP addresses returned in the DNS responses will be "192.168.1.1" and "192.168.1.2". Also, when expressing "aaa.windowsupdate.com" and "bbb.windowsupdate.com" as wildcarded URLs, it becomes "*.windowsupdate.com".

[0025] In such a case, when connection destination information regarding servers A and B is notified from relay devices 20A and 20B, two entries #1 and #2 as shown in FIG. 3 are registered in the aggregation list 14A corresponding to these servers A and B. That is, in entry #1, "*.windowsupdate.com", "aaa.windowsupdate.com", and "192.168.1.1" are registered as the WURL, URL, and IP address, respectively, and in entry #2, "*.windowsupdate.com", "bbb.windowsupdate.com", and "192.168.1.2" are registered as the WURL, URL, and IP address, respectively. Also, the number of times the same connection destination information has been notified is registered in the acquisition counts of entries #1 and #2. It is recorded that entry #1 has been notified twice from relay device 20A and entry #2 has been notified once from relay device 20B.

[0026] [Permission List] Generally, since security measures such as web filtering and virus checking are implemented in the relay device 20, the destination information obtained from the name resolution message in the relay device 20 can be determined to be that of a destination with recognized security. However, considering security measure leaks and new destinations, there may be destinations with unrecognized security included. Therefore, it is also necessary to select the destination information provided from the aggregation device 10.

[0027] As shown in FIG. 4, the permission list 14B is a data list in which URLs indicating destinations with recognized security are registered. Therefore, when providing destination information in the aggregation device 10 by referring to the aggregation list 14A, it is possible to determine whether to provide it based on whether the destination is registered in the permission list 14B. In the example of FIG. 4, the URLs “*.windowsupdate.com” and “*.support.apple.com*” are registered in the permission list 14B. These URLs are URLs of well-known websites with recognized security and are publicly available from the site operators.

[0028] [Control Unit] The control unit 15 has a CPU and its peripheral circuits, and by cooperating with the program 14P in the storage unit 14, realizes various processing units for executing processing such as collection, aggregation, and provision of destination information in the control unit 15. The main processing units realized in the control unit 15 include a collection unit 15A, an aggregation unit 15B, and a provision unit 15C.

[0029] [Collection Unit] The collection unit 15A is configured to collect the destination information acquired by the relay devices 20A and 20B via the communication network NW and the communication I / F 11. Regarding the destination information, when the relay devices 20A and 20B acquire the destination information from the name resolution message, the collection unit 15A may collect the information sequentially transmitted from the relay devices 20A and 20B. Alternatively, the relay devices 20A and 20B may temporarily store the destination information acquired from the name resolution message and reply from the relay devices 20A and 20B in response to the collection request periodically transmitted from the collection unit 15A.

[0030] [Aggregation unit] The aggregation unit 15B is configured to register the destination information including the IP address of the destination in the aggregation list 14A by aggregating the destination information collected by the collection unit 15A. As a result, the aggregation list 14A shown in FIG. 3 described above is updated and stored in the storage unit 14.

[0031] [Provision unit] The provision unit 15C is configured to provide the destination information used in the white list for Web filtering based on the aggregation list 14A of the storage unit 14. Regarding the provision method, it may be provided on a homepage or the like to a network administrator who has logged in to the aggregation device 10 through the authentication process, or it may be provided as a downloadable file. Also, in response to an instruction from the network administrator, the URL and source information registered in the aggregation list 14A may be narrowed down and searched, and only the obtained destination information may be provided. Further, it may be notified to a pre-registered network administrator by email. Regarding the email transmission timing, it may be periodic or at the time when the destination information to be provided is updated.

[0032] Also, when providing the destination information registered in the aggregation list 14A by the providing unit 15C, all the destination information may be provided, or only some of the destination information considered useful may be selected and provided. As described above, the destination information obtained from the name resolution message by the relay device 20 may include that of destinations whose security is not recognized. Also, it may include that of destinations that are not accessed very often. Therefore, it may be desirable to exclude the destination information of these destinations.

[0033] At this time, regarding the destination information obtained by the first relay device among the relay devices 20 that applies web filtering with a white list, a certain degree of security is recognized. Also, regarding the destination information obtained repeatedly by these first relay devices, it can be determined that they are accessed at a certain frequency. From such a perspective, the providing unit 15C may be configured to provide only the destination information obtained repeatedly by the first relay devices with a number equal to or greater than the first threshold among the destination information obtained by the first relay devices among the relay devices 20 that apply web filtering with a white list. Thereby, it is possible to select and provide only the destination information with a certain degree of security and accessed at a certain frequency.

[0034] Also, regarding the destination information obtained by the second relay devices among the relay devices 20 that do not apply web filtering with a white list, it is better to consider that the security is relatively low. At this time, the second relay device performs a security check such as a virus check to determine the risk of accessing the destination. Regarding the result of the security check, the collection unit 15A may collect it from the second relay device in the same manner as the destination information. Therefore, regarding the destination information for which access to the destination is not determined to be dangerous, a certain degree of security is recognized. Also, regarding the destination information obtained repeatedly by these second relay devices, it can be determined that they are accessed at a certain frequency.

[0035] From such a perspective, the providing unit 15C may be configured to provide only the destination information obtained from the second relay device among the relay devices 20 to which web filtering is not applied in the whitelist and that is obtained by a second threshold number or more of second relay devices and for which access to the destination is not determined to be dangerous by the second relay device. Thereby, a certain degree of security can be recognized, and only the destination information accessed at a certain frequency can be selected and provided.

[0036] [Operation of the present embodiment] Next, with reference to the sequence diagram of FIG. 5, the operation of the aggregation device 10 according to the present embodiment will be described. Hereinafter, a case will be described as an example in which the aggregation device 10 aggregates the destination information including the IP address acquired by the relay devices 20A and 20B and provides it to the administrator terminal 25, and the whitelist of the relay device 20C is updated from the administrator terminal 25.

[0037] The relay device 20A acquires destination information including the destination IP address from the name resolution message exchanged between the subordinate information terminal 21 and the DNS server 30 (step 100), and notifies the aggregation device 10 via the communication network NW (step 101). Similarly, the relay device 20B acquires destination information including the destination IP address from the name resolution message exchanged between the subordinate information terminal 21 and the DNS server 30 (step 102), and notifies the aggregation device 10 via the communication network NW (step 103). The aggregation device 10 aggregates the destination information from the relay devices 20A and 20B collected by the collection unit 15A in the aggregation unit 15B, and registers it in the aggregation list 14A of the storage unit 14 (step 104).

[0038] Thereafter, in response to the acquisition request notified from the administrator terminal 25 after login authentication (step 110), the aggregation device 10 searches the aggregation list 14A of the storage unit 14 in the provision unit 15C based on the conditions specified in this acquisition request (step 111), and provides the obtained destination information from the communication I / F 11 to the administrator terminal 25 via the communication network NW (step 112). As a result, the destination information provided from the aggregation device 10 is displayed on the screen of the administrator terminal 25, and the network administrator can visually recognize the destination information (step 113).

[0039] Subsequently, in response to the setting request notified from the administrator terminal 25 after login authentication (step 120), the administrator terminal 25 sets the destination information including the IP address specified in this setting request to the white list (step 121). As a result, the destination information including the IP address acquired by the relay devices 20A and 20B is aggregated by the aggregation device 10 and provided to the administrator terminal 25, and the destination information including the IP address is set to the white list of the relay device 20C from the administrator terminal 25.

[0040] Therefore, even when the IP address is used as the destination information in the white list of the relay device 20C, the network administrator can set the white list of the relay device 20C based on the destination information acquired by the relay devices 20A and 20B. Therefore, even when a URL or a URL with a wildcard is used as the destination information in the white lists of the relay devices 20A and 20B, the network administrator can omit the work of investigating the IP addresses of these URLs in advance, and can greatly reduce the work load of the network administrator.

[0041] In the search process of step 111 described above, for the destination information obtained by the providing unit 15C from the first relay device among the relay devices 20 to which web filtering is applied using the white list, only the destination information that is repeatedly obtained by a number of first relay devices equal to or greater than the first threshold may be provided. Thereby, a certain degree of security is ensured, and only the destination information that is accessed at a certain frequency can be selected and provided.

[0042] Similarly, in the search process of step 111 described above, for the destination information obtained by the providing unit 15C from the second relay device among the relay devices 20 to which web filtering is not applied using the white list, only the destination information that is repeatedly obtained by a number of second relay devices equal to or greater than the second threshold and for which access to the destination is not determined to be dangerous by the second relay device may be provided. Thereby, a certain degree of security is ensured, and only the destination information that is accessed at a certain frequency can be selected and provided.

[0043] [Effects of the Present Embodiment] As described above, in the present embodiment, each of the relay devices 20 is configured to obtain destination information including the IP address of the destination of the subordinate information terminal 21 by name resolution at the DNS server on the communication network NW, and the aggregating device 10 aggregates the destination information obtained by each of the relay devices 20, thereby registering the destination information including the IP address of the destination in the aggregation list 14A, and is configured to provide the destination information including the IP address used in the white list for web filtering based on the aggregation list 14A.

[0044] Thereby, since the destination information including the IP address can be provided from the aggregating device 10, compared with the case of providing the destination information consisting of the URL, the work for the network administrator to investigate the IP address of the URL in advance can be omitted, and the work load of the network administrator can be significantly reduced.

[0045] [Expansion of Embodiment] Although the present invention has been described with reference to the embodiments, the present invention is not limited to the above embodiments. Various modifications that can be understood by those skilled in the art can be made to the configuration and details of the present invention within the scope of the present invention. In addition, each embodiment can be implemented by arbitrarily combining them within a non - conflicting range.

Description of Reference Numerals

[0046] 1... Communication system, 10... Aggregation device, 11... Communication I / F, 12... Operation input unit, 13... Display unit, 14... Storage unit, 14A... Aggregation list, 14B... Permission list, 14P... Program, 15... Control unit, 15A... Collection unit, 15B... Aggregation unit, 15C... Provision unit, 20, 20A, 20B... Relay device, 21, 22... Information terminal, 25... Administrator terminal, 30... DNS server, 40... Server, L... Communication line, NW... Communication network.

Claims

1. A communication system comprising a plurality of relay devices and an aggregation device connected to the plurality of relay devices via a communication network, wherein each of the plurality of relay devices is configured to obtain connection destination information including the IP address of the connection destination of the subordinate information terminals by name resolution at the DNS server of the communication network, and the aggregation device is configured to register, in an aggregation list, connection destination information including the IP address of the connection destination by aggregating the connection destination information obtained in each of the relay devices, and to provide connection destination information including the IP address for use in a white list for Web filtering based on the aggregation list. A communication system characterized by the above.

2. In the communication system according to Claim 1, when providing the connection destination information registered in the aggregation list, the aggregation device is configured to provide only the connection destination information that is repeatedly obtained by a number of the first relay devices equal to or greater than a first threshold among the plurality of relay devices, for the connection destination information obtained by the first relay device that applies Web filtering with the white list.

3. In the communication system according to Claim 1 or Claim 2, when providing the connection destination information registered in the aggregation list, the aggregation device is configured to provide only the connection destination information that is repeatedly obtained by a number of the second relay devices equal to or greater than a second threshold among the plurality of relay devices, for the connection destination information obtained by the second relay device that does not apply Web filtering with the white list, and that is not determined to be dangerous to access the connection destination at the second relay device.

4. An aggregation device used in a communication system comprising a plurality of relay devices and an aggregation device connected to the plurality of relay devices via a communication network, wherein each of the plurality of relay devices is configured to obtain connection destination information including the IP address of the connection destination of the subordinate information terminals by name resolution at the DNS server of the communication network, the aggregation device includes a control unit configured to register, in an aggregation list, connection destination information including the IP address of the connection destination by aggregating the connection destination information obtained in each of the relay devices, and to provide connection destination information including the IP address for use in a white list for Web filtering based on the aggregation list. An aggregating device characterized by the above.

Citation Information

Patent Citations

  • JP1973092937A