Information processing apparatus and monitoring program

The information processing apparatus uses a dual determination unit to check startup and dedicated program integrity, addressing the vulnerability of pre-startup tampering and ensuring efficient monitoring within time constraints.

JP2025109000APending Publication Date: 2025-07-24TOSHIBA TEC KK
View PDF 9 Cites 0 Cited by

Patent Information

Application Number
JP2024002629
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-01-11
Publication Date
2025-07-24

AI Technical Summary

Technical Problem

Existing monitoring programs using whitelists are ineffective in detecting tampering of programs that start up before the monitoring program, creating a vulnerability.

Method used

An information processing apparatus with a determination unit that includes a first determination unit to check the integrity of startup programs before the monitoring program activates and a second determination unit to check the integrity of dedicated programs after activation, using hash values and file paths to identify tampering.

Benefits of technology

The solution allows for rapid detection of tampering in startup programs during the startup process and continuous monitoring of dedicated programs, ensuring the integrity of all executed programs while adhering to startup time constraints and reducing security management costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025109000000001_ABST
    Figure 2025109000000001_ABST
Patent Text Reader

Abstract

To provide an information processing apparatus and a monitoring program that can monitor alteration of a program that starts prior to the monitoring program.SOLUTION: An information processing apparatus includes: a determination unit that executes a determination operation of determining integrity of a program; and an output unit that outputs an alert relating to a program that fails in the determination operation. The determination unit includes: a first determination unit that determines integrity of a first program that is executed before activation of the determination unit in accordance with the activation of the determination unit; and a second determination unit that determines integrity of a second program in accordance with execution of a second program that is executed after activation of the determination unit.SELECTED DRAWING: Figure 6
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of the present invention relate to an information processing apparatus and a monitoring program.

Background Art

[0002] As anti-malware software for monitoring program tampering, there is a monitoring program that uses a whitelist. The whitelist is a list that stores a set of a file path and a hash value for each program. When the monitoring program detects the execution of a program, it determines the integrity of the program using the whitelist.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] However, there are programs that start up before the monitoring program. Therefore, with a monitoring program that uses a whitelist, there is a possibility that tampering with a program that starts up before the monitoring program cannot be monitored.

[0005] The problem to be solved by the embodiments of the present invention is to provide an information processing apparatus and a monitoring program that can monitor tampering with a program that starts up before the monitoring program.

Means for Solving the Problems

[0006] In one embodiment, an information processing apparatus includes a determination unit that executes a determination operation for determining the integrity of a program, and an output unit that outputs a warning regarding a program that has failed in the determination operation. The determination unit includes a first determination unit that determines the integrity of a first program executed before the activation of the determination unit in response to the activation of the determination unit, and a second determination unit that determines the integrity of a second program executed after the activation of the determination unit in response to the execution of the second program.

Brief Description of the Drawings

[0007]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Embodiments for Carrying Out the Invention

[0008] Hereinafter, the information processing apparatus according to the embodiment will be described with reference to the drawings. 1. Embodiment The information processing apparatus according to the embodiment is a computer and its peripheral devices that have security requirements for the integrity of programs. Specifically, for example, the information processing apparatus according to the embodiment is an MFP (multifunction peripheral). Also, for example, the information processing apparatus according to the embodiment may be an office device such as a POS (point of sale) terminal.

[0009] 1.1 Configuration First, the configuration of the information processing apparatus according to the embodiment will be described.

[0010] 1.1.1 Hardware Configuration FIG. 1 is a diagram showing an example of the hardware configuration of the information processing apparatus according to the embodiment. As shown in FIG. 1, the information processing apparatus 1 includes a control circuit 11, a storage 12, a communication module 13, a user interface 14, a drive 15, and a storage medium 16.

[0011] The control circuit 11 is a circuit that controls each component of the information processing apparatus 1 as a whole. The control circuit 11 includes a CPU (central processing unit), a RAM (random access memory), a ROM (read only memory), and the like. The CPU of the control circuit 11 controls the entire information processing apparatus 1 according to the program stored in the ROM of the control circuit 11. The RAM of the control circuit 11 has a working area for the CPU of the control circuit 11. The ROM of the control circuit 11 stores programs (monitoring programs) and the like used by the information processing apparatus 1 in monitoring processing. The monitoring processing is a process of monitoring whether there is any tampering with the program to be monitored. The monitoring processing includes a first determination process and a second determination process. Details of the monitoring processing will be described later.

[0012] Storage 12 includes, for example, a HDD (Hard Disk Drive) or an SSD (Solid State Drive). Storage 12 stores information used in the monitoring process in the information processing apparatus 1.

[0013] The communication module 13 is a circuit used for transmitting and receiving data between the information processing apparatus 1 and a network (not shown).

[0014] The user interface 14 is a device that controls communication between the information processing apparatus 1 and the user. The user interface 14 includes an input device and an output device. The input device includes, for example, a touch panel and operation buttons. The output device includes, for example, a printer, a speaker, and a display. When the information processing apparatus 1 is an MFP, the output device may be, for example, an operation panel attached to the printer.

[0015] The drive 15 is a device for reading software stored in the storage medium 16. The drive 15 includes, for example, a CD (Compact Disk) drive or a DVD (Digital Versatile Disk) drive.

[0016] The storage medium 16 is a medium that stores software by means of an electrical, magnetic, optical, mechanical, or chemical action. The storage medium 16 may store a monitoring program.

[0017] 1.1.2 Functional Configuration FIG. 2 is a block diagram showing an example of the functional configuration of the information processing apparatus according to the embodiment.

[0018] As shown in FIG. 2, the CPU of the control circuit 11 expands the program stored in the ROM or the storage medium 16 of the control circuit 11 into the RAM of the control circuit 11. Then, the CPU of the control circuit 11 interprets and executes the program expanded in the RAM of the control circuit 11. Thereby, the information processing apparatus 1 functions as a computer including a management unit 21, a determination unit 22, and an output unit 23. Further, the information processing apparatus 1 stores a first list 24 and a second list 25 in the storage 12.

[0019] The management unit 21 is a functional block that manages the execution of various programs. The management unit 21 starts a startup program and a monitoring program in response to the startup (power-on) of the information processing apparatus 1. The startup program includes executed programs and programs being executed with reference to the startup time of the monitoring program. Further, the management unit 21 executes a dedicated program after the startup of the information processing apparatus 1. When the information processing apparatus 1 is an MFP, the dedicated program is, for example, a program for causing the information processing apparatus 1 to function as an MFP. The dedicated program is a program scheduled to be executed with reference to the startup time of the monitoring program. The number of dedicated programs can be significantly larger than the number of startup programs.

[0020] The management unit 21 notifies the determination unit 22 of the start of execution of the program to be monitored. When the management unit 21 receives a notification from the determination unit 22 that a program being executed among the programs to be monitored may have been tampered with, the management unit 21 stops the program. When the management unit 21 receives a notification from the determination unit 22 that a program scheduled to be executed among the programs to be monitored may have been tampered with, the management unit 21 rejects the execution of the program.

[0021] The determination unit 22 is a functional block that executes monitoring processing. The determination unit 22 determines the integrity of the program to be monitored in the monitoring processing. Specifically, the determination unit 22 includes a first determination unit 31 and a second determination unit 32.

[0022] The first determination unit 31 is a functional block that executes a first determination process based on the first list 24. The first determination process is a process of determining the integrity of the startup program among the programs to be monitored.

[0023] FIG. 3 is a diagram showing an example of the data structure of the first list according to the embodiment.

[0024] As shown in FIG. 3, the first list 24 is a whitelist corresponding to the startup program to be monitored. The first list 24 is composed of a plurality of entries each corresponding to the startup program to be monitored. Each of the plurality of entries stores a pair of the file path and the hash value of the corresponding startup program to be monitored.

[0025] In the example of FIG. 3, the entry in the first row indicates that the file path and the hash value of program A are " / bin / A" and "1234…", respectively. The entry in the second row indicates that the file path and the hash value of program B are " / bin / B" and "2345…", respectively. The entry in the third row indicates that the file path and the hash value of program C are " / bin / C" and "3456…", respectively.

[0026] When it is determined that there is a possibility of forgery in the startup program to be monitored, the first determination unit 31 notifies the output unit 23 of the notification indicating that there is a possibility of forgery. Also, when it is determined that there is a possibility of forgery in the program being executed among the startup programs to be monitored, the first determination unit 31 further notifies the management unit 21 of the notification indicating that there is a possibility of forgery.

[0027] The second determination unit 32 is a functional block that executes a second determination process based on the second list 25. The second determination process is a process of determining whether there is a possibility of forgery in the dedicated program among the programs to be monitored.

[0028] FIG. 4 is a diagram showing an example of the data structure of the second list according to the embodiment.

[0029] As shown in FIG. 4, the second list 25 is a whitelist corresponding to the dedicated program to be monitored. The second list 25 is composed of a plurality of entries each corresponding to the dedicated program to be monitored. Each of the plurality of entries stores a pair of the file path and the hash value of the corresponding dedicated program to be monitored.

[0030] In the example of FIG. 4, the entry in the first row indicates that the file path and the hash value of program AA are " / bin / AA" and "abcd…", respectively. The entry in the second row indicates that the file path and the hash value of program BB are " / bin / BB" and "bcde…", respectively. The entry in the third row indicates that the file path and the hash value of program CC are " / bin / CC" and "cdef…", respectively.

[0031] When it is determined that there is a possibility of forgery for the dedicated program to be monitored, the second determination unit 32 notifies the output unit 23 and the management unit 21 of the notification to the effect that there is a possibility of forgery.

[0032] When the output unit 23 receives from the determination unit 22 a notification to the effect that there is a possibility of forgery for the program to be monitored (that is, a notification that the determination process has failed), the output unit 23 outputs, via the user interface 14, a warning including information to the effect that there is a possibility of forgery to the user. When the information processing apparatus 1 is an MFP, the output unit 23 displays, for example, a warning on the operation panel of the printer. The output unit 23 may output a warning sound in conjunction with the display of the warning.

[0033] 1.2 Operation Next, the operation of the information processing apparatus according to the embodiment will be described.

[0034] 1.2.1 Monitoring Process FIG. 5 is a flowchart showing an example of the monitoring process in the information processing apparatus according to the embodiment. FIG. 5 shows an overview of the process for monitoring the forgery of a program after the information processing apparatus 1 is powered on.

[0035] When the information processing apparatus 1 is powered on (start), the management unit 21 executes the startup program to start up the information processing apparatus 1. Further, the management unit 21 starts the monitoring program (ACT1). After the monitoring program is started, the startup program may include any of the executed programs and the programs being executed.

[0036] After the process of ACT1, the first determination unit 31 executes the first determination process (ACT2). The first determination unit 31 executes the first determination process of ACT2 within a predetermined time. The predetermined time is the upper limit value of the time required for the startup of the information processing apparatus 1, and is, for example, a value defined as the specification of the information processing apparatus 1. That is, the first determination unit 31 executes the first determination process while satisfying the constraints regarding the startup time of the information processing apparatus 1.

[0037] After the process of ACT2, the second determination unit 32 executes the second determination process (ACT3) with the start of execution of the dedicated program. The second determination unit 32 executes the second determination process after the startup of the information processing apparatus 1 is completed.

[0038] When the second determination process of ACT3 ends, the monitoring process ends (end).

[0039] 1.2.2 First Determination Process FIG. 6 is a flowchart showing an example of the first determination process in the information processing apparatus according to the embodiment. The processes of ACT11 to ACT19 shown in FIG. 6 correspond to the process of ACT2 in FIG. 5.

[0040] When the monitoring program starts (start), the first determination unit 31 refers to the first list 24 (ACT11).

[0041] The first determination unit 31 selects an entry from the first list 24 (ACT12).

[0042] The first determination unit 31 determines whether a program corresponding to the entry (selected entry) selected in the process of ACT12 exists in the file path (designated path) specified by the entry (ACT13).

[0043] If the program corresponding to the selected entry exists in the designated path (ACT13; yes), the first determination unit 31 calculates the hash value of the program corresponding to the selected entry (ACT14).

[0044] The first determination unit 31 determines whether the hash value calculated in the process of ACT14 matches the hash value stored in the selected entry (ACT15).

[0045] If the hash value calculated in the process of ACT14 does not match the hash value stored in the selected entry (ACT15; no), the first determination unit 31 determines whether the program corresponding to the selected entry is being executed (ACT16).

[0046] If the program corresponding to the selected entry is being executed (ACT16; yes), the first determination unit 31 notifies the management unit 21 that there is a possibility of forgery for the program corresponding to the selected entry.

[0047] Upon receiving the notification that there is a possibility of forgery, the management unit 21 stops the execution of the program corresponding to the selected entry (ACT17).

[0048] If the program corresponding to the selected entry does not exist in the designated path (ACT13; no), if the program corresponding to the selected entry is not being executed (ACT16; no), or after the process of ACT17, the first determination unit 31 further notifies the output unit 23 that there is a possibility of forgery for the program corresponding to the selected entry.

[0049] Upon receiving a notification that there is a possibility of tampering, the output unit 23 outputs a warning regarding the program corresponding to the selected entry to the user (ACT18). More specifically, when the program corresponding to the selected entry does not exist in the specified path (ACT13; no), the output unit 23 displays a warning screen indicating that the startup program does not exist on the display or the operation panel. When the program corresponding to the selected entry is not being executed (ACT16; no) or after the processing of ACT17 (i.e., when ACT15; no), the output unit 23 outputs a warning to the user that there is a possibility of tampering with the program corresponding to the selected entry.

[0050] When the hash value calculated in the processing of ACT14 matches the hash value stored in the selected entry (ACT15; yes), or after the processing of ACT18, the first determination unit 31 determines whether all the entries in the first list 24 have been selected (ACT19).

[0051] When there is an unselected entry in the first list 24 (ACT19; no), the first determination unit 31 selects the unselected entry from the first list 24 (ACT12). Then, the first determination unit 31, the management unit 21, and the output unit 23 execute the subsequent processing of ACT13 to ACT19. In this way, the first determination unit 31, the management unit 21, and the output unit 23 repeat the processing of ACT12 to ACT19 until all the entries in the first list 24 have been selected.

[0052] When all the entries in the first list 24 have been selected (ACT19; yes), the first determination process ends (end).

[0053] 1.2.3 Second Determination Process FIG. 7 is a flowchart showing an example of the second determination process in the information processing apparatus according to the embodiment. The processing of ACT21 to ACT29 shown in FIG. 7 corresponds to the processing of ACT3 in FIG. 5.

[0054] When the first determination process ends (starts), the second determination unit 32 waits until the management unit 21 detects the start of execution of the dedicated program (ACT21).

[0055] When the management unit 21 detects the start of execution of the dedicated program, the management unit 21 notifies the second determination unit 32 of the dedicated program scheduled to start execution as the program to be monitored.

[0056] Upon receiving a notification regarding the program to be monitored, the second determination unit 32 refers to the second list 25 (ACT22).

[0057] The second determination unit 32 selects an entry corresponding to the program to be monitored (entry to be monitored) from the second list 25 (ACT23).

[0058] The second determination unit 32 determines whether the program to be monitored exists at the file path (designated path) specified by the entry to be monitored (ACT24).

[0059] If the program to be monitored exists at the designated path (ACT24; yes), the second determination unit 32 calculates the hash value of the program to be monitored (ACT25).

[0060] The second determination unit 32 determines whether the hash value calculated in the process of ACT25 matches the hash value stored in the entry to be monitored (ACT26).

[0061] If the program to be monitored does not exist at the designated path (ACT24; no), or if the hash value calculated in the process of ACT26 does not match the hash value stored in the entry to be monitored (ACT26; no), the second determination unit 32 notifies the management unit 21 that there is a possibility of forgery of the program to be monitored.

[0062] Upon receiving a notification that there is a possibility of forgery, the management unit 21 rejects the execution of the program to be monitored (ACT27).

[0063] After the process of ACT27, the second determination unit further notifies the output unit 23 that there is a possibility of forgery in the program to be monitored.

[0064] Upon receiving the notification that there is a possibility of forgery, the output unit 23 outputs a warning regarding the program to be monitored to the user (ACT28). More specifically, when the program to be monitored does not exist in the specified path (ACT24; no), the output unit 23 displays a warning screen indicating that the dedicated program does not exist on the display or the operation panel. When the hash value calculated in the process of ACT26 does not match the hash value stored in the entry to be monitored (ACT26; no), the output unit 23 outputs a warning to the user that there is a possibility of forgery in the program to be monitored.

[0065] When the hash value calculated in the process of ACT26 matches the hash value stored in the entry to be monitored (ACT26; yes), or after the process of ACT28, the second determination unit 32 determines whether to end the monitoring by the second determination process (ACT29).

[0066] When continuing the monitoring by the second determination process (ACT29; no), the second determination unit 32 waits until the management unit 21 detects the start of execution of the dedicated program (ACT21). Then, the second determination unit 32, the management unit 21, and the output unit 23 execute the subsequent processes of ACT22 to ACT29. In this way, the second determination unit 32, the management unit 21, and the output unit 23 repeat the processes of ACT21 to ACT29 until the monitoring by the second determination process ends.

[0067] When ending the monitoring by the second determination process (ACT29; yes), the second determination process ends (End).

[0068] 1.3 Effects of the Embodiment According to the embodiment, the first determination unit 31 executes a first determination process of referring to the first list 24 and determining the integrity of the startup program executed before the startup of the monitoring program in response to the startup of the monitoring program. Thereby, it is possible to monitor whether there is any tampering for all programs that may be executed before the startup of the monitoring program. Note that the first determination unit 31 executes the first determination process within the constraints of the startup time of the information processing apparatus 1. Therefore, it is possible to quickly determine the integrity of the startup program while satisfying the requirements regarding the startup time of the information processing apparatus 1.

[0069] Also, the second determination unit 32 refers to the second list 25 and executes a second determination process of determining the integrity of the dedicated program executed after the startup of the monitoring program each time the dedicated program is executed. Thereby, for the programs executed after the startup of the monitoring program, it is possible to monitor whether there is any tampering for each program at the timing of execution. Therefore, it is not necessary to determine all the programs in the second list 25 at once, and the load of the determination process can be dispersed.

[0070] 2. Modification Various modifications can be applied to the above-described embodiment.

[0071] In the above-described embodiment, the determination unit 22 has been described as executing the first determination process and the second determination process based on the mutually different first list 24 and second list 25, respectively, but it is not limited thereto. For example, the determination unit 22 may execute the first determination process and the second determination process based on the same list.

[0072] Hereinafter, the configurations and operations different from the embodiment will be mainly described. The descriptions of the configurations and operations equivalent to those of the embodiment will be omitted as appropriate.

[0073] 2.1 Configuration FIG. 8 is a block diagram showing an example of the functional configuration of an information processing apparatus according to a modified example. FIG. 8 corresponds to FIG. 2 in the embodiment. As shown in FIG. 8, the information processing apparatus 1 stores a third list 26 in the storage 12. The determination unit 22 includes a first determination unit 33 and a second determination unit 34.

[0074] The first determination unit 33 is a functional block that executes a first determination process based on the third list 26. When it is determined that there is a possibility of forgery in the startup program to be monitored, the first determination unit 33 notifies the output unit 23 of the fact that there is a possibility of forgery. Further, when it is determined that there is a possibility of forgery in the program being executed among the startup programs to be monitored, the first determination unit 33 further notifies the management unit 21 of the fact that there is a possibility of forgery.

[0075] The second determination unit 34 is a functional block that executes a second determination process based on the third list 26. When it is determined that there is a possibility of forgery in the dedicated program to be monitored, the second determination unit 32 notifies the output unit 23 and the management unit 21 of the fact that there is a possibility of forgery.

[0076] FIG. 9 is a diagram showing an example of the data structure of the third list according to the modified example.

[0077] As shown in FIG. 9, the third list 26 is a whitelist corresponding to all programs to be monitored. The third list 26 is composed of a plurality of entries each corresponding to a program to be monitored. Each of the plurality of entries stores a pair of the file path and the hash value of the corresponding program to be monitored. Among the plurality of entries, all startup programs to be monitored in the first determination process are arranged at a predetermined same file path. Further, among the plurality of entries, all dedicated programs to be monitored in the second determination process are arranged at a file path different from the predetermined file path where the startup programs are arranged.

[0078] In the example of FIG. 9, the entry in the first row indicates that the file path and hash value of Program A are “ / bin / X” and “1234…”, respectively. The entry in the second row indicates that the file path and hash value of Program B are “ / bin / X” and “2345…”, respectively. The entry in the third row indicates that the file path and hash value of Program C are “ / bin / X” and “3456…”, respectively. Also, the entry in the fourth row indicates that the file path and hash value of Program AA are “ / bin / AA” and “abcd…”, respectively. The entry in the fifth row indicates that the file path and hash value of Program BB are “ / bin / BB” and “bcde…”, respectively. The entry in the sixth row indicates that the file path and hash value of Program CC are “ / bin / CC” and “cdef…”, respectively. Assuming that the file path “ / bin / X” is a predetermined file path, Programs A to C are startup programs to be monitored in the first determination process. Also, Programs AA to CC are dedicated programs to be monitored in the second determination process.

[0079] 2.2 Operation FIG. 10 is a flowchart showing an example of the first determination process in the information processing apparatus according to the modified example. FIG. 10 corresponds to FIG. 6 in the embodiment. That is, the processes of ACT31 to ACT38 shown in FIG. 10 correspond to the process of ACT2 in FIG. 5.

[0080] When the monitoring program is started (start), the first determination unit 33 refers to the third list 26 (ACT31).

[0081] The first determination unit 33 selects an entry specifying a predetermined file path from the third list 26 (ACT32). The predetermined file path is “ / bin / X” in the example of FIG. 9.

[0082] The first determination unit 33 calculates the hash value of the program corresponding to the entry (selected entry) selected in the process of ACT32 (ACT33).

[0083] The first determination unit 33 determines whether or not the hash value calculated in the process of ACT33 matches the hash value stored in the selected entry (ACT34).

[0084] If the hash value calculated in the process of ACT33 does not match the hash value stored in the selected entry (ACT34; no), the first determination unit 33 determines whether or not the program corresponding to the selected entry is being executed (ACT35).

[0085] If the program corresponding to the selected entry is being executed (ACT35; yes), the first determination unit 33 notifies the management unit 21 that there is a possibility of forgery in the program corresponding to the selected entry.

[0086] Upon receiving the notification that there is a possibility of forgery, the management unit 21 stops the execution of the program corresponding to the selected entry (ACT36).

[0087] If the program corresponding to the selected entry is not being executed (ACT35; no), or after the process of ACT36, the first determination unit 33 further notifies the output unit 23 that there is a possibility of forgery in the program corresponding to the selected entry.

[0088] Upon receiving the notification that there is a possibility of forgery, the output unit 23 outputs a warning regarding the program corresponding to the selected entry to the user (ACT37). More specifically, if the program corresponding to the selected entry is not being executed (ACT35; no) or after the process of ACT36 (that is, in the case of ACT34; no), the output unit 23 outputs a warning to the user that there is a possibility of forgery in the program corresponding to the selected entry.

[0089] If the hash value calculated in the process of ACT33 matches the hash value stored in the selected entry (ACT34; yes), or after the process of ACT37, the first determination unit 33 determines whether or not all entries corresponding to the predetermined file path of the third list 26 have been selected (ACT38).

[0090] If there is an unselected entry corresponding to the predetermined file path in the third list 26 (ACT38; no), the first determination unit 33 selects the unselected entry from the third list 26 (ACT32). Then, the first determination unit 33, the management unit 21, and the output unit 23 execute the subsequent processes of ACT33 to ACT38. In this way, the first determination unit 33, the management unit 21, and the output unit 23 repeat the processes of ACT32 to ACT39 until all the entries corresponding to the predetermined file path in the third list 26 are selected.

[0091] If all the entries corresponding to the predetermined file path in the third list 26 are selected (ACT38; yes), the first determination process ends (end).

[0092] 2.3 Effects according to the modified example According to the modified example, the first determination unit 33 refers to a predetermined path in the third list 26 and executes the first determination process for all the programs in the predetermined path. The second determination unit 34 executes the second determination process of determining the integrity of the dedicated program each time the dedicated program executed after the start of the monitoring program is executed by referring to the third list 26. Thereby, the same processing as in the embodiment can be executed without having two or more lists storing the combinations of the file path and the hash value. For this reason, it becomes unnecessary to manage a plurality of types of data structures related to security, and the security management cost can be reduced.

[0093] Although some embodiments of the present invention have been described, these embodiments are presented by way of example and are not intended to limit the scope of the invention. These novel embodiments can be implemented in various other forms, and various omissions, replacements, and changes can be made without departing from the gist of the invention. These embodiments and their modifications are included in the scope and gist of the invention, and are included in the invention described in the claims and its equivalent scope.

Explanation of reference numerals

[0094] 1... Information processing apparatus, 11... Control circuit, 12... Storage, 13... Communication module, 14... User interface, 15... Drive, 16... Storage medium, 21... Management unit, 22... Determination unit, 23... Output unit, 24... First list, 25... Second list, 26... Third list, 31, 33... First determination unit, 32, 34... Second determination unit.

Claims

1. A determination unit that executes a determination operation for determining the integrity of a program, An output unit that outputs a warning regarding a program that has failed in the determination operation, Comprising, The determination unit, A first determination unit that determines the integrity of a first program executed before the activation of the determination unit in response to the activation of the determination unit; A second determination unit that determines the integrity of a second program in response to the execution of the second program executed after the activation of the determination unit, Including, An information processing apparatus.

2. The first program is a startup program executed in response to the startup of the information processing apparatus, The first determination unit determines the integrity of the first program while satisfying the constraints regarding the startup time of the information processing apparatus, The information processing apparatus according to Claim 1.

3. The first determination unit determines the integrity of the first program based on a first list composed of a plurality of entries each storing a pair of a file path and a hash value, The second determination unit determines the integrity of the second program based on a second list different from the first list, the second list being composed of a plurality of entries each storing a pair of a file path and a hash value, The information processing apparatus according to Claim 1.

4. Each of the first determination unit and the second determination unit determines the integrity of the first program and the second program based on a third list composed of a plurality of entries each storing a pair of a file path and a hash value, The first determination unit determines the integrity of the first program based on a first entry that stores the same file path among the plurality of entries, The second determination unit determines the integrity of the second program based on a second entry that stores different file paths among the plurality of entries, The information processing apparatus according to Claim 1.

5. A monitoring program for causing a computer to Function as a determination unit that executes a determination operation for determining the integrity of a program, And an output unit that outputs a warning regarding a program that has failed in the determination operation, Wherein the determination unit, In response to the activation of the determination unit, a first determination unit that determines the integrity of a first program executed before the activation of the determination unit; A second determination unit that determines the integrity of a second program in response to the execution of the second program executed after the activation of the determination unit, Including, ​ Monitoring program.

Citation Information

Patent Citations

  • Operating system monitoring setting information generation apparatus and operating system monitoring apparatus

    JP2008135004A

  • System and method for preventing unauthorized program start

    JP2009259160A

  • Malware mitigation

    JP2018524720A

  • Information processing apparatus, control method, and program thereof

    JP2019191698A

  • Information processing device, information processing method and program

    JP2020046829A