Electronic apparatus, control method, and program
The electronic device addresses the user burden in malware detection by automatically restarting and adjusting settings upon detecting DNS errors, effectively preventing malware re-intrusion and reducing user intervention.
Patent Information
- Application Number
- JP2024023567
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-02-20
- Publication Date
- 2025-09-01
AI Technical Summary
Existing malware detection systems place a heavy burden on users by requiring them to take measures after detection, lacking proactive countermeasures.
An electronic device with a detection unit that identifies malware intrusion through DNS name resolution errors, followed by automatic restarts and setting changes, including altering detection thresholds, blocking specific ports, disabling wireless or wired communication, and user-confirmed settings adjustments.
Reduces user burden by implementing automatic countermeasures upon malware detection, enhancing malware detection efficiency and preventing re-intrusion, suitable for devices with limited resources.
Smart Images

Figure 2025127071000001_ABST
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to an electronic device, a control method, and a program. [Background technology]
[0002] Various techniques have been proposed to combat malware. For example, Patent Document 1 discloses a system for detecting whether a computing device has been infected with malware. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Special Publication No. 2019-500712 Summary of the Invention [Problem to be solved by the invention]
[0004] The technology disclosed in Patent Document 1 focuses only on detecting malware infections, and leaves it up to the user to take measures when a malware infection is detected, which places a heavy burden on the user. [Means for solving the problem]
[0005] The electronic device disclosed herein includes a detection unit that detects malware intrusion into the electronic device by detecting a name resolution error that occurs in response to a DNS (Domain Name System) packet sent from the electronic device, and a countermeasure execution unit that, when malware intrusion is detected, restarts the electronic device and changes the settings of the electronic device, where the setting changes include at least one of (1) changing the detection period for the occurrence of the name resolution error and the threshold for the number of occurrences of the name resolution error for determining that malware has intruded, (2) blocking the transmission of packets addressed to a specified port, (3) disabling wireless communication, and (4) disabling wired communication.
[0006] In addition, the control method according to the present disclosure is a control method for an electronic device, which detects the intrusion of malware into the electronic device by detecting a name resolution error that occurs in response to a DNS packet sent from the electronic device, and when the intrusion of malware is detected, restarts the electronic device and changes the settings of the electronic device, and the changes in settings include at least one of (1) changing the detection period for the occurrence of the name resolution error and / or the threshold for the number of occurrences of the name resolution error for determining that malware has intruded, (2) blocking the transmission of packets addressed to a specified port, (3) disabling wireless communication, and (4) disabling wired communication.
[0007] In addition, the program disclosed herein causes a computer of an electronic device to execute a detection step of detecting malware intrusion into the electronic device by detecting a name resolution error that occurs in response to a DNS packet sent from the electronic device, and a countermeasure execution step of restarting the electronic device and changing the settings of the electronic device when malware intrusion is detected, wherein the setting change includes at least one of (1) changing the detection period for the occurrence of the name resolution error and the threshold for the number of occurrences of the name resolution error for determining that malware has intruded, (2) blocking the transmission of packets addressed to a specified port, (3) disabling wireless communication, and (4) disabling wired communication. [Brief explanation of the drawings]
[0008] [Figure 1] FIG. 1 is a block diagram illustrating an example of a configuration of an electronic device according to an embodiment. [Figure 2] FIG. 2 is a block diagram showing an example of functions realized by firmware. [Figure 3] 10 is an example of a GUI screen for setting the detection process of a detection unit. [Figure 4] FIG. 10 is a schematic diagram illustrating an example of a GUI screen for receiving instructions from a user regarding the implementation of setting changes. [Figure 5]1 is a flowchart illustrating an example of an operation flow of the electronic device according to the embodiment. [Figure 6] 6 is a flowchart showing an example of the process flow of step S107 in FIG. 5. [Figure 7] 10A and 10B are schematic diagrams showing other detection methods by the detection unit. [Figure 8] FIG. 4 is a schematic diagram showing an example of information displayed by an information output unit. DETAILED DESCRIPTION OF THE INVENTION
[0009] Hereinafter, embodiments will be described with reference to the drawings. For clarity of explanation, the following description and drawings have been omitted and simplified as appropriate. In addition, the same elements in each drawing are designated by the same reference numerals, and duplicate explanations have been omitted as necessary.
[0010] FIG. 1 is a block diagram showing an example of the configuration of an electronic device 100 according to an embodiment. As shown in FIG. 1, the electronic device 100 includes firmware 110, a processor 120, a memory 130, a power supply unit 140, a UI (user interface) device 150, and a network interface 160. The electronic device 100 is, for example, an embedded device such as a printer, but is not limited thereto and may be any information processing device that performs information processing. In this embodiment, the electronic device 100 is connected to a network such as the Internet, and therefore the electronic device 100 can also be referred to as an IoT (Internet of Things) device.
[0011] The firmware 110 is software that controls the operation of the electronic device 100. In particular, in this embodiment, the firmware 110 is also software that has the function of detecting malware and taking measures against malware, as will be described later.
[0012] The processor 120 reads and executes a program from the memory 130. In this way, the processor 120 realizes the functions of the firmware 110. Note that malware that has invaded the electronic device 100 also operates using the memory 130 and the processor 120, similar to the firmware 110. The processor 120 may be, for example, a microprocessor, an MPU (Micro Processor Unit), or a CPU (Central Processing Unit). The processor 120 may include multiple processors.
[0013] The memory 130 is configured, for example, by a combination of volatile memory and non-volatile memory. The memory 130 is used to store programs executed by the processor 120. The memory 130 may include multiple memories.
[0014] The power supply unit 140 is a circuit that controls the supply of power to each component of the electronic device 100. The power supply unit 140 restarts the electronic device 100, particularly under the control of the firmware 110. Specifically, if malware is detected in the electronic device 100, the electronic device 100 is restarted in accordance with a restart instruction from the firmware 110.
[0015] The UI device 150 is a device that functions as a user interface. Specifically, the UI device 150 is configured with a display that displays various information and an input device such as a button or a pointing device that accepts input operations from the user U. The UI device may be configured as a touch panel in which the display and the input device are integrated. The UI device 150 is used to notify the user U of information and to obtain instructions from the user U during processing by the firmware 110. In particular, in this embodiment, the UI device 150 is used when changing settings of the electronic device 100 after a reboot process of the electronic device 100 in which malware has been detected.
[0016] The network interface 160 is a network device that enables the electronic device 100 to communicate with other devices via a network such as the Internet or a LAN (Local Area Network). Specifically, the network interface 160 includes a hardware circuit such as a wired LAN terminal that enables the electronic device 100 to perform wired communication, and a hardware circuit such as a Wi-Fi (registered trademark) chip that enables the electronic device 100 to perform wireless communication. Note that the network interface 160 may have only one of a hardware circuit for wired communication and a hardware circuit for wireless communication. The network interface 160 switches between an enabled and disabled state of its communication function under the control of the firmware 110. Note that the enabled and disabled states of the communication function can be switched separately for wired communication and wireless communication.
[0017] Next, details of the firmware 110 will be described. Fig. 2 is a block diagram showing an example of functions realized by the firmware 110. The electronic device 100 has, as functions of the firmware 110, a detection unit 111, a countermeasure execution unit 112, a setting storage unit 113, and a UI processing unit 114. Note that in Fig. 2, in order to show the relationship between these functions of the firmware 110 and malware 200 that has invaded the electronic device 100, the malware 200 and a C&C server (Command and Control Server) 201 with which the malware 200 communicates are also shown.
[0018] The malware 200 is malicious and harmful software such as a computer virus, worm, or spyware, which somehow infiltrates the electronic device 100 (firmware 110) and resides in the memory 130. The malware 200 infiltrates the electronic device 100 via a network, for example. The C&C server 201 is a command server used by cyber attackers to issue commands to the malware 200 and to receive information stolen by the malware 200. For this purpose, the malware 200 communicates with the C&C server 201. Through this communication, for example, the malware 200 uploads information stored in the electronic device 100 to the C&C server 201. To communicate with the C&C server 201, the malware 200 generates a large number of domain names using a domain generation algorithm (DGA) and attempts to communicate with the destination identified by each of the generated domain names. The large number of domain names generated includes the domain name of the C&C server 201, many of which fail to be resolved by a Domain Name System (DNS) server. In other words, many of the DNS packets used to resolve domain names generated by the domain generation algorithm result in name resolution errors. Here, a DNS packet refers to a packet that requests a DNS server to resolve a domain name, and may also be referred to as a DNS name resolution packet.
[0019] The detection unit 111 detects the intrusion of malware 200 into the electronic device 100. In this embodiment, the detection unit 111 detects the intrusion of malware 200 into the electronic device 100 by detecting a name resolution error that occurs in response to a DNS packet transmitted from the electronic device 100. Specifically, the detection unit 111 performs the following process to detect the intrusion of malware 200 into the electronic device 100. The detection unit 111 acquires a response packet in response to a DNS packet transmitted to the outside of the electronic device 100. The detection unit 111 then parses the acquired response packet and checks response information in accordance with RFC1035, a standard related to domain names. In particular, the detection unit 111 checks whether the response information included in the response packet includes information indicating a name resolution error. The detection unit 111 then determines that malware 200 has infiltrated the electronic device 100 if the number of name resolution errors that occur within a predetermined period is equal to or greater than a predetermined threshold. Hereinafter, this predetermined period will be referred to as a detection period, and this predetermined threshold will be referred to as a detection threshold. In this embodiment, the detection unit 111 performs the above-described detection process using the detection period value and the detection threshold value stored in the setting storage unit 113, which will be described later. The detection period value and the detection threshold value are set to initial values in advance, but as will be described later, if the detection unit 111 detects malware 200, these values may be changed by the countermeasure execution unit 112. As described above, if malware 200 infiltrates the electronic device 100, it is expected that many name resolution errors will occur during name resolution of domain names generated by the domain generation algorithm. For this reason, the detection unit 111 can detect the intrusion of malware 200 by monitoring DNS packets as described above.
[0020] The countermeasure execution unit 112 executes countermeasures when the detection unit 111 detects the intrusion of malware 200. Specifically, first, when the detection unit 111 detects the intrusion of malware 200, the countermeasure execution unit 112 executes a restart of the electronic device 100 in order to eliminate the intruding malware 200. More specifically, for example, the countermeasure execution unit 112 restarts the electronic device 100 by issuing a restart instruction to the power supply unit 140. As a result, the malware 200 operating on the memory 130 serving as a volatile memory is eliminated by deleting the data in the memory 130 upon restart.
[0021] Furthermore, after restarting the electronic device 100, the countermeasure execution unit 112 executes changes to the settings of the electronic device 100 as a countermeasure against the intrusion of the malware 200. In this embodiment, the countermeasure execution unit 112 executes the following setting changes (1) to (4) specifically in accordance with an execution instruction from the user U. Note that the countermeasure execution unit 112 may execute any one of the following setting changes (1) to (4), or may execute any combination of two or more setting changes.
[0022] <Setting change (1): Change the setting value of the detection process> The countermeasure execution unit 112 changes the setting value of the detection process by the detection unit 111. Specifically, the setting value is changed so that the intrusion of malware 200 is more easily detected than at present. More specifically, the countermeasure execution unit 112 changes the value of the detection period to be longer than the current setting value. That is, when changing the detection period as a countermeasure, the countermeasure execution unit 112 changes the length of the detection period to be longer than the currently set length of the detection period. The countermeasure execution unit 112 also changes the value of the detection threshold to be smaller than the currently set value. That is, when changing the detection threshold as a countermeasure, the countermeasure execution unit 112 changes the value of the threshold to be smaller than the currently set value of the threshold. Note that the countermeasure execution unit 112 may change only either the detection period or the detection threshold. That is, the countermeasure execution unit 112 changes at least one of the detection period for the occurrence of a name resolution error and the threshold for the number of occurrences of name resolution errors for determining that malware has intruded. By the countermeasure execution unit 112 changing the setting value of the detection process, even if the malware 200 invades the electronic device 100 again, it becomes possible to detect the intrusion early.
[0023] <Setting change (2): Blocking packets sent to a specific port> The countermeasure execution unit 112 may change the settings of TCP (Transmission Control Protocol) communication or UDP (User Datagram Protocol) communication to block the transmission of packets to a predetermined port used to listen for DNS packets. Specifically, for example, the countermeasure execution unit 112 blocks the transmission of packets addressed to TCP / UDP port 53. That is, the countermeasure execution unit 112 blocks the transmission of packets to port 53, which is used in TCP or UDP. Note that the countermeasure execution unit 112 instructs the network interface 160 to block the transmission of packets whose destination includes the predetermined port. By the countermeasure execution unit 112 blocking the transmission of packets to the predetermined port, the transmission of DNS packets to the DNS server can be blocked. Therefore, even if the malware 200 infiltrates the electronic device 100 again, the malware 200 can be prevented from communicating with the C&C server 201. This makes it possible to suppress damage caused by the malware 200.
[0024] <Setting change (3): Disable wireless communication> The countermeasure execution unit 112 changes the communication settings of the electronic device 100 to disable wireless communication of the electronic device 100. Specifically, the countermeasure execution unit 112 disables Wi-Fi communication by stopping the operation of the device driver of the network interface 160 that performs processing related to wireless communication. This makes it possible to prevent the malware 200 from invading the electronic device 100 again. Furthermore, even if the malware 200 does invade the electronic device 100, it is possible to prevent the malware 200 from communicating with the C&C server 201 and thereby suppress damage caused by the malware 200.
[0025] <Setting change (4): Disable wired communication> The countermeasure execution unit 112 changes the communication settings of the electronic device 100 so as to disable wired communication of the electronic device 100. Specifically, the countermeasure execution unit 112 blocks Ethernet communication by stopping the operation of the device driver of the network interface 160 that performs processing related to wired communication. As a result, the countermeasure execution unit 112 disables communication using a LAN port (i.e., an Ethernet port). This makes it possible to prevent the malware 200 from invading the electronic device 100 again. Furthermore, even if the malware 200 does invade the electronic device 100, it is possible to prevent the malware 200 from communicating with the C&C server 201, thereby suppressing damage caused by the malware 200.
[0026] In this embodiment, the countermeasure execution unit 112 executes some or all of the above-described setting changes when a change instruction is received from the user U, but may execute some or all of the above-described setting changes regardless of an instruction from the user U. Also, although setting changes (1) to (4) have been given as specific examples of setting changes, the setting changes executed by the countermeasure execution unit 112 are not limited to these, and other setting changes, such as setting changes that degrade the functions of the electronic device 100, may also be executed.
[0027] The setting storage unit 113 stores setting information of the electronic device 100. In the present embodiment, the setting storage unit 113 stores setting values of a detection period and a detection threshold used by the detection unit 111 in the detection process. Therefore, when the countermeasure execution unit 112 changes the setting values of the detection process by the detection unit 111, the countermeasure execution unit 112 stores the changed setting values in the setting storage unit 113. That is, the countermeasure execution unit 112 updates the setting values stored in the setting storage unit 113. Note that the setting storage unit 113 may store information other than the setting values of the detection period and the detection threshold. For example, the setting storage unit 113 may store setting information of settings to be changed in the above-described setting changes (2) to (4) as necessary. Furthermore, for example, information setting whether or not the detection process by the detection unit 111 is to be performed may be stored. In this case, the detection unit 111 performs the detection process when setting information indicating that the detection process is to be performed is stored, and does not perform the detection process when setting information indicating that the detection process is not to be performed is stored. Note that the setting storage unit 113 is specifically realized by an arbitrary storage device. For example, the setting storage unit 113 may be realized by the memory 130, or may be realized by an auxiliary storage device such as a hard disk drive or a solid state drive.
[0028] The UI processing unit 114 performs processing related to the user interface. In this embodiment, the UI processing unit 114 includes an information output unit 114a that performs output processing to notify the user U of information, and an input receiving unit 114b that performs receiving processing of input from the user U.
[0029] The information output unit 114a outputs a GUI (Graphical User Interface) screen, and the input accepting unit 114b acquires information input to this GUI screen. The information output unit 114a outputs the GUI screen to, for example, a display of the UI device 150. Furthermore, the input accepting unit 114b acquires information input to the GUI screen displayed by the UI device 150. Specifically, for example, the information output unit 114a outputs a GUI screen including information related to the settings of the electronic device 100 and GUI components for accepting input. Furthermore, the input accepting unit 114b acquires information input to the GUI screen by an operation on the GUI component for accepting input (for example, a selection operation from options or an input operation of information into an input box).
[0030] The information output unit 114a and the input accepting unit 114b do not necessarily need to use the UI device 150. The information output unit 114a may output information to a terminal device capable of communicating with the electronic device 100, such as a smartphone, tablet terminal, or personal computer used by the user U, in order to display the information on a web browser installed on the terminal device. The input accepting unit 114b may also acquire information input via the web browser from the terminal device capable of communicating with the electronic device 100. Specifically, for example, the information output unit 114a outputs, as a GUI screen, a configuration page including information related to the settings of the electronic device 100 and GUI components for accepting input. The input accepting unit 114b acquires information input to the configuration page by an operation on the GUI component for accepting input (for example, a selection operation from options or an operation for inputting information into an input box).
[0031] As will be described later, in this embodiment, when the detection unit 111 detects intrusion of malware 200 into the electronic device 100, the UI processing unit 114 interacts with the user U. However, the UI processing unit 114 may also interact with the user U in other cases. For example, the user U may be able to freely change the initial values of the detection period and the detection threshold. Furthermore, the user U may be able to change the values of the detection period or the detection threshold changed by the countermeasure execution unit 112 back to their original initial values or to any other value. Furthermore, the user U may be able to set whether or not the detection unit 111 will perform malware detection processing. FIG. 3 is an example of a GUI screen for setting the detection processing of the detection unit 111. In the example shown in FIG. 3, the GUI screen can accept from the user U settings of whether or not to perform malware detection processing, the detection period, and the detection threshold. A GUI screen may also be displayed that accepts an instruction to restore any or all of the settings changed by the countermeasure execution unit 112, not limited to the detection period or the detection threshold. As described above, this GUI screen may be displayed on a web browser of the user U's terminal device, or may be displayed on the UI device 150 of the electronic device 100. In this way, the UI processing unit 114 may perform processing to display a GUI screen for accepting input of various settings, and may perform processing to store the setting information input by the user U on this GUI screen in the setting storage unit 113. Furthermore, the information output unit 114a of the UI processing unit 114 may read out default initial values or current setting values for the detection period or the detection threshold from the setting storage unit 113 and display them on the GUI screen. Note that the specifications may be such that the user U is not allowed to freely change either or both of the initial values of the detection period and the detection threshold.
[0032] In particular, in this embodiment, when the detection unit 111 detects the intrusion of malware 200 into the electronic device 100, the UI processing unit 114 interacts with the user U. Specifically, the UI processing unit 114 performs processing to receive an instruction from the user U regarding the implementation of the above-described setting change by the countermeasure execution unit 112. For example, after the detection unit 111 detects the intrusion of malware 200 and the countermeasure execution unit 112 performs a reboot process, the information output unit 114a of the UI processing unit 114 performs processing to display a GUI screen, for example, as shown in FIG. 4. FIG. 4 is a schematic diagram illustrating an example of a GUI screen for receiving an instruction from the user U regarding the implementation of the setting change. In the example shown in FIG. 4, the GUI screen can receive an instruction from the user U regarding whether or not to implement the setting change. An input from the user U to the GUI screen is received by the input receiving unit 114b of the UI processing unit 114. Note that this GUI screen may include a message warning the user U that the intrusion of malware 200 has been detected and a message notifying the user U that a reboot has been performed. However, these messages may be displayed as a screen separate from the screen that receives an instruction from the user U as to whether or not to implement the setting change. Note that the GUI screen shown in FIG. 4 asks the user U whether or not to implement the setting change without specifying the setting to be changed, but a GUI screen that asks whether or not to implement the setting change for each item to be changed may be displayed. That is, the information output unit 114a of the UI processing unit 114 may perform processing to display a GUI screen that asks the user U whether or not to implement the setting change for each of the above-mentioned setting changes (1) to (4). Then, the input receiving unit 114b may receive an input from the user U instructing whether or not to implement the setting change for each of the setting changes (1) to (4).
[0033] In this embodiment, the countermeasure execution unit 112 executes the above-described setting changes when the UI processing unit 114 (input receiving unit 114b) receives an input from the user U instructing the user to change the settings. For example, the setting changes are executed when a button instructing the user to execute the setting changes is pressed on the GUI screen. Note that if the user is instructed to execute setting changes for only some of the setting changes (1) to (4), the countermeasure execution unit 112 executes only the setting changes that the user is instructed to execute. In this way, in this embodiment, the countermeasure execution unit 112 executes the setting changes in accordance with the instructions from the user U. This makes it possible to prevent setting changes that the user U does not want from being executed.
[0034] Next, a description will be given of the flow of operation of the above-mentioned electronic device 100. Fig. 5 is a flowchart showing an example of the flow of operation of the electronic device 100. Fig. 6 is a flowchart showing an example of the processing flow of step S107 in Fig. 5. The flow of operation of the electronic device 100 will be described below with reference to Figs. 5 and 6.
[0035] In step S100, the detection unit 111 starts the detection process for the malware 200. Accordingly, in step S101, the detection unit 111 initializes the value of an error counter, which is a variable for counting the number of occurrences of name resolution errors, to 0. Then, the detection period begins. Since the malware 200 has not yet been detected at this point, the period set as the initial value is used as the detection period. This initial value may be, for example, five minutes or one week, or any other period. In step S102, the detection unit 111 checks whether the detection period has expired. If the detection period has not yet expired (NO in step S102), the process proceeds to step S103. On the other hand, if the detection period has expired, the process returns to step S101 to reset the results of the detection process up to that point and start the next detection process.
[0036] In step S103, the detection unit 111 checks the DNS packet transmitted from the electronic device 100 to the outside. More specifically, the detection unit 111 checks the response packet in response to the transmitted DNS packet. Then, in step S104, the detection unit 111 checks whether the response packet includes information indicating a name resolution error. That is, the detection unit 111 checks whether a name resolution error has occurred for the DNS packet. If a name resolution error has occurred (YES in step S104), the process proceeds to step S105. On the other hand, if a name resolution error has not occurred (NO in step S104), the process returns to step S102. Note that if the name resolution was successful or an error other than a name resolution error has occurred, the process returns to step S102.
[0037] In step S105, the detection unit 111 increments the value of the error counter by 1. Subsequently, in step S106, the detection unit 111 determines whether the value of the error counter is equal to or greater than the detection threshold. At this point, since malware 200 has not yet been detected, a threshold set as an initial value is used as the detection threshold. This initial value may be, for example, 4 or 100, or may be any value without being limited to these. If the value of the error counter is less than the detection threshold (NO in step S106), the process returns to step S102. On the other hand, if the value of the error counter is equal to or greater than the detection threshold (YES in step S106), the process proceeds to step S107. That is, in this case, the detection unit 111 determines that malware has infiltrated the electronic device 100.
[0038] In step S107, countermeasures against the intrusion of malware 200 are executed. A specific processing flow of step S107 will be described below with reference to FIG. 6. First, in step S151, countermeasure execution unit 112 restarts electronic device 100 to eliminate the intruded malware 200. This removes the malware 200 present in memory 130. Note that in step S151 in the flowchart shown in FIG. 6, electronic device 100 starts up in a setting mode, which is a mode that allows settings to be changed.
[0039] Next, in step S152, the information output unit 114a of the UI processing unit 114 displays a GUI screen on the display of the UI device 150 or the like to receive instructions from the user U regarding the implementation of setting changes. This GUI screen may display the contents of setting changes that can be implemented as countermeasures against the malware 200, as shown in FIG. 4. Furthermore, this GUI screen may include warning information that warns that malware 200 has invaded the electronic device 100. Furthermore, the information output unit 114a may display such warning information separately from the GUI screen to receive instructions from the user U regarding the implementation of setting changes.
[0040] After step S152, in step S153, the countermeasure execution unit 112 determines whether or not an input instructing the implementation of a setting change has been accepted by the input accepting unit 114b. That is, in this step, it is determined whether or not the user U has pressed a button provided on the GUI screen described above that instructs the implementation of a setting change. As described above, the user U may instruct whether or not to implement a setting change for each change item. If the user U has instructed the implementation of a setting change (YES in step S153), the process proceeds to step S154. On the other hand, if the user U has not instructed the implementation of a setting change (NO in step S153), the process proceeds to step S155.
[0041] In step S154, the countermeasure execution unit 112 performs processing to make the setting changes instructed to be made by the user U. Thereafter, the processing proceeds to step S155.
[0042] In step S155, the countermeasure execution unit 112 restarts the electronic device 100 to start it in the normal mode. If a process for changing the settings has been performed in step S154, this restart causes the electronic device 100 to start up in a state in which the changes have been reflected in the electronic device 100. Note that if a restart is not required to reflect the setting changes in the electronic device 100, the restart in step S155 may be omitted. In this case, in the restart in step S151, the electronic device 100 restarts in the normal mode, not the setting mode.
[0043] 6, the settings are changed in response to an instruction from the user U, but as described above, the settings may be changed without requiring an instruction from the user U. In this case, the display of the GUI screen may be omitted.
[0044] The above describes the embodiment. In the present embodiment, when the detection unit 111 detects the intrusion of malware 200 into the electronic device 100 through a detection process, the countermeasure execution unit 112 executes a change to the settings of the electronic device 100. This allows for easy implementation of countermeasures against malware intrusion. That is, according to the present embodiment, not only malware detection but also countermeasure implementation are performed, thereby reducing the burden on the user. Specifically, by performing any of the above-described setting changes (1) to (4), countermeasures such as preventing re-intrusion of malware 200 or early detection of malware 200 can be implemented. In particular, the detection unit 111 determines the intrusion of malware 200 into the electronic device 100 by checking the number of occurrences of name resolution errors. Then, the countermeasure execution unit 112 performs processes with relatively low processing loads, such as rebooting and setting changes (1) to (4). This makes it easy to implement the detection process and post-detection countermeasure processing even in electronic devices 100 with limited computer resources, such as embedded devices.
[0045] Next, several variations of the above-described embodiment will be described. The detection unit 111 described with reference to the flowchart shown in FIG. 5 detects the intrusion of malware 200 into electronic device 100 by comparing the number of name resolution errors that occurred from a certain point in time until a predetermined detection period has elapsed with a detection threshold. However, the detection unit 111 may detect the intrusion of malware 200 into electronic device 100 as follows. FIG. 7 is a schematic diagram illustrating another detection method by the detection unit 111. As shown in FIG. 7, the detection unit 111 may detect the intrusion of malware 200 into electronic device 100 by comparing the number of name resolution errors that occurred from the most recent name resolution error to a time period corresponding to the detection period (30 minutes in the example of FIG. 7) back with a detection threshold (4 in the example of FIG. 7). In this case, the detection unit 111 records a timestamp indicating the time of occurrence in memory 130 each time a name resolution error occurs. Then, the detection unit 111 refers to the recorded timestamps and identifies the number of name resolution errors that occurred from the time of the most recent name resolution error to a time going back a period of time equivalent to the detection period. If this number exceeds the detection threshold, the detection unit 111 determines that the malware 200 has infiltrated the electronic device 100. In the example shown in FIG. 7, four name resolution errors have occurred, and the times at which they occurred are recorded as timestamps T1 to T4. Therefore, when a name resolution error whose timestamp is recorded as timestamp T4 occurs, the detection unit 111 determines that the malware 200 has infiltrated the electronic device 100. This is because the total number of name resolution errors that occurred from the time indicated by timestamp T4 to a time going back 30 minutes is equal to or greater than the detection threshold (four times). Note that the detection unit 111 may perform a detection process based on the number of name resolution errors that occurred, and the specific detection process is not limited to the method described in the present disclosure.
[0046] Alternatively, the countermeasure execution unit 112 may disable only one of wireless communication and wired communication based on whether the DNS packet causing the name resolution error was transmitted via wireless communication or wired communication. In this case, for example, the countermeasure execution unit 112 may check a communication log for packet transmission from the electronic device 100 to determine whether the DNS packet causing the name resolution error was transmitted via wireless communication or wired communication. That is, the countermeasure execution unit 112 analyzes whether the malware communication is via wireless communication or wired communication. If the communication used to transmit the DNS packet causing the name resolution error is biased toward either wireless communication or wired communication, the countermeasure execution unit 112 disables the communication that is more frequently used to transmit the DNS packet causing the name resolution error. For example, if the malware communication is biased toward wired communication, the countermeasure execution unit 112 disables only wired communication. This allows communication for normal processing to continue using a communication method that has not been disabled. For example, the user U can change any setting of the electronic device 100, such as restoring the settings, via a web browser using a communication method that has not been disabled.
[0047] Furthermore, for example, when receiving an input instructing the implementation of a setting change, the information output unit 114a may output information indicating the disadvantages of each change item of the setting change. This allows the user U to determine whether or not to implement the setting change after recognizing the disadvantages. For example, the information output unit 114a may perform a process to display information such as that shown in FIG. 8. Furthermore, as shown in FIG. 8, the information output unit 114a may output the level of disadvantage for each change item, or the relative level of effect for each change item compared to other change items. For example, for a setting change to disable wired communication and a setting change to disable wireless communication, the information output unit 114a outputs disadvantage information that processing using wired communication or wireless communication will become impossible, a disadvantage level of "high," and an effect level of "high." Furthermore, for a setting change to block transmissions to a specific port (TCP / UDP port 53), the information output unit 114a outputs disadvantage information that communication using DNS will become impossible, a disadvantage level of "medium," and an effect level of "medium." Furthermore, for example, for a setting change such as a change in the setting value of the detection process, the information output unit 114a outputs demerit information indicating that there is no demerit, a demerit level of "none," and an effect level of "low." Note that these are merely examples, and information other than the above-mentioned information may be output as demerit information, a demerit level, or an effect level for each change item.
[0048] In the present disclosure, a program includes a set of instructions (or software code) that, when loaded into a computer, causes the computer to perform one or more functions described in the embodiments. The program may be stored in a non-transitory computer-readable medium or a tangible storage medium. By way of example and not limitation, computer-readable media or tangible storage media include random-access memory (RAM), read-only memory (ROM), flash memory, solid-state drive (SSD) or other memory technologies, CD-ROM, digital versatile disc (DVD), Blu-ray (registered trademark) disc or other optical disk storage, magnetic cassette, magnetic tape, magnetic disk storage or other magnetic storage device. The program may also be transmitted on a transitory computer-readable medium or communication medium. By way of example and not limitation, transitory computer-readable media or communication media include electrical, optical, acoustic, or other forms of propagated signals.
[0049] Although the embodiments have been described above, the present invention is not limited to the above embodiments and can be modified as appropriate without departing from the spirit of the present invention. Furthermore, some or all of the above embodiments can be described as follows, but are not limited to the following. (Appendix 1) An electronic device, a detection unit that detects intrusion of malware into the electronic device by detecting a name resolution error that occurs in a DNS (Domain Name System) packet transmitted from the electronic device; a countermeasure execution unit that restarts the electronic device and changes the settings of the electronic device when malware intrusion is detected; Equipped with In changing the settings, (1) changing at least one of the detection period for the occurrence of the name resolution error and the threshold value for the number of occurrences of the name resolution error for determining that malware has invaded; (2) Blocking packets sent to a specific port; (3) Disabling wireless communications; (4) Disable wired communication At least one of the following is performed electronic equipment. (Appendix 2) When changing the detection period, the countermeasure execution unit changes the length of the detection period to a period longer than the length of the currently set detection period. 1. The electronic device described in Appendix 1. (Appendix 3) When changing the threshold value, the countermeasure execution unit changes the threshold value to a value smaller than the currently set threshold value. 3. An electronic device according to claim 1 or 2. (Appendix 4) The port number used in TCP (Transmission Control Protocol) or UDP (User Datagram Protocol) is port 53. 4. An electronic device according to any one of claims 1 to 3. (Appendix 5) The countermeasure execution unit disables only one of the wireless communication and the wired communication based on whether the transmission of the DNS packet that caused the name resolution error was performed using the wireless communication or the wired communication. 5. An electronic device according to any one of claims 1 to 4. (Appendix 6) The countermeasure execution unit changes the settings in accordance with instructions from the user. 6. An electronic device according to any one of claims 1 to 5. (Appendix 7) An information output unit that outputs information indicating the disadvantages of each change item of the setting change. 7. An electronic device according to any one of claims 1 to 6. (Appendix 8) A method for controlling an electronic device, comprising: Detecting a name resolution error that occurs in a DNS (Domain Name System) packet sent from the electronic device, thereby detecting the intrusion of malware into the electronic device; When malware intrusion is detected, rebooting the electronic device and changing the settings of the electronic device; In changing the settings, (1) changing at least one of the detection period for the occurrence of the name resolution error and the threshold value for the number of occurrences of the name resolution error for determining that malware has invaded; (2) Blocking packets sent to a specific port; (3) Disabling wireless communications; (4) Disable wired communication At least one of the following is performed Control method. (Appendix 9) For electronic devices, computers, a detection step of detecting an intrusion of malware into the electronic device by detecting a name resolution error that occurs in a DNS (Domain Name System) packet transmitted from the electronic device; a countermeasure execution step of restarting the electronic device and changing settings of the electronic device when malware intrusion is detected; Execute In changing the settings, (1) changing at least one of the detection period for the occurrence of the name resolution error and the threshold value for the number of occurrences of the name resolution error for determining that malware has invaded; (2) Blocking packets sent to a specific port; (3) Disabling wireless communications; (4) Disable wired communication At least one of the following is performed program. [Explanation of symbols]
[0050] 100...electronic device, 110...firmware, 111...detection unit, 112...countermeasure execution unit, 113...setting storage unit, 114...UI processing unit, 114a...information output unit, 114b...input reception unit, 120...processor, 130...memory, 140...power supply unit, 150...UI device, 160...network interface, 200...malware, 201...C&C server, T1 to T4...timestamps, U...user
Claims
1. An electronic device, a detection unit that detects a name resolution error that occurs in a DNS (Domain Name System) packet transmitted from the electronic device, thereby detecting the intrusion of malware into the electronic device; a countermeasure execution unit that restarts the electronic device and changes the settings of the electronic device when malware intrusion is detected; Equipped with In changing the settings, (1) changing at least one of the detection period for the occurrence of the name resolution error and the threshold value for the number of occurrences of the name resolution error for determining that malware has invaded; (2) blocking packets sent to a specific port; (3) Disabling wireless communications; (4) Disabling wired communication At least one of the following is performed electronic equipment.
2. When changing the detection period, the countermeasure execution unit changes the length of the detection period to a period longer than the length of the currently set detection period. The electronic device according to claim 1 .
3. When changing the threshold value, the countermeasure execution unit changes the threshold value to a value smaller than the currently set threshold value.
3. The electronic device according to claim 1 or 2.
4. The port number is port 53, which is used in TCP (Transmission Control Protocol) or UDP (User Datagram Protocol). The electronic device according to claim 1 .
5. The countermeasure execution unit disables only one of the wireless communication and the wired communication based on whether the transmission of the DNS packet that caused the name resolution error was performed using the wireless communication or the wired communication. The electronic device according to claim 1 .
6. The countermeasure execution unit changes the settings in accordance with instructions from the user. The electronic device according to claim 1 .
7. An information output unit that outputs information indicating the disadvantages of each change item of the setting change. The electronic device according to claim 1 .
8. A method for controlling an electronic device, comprising: Detecting a name resolution error that occurs in a DNS packet sent from the electronic device, thereby detecting malware intrusion into the electronic device; When malware intrusion is detected, rebooting the electronic device and changing the settings of the electronic device; In changing the settings, (1) changing at least one of the detection period for the occurrence of the name resolution error and the threshold value for the number of occurrences of the name resolution error for determining that malware has invaded; (2) blocking packets sent to a specific port; (3) Disabling wireless communications; (4) Disabling wired communication At least one of the following is performed Control method.
9. For electronic devices, computers, a detection step of detecting intrusion of malware into the electronic device by detecting a name resolution error that occurs in a DNS packet transmitted from the electronic device; a countermeasure execution step of restarting the electronic device and changing settings of the electronic device when malware intrusion is detected; Execute In changing the settings, (1) changing at least one of the detection period for the occurrence of the name resolution error and the threshold value for the number of occurrences of the name resolution error for determining that malware has invaded; (2) blocking packets sent to a specific port; (3) Disabling wireless communications; (4) Disabling wired communication At least one of the following is performed program.
Citation Information
Patent Citations
SYSTEM AND METHOD FOR DETECTING MALWARE INFECTIONS VIA DOMAIN NAME SERVICE TRAFFIC ANALYSIS - Patent application
JP2019500712A