Information processing apparatus, method for controlling information processing apparatus, and program
The information processing device addresses the challenge of unauthorized access in IoT devices by implementing detection, blocking, and countermeasures to restrict attacker functions, ensuring quick recovery and minimal usability impact.
Patent Information
- Application Number
- JP2024031612
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-03-01
- Publication Date
- 2025-09-11
AI Technical Summary
Existing security measures, such as Endpoint Detection and Response (EDR), struggle to identify and counter unauthorized access in resource-limited IoT devices, leading to prolonged functional restrictions and usability issues during cyber attacks, especially zero-day attacks.
An information processing device with detection, blocking, limiting, identification, and countermeasure mechanisms to isolate and restrict functions exploited by attackers, while maintaining basic operations and identifying the source of unauthorized access.
Prevents damage spread and maintains essential functions by restricting only attacker-exploited functions, enabling quick recovery and minimizing usability impact during unauthorized access.
Smart Images

Figure 2025133580000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to an information processing device, a control method for an information processing device, and a program. [Background technology]
[0002] In recent years, damage caused by cyber attacks targeting information processing devices has been increasing. Various security measures have been implemented in response to this trend, but the increasing sophistication of cyber attacks has made it difficult to counter them with traditional security measures such as malware detection and firewalls. Zero-day attacks, which exploit unknown vulnerabilities, are particularly difficult to defend against. For example, there have been numerous cases in which attackers who have infiltrated information processing device systems through zero-day attacks have exploited the systems to cause damage to individuals and companies.
[0003] To counter such sophisticated attacks, in addition to traditional defenses at the network perimeter, security measures that monitor system behavior and detect attacks that attempt to exploit the system are becoming widespread. This security measure is realized by the well-known technology, Endpoint Detection and Response (EDR), and is widely used for personal computers (PCs).
[0004] When EDR detects attacker behavior, it is common to isolate the targeted device from the network and protect other devices, servers, and other assets. In this case, the device cannot be used until the attacker's intrusion route and attack method are identified. Identification can take time even for experts, and it could result in business being unable to be carried out for an extended period of time.
[0005] Patent Document 1 discloses that when a computer virus is detected in an information processing device, functions that are restricted and functions that are permitted to be used are identified depending on the type of computer virus and the location of the infection. This allows functions unrelated to the damage caused by the computer virus to be used, preventing the information processing device that is the target of the attack from becoming completely unusable. In addition, after the virus is detected, removal is performed, and restrictions are gradually relaxed depending on the progress of the removal. This reduces the impact of functional restrictions on usability. [Prior art documents] [Patent documents]
[0006] [Patent Document 1] Japanese Patent Application Publication No. 2023-137656 Summary of the Invention [Problem to be solved by the invention]
[0007] However, in the case of an attack in which an attacker remotely accesses an information processing device and manipulates the information processing device's system, Patent Document 1 is unable to uniquely identify the attacker's behavior and therefore is unable to identify the functions that should be prohibited. Furthermore, Patent Document 1 is able to identify viruses at the detection stage and remove them accordingly. However, in the case of unauthorized access, it is unable to identify the method of intrusion and therefore is unable to take countermeasures. Therefore, even if an attack is detected and functional restrictions are imposed, there is no indicator for relaxing the restrictions, so the functional restrictions remain in place. Furthermore, while countermeasures such as EDR are widely used on PCs and other devices, they require a certain amount of resources to operate, making them unrealistic for implementation in resource-limited IoT devices. In other words, the technology described in Patent Document 1 has the problem of making it difficult to prevent the spread of damage while maintaining some of the functions of the information processing device during unauthorized access.
[0008] The present invention has been made in view of the above-mentioned problems, and aims to provide a technique for preventing the spread of damage while maintaining some functions of an information processing device when unauthorized access occurs. [Means for solving the problem]
[0009] To achieve the above object, an information processing device according to the present invention comprises: a detection means for detecting unauthorized access to the information processing device; blocking means for blocking the unauthorized access; a limiting means for limiting some functions of the information processing device; an identification means for identifying a source of unauthorized access based on the access status of the partial function restricted by the restriction means; Countermeasure means for implementing countermeasures based on the information on the source of the unauthorized access; a release means for releasing the restriction on the partial functions after the countermeasure is implemented; The present invention is characterized by comprising: [Effects of the Invention]
[0010] According to the present invention, when unauthorized access occurs, it is possible to prevent damage from spreading while maintaining some functions of the information processing device. [Brief explanation of the drawings]
[0011] [Figure 1] FIG. 2 is a block diagram showing a connection configuration between the MFP and peripheral devices according to the first embodiment. [Figure 2] FIG. 2 is a hardware configuration diagram of a controller unit of the MFP according to the first embodiment. [Figure 3] FIG. 2 is a functional configuration diagram of a controller unit of the MFP according to the first embodiment. [Figure 4] FIG. 3 is a diagram showing an example of a startup control table according to the first embodiment. [Figure 5] FIG. 4 is a diagram showing an example of an unauthorized access log record table according to the first embodiment. [Figure 6] 4 is a flowchart showing the procedure of processing performed by the MFP according to the first embodiment. [Figure 7] FIG. 10 is a functional configuration diagram of a controller unit of an MFP according to a first modification of the first embodiment. [Figure 8] 10 is a flowchart showing the procedure of processing performed by an MFP according to a first modification of the first embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0012] Hereinafter, embodiments will be described in detail with reference to the accompanying drawings. Note that the following embodiments do not limit the scope of the claimed invention. Although multiple features are described in the embodiments, not all of these multiple features are necessarily essential to the invention, and multiple features may be combined arbitrarily. Furthermore, in the accompanying drawings, the same reference numerals are used to designate the same or similar components, and redundant explanations will be omitted.
[0013] (Embodiment 1) In this embodiment, a process for preventing the spread of damage while maintaining basic functions by restricting only functions that an attacker may exploit when unauthorized access to an information processing device is detected will be described. In this embodiment, a multi-functional peripheral (MFP), which is an image forming device, will be described as an example of an information processing device, but this embodiment can also be applied to information processing devices other than MFPs.
[0014] <System configuration> Referring to FIG. 1, the connection configuration between the MFP and peripheral devices according to this embodiment will be described. The MFP 100, a PC (Personal Computer) 110, and an authentication server 120 are connected via a LAN 140. The PC 110 performs processes such as sending and receiving print jobs and scan jobs to the MFP 100. The authentication server 120 authenticates and authorizes users who access the MFP 100. A protocol such as Lightweight Directory Access Protocol (LDAP) is used for authentication. When the MFP 100 or the PC 110 connects to the Internet, the connection is made via a firewall 130. The PC 150 can access the MFP 100 via the Internet.
[0015] The MFP 100 has a controller unit 101, a panel operation unit 102, a button operation unit 103, a card reader unit 104, a printer unit 105, and a scanner unit 106. The controller unit 101 controls various operations of the MFP 100. The panel operation unit 102 performs input and output with the user. The panel operation unit 102 is composed of an electronic panel, and the user can operate the MFP by performing touch input. The button operation unit 103 performs input and output with the user. The button operation unit 103 is composed of physical buttons, and the user can operate the MFP by pressing the buttons. The card reader unit 104 can authenticate the user by the user holding an IC card over it. The printer unit 105 outputs electronic data to paper media. The scanner unit 106 reads paper media and converts it into electronic data. The panel operation unit 102, button operation unit 103, card reader unit 104, printer unit 105, and scanner unit 106 are connected to the controller unit 101, and function as an MFP under the control of the controller unit 101.
[0016] <Hardware configuration> 2 is a block diagram showing the hardware configuration of the controller unit 101 of the MFP according to this embodiment. A CPU 201 performs the main arithmetic processing within the controller unit 101. The CPU 201 is connected to a DRAM 202 via a bus. The DRAM 202 is used by the CPU 201 as a working memory for temporarily storing program data representing arithmetic instructions and data to be processed during the course of arithmetic operations performed by the CPU 201.
[0017] The CPU 201 is connected to an I / O controller 203 via a bus. The I / O controller 203 performs input and output to various devices according to instructions from the CPU 201. A network I / F 204 is connected to the I / O controller 203. A wired LAN device 220 is connected to the network I / F 204. The CPU 201 realizes communication on the LAN 140 by controlling the wired LAN device 220 via the network I / F 204.
[0018] A SATA (Serial Advanced Technology Attachment) I / F 205 is connected to the I / O controller 203, and a flash memory 221 and a secure memory 222 are connected to the SATA I / F 205. The CPU 201 uses the flash memory 221 to permanently store programs for implementing the functions of the MFP and document files. The CPU 201 also uses the secure memory 222 to store data that is important from a security standpoint. The secure memory 222 is encrypted, and access control allows it to be accessed only from specific modules. This protects confidential information from leaks and unauthorized rewriting.
[0019] A panel I / F 206 is also connected to the I / O controller 203. The panel I / F 206 converts a user's physical operation input via the panel operation unit 102 into electronic data and transmits the data to the CPU 201, thereby realizing the user's operation. A button I / F 207 is also connected to the I / O controller 203. The button I / F 207 converts a user's physical operation input via the button operation unit 103 into electronic data and transmits the data to the CPU 201, thereby realizing the user's operation.
[0020] A card reader I / F 208 is also connected to the I / O controller 203. The card reader I / F 208 converts IC card read information input to the card reader unit 104 into electronic data and transmits the data to the CPU 201 to perform authentication operations, etc. A printer I / F 209 is also connected to the I / O controller 203. The CPU 201 performs output processing on paper media using the printer unit 105 via the printer I / F 209.
[0021] A scanner I / F 210 is also connected to the I / O controller 203. The CPU 201 performs document reading processing using the scanner unit 106 via the scanner I / F 210. A USB I / F 211 is also connected to the I / O controller 203. The USB I / F 211 controls any device connected to the USB I / F 211.
[0022] When the copy function is to be performed, the CPU 201 loads program data from the flash memory 221 into the DRAM 202 via the SATA I / F 205. In accordance with the program loaded into the DRAM 202, the CPU 201 detects a copy instruction from the user via the panel I / F 206 and the button I / F 207 to the panel operation unit 102 and the button operation unit 103. Upon detecting the copy instruction, the CPU 201 receives an original document as electronic data from the scanner unit 106 via the scanner I / F 210 and stores the data in the DRAM 202. The CPU 201 performs color conversion processing suitable for output on the image data stored in the DRAM 202. The CPU 201 transfers the image data stored in the DRAM 202 to the printer unit 105 via the printer I / F 209, where it performs output processing onto paper media. As described above, the copy function can be realized by combining the print function and the scan function.
[0023] When the PDL printing function is implemented, the client PC 110 issues a print instruction via the LAN 140. The CPU 201 loads program data from the flash memory 221 into the DRAM 202 via the SATA I / F 205 and detects a print instruction via the network I / F 204 in accordance with the module loaded into the DRAM 202. When the CPU 201 detects a PDL transmission instruction, it receives print data via the network I / F 204 and stores the print data in the flash memory 221 via the SATA I / F 205. After the print data has been stored, the CPU 201 develops the print data stored in the flash memory 221 into the DRAM 202 as image data. The CPU 201 performs color conversion processing suitable for output on the image data stored in the DRAM 202. The CPU 201 transfers the image data stored in the DRAM 202 to the printer unit 105 via the printer I / F 209 and performs output processing onto paper media.
[0024] The functional configuration and processing flow of this embodiment will be described below.
[0025] <Functional configuration> 3, an example of the functional configuration of the controller unit 101 of the MFP 100 according to the first embodiment will be described. The controller unit 101 includes a panel operation control unit 301, a button operation control unit 302, a card reader control unit 303, a data storage unit 304, a job control unit 305, and an image processing unit 306. The controller unit 101 also includes a print processing unit 307, a reading processing unit 308, a network control unit 309, a TCP / IP control unit 310, a USB control unit 311, and a communication port control unit 312. The controller unit 101 also includes an unauthorized access detection unit 320, a startup control unit 321, a startup mode control unit 322, an unauthorized access information collection unit 323, an unauthorized access identification unit 324, and an unauthorized access countermeasure unit 325.
[0026] The panel operation control unit 301 displays a screen image for the user on the panel operation unit 102, detects touch operations by the user, and executes processes linked to screen components such as buttons displayed on the screen. The button operation control unit 302 executes processes linked to buttons when the user presses a button arranged on the button operation unit 103.
[0027] Card reader control unit 303 executes processing according to information read by a reader disposed in card reader unit 104 when the reader reads an IC card held over by the user. Data storage unit 304 stores data in flash memory 221 or reads data from flash memory 221 in response to requests from other control units. For example, when a user wants to change some device setting, panel operation control unit 301 detects the content input by the user via panel operation unit 102. Then, in response to a request from panel operation control unit 301, data storage unit 304 saves the content as a setting value in flash memory 221.
[0028] A job control unit 305 controls job execution in accordance with instructions from other control units. An image processing unit 306 processes image data into a format suitable for each application in accordance with instructions from the job control unit 305. A print processing unit 307 prints and outputs an image on paper media via a printer I / F 209 in accordance with instructions from the job control unit 305. A reading processing unit 308 reads a placed document via a scanner I / F 210 in accordance with instructions from the job control unit 305.
[0029] The network control unit 309 performs network settings such as IP addresses on the TCP / IP control unit 310 at system startup or when a setting change is detected, in accordance with the setting values stored in the data storage unit 304. The TCP / IP control unit 310 performs network packet transmission and reception processing via the network I / F 204 in accordance with instructions from other control units. The USB control unit 311 controls the USB I / F 211 and controls any device connected via USB. The communication port control unit 312 controls the ports used by the TCP / IP control unit 310 when transmitting and receiving packets.
[0030] The unauthorized access detection unit 320 detects unauthorized access to the MFP. An attacker may exploit unknown vulnerabilities in the MFP to perform unauthorized access to the MFP. If unauthorized access is achieved, the attacker uses the shell of the MFP to execute various commands and make unauthorized use of functions.
[0031] In response to this, the unauthorized access detection unit 320 detects as unauthorized access when an attacker or the like causes the MFP to behave in a way that it would not normally do. In other words, it detects behavior that would not be performed by the MFP when there is no unauthorized access as behavior during unauthorized access. For example, an attacker may launch an editor using the MFP's shell to execute an attack by tampering with the MFP's programs or setting values, or execute a search command to find the program that the attacker targets. The MFP is equipped with commands that realize the above-mentioned processing, but these commands are not executed in normal use cases.
[0032] The unauthorized access detection unit 320 can determine that unauthorized access has occurred when it detects typical attacker behavior that would not occur in a normal use case of an MFP. While an example of detecting unauthorized access based on commands that would not be executed in a normal use case of an MFP has been shown here, unauthorized access may also be detected based on other system behaviors, such as unusual process behavior or library loading. Alternatively, AI may be used to detect unusual behavior and identify it as unauthorized access. When unauthorized access is detected, the unauthorized access detection unit 320 instructs the startup control unit 321 to perform a reboot.
[0033] The startup control unit 321 controls the startup and restart of the MFP. The startup control unit 321 restarts the MFP in response to an instruction from the unauthorized access detection unit 320. This restart can cut off access by an attacker. At the time of restart, the startup control unit 321 instructs the startup mode control unit 322 to transition to a limited function mode. Details of the limited function mode will be described later. Furthermore, when an instruction to release the limited function mode is issued in response to an instruction from the unauthorized access countermeasure unit 325, which will be described later, the startup control unit 321 executes a restart and instructs the startup mode control unit 322 to transition to a normal mode. Details of the normal mode will be described later.
[0034] The activation mode control unit 322 controls the activation mode in response to instructions from the activation control unit 321. The activation mode includes a normal mode and a limited function mode, and the activation mode control unit 322 selects the functions to be enabled depending on the selected function mode.
[0035] When selecting a function to be enabled, the function control table 401 shown in FIG. 4 is referenced. The function control table 401 lists the functions available in each startup mode. In normal mode, the enabled / disabled state of the function set by a user with administrator privileges is reflected. In normal mode, all functions are enabled by default, but functions disabled by user operation are recorded as disabled in the function control table 401. For example, if a user applies a setting to prohibit the use of USB, the item related to USB in the function control table 401 is recorded as disabled. In normal mode, the disabled state is a state in which the use of the function is stopped, and can be changed to an enabled state by user operation while the MFP is running. Note that functions disabled by the unauthorized access countermeasure unit 325 (described later) remain disabled even when switching to normal mode.
[0036] In limited functionality mode, functions that prohibit use when an attacker gains unauthorized access to the MFP are disabled. For example, the file sharing function uses Server Message Block (SMB) to use the MFP as a server to share files with client PCs. Attackers can place malicious files, such as malware, on the SMB server disguised as normal files, potentially spreading damage to client PCs.
[0037] The LDAP authentication function is a function that authenticates the MFP via an LDAP server. The LDAP server stores authentication information for MFP users, and this authentication information is usually an employee account at the company that owns the MFP. By obtaining this employee account, an attacker may be able to access other systems in the company (other devices connected to the MFP) and obtain information, so it is expected that an attacker will use the LDAP authentication function to launch an attack on the LDAP server.
[0038] The account management function can manage the accounts of users who use the MFP, and is a function for performing operations such as changing user privileges and adding accounts. Attackers are expected to carry out attacks such as granting administrator privileges to an account used to illegally access the MFP, or adding a new account for the attacker's use. By restricting functions that can cause significant damage when abused by such attackers, it is possible to prevent the damage from spreading even if the attacker attempts unauthorized access again. Here, the above-mentioned functions are given as examples of functions to be restricted, but other functions that an attacker may abuse are also included in the restrictions.
[0039] On the other hand, basic functions such as copying, scanning, and faxing are not considered targets for attackers to exploit, as they are not expected to be used to expand damage. Therefore, these functions will be available in the same way as in normal mode.
[0040] This prevents the spread of damage caused by attackers while providing users with general MFP functions, thereby achieving both security measures and ensuring usability. Also, assuming unauthorized access from a remote environment, functions that require physical contact with the MFP can be used as usual without any problems, so the local authentication function and USB can be used.
[0041] However, functions that are prohibited in normal mode are also prohibited in limited-function mode. For example, in the startup control table 401 shown in FIG. 4, the use of USB is prohibited in normal mode, and this setting is carried over to limited-function mode. The limited-function mode has a different system configuration from normal mode, and functions that are subject to restriction are excluded from the system configuration. Therefore, while the MFP is running in limited-function mode, restricted functions cannot be enabled. To enable a restricted function, the startup mode must be changed to normal mode and then the MFP must be restarted. Therefore, in limited-function mode, restricted functions are not displayed on the UI, and the user cannot access the functions.
[0042] The unauthorized access information collection unit 323 collects information about attackers who have performed unauthorized access after switching to the function restriction mode. When unauthorized access is detected by the unauthorized access detection unit 320, the attacker's access is blocked once, but there is a possibility that the attacker will access the system again. In this case, the attacker will attempt to misuse the MFP's functions to achieve the purpose of the attack, so the unauthorized access information collection unit 323 collects information when the attacker attempts to use a function that is restricted. Functions that are subject to function restriction are excluded from the system configuration and are not used by users, so if any event occurs with respect to the relevant function, it can be identified as having been performed by an attacker.
[0043] These events include access to the directory where the binary for the function is located, API calls, system calls, and other events that may occur within the MFP. The unauthorized access information collection unit 323 records these event logs in the unauthorized access log recording table 501 shown in Fig. 5. The unauthorized access log recording table 501 records information such as an event in which a restricted function was attempted to be used, the IP address and port communicating when the event occurred, the protocol being used, and the process being started.
[0044] For example, if an attacker attempts to use a restricted file sharing function, they will attempt to use the SMB function. Therefore, events such as SMB API calls, SMB directory accesses, and SMB system calls, as well as the IP address and port accessing the MFP when the event occurred, the communicating protocol, and the running process are recorded.
[0045] If access from multiple IP addresses or the use of a protocol is detected when an event occurs, the accesses are recorded in association with a single event. For example, when an "SMB API call" event occurs in the unauthorized access log record table 501 shown in Figure 5, accesses from two IP addresses are recorded, and both of these are linked to the "SMB API call" event. Here, the IP address, port, protocol, and process are listed as information that is linked to and recorded with the event, but other information may also be included.
[0046] The unauthorized access identification unit 324 identifies the source of the unauthorized access based on the information collected by the unauthorized access information collection unit 323. To identify the source of the unauthorized access, the unauthorized access identification unit 324 refers to the unauthorized access log record table 501 shown in Fig. 5. The unauthorized access identification unit 324 identifies at least one of the IP address, used port, protocol, process, etc. of the attacker who caused the event recorded in the unauthorized access log record table 501 as the attacker's characteristics.
[0047] For example, when an "SMB system call" event occurs, the IP address "10.10.10.10", port "1234", protocol "FTP", and process "file transmission" are recorded in the unauthorized access log record table 501. This means that an attacker is accessing the system from these IP addresses and ports and disguising an FTP file transmission to distribute (transmit) a payload for exploiting SMB. The source of the unauthorized access can be identified from the unauthorized access event information recorded in this way.
[0048] That is, the unauthorized access identification unit 324 identifies the source of unauthorized access based on the status of access to the restricted portion of functions. More specifically, the unauthorized access identification unit 324 identifies the source of unauthorized access based on the characteristics of the attacker attempting to access the restricted portion of functions. The characteristics of the attacker can include at least one of the IP address, port, protocol, and executed process used to access the MFP at the time an event related to the restricted portion of functions occurred.
[0049] Note that multiple related events may be recorded, such as the "SMB API call" event in the unauthorized access log record table 501. When multiple events are recorded simultaneously, the source of unauthorized access is identified based on the correlation between multiple events, rather than on a single event. For example, access from IP address "10.10.10.10" recorded in the unauthorized access log record table 501 is related to events such as "SMB API call," "SMB directory access," and "SMB system call." On the other hand, access from IP address "192.168.10.10" is recorded during "SMB API call," but does not appear in other events. From this, it can be determined that the access from IP address "192.168.10.10" was accidentally recorded as an access from a user. In this way, the source of unauthorized access can be identified even if a user operation was performed. The above analysis example is merely an example; the source of unauthorized access may also be identified through correlation analysis between the event and other information, or through analysis using AI.
[0050] The process of identifying the source of unauthorized access is executed when any of the following conditions is met: a predetermined number of logs are recorded in the unauthorized access log record table 501, a certain amount of time has passed since the first log was recorded, a log that can uniquely identify the source of unauthorized access is recorded, etc. The conditions for executing the identifying process can be selected by the MFP administrator.
[0051] The unauthorized access countermeasure unit 325 implements countermeasures to block access from the unauthorized access source identified by the unauthorized access identification unit 324. The unauthorized access countermeasure unit 325 blocks access by adding the IP address identified by the unauthorized access identification unit 324 to the firewall's rejection list and closing the identified port. The unauthorized access countermeasure unit 325 also closes the attack interface by disabling the protocol used during the attack. This makes it possible to block the source of the attacker's unauthorized access. Note that the above countermeasures are merely examples, and additional processing such as prohibiting the execution of the process used may also be used.
[0052] After the unauthorized access countermeasure unit 325 has implemented countermeasures, the startup control unit 321 restarts the MFP and instructs the startup mode control unit 322 to transition to normal mode. The above instruction is executed when one of the following conditions is met: immediately after implementing countermeasures against unauthorized access, after a certain period of time has elapsed, or by operation of the administrator after notifying the administrator that the source of unauthorized access has been identified. The MFP administrator can select the conditions for the transition instruction. Note that if a new log is recorded in the unauthorized access log record table 501 again before the transition instruction is issued, the process of identifying the source of unauthorized access is executed again.
[0053] <Processing> Next, the procedure of the process performed by the information processing device (MFP) according to this embodiment will be described with reference to the flowchart in Fig. 6. More specifically, the flow of restricting functions that an attacker may exploit when unauthorized access is detected, identifying the source of the unauthorized access, and taking measures will be described.
[0054] In S601, the unauthorized access detection unit 320 detects unauthorized access to the MFP. In S602, the startup control unit 321 blocks the unauthorized access by restarting the MFP. In S603, the startup mode control unit 322 starts up the MFP in limited function mode.
[0055] In S604, after transitioning to the function restriction mode, the unauthorized access information collection unit 323 collects log information related to unauthorized access. In S605, the unauthorized access identification unit 324 analyzes the log information related to unauthorized access and determines whether the source of the unauthorized access has been identified. If the source of the unauthorized access cannot be identified (NO in S605), the process returns to S604 and continues to collect information. On the other hand, if the source of the unauthorized access has been identified (YES in S605), the process proceeds to S606.
[0056] In S606, the unauthorized access countermeasure unit 325 implements countermeasures against unauthorized access. In S607, after implementing countermeasures against unauthorized access, the unauthorized access information collection unit 323 determines whether or not a new unauthorized access log has been detected during the period set by the administrator. If a new unauthorized access log has been detected (NO in S607), the process returns to S604, and log information related to unauthorized access is collected until the source of the unauthorized access can be identified. If a new unauthorized access log has not been detected during the period set by the administrator (YES), the process proceeds to S608.
[0057] In S608, the startup control unit 321 restarts the MFP. In S609, the startup mode control unit 322 starts the MFP in normal mode. In this way, when unauthorized access is detected, it is possible to restrict functions that an attacker may exploit, identify the source of the unauthorized access, and take measures.
[0058] As described above, according to this embodiment, by restricting only the functions that an attacker exploits when unauthorized access to an information processing device is detected, it is possible to prevent the spread of damage while maintaining some functions (basic functions) of the information processing device. Therefore, it is possible to prevent the spread of damage caused by unauthorized access while maintaining usability.
[0059] [Modification 1 of Embodiment 1] In this modified example, an example will be described in which tampering detection processing and recovery processing are executed at startup after unauthorized access is detected. The restart processing after unauthorized access detection can block access by an attacker, but there is a possibility that the attacker may have tampered with settings, programs, etc. before the unauthorized access was detected. Therefore, tampering detection is executed to detect tampering with settings and programs, and recovery processing is executed to overwrite the tampered settings and programs with settings and files in a normal state that were previously stored. This makes it possible to invalidate the tampering executed by the attacker.
[0060] To perform recovery processing, it is necessary to retain settings and programs in a normal state, but because devices such as MFPs have limited storage space for data, it is not realistic to keep backups of all data. For this reason, recovery data is often kept only for important settings and programs. As a result, it may not be possible to restore all settings and programs that have been tampered with. Functions related to settings and programs that could not be restored by recovery processing may have a negative impact on the system, so they are added as functions that are restricted when the system switches to reduced functionality mode.
[0061] <Functional configuration> 7, an example of a functional configuration realized by software executed by controller unit 101 of MFP 100 according to Modification 1 will be described. Note that in this modification, the same components as those described in Embodiment 1 are denoted by the same reference numerals, and detailed description thereof will be omitted.
[0062] The tampering detection processing unit 701 detects tampering with the settings and programs of the MFP. To detect tampering, a hash value calculated from the tampering detection target is used. The hash value calculated from the settings and programs is recorded as the correct value in the MFP's secure memory 222, and the tampering detection processing unit 701 verifies whether tampering has occurred by checking whether the hash value calculated from the tampering detection target matches this correct value. If the result of the tampering detection processing shows no tampering, the system transitions directly to the limited function mode. If tampering has occurred, the recovery processing unit 702 is instructed to perform recovery processing.
[0063] The restoration processing unit 702 restores settings and programs whose tampering has been detected by the tampering detection processing unit 701. The restoration processing is realized by overwriting the tampered settings and programs with settings and programs in a normal state that have been saved in advance in the secure memory 222 of the MFP.
[0064] The tampered portion management unit 703 manages functions that are not subject to recovery processing by the recovery processing unit 702. After recovery processing is executed, the tampered portion management unit 703 lists the settings and files that are not subject to recovery and identifies the functions related to them. Since the functions in question have been tampered with by an attacker and may have a negative impact on the system, the functions are added to the list of functions to be restricted and the system transitions to limited-function mode. Note that even after measures against unauthorized access have been implemented, since tampered programs may have a negative impact on the system, the functions are not enabled even when transitioning to normal mode after measures against unauthorized access have been implemented.
[0065] <Processing> Next, the processing procedure performed by the information processing device (MFP) according to this embodiment will be described with reference to the flowchart in Figure 8. More specifically, the flow of executing tamper detection and recovery processing after unauthorized access detection according to this modification will be described. Note that in this modification, processing similar to that described in embodiment 1 is given the same reference numerals, and detailed description thereof will be omitted.
[0066] In S801, the tampering detection processing unit 701 executes tampering detection processing after restarting the MFP. In S802, the tampering detection processing unit 701 determines whether or not tampering has occurred based on the results of the tampering detection processing. If no tampering has occurred (NO in S802), the process proceeds to S603, where the system transitions to the limited function mode. On the other hand, if tampering has occurred (YES in S802), the process proceeds to S803.
[0067] In S803, the recovery processing unit 702 executes recovery processing for the tampering. In S804, the tampered portion management unit 703 determines whether all tampered portions have been recovered. If all tampered portions have been recovered (YES in S804), the process proceeds to S603, where a transition to the limited function mode is performed. On the other hand, if there are functions that have not been recovered from tampering (NO in S804), the process proceeds to S805. In S805, the tampered portion management unit 703 adds the functions that have not been recovered from tampering to the functions to be limited, and a transition to the limited function mode is performed in S603. In this way, processing for detecting tampering and executing recovery processing after detecting unauthorized access is achieved.
[0068] As described above, according to this modification, it is possible to invalidate the tampering performed by the attacker.
[0069] [Modification 2 of Embodiment 1] In the first embodiment, an example was described in which the mode was switched to the limited function mode after the detection of unauthorized access. In contrast to this, in this modified example, an example will be described in which measures to prevent information leakage are implemented when the mode is switched to the limited function mode.
[0070] Print job information and scanned data may be stored in the MFP's storage. After switching to limited functionality mode, even if an attacker re-enters the MFP, they will not be able to spread damage from the MFP to other devices, but they may be able to access the information stored within the MFP. Therefore, if an attacker obtains the above information, there is a possibility that information from the company or organization that owns the MFP may be leaked.
[0071] Therefore, after switching to limited-function mode, measures to prevent information leakage are implemented for the information stored in the MFP to prevent attackers from accessing confidential information (protecting confidential information). As a measure to prevent information leakage, information is protected by a deletion process that deletes the information itself or by encryption process. When performing a deletion process, the information is deleted after being evacuated to a server or cloud designated in advance by the MFP administrator. When performing an encryption process, decryption process is controlled so that it can only be performed when switching to normal mode, and decryption process cannot be performed in limited-function mode. The administrator can choose whether to delete or encrypt the information. In this way, measures to prevent information leakage after unauthorized access is detected are implemented. Note that information such as user IDs and passwords is also stored in the MFP, but this information is protected by secure memory 222, so attackers cannot steal this information.
[0072] As described above, according to this modification, it is possible to prevent information about a company or organization from being leaked.
[0073] [Modification 3 of Embodiment 1] In the first embodiment, an example was described in which the source of unauthorized access is identified and countermeasures are implemented after switching to the limited function mode, and then switching to the normal mode. In contrast, in this modified example, an example is described in which the process of switching to the normal mode is performed manually by an administrator.
[0074] Countermeasures against unauthorized access to the MFP may be implemented on a system other than the MFP. For example, if the organization that owns the MFP blocks unauthorized access using a firewall installed on the organization's network, attackers will be unable to access the MFP. In such a case, the MFP does not need to identify unauthorized access and implement countermeasures, so it will transition from limited function mode to normal mode in response to manual operation by the administrator.
[0075] This process can only be executed from the local UI of the MFP. This is because if it were possible to switch to normal mode from the remote UI, an attacker could impersonate the administrator and switch to normal mode.
[0076] As described above, according to this modification, the MFP does not need to identify unauthorized access and implement countermeasures, so unnecessary processing can be suppressed.
[0077] The disclosure of this specification includes the following information processing device, control method for an information processing device, and program.
[0078] (Item 1) An information processing device, a detection means for detecting unauthorized access to the information processing device; blocking means for blocking the unauthorized access; a limiting means for limiting some functions of the information processing device; an identification means for identifying a source of unauthorized access based on the access status of the partial function restricted by the restriction means; Countermeasure means for implementing countermeasures based on the information on the source of the unauthorized access; a release means for releasing the restriction on the partial functions after the countermeasure is implemented; An information processing device comprising:
[0079] (Item 2) 2. The information processing device according to item 1, wherein the detection means detects behavior that is not executed by the information processing device when there is no unauthorized access as behavior at the time of unauthorized access.
[0080] (Item 3) 3. The information processing device according to item 1 or 2, wherein the blocking means blocks the unauthorized access by restarting the information processing device.
[0081] (Item 4) 4. The information processing device according to any one of items 1 to 3, wherein the restriction unit restricts the partial functions by disabling the functions to be restricted.
[0082] (Item 5) 5. The information processing device according to any one of items 1 to 4, wherein the partial functions include a function of acquiring information from another device connected to the information processing device.
[0083] (Item 6) 6. The information processing device according to any one of items 1 to 5, wherein the part of the functions includes a function of distributing a payload to another device connected to the information processing device.
[0084] (Item 7) The information processing device described in any one of items 1 to 6, characterized in that the identification means identifies the source of the unauthorized access based on characteristics of an attacker attempting to access the part of the functions restricted by the restriction means.
[0085] (Item 8) The information processing device described in item 7, characterized in that the characteristics of the attacker include at least one of the IP address, port, protocol, and executed process used to access the information processing device at the time an event related to the part of the functions restricted by the restriction means occurred.
[0086] (Item 9) 9. The information processing device according to any one of items 1 to 8, wherein the countermeasure means adds the IP address of the source of the unauthorized access to a firewall denial list.
[0087] (Item 10) 10. The information processing device according to any one of items 1 to 9, wherein the countermeasure means closes a port that is the source of the unauthorized access.
[0088] (Item 11) 11. The information processing device according to any one of items 1 to 10, wherein the countermeasure means invalidates a protocol of the source of the unauthorized access.
[0089] (Item 12) 4. The information processing device according to item 3, further comprising a tamper detection unit that performs a tamper detection process after restarting the information processing device.
[0090] (Item 13) Item 13. The information processing device according to item 12, further comprising a recovery unit that, when tampering is detected by the tampering detection unit, performs recovery processing for the tampering.
[0091] (Item 14) The information processing device described in any one of items 1 to 13, characterized in that the countermeasure means implements leakage prevention measures for confidential information stored in the information processing device after the part of the functions is restricted by the restriction means.
[0092] (Item 15) 15. The information processing device according to any one of items 1 to 14, wherein the release means releases the restriction on the partial functions based on a manual operation by an administrator.
[0093] (Item 16) 16. The information processing device according to any one of items 1 to 15, wherein the information processing device is an image forming device.
[0094] (Item 17) A control method for an information processing device, comprising: a detection step of detecting unauthorized access to the information processing device; a blocking step of blocking the unauthorized access; a limiting step of limiting some functions of the information processing device; an identifying step of identifying a source of unauthorized access based on the access status of the part of the functions restricted by the restricting step; a countermeasure step of implementing countermeasures based on the information on the source of the unauthorized access; a release step of releasing the restriction on the partial functions after the countermeasure is implemented; 1. A method for controlling an information processing device, comprising:
[0095] (Item 18) Item 18. A program for causing a computer to execute the control method for an information processing device according to Item 17.
[0096] (Other embodiments) The present invention can also be realized by supplying a program that realizes one or more functions of the above-described embodiments to a system or device via a network or a storage medium, and having one or more processors in the computer of the system or device read and execute the program.The present invention can also be realized by a circuit (e.g., ASIC) that realizes one or more functions.
[0097] The invention is not limited to the above-described embodiments, and various changes and modifications can be made without departing from the spirit and scope of the invention. Accordingly, the following claims are appended to apprise the public of the scope of the invention. [Explanation of symbols]
[0098] 101: Controller unit, 320: Unauthorized access detection unit, 321: Startup control unit, 322: Startup mode control unit, 323: Unauthorized access information collection unit, 324: Unauthorized access identification unit, 325: Unauthorized access countermeasure unit
Claims
1. An information processing device, a detection means for detecting unauthorized access to the information processing device; blocking means for blocking the unauthorized access; a limiting means for limiting some functions of the information processing device; an identification means for identifying a source of unauthorized access based on the access status of the partial function restricted by the restriction means; Countermeasure means for implementing countermeasures based on the information on the source of the unauthorized access; a release means for releasing the restriction on the partial functions after the countermeasure is implemented; An information processing device comprising:
2. 2. The information processing apparatus according to claim 1, wherein said detection means detects, as the behavior at the time of unauthorized access, a behavior that is not executed by said information processing apparatus when there is no unauthorized access.
3. 2. The information processing apparatus according to claim 1, wherein the blocking means blocks the unauthorized access by restarting the information processing apparatus.
4. 2. The information processing apparatus according to claim 1, wherein the restricting means restricts the part of the functions by disabling the functions to be restricted.
5. The information processing apparatus according to claim 1 , wherein the partial functions include a function of acquiring information from another apparatus connected to the information processing apparatus.
6. 2. The information processing apparatus according to claim 1, wherein the partial functions include a function of distributing a payload to another apparatus connected to the information processing apparatus.
7. 2. The information processing apparatus according to claim 1, wherein the identifying unit identifies the source of the unauthorized access based on characteristics of an attacker attempting to access the part of the functions restricted by the restricting unit.
8. The information processing device according to claim 7, characterized in that the characteristics of the attacker include at least one of an IP address, a port, a protocol, and an executed process used to access the information processing device at the time an event related to the part of the functions restricted by the restriction means occurred.
9. 2. The information processing apparatus according to claim 1, wherein said countermeasure means adds the IP address of the source of said unauthorized access to a firewall denial list.
10. 2. The information processing apparatus according to claim 1, wherein the countermeasure means closes a port from which the unauthorized access originates.
11. 2. The information processing apparatus according to claim 1, wherein the countermeasure means invalidates a protocol of the source of the unauthorized access.
12. 4. The information processing apparatus according to claim 3, further comprising a tamper detection unit that performs a tamper detection process after the information processing apparatus is restarted.
13. 13. The information processing apparatus according to claim 12, further comprising: a recovery unit that, when the tampering detection unit detects tampering, performs a recovery process for the tampering.
14. 2. The information processing apparatus according to claim 1, wherein the countermeasure means implements a leak prevention measure for the confidential information stored in the information processing apparatus after the partial function has been restricted by the restriction means.
15. 2. The information processing apparatus according to claim 1, wherein the release means releases the restriction on some of the functions based on a manual operation by an administrator.
16. 2. The information processing apparatus according to claim 1, wherein the information processing apparatus is an image forming apparatus.
17. A control method for an information processing device, comprising: a detection step of detecting unauthorized access to the information processing device; a blocking step of blocking the unauthorized access; a limiting step of limiting some functions of the information processing device; an identifying step of identifying a source of unauthorized access based on the access status of the part of the functions restricted by the restricting step; a countermeasure step of implementing countermeasures based on the information on the source of the unauthorized access; a release step of releasing the restriction on the partial functions after the countermeasure is implemented; 1. A method for controlling an information processing device, comprising:
18. A program for causing a computer to execute the method for controlling an information processing device according to claim 17.
Citation Information
Patent Citations
Information processing apparatus
JP2023137656A