Information processing system

The information processing system facilitates controlled data acquisition during security incidents, reducing downtime by automating data transfer and enabling parallel forensic investigations.

JP2025136754APending Publication Date: 2025-09-19ALLIED TELESIS +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2024035576
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-03-08
Publication Date
2025-09-19

AI Technical Summary

Technical Problem

Existing methods require submitting affected electronic devices for forensic investigation, leading to downtime in business operations and loss of use during the investigation process.

Method used

An information processing system with a monitoring, control, and data acquisition system that allows controlled communication between managed systems and data acquisition systems during security incidents, enabling data acquisition without constant connection, using trigger detection and communication control units to manage network connections.

Benefits of technology

Enables quick restoration of electronic devices and reduces operational downtime while allowing parallel forensic investigations by automating data acquisition and transfer to investigation companies.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025136754000001_ABST
    Figure 2025136754000001_ABST
Patent Text Reader

Abstract

To provide an information processing system for acquiring data about evidence of a damage for an investigation including a forensic investigation in a case where a security accident occurs.SOLUTION: The information processing system includes a management object system, a monitoring system, a control system, and a data acquisition system. The monitoring system sends, to the control system, a notification that a security accident has occurred in the management object system. The control system includes a trigger detection processing unit that accepts the notification and detects a predetermined trigger, a communication control processing unit that instructs a network connection device that controls communication between the management object system and the data acquisition system when detecting the trigger to exert control of permitting or not permitting communication between the management object system and the data acquisition system, and a data processing unit that sends an instruction to acquire investigation data to the data acquisition system from the management object system.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an information processing system for acquiring evidence data of damage suffered for investigations, including forensic investigations, in the event of a cybersecurity (hereinafter referred to as "security") incident (hereinafter referred to as "security incident"). [Background technology]

[0002] Computers have become an essential tool in the daily operations of organizations such as companies and local governments. As a result, various measures are taken to prevent security incidents. Examples of security incidents include computer virus infections, including ransomware, unauthorized access to an organization's network from outside, and information leaks from within an organization's network.

[0003] However, at present, no matter what measures are taken, there is no completely safe solution, and accidents can occur. In such cases, it is common to prevent the damage from the security incident from spreading and to conduct an investigation to determine the cause. This investigation may also include forensic investigation, especially for civil lawsuits and criminal charges. A forensic investigation is the process of conducting various investigations based on data stored in electronic devices such as computers, in order to ensure that the data has admissible evidence, especially from a legal perspective.

[0004] In order to carry out such an investigation, conventionally, the actual electronic device that has been affected is submitted to a company that conducts the investigation, and the investigation is then carried out by the company (Non-Patent Document 1). [Prior art documents] [Non-patent literature]

[0005] [Non-Patent Document 1] AOS Data Corporation, "What is Forensics?" [online], Internet<URL:https: / / www.fss.jp / about-digital / > [Non-patent document 2] Otsuka Shokai Co., Ltd., "Digital Forensic Services", [online], Internet <URL:https: / / www.otsuka-shokai.co.jp / products / security / consulting-education / situation-plan / digital-forensics.html> [Non-patent document 3] PwC Advisory LLC, "Digital Forensics," [online], Internet<URL:https: / / www.pwc.com / jp / ja / services / forensic / digital-forensic.html> Summary of the Invention [Problem to be solved by the invention]

[0006] As mentioned above, when the actual electronic devices that were affected are submitted to the company that is conducting the investigation, the organization loses the electronic devices in question during that time, and is therefore unable to restore or use them. As a result, business operations using the electronic devices are suspended during that period. [Means for solving the problem]

[0007] In view of the above problems, the present inventors have invented the information processing system of the present invention.

[0008] A first invention is an information processing system that performs communication control to perform processing to acquire investigation data when a security incident occurs, the information processing system having a monitoring system that monitors security in a managed system, a control system, and a data acquisition system, the monitoring system sending a notification of a security incident occurring in the managed system to the control system, the control system having a trigger detection processing unit that receives the notification and detects a predetermined trigger, a communication control processing unit that, upon detecting the trigger, issues a control instruction to a network connection device that controls communication between the managed system and the data acquisition system to allow or disallow communication between the managed system and the data acquisition system, and a data processing unit that sends an instruction to the data acquisition system to acquire investigation data from the managed system.

[0009] By configuring the present invention as described above, communication can be permitted during the process of acquiring data for investigation in the event of a security incident, eliminating the need to maintain a constant connection between the managed system and the data acquisition system as in the past.

[0010] A second invention is a control system that performs communication control to perform processing to acquire investigation data when a security incident occurs in a managed system, the control system having a trigger detection processing unit that detects a predetermined trigger, and a communication control processing unit that, upon detecting the trigger, issues a control instruction to a network connection device that controls communication between the managed system and a data acquisition system to allow or disallow communication between the managed system and the data acquisition system.

[0011] By configuring the present invention as described above, communication can be permitted during the process of acquiring data for investigation in the event of a security incident, eliminating the need to maintain a constant connection between the managed system and the data acquisition system as in the past.

[0012] In the above-mentioned invention, the data acquisition system can be configured as a control system that acquires a disk image of a managed computer in which a security incident has occurred in the managed system.

[0013] The data acquisition system preferably acquires disk images as data for investigating security incidents.

[0014] In the above-mentioned invention, the communication control processing unit can be configured as a control system that, when a specified request or log is detected in the trigger detection processing unit, issues a control instruction to the network connection device to allow communication between the managed system and the data acquisition system.

[0015] In the above-mentioned invention, the communication control processing unit can be configured as a control system that, when a specified request or log is detected in the trigger detection processing unit, issues a control instruction to the network connection device to not allow communication between the managed system and the data acquisition system.

[0016] In the above-mentioned invention, the communication control processing unit can be configured as a control system that, when the trigger detection processing unit detects that a predetermined communication permission time has arrived, issues a control instruction to the network connection device to permit communication between the managed system and the data acquisition system.

[0017] In the above-mentioned invention, the communication control processing unit can be configured as a control system that, when the trigger detection processing unit detects that a predetermined communication disallowance time has arrived, issues a control instruction to the network connection device to disallow communication between the managed system and the data acquisition system.

[0018] As the trigger, various triggers such as a request, a log, or a schedule can be used.

[0019] In the above-mentioned invention, communication between the managed system and the data acquisition system can be configured as a control system in which communication is not permitted while communication is not permitted by the network connection device.

[0020] Preferably, communication between the managed systems and the data acquisition system is not permitted except during backup operations.

[0021] A ninth invention is a network connection device that controls communication between a managed system and a data acquisition system, wherein the network connection device allows communication between the managed system and the data acquisition system by receiving a control instruction to allow communication from a control system, causes the data acquisition system to acquire investigation data when a security incident occurs in the managed system, and disallows communication between the managed system and the data acquisition system by receiving a control instruction to not allow communication from the control system, and blocks communication between the managed system and the data acquisition system.

[0022] Even with the configuration of the present invention, communication can be permitted during the process of acquiring data for investigation in the event of a security incident, eliminating the need to maintain a constant connection between the managed system and the data acquisition system as in the past.

[0023] The control system of the second invention can be realized by loading and executing the information processing program of the present invention into a computer. That is, the information processing program causes the computer to function as a trigger detection processing unit that detects a predetermined trigger, and a communication control processing unit that, upon detecting the trigger, issues a control instruction to a network connection device that controls communication between a managed system and a data acquisition system that acquires data for investigation when a security incident occurs in the managed system, to permit or prohibit communication between the managed system and the data acquisition system.

[0024] A network connection device of a ninth aspect of the invention can be realized by loading and executing an information processing program of the present invention into a computer. That is, the information processing program causes a network connection device, which controls communication between a managed system and a data acquisition system, to execute the following steps: upon receiving a control instruction to permit communication from a control system, permitting communication between the managed system and the data acquisition system and causing the data acquisition system to acquire investigation data when a security incident occurs in the managed system; and upon receiving a control instruction to prohibit communication from the control system, prohibiting communication between the managed system and the data acquisition system and cutting off communication between the managed system and the data acquisition system. [Effects of the Invention]

[0025] By using the information processing control system of the present invention, there is no need to submit an electronic device that has been the victim of a security incident to an investigation company, and the electronic device can be quickly restored and used. This reduces the downtime of business operations using the electronic device. On the other hand, information necessary for investigations such as forensic investigations, such as disk images of the electronic device, can be automatically provided to the investigation company, making it possible to conduct investigations such as forensic investigations in parallel. [Brief explanation of the drawings]

[0026] [Figure 1] 1 is a diagram showing an example of the overall configuration of an information processing system including a control system of the present invention. [Figure 2] 1 is a block diagram showing an example of the configuration of a control system according to the present invention; [Figure 3] FIG. 2 is a diagram illustrating an example of a hardware configuration of a computer used in the control system of the present invention. [Figure 4] 1 is an example of a flowchart showing an example of processing of the control system of the present invention. [Figure 5] 1 shows a sequence diagram of processing in the first embodiment. [Figure 6] 10 shows a sequence diagram of processing in the second embodiment. [Figure 7] 10 shows a sequence diagram of processing in the third embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0027] An example of the overall configuration of an information processing system 1 including a control system 2 of the present invention is shown in schematic form in Fig. 1. Fig. 1 shows information processing system 1 used by an organization such as a company, educational institution, or other legal entity, a government agency, or any other organization, and includes a managed system 4 including a computer (managed computer 40) used by the organization to be managed, a monitoring system 3 that monitors the security of managed computer 40 in managed system 4, a control system 2 that performs processing such as communication control associated with the acquisition of investigation data when a security incident occurs, and a data acquisition system 8 that acquires the investigation data.

[0028] The managed system 4 is one or more computers (managed computers 40) used by an organization and subject to management. Each managed computer 40 may be any type of computer used in the organization's daily operations, and may include desktop computers, laptop computers, tablet computers, and even portable communication terminals such as smartphones. The managed computers 40 in the managed system 4 may be connected via a LAN, WAN, or the like.

[0029] It is preferable that a security monitoring program is running on each of the managed computers 40 in the managed system 4. When a security incident is detected in the managed computer 40, the monitoring system 3 is notified of the detection.

[0030] The monitoring system 3 is a computer that monitors the security of the managed computer 40 in the managed system 4. The monitoring system 3 receives notifications of detected security incidents from the managed computer 40 in the managed system 4. In addition to the above notifications, the monitoring system 3 may also monitor the security of the managed computer 40 in the managed system 4 from outside the computer.

[0031] When the monitoring system 3 receives a notification of the detection of the security incident or detects a security incident, it notifies the control system 2 and / or the data acquisition system 8 of the detection.

[0032] When the data acquisition system 8 receives a notification of a security incident from the control system 2 or the monitoring system 3, it executes a process of acquiring data for investigation from the managed computer 40 in which the security incident occurred.

[0033] The investigation data is preferably a disk image of the storage device 71 of the managed computer 40 where the security incident occurred, but any type of data that can be used for an investigation, particularly a forensic investigation, can be used. A disk image is data that physically copies the entire data stored in the storage device 71 from beginning to end and records it as a single file. The data format for the investigation data can be any file format that can be analyzed using the analysis tools used in the investigation by the investigation company. In addition, the system log, application log, etc. of the managed computer 40 where the security incident occurred can also be obtained as investigation data.

[0034] The data acquisition system 8 preferably stores the investigation data acquired from the managed computer 4 where a security incident has occurred in the memory area of ​​the data acquisition system 8 described later, but the data may also be stored in the memory area of ​​a system other than the data acquisition system 8, for example, in an external memory area such as a cloud system that can be accessed from the data analysis system 9 described later.

[0035] The control system 2 and the monitoring system 3 are connected to a data acquisition system 8 via network connection devices, preferably a first network connection device 5 and a second network connection device 6, and are capable of sending and receiving data. The control system 2 and the monitoring system 3 may be the same computer or different computers.

[0036] Communication between the managed system 4 and the data acquisition system 8 is controlled by the first network connection device 5. The managed system 4 and the first network connection device 5 are connected by a communication line 7a. Furthermore, the first network connection device 5 and the data acquisition system 8 are connected by a communication line 7b. Communication between the managed system 4 and the data acquisition system 8 via the first network connection device 5 is preferably performed using SSH (Secure Shell). The communication line 7b is a line used for data communication to acquire investigation data for a managed computer 40 in which a security incident has occurred in the managed system 4. The communication line 7b is normally controlled by the first network connection device 5 to disable communication from the managed system 4 to the data acquisition system 8, but communication is permitted when a communication permission instruction is received from the control system 2, which will be described later. Furthermore, communication from the managed system 4 to the data acquisition system 8 is controlled to a disallowed state when a communication prohibition instruction is received from the control system 2, which will be described later. Whether communication is permitted or not can be controlled in the first network connection device 5 by permitting / denying the use of a port used for communication from the managed system 4 to the data acquisition system 8, but other methods are also possible. For example, all packets from the managed system 4 to the data acquisition system 8 may be discarded / processed. A switch, more specifically an Ethernet (registered trademark) switch, or the like, can be used as the first network connection device 5, but other network connection devices may be used as long as they can control communication on the communication line 7.

[0037] The control instruction to not permit communication between the managed system 4 and the data acquisition system 8 may be a control instruction to at least not permit data communication from the managed system 4 to the data acquisition system 8, but may also be a control instruction to not permit two-way data communication between the data acquisition system 8 and the managed system 4. Furthermore, the control instruction to permit communication between the managed system 4 and the data acquisition system 8 may be a control instruction to at least permit data communication from the managed system 4 to the data acquisition system 8, but may also be a control instruction to permit two-way data communication between the data acquisition system 8 and the managed system 4.

[0038] The control system 2 and the monitoring system 3 are connected to the managed system 4 via the second network connection device 6 and a communication line 7c, preferably at all times. The communication line 7c is a line used for managing, controlling, and monitoring the information processing system 1. The first network connection device 5 and the second network connection device 6 are connected by a communication line 7d, preferably at all times. This allows the control system 2 to issue control instructions to the first network connection device 5. The monitoring system 3 can also monitor the security of the managed system 4. A switch, more specifically an Ethernet (registered trademark) switch, can be used as the second network connection device 6, but any other network connection device can be used as long as it can control communication over the communication line 7.

[0039] The first network connection device 5 and the second network connection device 6 are logically distinguished, not physically. The first network connection device 5 and the second network connection device 6 may be configured as a single device, or as multiple devices having the same functions. Furthermore, each may be configured as a multi-layered structure consisting of multiple devices.

[0040] The data analysis system 9 is a computer that allows an investigation company to use investigation data to analyze the causes of security incidents, etc. In order for the data analysis system 9 to acquire the investigation data from the data acquisition system 8, the investigation data acquired by the data acquisition system 8 can be acquired by sending and receiving the data by a predetermined method such as email, or the data analysis system 9 can access a storage area in which the data acquisition system 8 has stored the investigation data and acquire the data.

[0041] The control system 2, monitoring system 3, managed system 4, data acquisition system 8, and data analysis system 9 in the information processing system 1 are realized by various types of computers such as servers and personal computers. An example of the hardware configuration of a computer is shown in Figure 3. The computer has a calculation device 70 such as a CPU that executes the calculation processing of a program, a storage device 71 such as a RAM or hard disk that stores information, a display device 72 such as a display, an input device 73 such as a keyboard or pointing device (such as a mouse or numeric keypad), and a communication device 74 that sends and receives the processing results of the calculation device 70 and the information stored in the storage device 71 via a network such as the Internet or a LAN.

[0042] 1 and 2 show the case where each is realized by a single computer, but the functions may be distributed and realized on multiple computers. Furthermore, the functions of each processing unit in the present invention are only logically distinguished, and may be physically or practically in the same area.

[0043] An example of the system configuration of the information processing system 1 according to the present invention is shown in the block diagram of Fig. 2. The control system 2 has a trigger detection processing unit 20, a communication control processing unit 21, and a data processing unit 22.

[0044] The trigger detection processing unit 20 detects a trigger for permitting / denying communication between the managed system 4 and the data acquisition system 8. Examples of such triggers include, but are not limited to, the fulfillment of a preset schedule condition, or the receipt of a predetermined request (notification) from the monitoring system 3.

[0045] When the trigger detection processing unit 20 detects a trigger, the communication control processing unit 21 issues a control instruction (command) to the first network connection device 5 via the communication line 7c, the second network connection device 6, and the communication line 7d to permit / deny communication from the managed computer 40 of the managed system 4 to the data acquisition system 8.

[0046] The data processing unit 22 sends an instruction to the data acquisition system 8 to acquire the investigation data from the managed computer 40 in which a security incident has occurred, and causes the data acquisition system 8 to acquire the investigation data. After acquiring the investigation data, the data acquisition system 8 can acquire the investigation data by sending the investigation data to the data analysis system 9, thereby enabling investigations such as forensic investigations. [Example]

[0047] Next, an example of processing by the information processing system 1 of the present invention will be described with reference to the flowchart of Fig. 4 and the sequence diagram of Fig. 5. In this embodiment, an API request is used as a trigger.

[0048] As a trigger condition, a user of the present invention, for example, an administrator of the managed system 4, sets up API linkage settings for the network connection device (first network connection device 5) that is the target of communication control from a predetermined computer to the control system 2 via the second network connection device 6 (S100). This API linkage setting causes job identification information (job ID) for identifying the job for acquiring survey data to be sent from the control system 2 to the administrator's computer.

[0049] The administrator's computer uses the job identification information received from the managed system 4 to set up API linkage for the data acquisition system 8 (S100). When the data acquisition system 8 starts the process of acquiring survey data due to this API linkage setting, a request (API request in this embodiment) to start / end the process of acquiring survey data is sent from the data acquisition system 8 to the control system 2 together with the job identification information before / after the process starts.

[0050] The trigger detection processing unit 20 of the control system 2 waits until it receives this request.

[0051] Then, when a security incident is detected in a managed computer 40 in the managed system 4 (S110), a notification of the detection of the security incident is sent to the monitoring system 3. This notification may include information for identifying the managed computer 40 in which the security incident occurred.

[0052] Upon receiving this notification, the monitoring system 3 notifies the control system 2 of the occurrence of a security incident.

[0053] When the trigger detection processing unit 20 of the control system 2 receives a notification that a security incident has been detected (S120), the data processing unit 22 sends a notification of the security incident to the data acquisition system 8. Then, upon receiving this notification, the data acquisition system 8 sends an API request to the control system 2 to start the process of acquiring the investigation data, along with job identification information.

[0054] If the monitoring system 3 also notifies the data acquisition system 8 of the occurrence of a security incident, the data acquisition system 8 may receive this notification and send a request to start the process of acquiring data for investigation and job identification information to the control system 2. In this case, notification of the occurrence of a security incident from the data processing unit 22 of the control system 2 is not required.

[0055] Then, the communication control processing unit 21 sends a control instruction (command) for communication permission to allow communication from the managed computer 40 in which the security incident occurred to the data acquisition system 8 to the first network connection device 5 via the communication line 7c, the second network connection device 6, and the communication line 7d (S130). At this time, based on the identification information of the managed computer 40 in which the security incident occurred, the control instruction for communication permission may be issued only with that computer, or the control instruction for communication permission may be issued with the managed system 4 that has multiple managed computers 40 including the managed computer 40 in which the security incident occurred.

[0056] Upon receiving this command, the first network connection device 5 enables the port used for communication between the managed computer 40 in which the security incident occurred and the data acquisition system 8, thereby enabling data communication between the managed computer 40 in which the security incident occurred and the data acquisition system 8. Then, the data processing unit 22 sends an instruction to the data acquisition system 8 to acquire investigation data from the managed computer 40 in which the security incident occurred.

[0057] Then, when the data acquisition system 8 receives an instruction to acquire the investigation data from the data processing unit 22, it acquires the investigation data from the managed computer 40 in which the security incident occurred (S140).

[0058] The trigger detection processing unit 20 of the control system 2 waits until a request for completion of the process of obtaining the survey data is received (S150).

[0059] Then, when the data acquisition system 8 has successfully completed acquisition of the survey data, the data acquisition system 8 sends a request to the control system 2 notifying that acquisition of the survey data has been completed.

[0060] When the trigger detection processing unit 20 of the control system 2 detects a request sent from the data acquisition system 8 (S150), the communication control processing unit 21 sends a control instruction (command) to the first network connection device 5 via the communication line 7c, the second network connection device 6, and the communication line 7d to prohibit communication from the managed computer 40 in which a security incident has occurred to the data acquisition system 8 (S160).

[0061] Upon receiving this command, the first network connection device 5 disables the port used for communication between the managed computer 40 where the security incident occurred and the data acquisition system 8, thereby disabling data communication between the managed computer 40 where the security incident occurred and the data acquisition system 8.

[0062] The monitoring system 3 then sends the stored investigation data to the data analysis system 9 at a predetermined timing (S170).

[0063] By executing the above-mentioned process, it is possible to easily preserve evidence and send investigation data to an investigation company when a security incident occurs. Also, it is possible to automatically build a network for acquiring investigation data, acquire the data, automatically dismantle the network, and automatically send the investigation data to the investigation company. [Example]

[0064] Next, an example of processing of the information processing system 1 using the control system 2 of the present invention will be described with reference to the flowchart of Fig. 4 and the sequence diagram of Fig. 6. In this embodiment, a log is used as a trigger. Although a system log (Syslog) is used as the log, an application log may also be used.

[0065] A user of the present invention, for example, an administrator of the managed system 4, sets up log linkage settings such as the system log of the network connection device (first network connection device 5) that is the target of communication control from a predetermined computer to the control system 2 via the second network connection device 6 as a trigger condition (S100). This log linkage setting causes job identification information (job ID) for identifying the job for acquiring investigation data to be sent from the control system 2 to the administrator's computer.

[0066] The administrator's computer uses the job identification information received from the managed system 4 to set up log linkage for the data acquisition system 8. With this log linkage setting, when the data acquisition system 8 starts the process of acquiring survey data and outputs a log, or when the data acquisition system 8 ends the process of acquiring survey data, a request to start / end the process of acquiring survey data is sent from the data acquisition system 8 to the control system 2 together with the job identification information.

[0067] The trigger detection processing unit 20 of the control system 2 waits until it receives this request.

[0068] Then, when a security incident is detected in a managed computer 40 in the managed system 4 (S110), a notification of the detection of the security incident is sent to the monitoring system 3. This notification may include information for identifying the managed computer 40 in which the security incident occurred.

[0069] Upon receiving this notification, the monitoring system 3 notifies the control system 2 of the occurrence of a security incident.

[0070] When the trigger detection processing unit 20 of the control system 2 receives a notification that a security incident has been detected (S120), the data processing unit 22 sends a notification of the security incident to the data acquisition system 8. Then, upon receiving this notification, the data acquisition system 8 sends a request to start the process of acquiring investigation data and job identification information to the control system 2.

[0071] If the monitoring system 3 also notifies the data acquisition system 8 of the occurrence of a security incident, the data acquisition system 8 may receive this notification and send a request to start the process of acquiring data for investigation and job identification information to the control system 2. In this case, notification of the occurrence of a security incident from the data processing unit 22 of the control system 2 is not required.

[0072] Then, the communication control processing unit 21 sends a control instruction (command) for communication permission to allow communication from the managed computer 40 in which the security incident occurred to the data acquisition system 8 to the first network connection device 5 via the communication line 7c, the second network connection device 6, and the communication line 7d (S130). At this time, based on the identification information of the managed computer 40 in which the security incident occurred, the control instruction for communication permission may be issued only with that computer, or the control instruction for communication permission may be issued with the managed system 4 that has multiple managed computers 40 including the managed computer 40 in which the security incident occurred.

[0073] Upon receiving this command, the first network connection device 5 enables the port used for communication between the managed computer 40 in which the security incident occurred and the data acquisition system 8, thereby enabling data communication between the managed computer 40 in which the security incident occurred and the data acquisition system 8. Then, the data processing unit 22 sends an instruction to the data acquisition system 8 to acquire investigation data from the managed computer 40 in which the security incident occurred.

[0074] Then, when the data acquisition system 8 receives an instruction to acquire the investigation data from the data processing unit 22, it acquires the investigation data from the managed computer 40 in which the security incident occurred (S140).

[0075] The trigger detection processing unit 20 of the control system 2 waits until a request for completion of the process of obtaining the survey data is received (S150).

[0076] When the data acquisition system 8 has successfully completed acquisition of the survey data, the data acquisition system 8 detects the log and sends a request to the control system 2 to notify that acquisition of the survey data has been completed.

[0077] When the trigger detection processing unit 20 of the control system 2 detects a request sent from the data acquisition system 8 (S150), the communication control processing unit 21 sends a control instruction (command) to the first network connection device 5 via the communication line 7c, the second network connection device 6, and the communication line 7d to prohibit communication from the managed computer 40 in which a security incident has occurred to the data acquisition system 8 (S160).

[0078] Upon receiving this command, the first network connection device 5 disables the port used for communication between the managed computer 40 where the security incident occurred and the data acquisition system 8, thereby disabling data communication between the managed computer 40 where the security incident occurred and the data acquisition system 8.

[0079] The monitoring system 3 then sends the stored investigation data to the data analysis system 9 at a predetermined timing (S170).

[0080] By executing the above-described processing, it is possible to easily preserve evidence and send investigation data to an investigation company when a security incident occurs, as in Example 1. In addition, it is possible to automatically build a network for acquiring investigation data, acquire the investigation data, automatically dismantle the network, and automatically send the investigation data to the investigation company.

[0081] In this embodiment, when the data acquisition system 8 outputs a log indicating that the process of acquiring survey data has started and a log indicating that the process of acquiring survey data has ended, a specified request is sent from the data acquisition system 8 to the control system 2, and the trigger detection processing unit 20 detects the request, causing the communication control processing unit 21 to send a control instruction to allow / deny communication.

[0082] However, instead of sending a request from the data acquisition system 8 to the control system 2 and having the trigger detection processing unit 20 detect it, the trigger detection processing unit 20 of the control system 2 may be configured to monitor the log in the data acquisition system 8, and when it detects that the data acquisition system 8 has output a log indicating that the acquisition process for survey data has started or that the acquisition process for survey data has ended, the communication control processing unit 21 may send a control instruction to allow / deny communication. [Example]

[0083] Next, an example of processing of the information processing system 1 using the control system 2 of the present invention will be described with reference to the flowchart of Fig. 4 and the sequence diagram of Fig. 7. In this embodiment, a schedule is used as a trigger.

[0084] A user of the present invention, for example, an administrator of the managed system 4, sets, as trigger conditions, the time to issue a control instruction to permit communication, the time to issue a control instruction to deny communication, and the network connection device (first network connection device 5) to be subject to communication control, from a predetermined computer via the second network connection device 6 to the control system 2 (S100). This setting is preferably set, when the control system 2 receives a notification from the monitoring system 3 that a security incident has been detected, to the time to issue a control instruction to permit communication a predetermined interval, such as a predetermined time or a predetermined number of days, after the notification is received, or the time to issue a control instruction to deny communication a predetermined interval after the control instruction to permit communication has been received. For example, the setting can be set so that the control instruction to permit communication is issued one hour after the control system 2 receives a notification from the monitoring system 3 that a security incident has been detected, or the control instruction to deny communication is issued six hours after the control instruction to permit communication.

[0085] In addition to the settings described above, the time to issue a control instruction to permit communication and the time to issue a control instruction to deny communication can be scheduled under various conditions.

[0086] Furthermore, the schedule may be set before a security incident occurs, or may be set after a security incident occurs.

[0087] The time when a control instruction to permit communication is given is, for example, the scheduled start time of the investigation data acquisition process or the time immediately before that, and the time when a control instruction to prohibit communication is given is the time when communication is not permitted, preferably the scheduled end time of the investigation data acquisition process after a predetermined interval has elapsed since the control instruction to permit communication. As for "just before" or "just after," it is sufficient that the time required for switching between permitting / prohibiting communication by the control instruction sent from the control system 2 to the first network connection device 5 is secured, and it is sufficient that a setting is made to secure even more time margin.

[0088] The trigger detection processing unit 20 of the control system 2 waits until the set condition is met.

[0089] Then, when a security incident is detected in a managed computer 40 in the managed system 4 (S110), a notification of the detection of the security incident is sent to the monitoring system 3. This notification may include information for identifying the managed computer 40 in which the security incident occurred.

[0090] Upon receiving this notification, the monitoring system 3 notifies the control system 2 of the occurrence of a security incident.

[0091] The control system 2 stores the trigger conditions set in S100 in a predetermined storage device 71, and waits until a preset communication permission time arrives, for example, a time before the time when the instruction to acquire the survey data is issued (S120). The time information may be obtained by referring to the clock function of the control system 2 or an NTP server.

[0092] Then, when the trigger detection processing unit 20 detects that the time for communication permission has arrived, for example, the time before issuing an instruction to acquire the investigation data (S120), the communication control processing unit 21 sends a control instruction (command) for communication permission to permit communication from the managed computer 40 in which the security incident has occurred to the data acquisition system 8 to the first network connection device 5 via the communication line 7c, the second network connection device 6, and the communication line 7d (S130). At this time, based on the identification information of the managed computer 40 in which the security incident has occurred, the control instruction for communication permission may be issued only with that computer, or the control instruction for communication permission may be issued with the managed system 4 having multiple managed computers 40 including the managed computer 40 in which the security incident has occurred.

[0093] Upon receiving this command, the first network connection device 5 enables the port used for communication between the managed computer 40 in which the security incident occurred and the data acquisition system 8, thereby enabling data communication between the managed computer 40 in which the security incident occurred and the data acquisition system 8. Then, the data processing unit 22 sends an instruction to the data acquisition system 8 to acquire investigation data from the managed computer 40 in which the security incident occurred.

[0094] Then, when the data acquisition system 8 receives an instruction to acquire the investigation data from the data processing unit 22, it acquires the investigation data from the managed computer 40 in which the security incident occurred (S140).

[0095] The control system 2 waits until the time set in S100 when communication is not permitted, for example, the scheduled end time of the survey data acquisition process or a time thereafter, arrives.

[0096] When the trigger detection processing unit 20 detects that the time for communication denial, for example, the scheduled end time of the investigation data acquisition process or a time later, has arrived (S150), the communication control processing unit 21 sends a control instruction (command) for communication denial to the first network connection device 5 via the communication line 7c, the second network connection device 6, and the communication line 7d, disallowing communication from the managed computer 40 in which the security incident has occurred to the data acquisition system 8 (S160).

[0097] Upon receiving this command, the first network connection device 5 disables the port used for communication between the managed computer 40 where the security incident occurred and the data acquisition system 8, thereby disabling data communication between the managed computer 40 where the security incident occurred and the data acquisition system 8.

[0098] The monitoring system 3 then sends the stored investigation data to the data analysis system 9 at a predetermined timing (S170).

[0099] By executing the above-described processing, it is possible to easily preserve evidence and send investigation data to an investigation company when a security incident occurs, as in the case of the first and second embodiments. Also, it is possible to automatically construct a network for acquiring investigation data, acquire the investigation data, automatically dismantle the network, and automatically send the investigation data to the investigation company.

[0100] In this embodiment, the case where the schedule is set by the control system 2 has been described, but the schedule may be set by the data acquisition system 8 instead of the control system 2, and the trigger detection processing unit 20 may monitor the schedule stored in the data acquisition system 8 and detect the arrival of the pre-set time for communication permission / prohibition.

[0101] Furthermore, the schedule may be set in the data acquisition system 8 rather than the control system 2, and when a time (for example, the scheduled time for communication permission / scheduled end time) preset in the data acquisition system 8 arrives, a specified request is sent from the data acquisition system 8 to the control system 2, and the trigger detection processing unit 20 detects the request, causing the communication control processing unit 21 to send a control instruction to permit / deny communication. [Example]

[0102] The processes of the above-described first to third embodiments may be combined. For example, as in the third embodiment, at the start of the investigation data acquisition process, the trigger detection processing unit 20 monitors the scheduled time for communication permission set in the control system 2 or the data acquisition system 8, detects a trigger when the scheduled time for communication permission arrives, and sends a control instruction for communication permission by the communication control processing unit 21. Then, at the end of the investigation data acquisition process, as in the first or second embodiment, the trigger detection processing unit 20 can also be configured to detect a trigger by a request from the data acquisition system 8 or a log output indicating that the investigation data acquisition process in the data acquisition system 8 has ended, and send a control instruction for communication denial by the communication control processing unit 21. [Industrial Applicability]

[0103] By using the control system 2 of the present invention, the managed system 4 and the data acquisition system 8 are not always connected, but are connected via a network when the survey data acquisition process is performed, thereby improving the independence of the survey data acquisition process and ensuring security. [Explanation of symbols]

[0104] 1: Information processing system 2: Control system 3: Surveillance system 4: Managed Systems 5: First network connection device 6: Second network connection device 7: Communication lines 8: Data acquisition system 9: Data analysis system 20: Trigger detection processing unit 21: Communication control processing unit 22: Data processing section 40: Managed computers 70: Arithmetic device 71:Storage device 72:Display device 73: Input device 74:Communication equipment

Claims

1. An information processing system that performs communication control for acquiring data for investigation when a security incident occurs, The information processing system includes: The system includes a monitoring system that monitors security in a managed system, a control system, and a data acquisition system, The monitoring system includes: sending a notification of a security incident occurring in the managed system to the control system; The control system includes: a trigger detection processing unit that receives the notification and detects a predetermined trigger; a communication control processing unit that, upon detecting the trigger, issues a control instruction to a network connection device that controls communication between the managed system and the data acquisition system to permit or prohibit communication between the managed system and the data acquisition system; a data processing unit that sends an instruction to the data acquisition system to acquire survey data from the management system; An information processing system comprising:

2. A control system that performs communication control for acquiring data for investigation when a security incident occurs in a managed system, The control system includes: a trigger detection processing unit that detects a predetermined trigger; a communication control processing unit that, upon detecting the trigger, issues a control instruction to a network connection device that controls communication between the managed system and the data acquisition system to permit or prohibit communication between the managed system and the data acquisition system; A control system comprising:

3. The data acquisition system includes: acquiring a disk image of a managed computer in the managed system where a security incident has occurred; 3. The control system of claim 2.

4. The communication control processing unit When the trigger detection processing unit detects a predetermined request or log, it issues a control instruction to the network connection device to allow communication between the managed system and the data acquisition system.

4. The control system according to claim 2 or 3.

5. The communication control processing unit When the trigger detection processing unit detects a predetermined request or log, it issues a control instruction to the network connection device to prohibit communication between the managed system and the data acquisition system.

5. The control system of claim 4.

6. The communication control processing unit when the trigger detection processing unit detects that a predetermined communication permission time has arrived, it issues a control instruction to the network connection device to permit communication between the management target system and the data acquisition system.

4. The control system according to claim 2 or 3.

7. The communication control processing unit When the trigger detection processing unit detects that a predetermined communication disallowance time has arrived, it issues a control instruction to the network connection device to disallow communication between the managed system and the data acquisition system.

7. The control system of claim 6.

8. communication between the management target system and the data acquisition system is controlled to be prohibited from being permitted while the network connection device is not controlling permission of communication; 4. The control system according to claim 2 or 3.

9. A network connection device for controlling communication between a managed system and a data acquisition system, The network connection device By receiving a control instruction for communication permission from a control system, communication between the managed system and the data acquisition system is permitted, and investigation data is acquired by the data acquisition system when a security incident occurs in the managed system; by receiving a control instruction from the control system not to permit communication, the communication between the managed system and the data acquisition system is not permitted, and the communication between the managed system and the data acquisition system is cut off. A network connection device comprising:

10. Computer, a trigger detection processing unit that detects a predetermined trigger; a communication control processing unit that, upon detecting the trigger, issues a control instruction to a network connection device that controls communication between a managed system and a data acquisition system that performs acquisition processing of investigation data when a security incident occurs in the managed system, to control whether to permit or prohibit communication between the managed system and the data acquisition system; An information processing program characterized by causing the program to function as:

11. A network connection device that controls communication between the managed system and the data acquisition system, a step of permitting communication between the managed system and the data acquisition system by receiving a control instruction for permitting communication from a control system, and causing the data acquisition system to acquire data for investigation when a security incident occurs in the managed system; a step of receiving a control instruction from the control system not to permit communication, thereby prohibiting communication between the managed system and the data acquisition system and cutting off communication between the managed system and the data acquisition system; An information processing program characterized by causing the program to execute the above.