Program, method, information processing apparatus, and system

A program on terminal devices monitors user actions and clipboard content to prevent unauthorized service access, effectively mitigating information leakage by enforcing restrictions on unauthorized services.

JP2025153912APending Publication Date: 2025-10-10OPTIM
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2024056626
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-03-29
Publication Date
2025-10-10

AI Technical Summary

Technical Problem

Existing systems fail to identify and prevent access to unauthorized services before they are used, potentially leading to information leakage.

Method used

A program installed on a terminal device monitors user actions and clipboard content to determine if access to restricted services is intended, comparing character string information with a predefined list to enforce restrictions.

Benefits of technology

Enables proactive identification and prevention of access to unauthorized services, reducing the risk of information leakage by restricting operations based on real-time determinations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025153912000001_ABST
    Figure 2025153912000001_ABST
Patent Text Reader

Abstract

To determine, in advance, an access to a service of which the use is to be restricted.SOLUTION: A program to be executed by a computer equipped with a processor and a memory, causes the processor to execute the steps of: acquiring first character string information stored in a clip board region prepared in a memory; and comparing the first character string information with second character string information pertaining to a service of which the use is to be restricted, stored in advance in the memory, to determine whether the first character string information is character string information pertaining to the service of which the use is to be restricted.SELECTED DRAWING: Figure 16
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to a program, a method, an information processing device, and a system. [Background technology]

[0002] In recent years, the use of SaaS (Software as a Service) has been expanding. In SaaS, software running on a server is provided to users as a service via a network such as the Internet. Patent Document 1 describes an information processing device and the like that can identify the service being used. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Patent No. 7044451 Summary of the Invention [Problem to be solved by the invention]

[0004] In Patent Document 1, a server receives the results of monitoring an access log by a terminal device, and identifies services that are not managed by the server. However, if a user accesses a service that is not managed, there is a possibility that a problem such as information leakage has already occurred. Therefore, if it is possible to determine in advance that a user is attempting to access a service that is not managed, i.e., a service whose use should be restricted, it becomes possible to take appropriate measures before the service is actually used.

[0005] An object of the present disclosure is to determine in advance access to services whose use should be restricted. [Means for solving the problem]

[0006] A program to be executed by a computer having a processor and a memory, the program causing the processor to execute the steps of: acquiring first character string information stored in a clipboard area provided in the memory; and determining whether the first character string information is character string information relating to a service whose use should be restricted by comparing the first character string information with second character string information relating to a service whose use should be restricted, which is stored in advance in the memory. [Effects of the Invention]

[0007] According to the present disclosure, it is possible to determine in advance whether access to a service whose use should be restricted will occur. [Brief explanation of the drawings]

[0008] [Figure 1] 1 is a block diagram showing an example of the overall configuration of a system 1. FIG. [Figure 2] 2 is a block diagram illustrating an example of the configuration of a terminal device 10 shown in FIG. [Figure 3] FIG. 2 is a diagram illustrating an example of a functional configuration of a first server 20. [Figure 4] FIG. 2 is a diagram illustrating an example of a functional configuration of a second server 30. [Figure 5] FIG. 10 is a diagram showing the data structure of a correspondence table 182. [Figure 6] FIG. 10 is a diagram showing the data structure of an account table 183. [Figure 7] FIG. 10 is a diagram illustrating the data structure of a SaaS table 184. [Figure 8] FIG. 10 is a diagram showing the data structure of a determination result table 185. [Figure 9] FIG. 10 is a diagram showing the data structure of a restriction table 186. [Figure 10] FIG. 10 is a diagram showing the data structure of a detection target table 188. [Figure 11] FIG. 10 is a diagram showing the data structure of a detection log table 189. [Figure 12]10 is a diagram showing the data structure of an aggregation table 2022 stored in the first server 20. FIG. [Figure 13] FIG. 10 is a schematic diagram showing a process in which an agent application 187 installed in the terminal device 10 monitors a process performed by a user. [Figure 14] 10 is a flowchart illustrating an example of the operation of the terminal device 10 when monitoring the user's actions. [Figure 15] 2 is a schematic diagram illustrating an example of a display screen of a display 141 of a terminal device 10. FIG. [Figure 16] FIG. 10 is a schematic diagram illustrating a process in which an agent application 187 installed in the terminal device 10 monitors the clipboard area. [Figure 17] 10 is a flowchart illustrating an example of the operation of the terminal device 10 when monitoring the clipboard area. [Figure 18] 2 is a schematic diagram illustrating an example of a display screen of a display 141 of a terminal device 10. FIG. [Figure 19] 10 is a flowchart illustrating an example of the operation of the terminal device 10 when updating a detection target. [Figure 20] FIG. 2 is a block diagram showing the basic hardware configuration of a computer 90. DETAILED DESCRIPTION OF THE INVENTION

[0009] Hereinafter, embodiments of the present disclosure will be described with reference to the drawings. In the following description, the same components are denoted by the same reference numerals. The names and functions of the components are also the same. Therefore, detailed descriptions thereof will not be repeated.

[0010] <Summary> An agent application is installed on a terminal device, and an agent realized by the agent application monitors actions performed by a user. The agent identifies the service being used by the user based on the detected actions, and determines whether the identified service is a service to be managed.

[0011] The agent transmits the determination result to the server in accordance with the determination result, and also restricts the operation of the terminal device in accordance with the determination result.

[0012] In addition, the agent realized by the agent application monitors a specific storage area reserved for the clipboard function provided by the OS of the terminal device. The agent determines whether the character string information stored in the storage area is character string information related to a service whose use should be restricted. The agent executes a predetermined process according to the determination result.

[0013] <1 Overall system configuration> Fig. 1 is a block diagram showing an example of the overall configuration of a system 1. The system 1 shown in Fig. 1 includes, for example, a terminal device 10, a first server 20, and a second server 30. The terminal device 10, the first server 20, and the second server 30 are communicatively connected via, for example, a network 80.

[0014] 1 shows an example in which the system 1 includes two terminal devices 10, but the number of terminal devices 10 included in the system 1 is not limited to two. The number of terminal devices 10 included in the system 1 may be less than three, or may be three or more.

[0015] 1, a collection of multiple devices may be considered as one first server 20. The way in which multiple functions required to realize the first server 20 according to this embodiment are allocated to one or multiple pieces of hardware can be determined appropriately in consideration of the processing capacity of each piece of hardware and / or the specifications required for the first server 20.

[0016] 1, a collection of multiple devices may be treated as one second server 30. The way in which multiple functions required to realize the second server 30 according to this embodiment are allocated to one or multiple pieces of hardware can be determined appropriately in consideration of the processing capacity of each piece of hardware and / or the specifications required for the second server 30.

[0017] 1 is, for example, an information processing device operated by a user. Specifically, for example, the terminal device 10 is an information processing device operated by an employee of a company.

[0018] The terminal device 10 is realized by, for example, a desktop PC, a laptop PC, etc. The terminal device 10 may be, for example, a mobile terminal such as a smartphone or a tablet, etc. The terminal device 10 may be a wearable terminal such as an HMD (Head Mount Display) or a wristwatch-type terminal.

[0019] The terminal device 10 includes a communication IF (Interface) 12, an input device 13, an output device 14, a memory 15, a storage 16, and a processor 19. The input device 13 is a device for receiving input operations from a user (for example, a touch panel, a touch pad, a pointing device such as a mouse, a keyboard, etc.). The output device 14 is a device for presenting information to a user (a display, a speaker, etc.).

[0020] The first server 20 is, for example, an information processing device that manages web services used by employees of a company. The first server 20 is realized by, for example, a computer connected to a network 80. As shown in Fig. 1, the first server 20 includes a communication IF 22, an input / output IF 23, a memory 25, a storage 26, and a processor 29. The input / output IF 23 functions as an input device for receiving input operations from a user and as an interface with an output device for outputting information to the user.

[0021] The second server 30 is, for example, an information processing device that provides web services used by employees of a company. That is, the second server 30 is, for example, an information processing device that provides SaaS (Software as a Service). The second server 30 issues accounts to employees based on, for example, a contract with the company. The employees use the web services via the assigned accounts. The second server 30 is, for example, realized by a computer connected to the network 80. The second server 30 has, for example, a configuration similar to that of the first server 20 in FIG. 1.

[0022] Each information processing device is configured by a computer equipped with an arithmetic unit and a storage device. The basic hardware configuration of the computer and the basic functional configuration of the computer realized by the hardware configuration will be described later. For each of the terminal device 10, the first server 20, and the second server 30, descriptions that overlap with the basic hardware configuration and basic functional configuration of the computer will be omitted.

[0023] <1.1 Terminal device configuration> Fig. 2 is a block diagram showing an example configuration of the terminal device 10 shown in Fig. 1. As shown in Fig. 2, the terminal device 10 includes a communication unit 120, an input device 13, an output device 14, an audio processing unit 17, a microphone 171, a speaker 172, a camera 160, a position information sensor 150, a storage unit 180, and a control unit 190. The blocks included in the terminal device 10 are electrically connected by, for example, a bus or the like.

[0024] The communication unit 120 performs processing such as modulation and demodulation for the terminal device 10 to communicate with other devices. The communication unit 120 performs transmission processing on the signal generated by the control unit 190 and transmits it to the outside (for example, the first server 20 or the second server 30). The communication unit 120 performs reception processing on the signal received from the outside and outputs it to the control unit 190.

[0025] The input device 13 is a device for inputting instructions or information by a user operating the terminal device 10. The input device 13 is realized, for example, by a touch-sensitive device 131 or the like, which inputs instructions by touching an operation surface. When the terminal device 10 is a PC or the like, the input device 13 may be realized by a reader, keyboard, mouse, or the like. The input device 13 converts instructions input by the user into electrical signals and outputs the electrical signals to the control unit 190. The input device 13 may include, for example, a receiving port that receives electrical signals input from an external input device.

[0026] The output device 14 is a device for presenting information to a user operating the terminal device 10. The output device 14 is realized, for example, by a display 141 or the like. The display 141 displays data according to the control of the control unit 190. The display 141 is realized, for example, by an LCD (Liquid Crystal Display) or an organic EL (Electro-Luminescence) display or the like.

[0027] The audio processing unit 17 performs, for example, digital-to-analog conversion processing of an audio signal. The audio processing unit 17 converts a signal provided from the microphone 171 into a digital signal and provides the converted signal to the control unit 190. The audio processing unit 17 also provides the audio signal to the speaker 172. The audio processing unit 17 is realized, for example, by a processor for audio processing. The microphone 171 receives audio input and provides an audio signal corresponding to the audio input to the audio processing unit 17. The speaker 172 converts the audio signal provided from the audio processing unit 17 into audio and outputs the audio to the outside of the terminal device 10.

[0028] The camera 160 is a device that receives light with a light receiving element and outputs the light as an image capturing signal.

[0029] The position information sensor 150 is a sensor that detects the position of the terminal device 10, and is, for example, a GPS (Global Positioning System) module. The GPS module is a receiving device used in a satellite positioning system. In the satellite positioning system, signals are received from at least three or four satellites, and the current position of the terminal device 10 equipped with the GPS module is detected based on the received signals. The position information sensor 150 may detect the current position of the terminal device 10 from the position of the wireless base station to which the terminal device 10 is connected.

[0030] The storage unit 180 is realized by, for example, the memory 15, the storage 16, etc., and stores data and programs used by the terminal device 10. The storage unit 180 stores, for example, user information 181, a correspondence table 182, an account table 183, a SaaS table 184, a judgment result table 185, a restriction table 186, and an agent application 187. The tables and applications stored in the storage unit 180 are not limited to these.

[0031] The user information 181 includes, for example, information about the user who uses the terminal device 10. The information about the user includes, for example, a user ID, the user's name, age, address, date of birth, password, contact information (address), and the like.

[0032] The correspondence table 182 is a table that associates SaaS with processes executed by a user. Details will be described later. The correspondence table 182 is based on, for example, master information stored in the first server 20. For example, when the master information is updated, the correspondence table 182 is kept up to date by downloading the entire master information or the updated parts from the first server 20.

[0033] The account table 183 is a table that stores information about accounts set for users. Details will be described later. The account table 183 is based on, for example, master information stored in the first server 20. For example, when the master information is updated, the account table 183 is kept up to date by downloading the entire master information or the updated parts from the first server 20.

[0034] The SaaS table 184 is a table that stores SaaS to be managed. The SaaS stored in the SaaS table 184 is, for example, SaaS that is not permitted to be used. In other words, the SaaS table 184 is a blacklist. The SaaS stored in the SaaS table 184 may also be, for example, SaaS that is permitted to be used. In other words, the SaaS table 184 may be a whitelist. This will be described in detail later. The SaaS table 184 is based on, for example, master information stored in the first server 20. For example, when the master information is updated, the entire master information or only the updated parts are downloaded from the first server 20, thereby keeping the SaaS table 184 up to date.

[0035] The determination result table 185 is a table that stores the results of determinations made based on the detected processes, as will be described in detail later.

[0036] The restriction table 186 is a table that associates the judgment result with the restriction on the operation of the terminal device 10. Details will be described later. The restriction table 186 is based on, for example, master information stored in the first server 20. For example, when the master information is updated, the restriction table 186 is kept up to date by downloading the entire master information or the updated parts from the first server 20.

[0037] The agent application 187 is an application for managing the use of SaaS by a user. The agent application 187 is installed on the terminal device 10. The agent application 187 runs, for example, in the background of other applications installed on the terminal device 10, and monitors processes executed by the user.

[0038] The detection target table 188 is a table that stores character string information of detection targets related to services that should be restricted from being used by users. Details will be described later.

[0039] The detection log table 189 is a table that stores the detection history in the terminal device 10 of the character string information of the detection target registered in the detection target table 188. Details will be described later.

[0040] The control unit 190 is realized by the processor 19 reading a program including the agent application 187 stored in the storage unit 180 and executing instructions included in the program. The control unit 190 controls the operation of the terminal device 10. By operating in accordance with the program, the control unit 190 fulfills the functions of an operation reception unit 191, a transmission / reception unit 192, a presentation control unit 193, a first acquisition unit 194, a second acquisition unit 195, a determination unit 196, a restriction unit 197, a character string acquisition unit 199, a restriction target determination unit 1910, a post-detection processing unit 1911, and a detection target update unit 1912.

[0041] The operation reception unit 191 performs processing for receiving instructions or information input from the input device 13. Specifically, for example, the operation reception unit 191 receives instructions or information input from the touch-sensitive device 131 or the like.

[0042] Furthermore, the operation reception unit 191 receives voice instructions input from the microphone 171. Specifically, for example, the operation reception unit 191 receives a voice signal that is input from the microphone 171 and converted into a digital signal by the voice processing unit 17. For example, the operation reception unit 191 analyzes the received voice signal and extracts a predetermined noun, thereby acquiring an instruction from the user.

[0043] The transmitting / receiving unit 192 performs processing for the terminal device 10 to transmit and receive data to and from an external device such as the first server 20 or the second server 30 in accordance with a communication protocol. Specifically, for example, the transmitting / receiving unit 192 transmits information input by the user or instructions from the user to the first server 20 or the second server 30. In addition, the transmitting / receiving unit 192 receives information provided from the first server 20 or the second server 30.

[0044] The presentation control unit 193 controls the output device 14 to present information provided from the first server 20 or the second server 30 to the user. Specifically, for example, the presentation control unit 193 causes the information provided from the first server 20 or the second server 30 to be displayed on the display 141. In addition, the presentation control unit 193 causes the information provided from the first server 20 or the second server 30 to be output from the speaker 172.

[0045] The first acquisition unit 194 acquires information about a process executed by a user operating the terminal device 10. Specifically, for example, the first acquisition unit 194 acquires the name of an application executed by the user's operation and the process name of the application. The first acquisition unit 194 stores the acquired application name, process name, and the date and time when this information was acquired in the storage unit 180 (not shown).

[0046] Furthermore, the first acquisition unit 194 acquires information generated when the user operates the browser. The information generated when the user operates the browser is, for example, the browser usage history, and more specifically, the URLs and page titles of web pages visited by the user operating the browser. The first acquisition unit 194 acquires the information generated when the browser is operated from the browser used in the terminal device 10 at a predetermined timing, for example, at a predetermined cycle such as every five minutes. The first acquisition unit 194 stores the acquired information, the date and time when the information was acquired, the name of the browser that acquired the information, and identification information of the terminal device 10 (for example, a device GUID) in the storage unit 180 (not shown).

[0047] The second acquisition unit 195 acquires information about the SaaS used by the user based on information about the process executed by the user. Specifically, for example, the second acquisition unit 195 compares the URL of the web page visited by the user with the correspondence table 182 and acquires the SaaSID of the SaaS used by the user. In this way, the second acquisition unit 195 identifies the SaaS used by the user.

[0048] The determination unit 196 determines whether the SaaS used by the user is a SaaS to be managed based on the acquired SaaSID. In response to the determination, the determination unit 196 stores the determination result in the determination result table 185. This can be rephrased as, for example, the determination unit 196 stores in the determination result table 185 the process to be managed that has been executed by the user.

[0049] Specifically, for example, the determination unit 196 refers to the SaaS table 184, or refers to the account table 183 and the SaaS table 184, and determines whether the user's use of SaaS is appropriate.

[0050] More specifically, for example, if SaaS table 184 is a blacklist and SaaS whose use is prohibited (SaaS to be managed) is included in SaaS table 184, determination unit 196 determines whether the acquired SaaSID is included in SaaS table 184. If the acquired SaaSID is included in SaaS table 184, determination unit 196 stores in determination result table 185 the fact that the user has used SaaS whose use is not permitted. If the acquired SaaSID is not included in SaaS table 184, determination unit 196 refers to account table 183 and determines whether the user has an account for the acquired SaaSID. If the user has an account for the acquired SaaSID, determination unit 196 does not store information in determination result table 185. If the user does not have an account for the acquired SaaSID, determination unit 196 stores in determination result table 185 the fact that the user used the SaaS using a shadow ID.

[0051] Furthermore, for example, if the SaaS table 184 is a whitelist and the SaaS table 184 includes a SaaS whose use is permitted (a SaaS to be managed), the determination unit 196 determines whether the acquired SaaSID is included in the SaaS table 184. If the acquired SaaSID is not included in the SaaS table 184, the determination unit 196 stores in the determination result table 185 the fact that the user has used a SaaS whose use is not permitted. If the acquired SaaSID is included in the SaaS table 184, the determination unit 196 refers to the account table 183 and determines whether the user has an account for the acquired SaaSID. If the user has an account for the acquired SaaSID, the determination unit 196 does not store information in the determination result table 185. If the user does not have an account for the acquired SaaSID, the determination unit 196 stores in the determination result table 185 the fact that the user used the SaaS using a shadow ID.

[0052] The transmitting / receiving unit 192 transmits the judgment results stored in the judgment result table 185 to the first server 20. Specifically, for example, the transmitting / receiving unit 192 transmits the judgment results stored in the judgment result table 185 to the first server 20 at a predetermined interval.

[0053] The transmitting / receiving unit 192 does not have to transmit all of the judgment results stored in the judgment result table 185 to the first server 20. For example, the transmitting / receiving unit 192 may transmit to the first server 20, from among the judgment results stored in the judgment result table 185, those that satisfy a predetermined condition. Specifically, for example, the transmitting / receiving unit 192 determines whether or not the judgment results stored in the judgment result table 185 satisfy a predetermined condition. The predetermined condition includes, for example, the following: - Blacklisted SaaS was used The number of times the same decision has been made has reached a predetermined value. - The number of times the same decision has been made within a specified period of time has reached a specified value.

[0054] For example, if the determination result stored in the determination result table 185 satisfies at least one of the above conditions or at least one combination of the above conditions, the transmitting / receiving unit 192 transmits the determination result to the first server 20.

[0055] The restriction unit 197 imposes restrictions on the operation of the terminal device 10 based on the determination result of the determination unit 196. That is, the restriction unit 197 imposes restrictions on the operation of the processor of the terminal device 10 based on the determination result of the determination unit 196. Specifically, for example, the restriction unit 197 determines whether the determination result stored in the determination result table 185 satisfies a predetermined condition. The predetermined condition includes, for example, the following: - Blacklisted SaaS was used The number of times the same decision has been made has reached a predetermined value. - The number of times the same decision has been made within a specified period of time has reached a specified value. The user has the required permissions.

[0056] For example, when the judgment results stored in the judgment result table 185 satisfy at least one of the above conditions or at least one combination of the above conditions, the restriction unit 197 imposes a predetermined restriction on the operation of the terminal device 10. The predetermined restriction includes, for example, the following: - Prevent any operations on the terminal device 10 from being accepted - Prohibition of access to specified URLs - Prohibit execution of specified applications -Prohibit access to specified folders - Preventing execution of specified files - Prohibition of certain operations such as reading and writing Stopping running applications

[0057] The determination result and the restrictions on the operation of the terminal device 10 are stored, for example, in the restriction table 186. The restriction unit 197, for example, collates the determination result of the determination unit 196 with the restriction table 186 and determines the restrictions on the operation of the terminal device 10.

[0058] The character string acquisition unit 199 acquires character string information related to a character string from a storage area in the storage unit 180 that is provided for the clipboard function of the terminal device 10. Here, in the present disclosure, the clipboard function is a function provided by, for example, the OS of the terminal device 10, and refers to a function that transfers information stored in a specific storage area in the storage unit 180 between processes of a predetermined application. In the present disclosure, the storage area in the storage unit 180 that is provided for the clipboard function is referred to as a clipboard area.

[0059] Specifically, the character string acquisition unit 199 accesses the clipboard area at a predetermined timing. If character string information is stored in the clipboard area, the character string acquisition unit 199 acquires the character string information. Note that if the character string information stored in the clipboard area is the same as the character string information acquired at the previous timing, the character string acquisition unit 199 does not need to acquire the character string information.

[0060] The character string acquisition unit 199 accesses the clipboard area using the clipboard function at the timings shown below, for example, and acquires character string information. -Predetermined period When information is input to the clipboard area. For example, when a specific application calls an API related to the clipboard function to copy string information. When information is output from the clipboard area. For example, when a specific application calls an API related to the clipboard function to paste text information. The timing when a notification is received that the information stored in the clipboard area has been changed. For example, a notification is received from a specific application that the information stored in the clipboard area has been changed.

[0061] The restriction target determination unit 1910 determines whether the first character string information acquired by the character string acquisition unit 199 is character string information to be restricted regarding a service for which usage by the user should be restricted.

[0062] Specifically, the restriction target determination unit 1910 determines whether the first character string information is character string information that is subject to restriction by comparing the first character string information with the second character string information stored in the column of the item "detection target" in the detection target table 188.

[0063] For example, when the first character string information can be associated with the second character string information, the restriction target determination unit 1910 determines that the first character string information is character string information to be restricted. The first character string information can be associated with the second character string information when the character string information stored in the "detection target" item of at least one record in the detection target table 188 can be associated with the first character string information, for example, as follows: When the character string information stored in the "detection target" item of at least one record in the detection target table 188 matches the first character string information. When the character string information stored in the item "detection target" of at least one record in the detection target table 188 includes the first character string information. The first character string information includes character string information stored in the item “detection target” of at least one record in the detection target table 188.

[0064] The fact that the first character string information was able to be associated with the second character string information may also be expressed as "the detection target was detected from the first character string information" or "the first character string information was included in the second character string information."

[0065] Furthermore, the restriction target determination unit 1910 may determine whether the first character string information is character string information indicating a URL based on whether the first character string information includes a specific element such as a protocol name or a domain name. When the first character string information indicates a URI including a URL (hereinafter, simply referred to as a URL), the restriction target determination unit 1910 may extract a specific element or a combination of elements from the URL and treat it as the first character string information. For example, the restriction target determination unit 1910 may extract a domain portion from the URL and determine whether the character string information of the domain portion is character string information to be restricted.

[0066] Furthermore, the restriction target determination unit 1910 may extract a character string indicating a specific part of speech (for example, a noun) from the first character string information using any natural language processing technology and treat it as the first character string information. The character string to be extracted may be one or more. For example, the restriction target determination unit 1910 may determine whether the extracted character string information of a noun is character string information to be restricted.

[0067] Furthermore, when the restriction target determination unit 1910 determines that the first character string information is character string information related to a service whose use should be restricted, the presentation control unit 193 may present to the user that the first character string information has been determined to be character string information related to a service whose use should be restricted (the determination result).

[0068] The post-detection processing unit 1911 executes a predetermined process for the operation of the terminal device 10 when it is determined that the first character string information is character string information to be restricted.

[0069] The predetermined processing includes, for example, the following: The content of the predetermined processing executed by the post-detection processing unit 1911 is set in advance by, for example, an administrator or the like setting the agent application 187, whereby one or more processes are selected in advance from the following processes. (Restrictions on operations on terminal device 10) - Prevent any operations on the terminal device 10 from being accepted (Operations on the clipboard area) -Delete the first string information from the clipboard area Change the first string information stored in the clipboard (for example, change it to a predetermined notification message or warning message) (Restrictions on the operation of the application that inputs (copied from) the first string information) Stopping the application - Prohibition of inputting information into the clipboard area (copying operation) (Restrictions on the behavior of the application to which the first string information is output (pasted)) Stopping the application - Prohibition of outputting information from the clipboard area to a specified application (paste operation) (Prohibition of access to service providers) - Network communication interruptions Prohibition of connections to destinations that include the first character string information in their identification information. For example, prohibition of connections to destinations (including resources) identified by the first character string information (URL, etc.). Also, for example, prohibition of connections to search result pages that include the first character string information (word, etc.) in the search query portion, or prohibition of connections to destinations that can be reached from such search result pages. In this case, the character string indicating the word may be expressed in an arbitrarily encoded format for incorporation into a URL. (Presenting information to users) Presenting or notifying the user via the display 141, the speaker 172, etc., information that the first character string information has been determined to be character string information subject to restriction Present or notify the user of information regarding the execution of a predetermined process via the display 141, speaker 172, etc.

[0070] The detection target update unit 1912 updates the second character string information that is the detection target. Specifically, the detection target update unit 1912 acquires character string information that is to be newly set as the detection target, and stores the new character string information in the detection target table 188, thereby updating the second character string information.

[0071] For example, the detection target update unit 1912 acquires character string information to be newly set as a detection target as follows.

[0072] (Accepting input of string information) For example, the detection target update unit 1912 acquires character string information input by a user via the input device 13. Alternatively, for example, the detection target update unit 1912 receives character string information from another information processing device such as the first server 20 via the network 80. A user who operates these information processing devices is, for example, a user who manages the terminal device 10.

[0073] (Acquisition of string information related to unauthorized SaaS) Furthermore, for example, the detection target update unit 1912 acquires, at a predetermined timing, character string information relating to SaaS whose use is not permitted from the SaaS table 184 that manages SaaS as a blacklist. For example, the detection target update unit 1912 may acquire the following information about the updated parts of the SaaS table 184 when the SaaS table 184 is updated with information downloaded from the master information of the first server 20 to the terminal device 10. Note that the following information may also be acquired directly from the master information of the first server 20 via the network 80, without going through the SaaS table 184. SaaS name Information about the connection destination for accessing SaaS

[0074] (Obtains string information in response to the detection of inappropriate SaaS usage) Furthermore, for example, in response to detection of inappropriate use of SaaS by a user, the detection target update unit 1912 acquires character string information related to the SaaS. For example, the first acquisition unit 194 acquires information related to a process executed by a user, the second acquisition unit 195 acquires information related to the SaaS used in the process, and the determination unit 196 determines that the use of the SaaS related to the process is inappropriate, the detection target update unit 1912 may acquire the following information: Name of SaaS: For example, the detection target update unit 1912 searches the SaaS table 184 based on the SaaSID of the SaaS, and acquires character string information indicating the name of the SaaS. Information about the connection destination for accessing the SaaS: For example, the detection target update unit 1912 acquires information about the SaaS acquired by the second acquisition unit 195 (for example, information about the provider such as a URL).

[0075] The detection target update unit 1912 stores the character string information acquired as described above in the detection target table 188 as a new detection target, thereby updating the detection target.

[0076] At this time, the detection target update unit 1912 may store part of the acquired character string information in the detection target table 188. For example, if the acquired character string information is a URL, the detection target update unit 1912 may extract predetermined elements from the URL and store them in the detection target table 188. For example, the detection target update unit 1912 may store a domain name extracted from the acquired URL in the detection target table 188. This allows for more thorough detection than when the entire URL is used as the detection target. Furthermore, even if the URL structure of the SaaS is changed, the detection target can continue to be detected as long as the registered components (such as a domain name) remain unchanged.

[0077] <1.2 Functional configuration of the first server> 3 is a diagram illustrating an example of the functional configuration of the first server 20. As illustrated in FIG. 3, the first server 20 functions as a communication unit 201, a storage unit 202, and a control unit 203.

[0078] The communication unit 201 performs processing for the first server 20 to communicate with external devices.

[0079] The storage unit 202 includes, for example, a user information table 2021, an aggregation table 2022, a correspondence master table 2023, an account master table 2024, a SaaS master table 2025, and a restriction master table 2026. The tables stored in the storage unit 202 are not limited to these.

[0080] The user information table 2021 is a table that stores information about users as employees. The user information table 2021 stores, for example, information about a plurality of users. The user information table 2021 is updated when information about a new user is registered.

[0081] The tallying table 2022 is a table that stores information that tally the judgment results transmitted from the terminal device 10. For example, the human resources department of the company that manages the first server 20 may refer to the tallying table 2022 to evaluate the user.

[0082] The correspondence master table 2023 is a table that stores master information on the correspondence between SaaS and processes executed by a user. The correspondence master table 2023 is updated whenever a new correspondence between SaaS and information related to an operation is registered.

[0083] The account master table 2024 is a table that stores information about accounts set for multiple users. The account master table 2024 is updated whenever a new account is issued.

[0084] The SaaS master table 2025 is a table that stores master information of SaaS to be managed, and is updated whenever a new SaaS is registered.

[0085] The restriction master table 2026 is a table that stores master information of the correspondence between the judgment result and the restrictions on the operation of the terminal device 10. The restriction master table 2026 is updated whenever a new correspondence between the judgment result and the restrictions on the operation of the terminal device 10 is registered.

[0086] The control unit 203 is realized by the processor 29 reading a program stored in the storage unit 202 and executing instructions included in the program. The control unit 203 operates in accordance with the program to perform functions shown as a reception control module 2031, a transmission control module 2032, a counting module 2033, a management module 2034, and a creation module 2035.

[0087] The reception control module 2031 controls the process in which the first server 20 receives a signal from an external device in accordance with a communication protocol.

[0088] The transmission control module 2032 controls the process in which the first server 20 transmits a signal to an external device in accordance with a communication protocol.

[0089] The tallying module 2033 controls the tallying of the determination results transmitted from the terminal device 10. Specifically, for example, the tallying module 2033 updates the tallying table 2022 based on the determination results transmitted from the terminal device 10.

[0090] The management module 2034 manages information stored in the storage unit 202. Specifically, for example, when there is information about a new user, the management module 2034 updates the user information table 2021. Also, for example, when there is a new correspondence between a SaaS and a process executed by a user, the management module 2034 updates the correspondence master table 2023. Also, for example, when a new account is issued, the management module 2034 updates the account master table 2024. Also, for example, when there is a new SaaS, the management module 2034 updates the SaaS master table 2025. Also, for example, when there is a new correspondence between a determination result and an operational restriction on the terminal device 10, the management module 2034 updates the restriction master table 2026.

[0091] The creation module 2035 creates information that lists predetermined information based on information transmitted from the terminal device 10. Specifically, the creation module 2035 identifies the hardware used by the user based on the identification information of the terminal device 10 transmitted from the terminal device 10. The creation module 2035 creates information that lists the hardware and software (applications and SaaS) used by the user.

[0092] <1.3 Functional configuration of the second server> 4 is a diagram illustrating an example of the functional configuration of the second server 30. As illustrated in FIG. 4, the second server 30 functions as a communication unit 301, a storage unit 302, and a control unit 303.

[0093] The communication unit 301 performs processing for the second server 30 to communicate with external devices.

[0094] The storage unit 302 includes, for example, a user information table 3021. The tables stored in the storage unit 302 are not limited to these. For example, a table other than the user information table 3021 may be stored.

[0095] The user information table 3021 is a table that stores information about users of companies that receive services provided by the second server 30, for example.

[0096] The control unit 303 is realized by the processor reading a program stored in the storage unit 302 and executing instructions included in the program. The control unit 303 operates in accordance with the program to perform functions shown as a reception control module 3031, a transmission control module 3032, and a service providing module 3033.

[0097] The reception control module 3031 controls the process in which the second server 30 receives a signal from an external device in accordance with a communication protocol.

[0098] The transmission control module 3032 controls the process in which the second server 30 transmits a signal to an external device in accordance with a communication protocol.

[0099] The service providing module 3033 provides services to users of a company that receives the services provided by the second server 30, for example.

[0100] <2 Data Structure> 5 to 11 are diagrams showing the data structures of tables stored in the terminal device 10. Note that Figs. 5 to 11 are merely examples and do not exclude data that is not listed. Furthermore, even data that is listed in the same table may be stored in separate storage areas in the storage unit 180.

[0101] Fig. 5 is a diagram showing the data structure of correspondence table 182. Correspondence table 182 shown in Fig. 5 is a table having columns such as URL, with SaaSID as a key. Note that correspondence table 182 may also have columns for storing information other than the above.

[0102] The SaaSID is an item that stores an identifier for uniquely identifying the SaaS. The URL is an example of information that indicates that the SaaS has been executed. The "URL" item stores, for example, the URL of the homepage that provides the corresponding SaaS.

[0103] Fig. 6 is a diagram showing the data structure of account table 183. Account table 183 shown in Fig. 6 is a table having columns such as SaaSID, scope of use, and registration start date, with user ID as a key. Note that account table 183 may have columns for storing information other than these, or may not have any of these pieces of information.

[0104] The user ID is an item that stores an identifier for uniquely identifying a user. The usage range is an item that stores the range of functions that a user is permitted to use when using SaaS. The usage range is set, for example, when signing up for an account. The usage range may be changed at a predetermined time, for example, at any time during the contract or when applying for renewal. The registration start date is an item that stores the date on which the account was registered and SaaS use began.

[0105] Fig. 7 is a diagram showing the data structure of SaaS table 184. SaaS table 184 shown in Fig. 7 is a table having columns such as name, provider, version, and support information, with SaaSID as a key. Note that SaaS table 184 may have columns for storing information other than these, or may not have any of these pieces of information.

[0106] The "Name" field stores the name of the SaaS. The "Provider" field stores the entity that provides the SaaS. The "Provider" field stores, for example, the name of the company or the address of the website that provides the service. The "Provider" field may also store information about the connection destination for accessing the SaaS. The information about the connection destination is, for example, the URL of the website that provides the SaaS or at least one of the elements that make up the URL (protocol name, host name, domain name, path, etc.), the connection destination IP address, port number, etc. Alternatively / alternatively, the information about the connection destination may include information for identifying resources such as a server on which the SaaS is provided in a network space (this network space can be accessed via the Internet and / or an intranet).

[0107] The version is an item for storing the version of the SaaS that is provided. The support information is an item for storing information about the support provided for the SaaS.

[0108] Fig. 8 is a diagram showing the data structure of determination result table 185. Determination result table 185 shown in Fig. 8 is a table having columns such as software used, usable, and whether or not an account exists, with date and time as a key. Note that determination result table 185 may have columns that store information other than the above, or may not have any of the above information. For example, determination result table 185 may have a column that stores whether the SaaS is on a blacklist.

[0109] The date and time is an item for storing the date and time when use was detected. The software in use is an item for storing information about the SaaS whose use was detected. In the example shown in FIG. 8, the item "software in use" stores the SaaSID of the SaaS whose use was detected. The usable item is an item for storing whether or not the SaaS whose use was detected is licensed for use. The determination unit 196 determines whether or not the SaaS whose use was detected is licensed for use by referring to the SaaS table 184. In the example shown in FIG. 8, if the SaaS is usable, "1" is stored, and if the SaaS is unusable, "0" is stored. The account presence / absence is an item for storing whether or not the user has an account for the SaaS whose use was detected. The determination unit 196 determines whether or not the user has an account for the SaaS whose use was detected by referring to the account table 183. In the example shown in FIG. 8, if the user has an account, "1" is stored, and if the user does not have an account, "0" is stored.

[0110] Fig. 9 is a diagram showing the data structure of the restriction table 186. The restriction table 186 shown in Fig. 9 is a table having columns such as correspondence and priority, with conditions as keys. Note that the restriction table 186 may also have columns for storing information other than these.

[0111] The condition is an item that stores the condition for restricting the operation of the terminal device 10. For example, the following contents are stored in the item "condition". The user has the required permissions and the blacklisted SaaS is used. The number of times the same decision has been made has reached a predetermined value. - The number of times the same decision has been made within a specified period of time has reached a specified value.

[0112] The restriction is an item that stores restrictions imposed on the terminal device 10. The item "restriction" stores, for example, the following: - Prevent any operations on the terminal device 10 from being accepted - Prohibition of access to specified URLs - Prohibit execution of specified applications -Prohibit access to specified folders - Preventing execution of specified files - Prohibition of certain operations such as reading and writing Stopping running applications

[0113] The priority is an item that stores the priority level when adopting a restriction. For example, priority 1 is higher than priorities 2 and 3, and when multiple conditions are met simultaneously, the restriction with the higher priority is adopted. Note that when multiple conditions are met simultaneously, multiple restrictions may be adopted.

[0114] Fig. 10 is a diagram showing the data structure of detection target table 188. Detection target table 188 shown in Fig. 10 is a table having columns for detection targets, etc., with detection target IDs as keys. Note that detection target table 188 may also have columns for storing information other than the above.

[0115] The detection target ID is an item that stores an identifier for uniquely identifying a detection target from the clipboard area. The detection target is an item that stores character string information that is a detection target from the clipboard area. In other words, the item "detection target" is an item that stores character string information related to a service whose use should be restricted. For example, the item "detection target" stores the following:

[0116] - String information that identifies resources related to services that should be restricted from use Here, a resource refers to any type of element available on a network, including, for example, physical or virtual devices such as servers, as well as various types of data and information such as web pages, files, and databases. Furthermore, the character string information that identifies a resource refers to identification information for identifying the resource, such as a URI such as a URL, a local address, a directory path, a file path, an IP address, or character string information that indicates an element or combination of elements that constitute such identification information. For example, for a URL, the elements that constitute the identification information include the protocol, host name, domain name, and path.

[0117] Words related to services that should be restricted Words related to a service whose use should be restricted include, for example, words related to the name and provider of the service, and in particular words used to search for the service in a search engine.

[0118] In the present disclosure, the character string information stored in the item "detection target" may be simply referred to as "detection target."

[0119] Fig. 11 is a diagram showing the data structure of detection log table 189. Detection log table 189 shown in Fig. 11 is a table having columns such as time, detection character string, and detection target ID, with detection log ID as a key. Note that detection log table 189 may also have columns for storing information other than these.

[0120] The detection log ID is an item for storing an identifier for uniquely identifying a detection log, which is a log of character string detection by the character string acquisition unit 199.

[0121] The time is an item for storing the time when detection was performed. For example, the time stamp when the detection process corresponding to the detection log ID was performed is stored in the "time" item.

[0122] The detected character string is an item that stores character string information corresponding to the detection log ID. For example, the item "detected character string" stores a character string detected from the storage unit 180 by matching the detection target conditions in the detection target table 188 during the detection process.

[0123] The detection target ID is an item that stores a detection target ID associated with a detection process that corresponds to a detection log ID. For example, in a process of monitoring the clipboard area, when character string information corresponding to a specific record in the detection target table 188 is detected from character string information acquired from the clipboard area, the value of the item "detection target ID" of the record is stored in the "detection target ID" of the detection log table 189.

[0124] Fig. 12 is a diagram showing the data structure of the aggregation table 2022 stored in the first server 20. Note that Fig. 12 is an example and does not exclude data that is not listed. Furthermore, even data that is listed in the same table may be stored in separate storage areas in the storage unit 202.

[0125] 12 is a table having columns for reported events, number of detections, etc., with user IDs as keys. Note that the aggregation table 2022 may have columns for storing information other than these, or may not have any of these pieces of information.

[0126] The reportable event is an item that stores an event that can be reported. The item "reportable event" can include, for example, the following contents: -Unlicensed use of SaaS was confirmed. - The use of an application that is not permitted for use has been confirmed. - It has been confirmed that you have a shadow ID.

[0127] The number of detections is an item for storing the number of times an event defined as a reportable event has been detected.

[0128] <3 operations> The operation of the agent application 187 when monitoring the SaaS used in the terminal device 10 will be described.

[0129] 13 is a schematic diagram showing a process in which an agent application 187 installed in a terminal device 10 monitors a process by a user. In FIG. 13, a user operates the terminal device 10 on which the agent application 187 is running to use a predetermined SaaS. The terminal device 10 detects the user's use of the SaaS, makes a predetermined determination, and transmits the determination result to the first server 20.

[0130] 14 is a flowchart showing an example of the operation of the terminal device 10 when monitoring the user's actions. In the explanation of FIG. 14, an agent application 187 is installed in the terminal device 10.

[0131] First, a user of the terminal device 10 starts up the terminal device 10. The agent application 187 is set to start up automatically, for example, and is started up by the OS of the terminal device 10 when the terminal device 10 is started up. When the agent application 187 is started up, the control unit 190 may or may not present a message to the user that the agent application 187 is running so that the user can recognize it. The user operates the terminal device 10, for example, to perform a task assigned to the user.

[0132] In step S11, the control unit 190 acquires information about the processing executed by the user. Specifically, for example, the first acquisition unit 194 accesses the browser's log file at a predetermined cycle and acquires the URLs of web pages that the user visited by operating the browser during that cycle. The first acquisition unit 194 stores the acquired URL, the date and time when the URL was acquired, the name of the browser used by the user, and the identification information of the terminal device 10 in the storage unit 180 (not shown). Note that the date and time when the URL was acquired may be the date and time when the user visited the web page related to the URL.

[0133] In step S12, the control unit 190 acquires information about the SaaS used by the user. Specifically, for example, the second acquisition unit 195 compares the URLs of web pages visited by the user during a predetermined period with the correspondence table 182, and acquires the SaaSID of the SaaS used by the user.

[0134] In step S13, the control unit 190 determines whether the user's use of SaaS is appropriate. Specifically, for example, if the SaaS table 184 is a blacklist, the determination unit 196 determines whether the acquired SaaSID is included in the SaaS table 184. If the acquired SaaSID is "SID0001" included in the SaaS table 184, the determination unit 196 stores, for example, the following in the determination result table 185: item "Software in use": SID0001, item "Available for use": 0, and item "Account existence": 0. If the acquired SaaSID (for example, "SID0002") is not included in the SaaS table 184, the determination unit 196 refers to the account table 183 and determines whether the user has an account for the acquired SaaSID. If the user has an account for the acquired SaaSID, the determination unit 196 does not store information in the determination result table 185. If the user does not have an account for the acquired SaaSID, the determination unit 196 stores, for example, the following in the determination result table 185: item "Software in use": SID0002, item "Available for use": 1, and item "Account available": 0.

[0135] Furthermore, for example, if SaaS table 184 is a whitelist, determination unit 196 determines whether the acquired SaaSID is included in SaaS table 184. If the acquired SaaSID (for example, "SID0003") is not included in SaaS table 184, determination unit 196 stores, for example, the following in determination result table 185: item "Software in use": SID0003, item "Available for use": 0, and item "Account held": 0. If the acquired SaaSID is "SID0004" included in SaaS table 184, determination unit 196 refers to account table 183 and determines whether the user has an account for the acquired SaaSID. If the user has an account for the acquired SaaSID, determination unit 196 does not store information in determination result table 185. If the user does not have an account for the acquired SaaSID, the determination unit 196 stores, for example, the following in the determination result table 185: item "Software in use": SID0004, item "Available for use": 1, and item "Account existence": 0.

[0136] In step S14, the control unit 190 determines whether or not to transmit the determination result stored in the determination result table 185 to the first server 20. Specifically, for example, the transmitting / receiving unit 192 determines whether or not the determination result stored in the determination result table 185 satisfies a predetermined condition. If the determination result satisfies the predetermined condition, the transmitting / receiving unit 192 shifts the processing to step S15. If the determination result does not satisfy the predetermined condition, the transmitting / receiving unit 192 shifts the processing to step S16.

[0137] In step S15, the transmitting / receiving unit 192 transmits to the first server 20 the determination result that the condition is satisfied.

[0138] In step S16, the control unit 190 determines whether or not to impose restrictions on the operation of the terminal device 10. Specifically, for example, the restriction unit 197 determines whether or not the judgment result stored in the judgment result table 185 satisfies a predetermined condition. If the judgment result satisfies the predetermined condition, the restriction unit 197 shifts the processing to step S17. If the judgment result does not satisfy the predetermined condition, the restriction unit 197 shifts the processing to step S11.

[0139] In step S17, the restriction unit 197 imposes a predetermined restriction on the operation of the terminal device 10. Specifically, for example, the restriction unit 197 compares the judgment result stored in the judgment result table 185 with the restriction table 186, determines a restriction on the operation of the terminal device 10, and imposes the determined restriction on the terminal device 10.

[0140] More specifically, for example, if a user has the authority to access highly confidential information but uses a blacklisted SaaS, the restriction unit 197 controls the terminal device 10 so as not to accept any operations. For example, if the number of times that a SaaS whose use is not permitted reaches N, the restriction unit 197 prohibits access to the site that provides the SaaS. For example, if the number of times that a SaaS whose use is not permitted reaches N within a predetermined period, the restriction unit 197 prohibits access to the site that provides the SaaS. For example, if the number of times that a specific SaaS is used with a shadow ID reaches N, the restriction unit 197 prohibits access to the site that provides the SaaS. For example, if the number of times that a specific SaaS is used with a shadow ID reaches N within a predetermined period, the restriction unit 197 prohibits access to the site that provides the SaaS.

[0141] In step S18, the presentation control unit 193 presents to the user that the operation of the terminal device 10 has been restricted.

[0142] Fig. 15 is a schematic diagram illustrating an example of a display screen of the display 141 of the terminal device 10. Fig. 15 illustrates an example in which processing on the terminal device 10 is stopped due to the use of SaaS for which use is not permitted. The screen illustrated in Fig. 13 displays a first area 1411 for notifying the user that restrictions have been imposed on the operation of the terminal device 10. The presentation control unit 193 may display, in the first area 1411, processing for removing the restrictions imposed on the terminal device 10.

[0143] 16 is a schematic diagram showing a process in which agent application 187 installed in terminal device 10 monitors the clipboard area. In FIG. 16, a user operates terminal device 10 on which agent application 187 is running to execute a predetermined application. Then, based on the user's operation, terminal device 10 acquires predetermined character string information from a storage area allocated for the predetermined application and stores the information in the clipboard area. Terminal device 10 monitors the clipboard area and determines whether the character string information stored in the clipboard area is subject to restriction.

[0144] 17 is a flowchart showing an example of the operation of the terminal device 10 when monitoring the clipboard area. In the explanation of FIG. 17, an agent application 187 is installed in the terminal device 10.

[0145] First, a user of the terminal device 10 starts up the terminal device 10. The agent application 187 is set to start automatically, for example, and is started by, for example, the OS of the terminal device 10 when the terminal device 10 starts up. When the agent application 187 starts up, the control unit 190 may or may not present a notice that the agent application 187 is running so that the user can recognize it. The user operates the terminal device 10 to perform, for example, a task assigned to the user. In the process, the user performs a copy operation of character string information in a predetermined application. As a result, the character string information is stored in the clipboard area of ​​the terminal device 10.

[0146] In step S21, control unit 190 acquires character string information stored in the clipboard area. Specifically, for example, character string acquisition unit 199 accesses the clipboard area at a predetermined cycle, and acquires character string information if the character string information is stored in the clipboard area.

[0147] In step S22, the control unit 190 determines whether or not the first character string information acquired by the character string acquisition unit 199 is character string information to be restricted regarding a service whose use should be restricted. Specifically, for example, the restriction target determination unit 1910 refers to the item "detection target" in the detection target table 188 and determines whether or not the acquired first character string information can be associated with character string information stored in at least one record of the item "detection target" (whether or not the detection target can be detected from the first character string information).

[0148] If it is determined that the acquired first character string information is not character string information to be restricted (NO in step S22), the control unit 190 shifts the process to step S21.

[0149] If it is determined that the acquired first character string information is character string information to be restricted (YES in step S22), the control unit 190 acquires the detection target ID of the record of the character string information that can be associated with the character string information acquired in step S21, and then proceeds to step S23.

[0150] In step S23, the control unit 190 executes a predetermined process on the terminal device 10. Specifically, the post-detection processing unit 1911 executes a process that is determined to be for a case where the character string information is determined to be subject to restriction on the terminal device 10. As an example, when a user operates the terminal device 10 to paste the character string information from the clipboard area, the post-detection processing unit 1911 prohibits the output of the character string information from the clipboard area.

[0151] After step S22, the control unit 190 may proceed to step S24 without proceeding to step S23. In other words, the control unit 190 may not execute the process of this step for the terminal device 10.

[0152] In step S24, the control unit 190 presents the determination result to the user. Specifically, for example, the presentation control unit 193 displays on the display 141 of the terminal device 10 a message that the character string information acquired in step S21 has been determined to be character string information to be restricted. That is, the presentation control unit 193 displays on the display 141 a message that character string information to be restricted has been detected from the clipboard area of ​​the terminal device 10.

[0153] Fig. 18 is a schematic diagram showing an example of a display screen of the display 141 of the terminal device 10. Fig. 18 shows an example of a case where a character string to be restricted is detected in the clipboard area of ​​the terminal device 10, and therefore output of the character string information from the clipboard area is prohibited. The screen shown in Fig. 18 displays an area 1412 for notifying the user that a character string to be restricted has been detected in the clipboard area of ​​the terminal device 10.

[0154] For example, the following exemplary information may be displayed in area 1412: - Information about the detected restricted strings Information about the content of the processing executed by the post-detection processing unit 1911 in step S23. Information about SaaS related to the character string information to be restricted.

[0155] In step S25, control unit 190 records a detection log. Specifically, for example, control unit 190 stores the time when the character string information was acquired in step S21 in the item "Time" of a new record in detection log table 189, the character string information acquired in step S21 in the item "Detection character string," and the detection target ID acquired in step S22 in the item "Detection target ID." Control unit 190 then transitions the process to step S21.

[0156] In this way, by repeating steps S21 to S25, the control unit 190 monitors the clipboard area. Furthermore, the control unit 190 may transmit the detection results stored in the detection log table 189 to the first server 20 at a predetermined cycle.

[0157] (Detection target update process) FIG. 19 is a flowchart showing an example of the operation when the terminal device 10 updates character string information to be detected.

[0158] In step S31, the control unit 190 acquires character string information to be newly set as a detection target. Specifically, for example, the detection target update unit 1912 acquires the character string information from a predetermined information processing device.

[0159] In step S32, the control unit 190 updates the detection target. Specifically, the detection target update unit 1912 stores the character string information acquired in step S31 as a new detection target in the storage unit 180. For example, the detection target update unit 1912 creates a new record in the detection target table 188 and stores the character string information acquired in step S31 in the item "detection target."

[0160] <Summary> As described above, in the above embodiment, the character string acquisition unit 199 acquires character string information stored in the storage unit 180 by the clipboard function of the terminal device 10. The restriction target determination unit 1910 determines whether or not the first character string information acquired by the character string acquisition unit 199 is second character string information related to a service whose use by the user should be restricted. This makes it possible to determine whether or not the character string information stored in the clipboard area is character string information related to a service whose use by the user should be restricted.

[0161] When a user stores character string information in the clipboard area, the user may access a service related to the character string information by pasting the character string information into a search bar of a browser application or by searching the character string information on a search engine. Therefore, according to the above embodiment, the terminal device 10 can determine in advance whether the user is attempting to use a service whose use by the user should be restricted, before the user actually uses the service.

[0162] In the above embodiment, if the post-detection processing unit 1911 determines that the first character string information is related to a service whose use should be restricted, the post-detection processing unit 1911 restricts the operation of a predetermined application when the first character string information is output to the application, thereby restricting access to the service by the application.

[0163] Furthermore, in the above embodiment, when it is determined that the first character string information is character string information related to a service whose use should be restricted, the post-detection processing unit 1911 prohibits the output of the first character string information from the storage unit 180. This prohibits, for example, pasting of the first character string information by a predetermined application, thereby making it possible to restrict access to the service by the application.

[0164] Furthermore, in the above embodiment, if it is determined that the first character string information is character string information related to a service whose use should be restricted, the post-detection processing unit 1911 deletes the first character string information from the storage unit 180. This makes it impossible for a predetermined application to paste the first character string information, thereby making it possible to restrict access to the service by the application.

[0165] In the above embodiment, the second character string information includes character string information that identifies a resource related to a service whose use should be restricted. This allows the terminal device 10 to determine that character string information that identifies a resource related to a service whose use should be restricted is stored in the clipboard area.

[0166] In the above embodiment, the second character string information includes character string information indicating words related to services whose usage should be restricted, which allows the terminal device 10 to determine that character string information indicating words related to services whose usage should be restricted is stored in the clipboard area.

[0167] In the above embodiment, the detection target update unit 1912 acquires information about the services to be managed. The detection target update unit 1912 updates the second character string information based on the acquired information. This can improve the accuracy of the determination by the restriction target determination unit 1910.

[0168] Furthermore, in the above embodiment, the first acquisition unit 194 acquires information about a process executed by a user. Based on the information acquired by the first acquisition unit 194, the second acquisition unit 195 acquires information about a service associated with the process. The determination unit 196 determines whether the service related to the information acquired by the second acquisition unit 195 is a service that is appropriate for use by the user. If the service is determined to be a service that is inappropriate for use by the user, the detection target update unit 1912 updates the second character string information based on the information about the process executed by the user. This can improve the accuracy of determination by the restriction target determination unit 1910.

[0169] Furthermore, in the above embodiment, the first acquisition unit 194 acquires information about a process executed by a user. The second acquisition unit 195 acquires information about a service associated with the process based on the acquired information about the process. The determination unit 196 determines whether the acquired information about the service is a service to be managed. This enables the terminal device 10 to quickly determine whether there is a problem with the user's use of the service.

[0170] Therefore, according to the above embodiment, the terminal device 10 can take prompt action when there is a problem in using the service. Furthermore, edge computing reduces the cost of operating the first server 20. Furthermore, even if communication between the terminal device 10 and the network is interrupted, the terminal device 10 can monitor the processing performed by the user.

[0171] Furthermore, in the above embodiment, the first acquisition unit 194 acquires information related to the process at a preset cycle. The second acquisition unit 195 acquires information related to the service associated with the process based on the information acquired during the cycle. This reduces the frequency with which the terminal device 10 acquires information related to the process, but makes it possible to effectively monitor the operation of the terminal device 10 while suppressing power consumption.

[0172] In the above embodiment, the determination unit 196 determines whether or not the user has an account based on information about the service. This allows the terminal device 10 to determine whether or not the user has an account for the service that the user is using. In other words, the terminal device 10 can determine whether or not the user has a shadow ID.

[0173] In the above embodiment, the determination unit 196 determines whether or not the user has an account by referring to a pre-stored account list (account table 183). This enables the determination unit 196 to accurately determine whether or not the user has an account for the service that the user is using.

[0174] In the above embodiment, when the determination result satisfies a predetermined condition, the transmitter / receiver 192 transmits the determination result that satisfies the condition to an external device. The SaaS whose use is managed may have different levels of management. Some prohibited SaaS may become problematic if habitual use is permitted. Under such circumstances, transmitting information to the first server 20 every time a non-recommended SaaS is used increases the power consumption of the terminal device 10. Furthermore, events that do not need to be aggregated may accumulate in the first server 20, resulting in a waste of storage resources. In this embodiment, by transmitting a determination result that satisfies a predetermined condition to the first server 20, it is possible to reduce the power consumption of the terminal device 10 and avoid wasting storage resources of the first server 20.

[0175] Specifically, when a predetermined determination is made a preset number of times, the transmitting / receiving unit 192 transmits the determination result to the external device. Also, when a determination that the user does not have an account is made a preset number of times, the transmitting / receiving unit 192 transmits the determination result to the external device.

[0176] In the above embodiment, the limiting unit 197 limits the operation of the processor based on the determination result, which enables the terminal device 10 to immediately deal with any problem in the user's use of the service.

[0177] In the above embodiment, the terminal device 10 transmits information identifying the hardware used by the user to the first server 20. The first server 20 stores information about the software used by the user in advance, and creates a list of the hardware and software used by the user based on the information identifying the hardware. This enables the first server 20 to reduce the burden of managing the hardware and software used by employees.

[0178] <Modification> In the above embodiment, when the operation of the terminal device 10 is restricted because the user's use of a service is inappropriate, an example is described in which the user is notified of the restriction, as shown in FIG. 13 . The information presented to the user is not limited to the restriction on the operation of the terminal device 10. The presentation control unit 193 may also present to the user that the user's use of the service is inappropriate. Furthermore, the presentation control unit 193 may present to the user a grace period until the condition for transmitting determination information to the first server 20 is met, or until the condition for restricting the operation of the terminal device 10 is met.

[0179] In the above embodiment, the browser usage history is used as information about the processing performed by the user. However, the application name and process name of the application executed by the user may be used as information about the processing performed by the user. In this case, for example, the correspondence table 182 associates SaaS with the application name and process name of the application executed by the user. The second acquisition unit 195 compares the acquired application name and process name with the correspondence table 182 and acquires the SaaSID of the SaaS used by the user. In this way, the second acquisition unit 195 identifies the SaaS used by the user.

[0180] In the above embodiment, the determination unit 196 recognizes the existence of a shadow ID. However, the control unit 190 may perform the function of the identification unit 198 that identifies a shadow ID. When the determination unit 196 recognizes the existence of a shadow ID, the identification unit 198 accesses the second server 30 and acquires information about the account through which the user is using the SaaS. This enables the identification unit 198 to identify the user's shadow ID. When the identification unit 198 identifies the shadow ID, the transmission / reception unit 192 transmits the identified shadow ID to the first server 20.

[0181] Furthermore, in the above embodiment, an example has been described in which the use of SaaS is monitored, but the use of an application may also be monitored by an agent executed on the terminal device 10. In this case, the terminal device 10 stores, for example, a table that stores applications whose use needs to be managed or processes whose use needs to be managed. The restriction unit 197 compares the acquired information with the table and determines whether the application or process used by the user is appropriate. The restriction unit 197 stores the determination result in the determination result table 185.

[0182] In the above embodiment, the character string acquisition unit 199 acquires character string information stored in the clipboard area. However, the character string acquisition unit 199 may acquire character string information before being transferred (copied) to the clipboard area in response to an API call associated with a copy operation of a predetermined application. The character string acquisition unit 199 may acquire character string information transferred (pasted) from the clipboard area in response to an API call associated with a paste operation of a predetermined application.

[0183] Furthermore, in the above embodiment, the content of the processing executed by post-detection processing unit 1911 was set in advance by an administrator or the like. However, the content of the processing may be determined for each detection target ID stored in detection target table 188. Then, post-detection processing unit 1911 may determine and execute the content of the processing based on the detection target ID associated with the item "detection target" in detection target table 188 in which the character string information that can be associated with the first character string information is stored.

[0184] In the above embodiment, the post-detection processing unit 1911 executes a predetermined process each time a detection target is detected from the first character string information. However, the post-detection processing unit 1911 may execute the predetermined process only when a specific condition is met. For example, the post-detection processing unit 1911 may execute the predetermined process on the condition that the same detection target has been detected a predetermined number of times in the terminal device 10 or that the same detection target has been detected a predetermined number of times within a predetermined period. The condition may be associated with the detection target ID and stored in the detection target table 188.

[0185] In the above embodiment, the terminal device 10 acquires string information from the clipboard area and determines whether the acquired first string information is string information to be restricted. However, the first server 20 may perform at least one of the processes performed by the terminal device 10 in the above embodiment. For example, as in the example described below, the first server 20 may determine whether the first string information is string information to be restricted.

[0186] In this modification, the storage unit 202 of the first server 20 further includes a correspondence table 202a, an account table 202b, a SaaS table 202c, a determination result table 202d, a restriction table 202e, a detection target table 202f, and a detection log table 202g.

[0187] The correspondence table 202a is a table that associates SaaS with processes executed by users, and is updated whenever a new correspondence between a SaaS and information related to an operation is registered.

[0188] Correspondence table 202a is a table that uses SaaSID as a key and has columns for URL, etc. Note that correspondence table 202a may also have columns for storing information other than these.

[0189] The SaaSID is an item that stores an identifier for uniquely identifying the SaaS. The URL is an example of information that indicates that the SaaS has been executed. The "URL" item stores, for example, the URL of the homepage that provides the corresponding SaaS.

[0190] The account table 202b is a table that stores information about accounts set for users, and is updated whenever a new account is issued.

[0191] Account table 202b is a table that uses user ID as a key and has columns for SaaSID, scope of use, registration start date, etc. Note that account table 202b may have columns that store information other than these, or may not have any of these pieces of information.

[0192] The user ID is an item that stores an identifier for uniquely identifying a user. The usage range is an item that stores the range of functions that a user is permitted to use when using SaaS. The usage range is set, for example, when signing up for an account. The usage range may be changed at a predetermined time, for example, at any time during the contract or when applying for renewal. The registration start date is an item that stores the date on which the account was registered and SaaS use began.

[0193] The SaaS table 202c is a table that stores SaaS to be managed. The SaaS stored in the SaaS table 202c is, for example, SaaS that are not permitted to be used. In other words, the SaaS table 202c is a blacklist. The SaaS stored in the SaaS table 202c may also be, for example, SaaS that are permitted to be used. In other words, the SaaS table 202c may be a whitelist. The SaaS table 202c is updated whenever a new SaaS is registered.

[0194] The SaaS table 202c is a table that uses SaaSID as a key and has columns for name, provider, version, support information, etc. Note that the SaaS table 202c may have columns that store information other than these, or may not have any of these pieces of information.

[0195] The "Name" field stores the name of the SaaS. The "Provider" field stores the entity that provides the SaaS. For example, the "Provider" field stores the name of the company or the address of the website that provides the service. The "Provider" field may also store information about the connection destination for accessing the SaaS. The information about the connection destination may be, for example, the URL of the website that provides the SaaS or at least one of the elements that make up the URL (protocol name, host name, domain name, path, etc.), the connection destination IP address, port number, etc. Alternatively / additionally, the information about the connection destination may include information for identifying resources such as a server on which the SaaS is provided in a network space (this network space can be accessed via the Internet and / or an intranet).

[0196] The version is an item for storing the version of the SaaS that is provided. The support information is an item for storing information about the support provided for the SaaS.

[0197] The determination result table 202d is a table that stores the results of determination based on the detected processing.

[0198] The determination result table 202d is a table having columns such as software used, usable, and whether an account exists, with date and time as a key. Note that the determination result table 202d may have columns storing information other than the above, or may not have any of the above information. For example, the determination result table 202d may have a column storing that the SaaS is on a blacklist.

[0199] The date and time is an item that stores the date and time when use was detected. The software in use is an item that stores information about the SaaS whose use was detected. The usable item is an item that stores whether or not the SaaS whose use was detected is a licensed SaaS. The determination module 203d determines whether or not the SaaS whose use was detected is licensed by referring to the SaaS table 202c. If it is usable, "1" is stored, and if it is unusable, "0" is stored. The account presence / absence is an item that stores whether or not the user has an account for the SaaS whose use was detected. The determination module 203d determines whether or not the user has an account for the SaaS whose use was detected by referring to the account table 202b. If the user has an account, "1" is stored, and if the user does not have an account, "0" is stored.

[0200] The restriction table 202e is a table that associates the determination result with the operation restriction of the terminal device 10. The restriction table 202e is updated whenever a new correspondence between the determination result and the operation restriction of the terminal device 10 is registered.

[0201] The restriction table 202e is a table that uses conditions as keys and has columns for correspondence, priority, etc. Note that the restriction table 202e may also have columns for storing information other than these.

[0202] The condition is an item that stores the condition for restricting the operation of the terminal device 10. For example, the following contents are stored in the item "condition". The user has the required permissions and the blacklisted SaaS is used. The number of times the same decision has been made has reached a predetermined value. - The number of times the same decision has been made within a specified period of time has reached a specified value.

[0203] The restriction is an item that stores restrictions imposed on the terminal device 10. The item "restriction" stores, for example, the following: - Prevent any operations on the terminal device 10 from being accepted - Prohibition of access to specified URLs - Prohibit execution of specified applications -Prohibit access to specified folders - Preventing execution of specified files - Prohibition of certain operations such as reading and writing Stopping running applications

[0204] The priority is an item that stores the priority level when adopting a restriction. For example, priority 1 is higher than priorities 2 and 3, and when multiple conditions are met simultaneously, the restriction with the higher priority is adopted. Note that when multiple conditions are met simultaneously, multiple restrictions may be adopted.

[0205] The detection target table 202f is a table that stores character string information of detection targets related to services that should be restricted from being used by users. The detection target table 202f is a table that uses the detection target ID as a key and has columns for detection targets, etc. Note that the detection target table 202f may also have columns that store information other than the above.

[0206] The detection target ID is an item that stores an identifier for uniquely identifying a detection target from the clipboard area. The detection target is an item that stores character string information that is a detection target from the clipboard area. In other words, the item "detection target" is an item that stores character string information related to a service whose use should be restricted. For example, the item "detection target" stores the following:

[0207] - String information that identifies resources related to services that should be restricted from use Here, a resource refers to any type of element available on a network, including, for example, physical or virtual devices such as servers, as well as various types of data and information such as web pages, files, and databases. Furthermore, the character string information that identifies a resource refers to identification information for identifying the resource, such as a URI such as a URL, a local address, a directory path, a file path, an IP address, or character string information that indicates an element or combination of elements that constitute such identification information. For example, for a URL, the elements that constitute the identification information include the protocol, host name, domain name, and path.

[0208] Words related to services that should be restricted Words related to a service whose use should be restricted include, for example, words related to the name and provider of the service, and in particular words used to search for the service in a search engine.

[0209] The detection log table 202g is a table that stores the detection history of the character string information of the detection targets registered in the detection target table 202f. The detection log table 202g is a table that uses the detection log ID as a key and has columns such as time, detected character string, and detection target ID. Note that the detection log table 202g may also have columns that store information other than these.

[0210] The detection log ID is an item for storing an identifier for uniquely identifying a detection log, which is a log of character string detection by the character string acquisition module 203f.

[0211] The time is an item for storing the time when detection was performed. For example, the time stamp when the detection process corresponding to the detection log ID was performed is stored in the "time" item.

[0212] The detected character string is an item that stores character string information corresponding to the detection log ID. For example, the item "detected character string" stores a character string detected from the first character string information acquired by the first acquisition module 203b in the detection process by matching the detection target conditions in the detection target table 202f.

[0213] The detection target ID is an item that stores a detection target ID associated with a detection process corresponding to the detection log ID. For example, when character string information corresponding to a specific record in the detection target table 202f is detected from the first character string information acquired from the terminal device 10, the value of the item "detection target ID" of the record is stored in "detection target ID" in the detection log table 202g.

[0214] In addition, in this modified example, the control unit 203 operates according to a program to further perform functions shown as a presentation control module 203a, a first acquisition module 203b, a second acquisition module 203c, a judgment module 203d, a restriction module 203e, a string acquisition module 203f, a restriction target judgment module 203g, a post-detection processing module 203h, and a detection target update module 203i.

[0215] The presentation control module 203a controls the process of presenting to the user the information stored in the storage unit 202. For example, the presentation control module 203a presents to the user via the terminal device 10 information on the restriction by the restriction module 203e, information on the processing by the post-detection processing module 203h, and the like.

[0216] The first acquisition module 203b acquires information related to processing executed by a user operating the terminal device 10. The first acquisition module 203b transmits a request for information acquired by the first acquisition unit 194 of the terminal device 10 to the terminal device 10 at a predetermined timing (for example, at a predetermined cycle). The terminal device 10 transmits the information acquired by the first acquisition unit 194 to the first server 20 in response to the request. The first acquisition module 203b acquires the information transmitted from the terminal device 10.

[0217] Alternatively, the terminal device 10 transmits the information acquired by the first acquisition unit 194 to the first server 20 at a predetermined timing (for example, at a predetermined cycle or at the timing when the first acquisition unit 194 acquires the information). The first acquisition module 203b acquires the information transmitted from the terminal device 10.

[0218] The second acquisition module 203c acquires information about the SaaS used by the user based on information about the process performed by the user. Specifically, for example, the second acquisition module 203c compares the URL of the web page visited by the user with the correspondence table 202a and acquires the SaaS ID of the SaaS used by the user. In this way, the second acquisition module 203c identifies the SaaS used by the user.

[0219] The determination module 203d determines whether the SaaS used by the user is a SaaS to be managed based on the acquired SaaSID. The determination module 203d stores the determination result in the determination result table 202d in accordance with the determination. This can be rephrased as, for example, the determination module 203d stores the processes to be managed that have been performed by the user in the determination result table 202d.

[0220] Specifically, for example, the determination module 203d refers to the SaaS table 202c, or refers to both the account table 202b and the SaaS table 202c, and determines whether the user's use of SaaS is appropriate.

[0221] More specifically, for example, if the SaaS table 202c is a blacklist and the SaaS table 202c contains prohibited SaaS (SaaS to be managed), the determination module 203d determines whether the acquired SaaSID is included in the SaaS table 202c. If the acquired SaaSID is included in the SaaS table 202c, the determination module 203d stores in the determination result table 202d that the user has used SaaS whose use is not permitted. If the acquired SaaSID is not included in the SaaS table 202c, the determination module 203d refers to the account table 202b and determines whether the user has an account for the acquired SaaSID. If the user has an account for the acquired SaaSID, the determination module 203d does not store information in the determination result table 202d. If the user does not have an account for the acquired SaaSID, the determination module 203d stores in the determination result table 202d that the user used the SaaS using a shadow ID.

[0222] Furthermore, for example, if the SaaS table 202c is a whitelist and the SaaS table 202c includes a SaaS whose use is permitted (SaaS to be managed), the determination module 203d determines whether the acquired SaaSID is included in the SaaS table 202c. If the acquired SaaSID is not included in the SaaS table 202c, the determination module 203d stores in the determination result table 202d that the user has used SaaS whose use is not permitted. If the acquired SaaSID is included in the SaaS table 202c, the determination module 203d refers to the account table 202b and determines whether the user has an account for the acquired SaaSID. If the user has an account for the acquired SaaSID, the determination module 203d does not store information in the determination result table 202d. If the user does not have an account for the acquired SaaSID, the determination module 203d stores in the determination result table 202d that the user used the SaaS using a shadow ID.

[0223] The restriction module 203e imposes restrictions on the operation of the terminal device 10 based on the determination result of the determination module 203d. That is, the restriction module 203e transmits an instruction to the terminal device 10 to impose restrictions on the operation of the processor of the terminal device 10 based on the determination result of the determination module 203d. Upon receiving the instruction from the first server 20, the terminal device 10 executes a predetermined process corresponding to the instruction.

[0224] Specifically, for example, the restriction module 203e determines whether the judgment results stored in the judgment result table 202d satisfy a predetermined condition. The predetermined condition includes, for example, the following. - Blacklisted SaaS was used The number of times the same decision has been made has reached a predetermined value. - The number of times the same decision has been made within a specified period of time has reached a specified value. The user has the required permissions.

[0225] For example, when the judgment results stored in the judgment result table 202d satisfy at least one of the above conditions or at least one combination of the above conditions, the restriction module 203e imposes a predetermined restriction on the operation of the terminal device 10. The predetermined restriction includes, for example, the following: - Prevent any operations on the terminal device 10 from being accepted - Prohibition of access to specified URLs - Prohibit execution of specified applications -Prohibit access to specified folders - Preventing execution of specified files - Prohibition of certain operations such as reading and writing Stopping running applications

[0226] The determination result and the restrictions on the operation of the terminal device 10 are stored in, for example, a restriction table 202e. The restriction module 203e, for example, collates the determination result of the determination module 203d with the restriction table 202e and determines the restrictions on the operation of the terminal device 10.

[0227] The character string acquisition module 203f acquires character string information stored in the clipboard of the terminal device 10. The character string acquisition module 203f transmits a request for character string information stored in the clipboard area of ​​the terminal device 10 to the terminal device 10 at a predetermined timing (for example, at a predetermined cycle). The terminal device 10 transmits the character string information acquired by the character string acquisition unit 199 to the first server 20 in response to the request. The character string acquisition module 203f acquires character string information transmitted from the terminal device 10. Note that if the character string information transmitted from the terminal device 10 is the same as the character string information acquired at the previous timing, the character string acquisition module 203f does not need to acquire the character string information.

[0228] Alternatively, the terminal device 10 transmits the character string information acquired by the character string acquisition unit 199 to the first server 20 at a predetermined timing (for example, at a predetermined cycle or at the timing when the character string acquisition unit 199 acquires the character string information). The character string acquisition module 203f acquires the character string information transmitted from the terminal device 10.

[0229] The restriction target determination module 203g determines whether or not the first character string information acquired by the character string acquisition module 203f is character string information to be restricted regarding a service for which usage by the user should be restricted.

[0230] Specifically, the restriction target determination module 203g determines whether the first string information is string information that is subject to restriction by comparing the first string information with the second string information stored in the column of the item "detection target" in the detection target table 202f.

[0231] For example, the restriction target determination module 203g determines that the first character string information is character string information to be restricted when the first character string information can be associated with the second character string information. The first character string information can be associated with the second character string information when the character string information stored in the "detection target" item of at least one record in the detection target table 202f can be associated with the first character string information, for example, as follows: When the character string information stored in the item "detection target" of at least one record in the detection target table 202f matches the first character string information. When the first character string information is included in the character string information stored in the item "detection target" of at least one record in the detection target table 202f. The first character string information includes character string information stored in the item "detection target" of at least one record in the detection target table 202f.

[0232] The fact that the first character string information was able to be associated with the second character string information may also be expressed as "the detection target was detected from the first character string information" or "the first character string information was included in the second character string information."

[0233] Furthermore, the restriction target determination module 203g may determine whether the first string information is string information indicating a URL based on whether the first string information contains a specific element such as a protocol name or a domain name. When the first string information indicates a URI containing a URL (hereinafter, simply referred to as a URL), the restriction target determination module 203g may extract a specific element or a combination of elements from the URL and treat it as the first string information. For example, the restriction target determination module 203g may extract the domain portion from the URL and determine whether the string information of the domain portion is string information to be restricted.

[0234] Furthermore, the restriction target determination module 203g may extract a character string indicating a specific part of speech (for example, a noun) from the first character string information using any natural language processing technology and treat it as the first character string information. One or more character strings may be extracted. For example, the restriction target determination module 203g may determine whether the extracted character string information of a noun is character string information to be restricted.

[0235] In addition, if the restriction target determination module 203g determines that the first string information is string information related to a service whose use should be restricted, the presentation control module 203a may present to the user that the first string information has been determined to be string information related to a service whose use should be restricted (the determination result).

[0236] When it is determined that the first character string information is character string information to be restricted, the post-detection processing module 203h transmits an instruction to the terminal device 10 to perform a predetermined process. Upon receiving the instruction from the first server 20, the terminal device 10 executes the predetermined process corresponding to the instruction.

[0237] The predetermined process includes, for example, the following: The content of the predetermined process is set in advance by, for example, an administrator or the like setting the first server 20, so that one or more processes are selected from the following processes. (Restrictions on operations on terminal device 10) - Prevent any operations on the terminal device 10 from being accepted (Operations on the clipboard area) -Delete the first string information from the clipboard area Change the first string information stored in the clipboard (for example, change it to a predetermined notification message or warning message) (Restrictions on the operation of the application that inputs (copied) the first string information) Stopping the application - Prohibition of inputting information into the clipboard area (copying operation) (Restrictions on the behavior of the application to which the first string information is output (pasted)) Stopping the application - Prohibition of outputting information from the clipboard area to a specified application (paste operation) (Prohibition of access to service providers) - Network communication interruptions Prohibition of connections to destinations that include the first character string information in their identification information. For example, prohibition of connections to destinations (including resources) identified by the first character string information (URL, etc.). Also, for example, prohibition of connections to search result pages that include the first character string information (word, etc.) in the search query portion, or prohibition of connections to destinations that can be reached from such search result pages. In this case, the character string indicating the word may be expressed in an arbitrarily encoded format for incorporation into a URL. (Presenting information to users) Presenting or notifying the user via the display 141, the speaker 172, etc., information that the first character string information has been determined to be character string information subject to restriction Present or notify the user of information regarding the execution of a predetermined process via the display 141, speaker 172, etc.

[0238] In addition, the post-detection processing module 203h records a new detection log by storing in the detection log table 202g the time when the first character string information was acquired by the first acquisition module 203b, the acquired first character string information, and the detection target ID of the detection target that was able to be associated with the first character string information by the restriction target determination module 203g.

[0239] The detection target update module 203i updates the second character string information that is the detection target. Specifically, the detection target update module 203i acquires character string information that is to be newly set as the detection target, and stores the new character string information in the detection target table 202f, thereby updating the second character string information.

[0240] For example, the detection target update module 203i acquires character string information to be newly set as a detection target as follows.

[0241] (Accepting input of string information) For example, the detection target update module 203i receives character string information from another information processing device via the network 80. The user who operates the other information processing device is, for example, the user who manages the terminal device 10.

[0242] (Acquisition of string information related to unauthorized SaaS) Furthermore, for example, the detection target update module 203i acquires, at a predetermined timing, character string information relating to SaaS that is not permitted to be used from the SaaS table 202c that manages SaaS as a blacklist. For example, when the SaaS table 202c is updated, the following information may be acquired about the updated parts of the SaaS table 202c. SaaS name Information about the connection destination for accessing SaaS

[0243] (Obtains string information in response to the detection of inappropriate SaaS usage) Furthermore, for example, in response to detection of inappropriate use of SaaS by a user, the detection target update module 203i acquires character string information related to the SaaS. For example, in response to the first acquisition module 203b acquiring information related to a process executed by the user, the second acquisition module 203c acquiring information related to the SaaS used in the process, and the determination module 203d determining that the use of the SaaS related to the process is inappropriate, the detection target update module 203i may acquire the following information: Name of SaaS: For example, the detection target update module 203i searches the SaaS table 202c based on the SaaSID of the SaaS, and acquires character string information indicating the name of the SaaS. Information about the connection destination for accessing the SaaS: For example, the detection target update module 203i acquires information about the SaaS acquired by the second acquisition module 203c (for example, information about the provider such as a URL).

[0244] The detection target update module 203i stores the character string information acquired as described above as a new detection target in the detection target table 202f, thereby updating the detection target.

[0245] At this time, the detection target update module 203i may store part of the acquired character string information in the detection target table 202f. For example, if the acquired character string information is a URL, the detection target update module 203i may extract predetermined elements from the URL and store them in the detection target table 202f. For example, the detection target update module 203i may store a domain name extracted from the acquired URL in the detection target table 202f. This enables more thorough detection than if the entire URL were used as the detection target. Furthermore, even if the URL structure of the SaaS is changed, the detection target can continue to be detected as long as the registered components (such as a domain name) remain unchanged.

[0246] <4 Basic computer hardware configuration> 14 is a block diagram showing the basic hardware configuration of a computer 90. The computer 90 includes at least a processor 91, a main memory device 92, an auxiliary memory device 93, and a communication IF (interface) 99. These are electrically connected to each other by a bus.

[0247] The processor 91 is hardware for executing an instruction set written in a program, and is composed of an arithmetic unit, registers, peripheral circuits, and the like.

[0248] The main storage device 92 is used to temporarily store programs, data to be processed by the programs, etc. For example, it is a volatile memory such as a DRAM (Dynamic Random Access Memory).

[0249] The auxiliary storage device 93 is a storage device for saving data and programs, such as a flash memory, a hard disk drive (HDD), a magneto-optical disk, a CD-ROM, a DVD-ROM, or a semiconductor memory.

[0250] The communication IF 99 is an interface for inputting and outputting signals for communicating with other computers via a network using wired or wireless communication standards. The network is composed of the Internet, a LAN, various mobile communication systems constructed by wireless base stations, etc. For example, the network includes 3G, 4G, and 5G mobile communication systems, LTE (Long Term Evolution), and wireless networks (e.g., Wi-Fi (registered trademark)) that can connect to the Internet via a predetermined access point. In the case of a wireless connection, communication protocols include, for example, Z-Wave (registered trademark), ZigBee (registered trademark), and Bluetooth (registered trademark). In the case of a wired connection, the network also includes a direct connection using a USB (Universal Serial Bus) cable, etc.

[0251] It should be noted that the computer 90 can be virtually realized by distributing all or part of each hardware configuration across multiple computers 90 and interconnecting them via a network. In this way, the computer 90 is a concept that includes not only a computer 90 housed in a single housing or case, but also a virtualized computer system.

[0252] <Basic functional configuration of computer 90> A description will be given of the functional configuration of a computer realized by the basic hardware configuration of a computer 90 shown in Fig. 20. The computer includes at least the functional units of a control unit, a storage unit, and a communication unit.

[0253] The functional units of the computer 90 can also be realized by distributing all or part of the functional units among multiple computers 90 interconnected via a network. The computer 90 is a concept that includes not only a single computer 90 but also a virtualized computer system.

[0254] The control unit is realized by the processor 91 reading various programs stored in the auxiliary storage device 93, expanding them in the main storage device 92, and executing processing in accordance with the programs. The control unit can realize functional units that perform various types of information processing depending on the type of program. In this way, the computer is realized as an information processing device that processes information.

[0255] The storage unit is realized by a main storage device 92 and an auxiliary storage device 93. The storage unit stores data, various programs, and various databases. Furthermore, the processor 91 can allocate a storage area corresponding to the storage unit in the main storage device 92 or the auxiliary storage device 93 in accordance with the programs. Furthermore, the control unit can cause the processor 91 to execute processes for adding, updating, and deleting data stored in the storage unit in accordance with the various programs.

[0256] A database refers to a relational database, which manages data sets called tables, which are structured by rows and columns, by relating them to each other. In a database, a table is called a table, a column in a table is called a column, and a row in a table is called a record. In a relational database, relationships between tables can be set and associated. Usually, each table has a column set as a key for uniquely identifying a record, but setting a key to a column is not essential. The control unit can cause the processor 91 to add, delete, or update records in a specific table stored in the storage unit according to various programs.

[0257] The communication unit is realized by the communication IF 99. The communication unit realizes the function of communicating with other computers 90 via a network. The communication unit can receive information transmitted from other computers 90 and input the information to the control unit. The control unit can cause the processor 91 to execute information processing on the received information in accordance with various programs. In addition, the communication unit can transmit information output from the control unit to other computers 90.

[0258] The functions performed by the components described herein may be implemented in circuitry or processing circuitry, including general-purpose processors, application-specific processors, integrated circuits, ASICs (Application Specific Integrated Circuits), a CPU (a Central Processing Unit), conventional circuits, and / or combinations thereof, programmed to perform the described functions. A processor includes transistors and other circuits and is considered to be circuitry or processing circuitry. A processor may also be a programmed processor that executes programs stored in memory. In this specification, a circuitry, unit, or means is hardware that is programmed to realize or performs the described functions, which may be any hardware disclosed herein or any hardware known to be programmed to realize or perform the described functions. If the hardware is a processor considered to be a type of circuitry, the circuitry, means, or unit is a combination of the hardware and software used to configure the hardware and / or processor.

[0259] Although several embodiments of the present disclosure have been described above, these embodiments can be embodied in various other forms, and various omissions, substitutions, and modifications can be made without departing from the spirit of the invention. These embodiments and modifications are intended to be included in the scope of the inventions and their equivalents as defined in the claims, as well as in the scope and spirit of the inventions.

[0260] <Additional Notes> The matters described in the above embodiments will be supplemented below. (Appendix 1) A program to be executed by a computer having a processor and a memory, the program causing the processor to execute the steps of: acquiring first character string information stored in a clipboard area provided in the memory; and determining whether the first character string information is character string information relating to a service whose use should be restricted by comparing the first character string information with second character string information relating to a service whose use should be restricted, which is stored in advance in the memory. (Appendix 2) The program described in Appendix 1 causes the processor to execute a step of restricting the operation of a specified application when the first string information is output to the application if it is determined in the determining step that the first string information is string information related to a service whose use should be restricted. (Appendix 3) The program described in Appendix 1 causes the processor to execute a step of prohibiting output of the first string information from the memory to a specified application if it is determined in the determining step that the first string information is string information related to a service whose use should be restricted. (Appendix 4) The program described in Appendix 1, wherein the program causes the processor to execute a step of deleting the first string information from the memory if it is determined in the determining step that the first string information is string information related to a service whose use should be restricted. (Appendix 5) 2. The program according to claim 1, wherein the second string information includes string information that identifies a resource related to a service whose use should be restricted. (Appendix 6) The program according to claim 1, wherein the second character string information includes character string information indicating words related to services whose use should be restricted. (Appendix 7) The program described in Appendix 1 causes a processor to execute the steps of acquiring information about the services to be managed, and updating second string information based on the information acquired in the step of acquiring information about the services to be managed. (Appendix 8) The program described in Appendix 1 causes a processor to execute the following steps: acquiring information about a process performed by a user; acquiring information about a service associated with the process based on the acquired information about the process performed by the user; determining whether the service related to the acquired information is a service that is appropriate for use by the user; and if the service is determined to be a service that is not appropriate for use by the user, updating second string information based on the information about the process performed by the user. (Appendix 9) A method executed by a computer having a processor, the method comprising the steps of: acquiring first character string information stored in a clipboard area provided in a memory; and determining whether the first character string information is character string information related to a service whose use should be restricted by comparing the first character string information with second character string information related to a service whose use should be restricted, which is pre-stored in the memory. (Appendix 10) An information processing device comprising a control unit and a storage unit, wherein the control unit executes the steps of: acquiring first character string information stored in a clipboard area provided in the storage unit; and determining whether the first character string information is character string information relating to a service whose use should be restricted by comparing the first character string information with second character string information relating to a service whose use should be restricted, which is stored in advance in the storage unit. (Appendix 11) A system comprising a plurality of terminal devices and at least one server, each terminal device having means for executing the steps of: acquiring first character string information stored in a clipboard area provided in a memory; and determining whether the first character string information is character string information relating to a service whose use should be restricted by comparing the first character string information with second character string information relating to a service whose use should be restricted, which is stored in advance in the memory. [Explanation of symbols]

[0261] 1. System 10...Terminal device 120…Communications Department 13...Input device 131...Touch-sensitive devices 14...Output device 15...Memory 16…Storage 19...Processor 20...First server 22...Communication IF 23...Input / output interface 25…Memory 26…Storage 29...Processor 30...Second server

Claims

1. A program to be executed by a computer having a processor and a memory, the program causing the processor to: acquiring first character string information stored in a clipboard area provided in the memory; a step of determining whether or not the first character string information is character string information related to a service whose use should be restricted by comparing the first character string information with second character string information related to a service whose use should be restricted, the second character string information being stored in advance in the memory; A program that executes the following.

2. The program causes the processor to: a step of restricting operation of a predetermined application when the first character string information is output to the application if the first character string information is determined to be character string information related to a service whose use should be restricted in the determining step; The program according to claim 1, which causes the program to execute the following.

3. The program causes the processor to: a step of prohibiting output of the first character string information from the memory to a predetermined application when it is determined in the determining step that the first character string information is character string information related to a service whose use should be restricted. The program according to claim 1, which causes the program to execute the following.

4. The program causes the processor to: a step of deleting the first character string information from the memory when it is determined in the determining step that the first character string information is character string information related to a service whose use should be restricted; The program according to claim 1, which causes the program to execute the following.

5. 2. The program according to claim 1, wherein the second character string information includes character string information that identifies a resource related to the service whose use should be restricted.

6. 2. The program according to claim 1, wherein the second character string information includes character string information indicating a word related to the service whose use should be restricted.

7. The program causes the processor to: obtaining information about the services to be managed; updating the second character string information based on information acquired in the step of acquiring information related to the service to be managed; The program according to claim 1, which causes the program to execute the following.

8. The program causes the processor to: obtaining information about an operation performed by a user; acquiring information about a service associated with the process based on the acquired information about the process performed by the user; determining whether the service related to the acquired information is a service that is appropriate for use by the user; updating the second character string information based on information regarding a process executed by the user when the service is determined to be an inappropriate service for the user; The program according to claim 1, which causes the program to execute the following.

9. 1. A computer-implemented method comprising a processor and a memory, the processor: acquiring first character string information stored in a clipboard area provided in the memory; a step of determining whether or not the first character string information is character string information related to a service whose use should be restricted by comparing the first character string information with second character string information related to a service whose use should be restricted, the second character string information being stored in advance in the memory; How to do it.

10. An information processing device including a control unit and a storage unit, wherein the control unit: acquiring first character string information stored in a clipboard area provided in the storage unit; a step of determining whether or not the first character string information is character string information related to a service whose use should be restricted by comparing the first character string information with second character string information related to a service whose use should be restricted, the second character string information being stored in advance in the storage unit; An information processing device that executes the above.

11. A system including a control unit and a storage unit, means for acquiring first character string information stored in a clipboard area provided in the storage unit; means for determining whether the first character string information is character string information relating to a service whose use should be restricted by comparing the first character string information with second character string information relating to a service whose use should be restricted, the second character string information being stored in advance in the storage unit; A system comprising:

Citation Information

Patent Citations

  • Security gateway and identity verification method

    CN117439805A

  • Information processing method and control method thereof

    JP2004013483A

  • Information processor, application activation control program, and application activation control method

    JP2007041631A

  • Method to classify compliance protocols for saas apps based on web page content

    US20240037158A1

  • Information processing device and program

    JP7044451B1