Information processing apparatus, method for controlling information processing apparatus, and program
By integrating a learning model to estimate and transmit linked usage environment data with communication tendency data, the device addresses the challenge of separate data processing on external servers, enhancing transmission efficiency.
Patent Information
- Application Number
- JP2024077968
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-05-13
- Publication Date
- 2025-11-26
AI Technical Summary
Existing information processing devices face challenges in transmitting estimation results and communication tendency data to external servers in a form that is easily usable, requiring separate processing on the server side to link these data types.
The device integrates an identification mechanism to identify features from packets, estimates the usage environment using a learning model, and transmits the estimation results and communication tendency data together in a linked format to an external server.
This approach allows for seamless transmission of usage environment estimation results and associated data to external servers, reducing processing load and improving efficiency by eliminating the need for separate linking on the server side.
Smart Images

Figure 2025172452000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to an information processing device, a control method for an information processing device, and a program. [Background technology]
[0002] As a security measure, various security-related functions of information processing devices must be properly configured. For information processing devices that are used in a single environment, factory settings tailored to that environment can be applied, allowing the device to operate with appropriate security measures without the need for user configuration. For example, when it comes to multifunction devices, their use in office environments, where robust network boundary defenses exist, has traditionally been the norm, and factory settings tailored to office environments were sufficient. However, with the recent diversification of usage environments, the proportion of new usage patterns, such as telecommuting and use in public spaces shared by an unspecified number of people, has increased. In these new usage environments, settings must be changed from the factory defaults for office environments to suit the environment. For example, in an office environment, where boundary defenses are in place, it is desirable to prioritize convenience and allow connections to the management console via the network. However, in public spaces, where there is no boundary defense and the risk of attack is high, it is desirable to prohibit such connections. As such, appropriate security settings vary depending on the usage environment, and settings must be changed when the usage environment changes. An administrator of an information processing device with specialized security knowledge can recognize that settings need to be changed for each usage environment and take measures such as changing the settings to suit changes in the usage environment before using the device. However, there are also cases where users without specialized security knowledge manage information processing devices. Estimating the usage environment of an information processing device is being carried out to provide users without specialized security knowledge with appropriate security settings tailored to their usage environment. One method for estimating the usage environment of an information processing device is to estimate the usage environment from trends in packet information such as collected audit logs. Patent Document 1, for example, discloses a technology for transmitting audit logs from an information processing device, in which a printing device transmits only audit logs associated with specified application functions to a server. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Japanese Patent Publication No. 2022-131233 Summary of the Invention [Problem to be solved by the invention]
[0004] However, it was not anticipated that the estimation result and the communication tendency data would be transmitted from the information processing device to an external server such as a cloud server in the same event. If the estimation result and the communication tendency data were transmitted in separate events, for example, when the estimation result and the communication tendency data are used in combination on the external server, a linking process would be required on the external server side.
[0005] An object of the present invention is to transmit the estimation result of the usage environment of an information processing device and the information used for the estimation in a form that is easy to use on an external server. [Means for solving the problem]
[0006] In order to solve the above problem, the information processing device of the present invention has an identification means for identifying features from packets sent and received by the information processing device, an estimation means for estimating the usage environment of the information processing device using a learning model and the features as input data, and a transmission means for transmitting the features used to estimate the usage environment and information on the usage environment that is the estimation result of the estimation of the usage environment to an external server in the same event. [Effects of the Invention]
[0007] According to the present invention, it is possible to transmit the estimation result of the usage environment of the information processing device and the information used for the estimation in a form that is easily usable by an external server. [Brief explanation of the drawings]
[0008] [Figure 1] FIG. 1 is a diagram illustrating a configuration of a management system. [Figure 2] FIG. 2 is a diagram illustrating the configuration of a controller unit of the MFP. [Figure 3]FIG. 2 is a diagram illustrating the software configuration of the MFP. [Figure 4] 10 is a flowchart showing a process for generating and storing communication tendency data and estimation results of a usage environment. [Figure 5] 10 is a flowchart showing a process of transmitting communication tendency data and an estimation result of a usage environment. [Figure 6] FIG. 10 illustrates an example of an audit log. [Figure 7] FIG. 10 is a diagram illustrating an example of communication tendency data. [Figure 8] FIG. 10 is a diagram illustrating an example of transmission data. DETAILED DESCRIPTION OF THE INVENTION
[0009] Example 1 1 is a diagram illustrating the configuration of a system that manages information processing devices. The system includes an information processing device to be managed and a management cloud system 121 that communicates with the information processing device via a network. In this embodiment, a form is described in which communication tendency data (feature amounts) is created from packets on the information processing device side, the communication tendency data is used to estimate the environment in which the information processing device is installed, and then the estimation result and the feature amounts are notified to the cloud system using the same event.
[0010] In this embodiment, an MFP (Multi Function Printer) 100 will be described as an example of an information processing device to be managed by the management cloud system 121. The MFP 100 is an example of an image forming device managed by the management cloud system 121, which is an external server. There may be multiple MFPs 100 managed by the management cloud system 121. The MFP 100 is a multifunction peripheral that integrates multiple functions such as a printing function and a scanning function. Note that the information processing device to be managed by the management cloud system 121 may be a printer, a scanner, a 3D printer, or the like, or may be an image processing device such as a camera, or a network device capable of communication such as a smart home appliance.
[0011] The MFP 100 has a controller unit 101, an operation unit 102, a printer unit 103, and a scanner unit 104. The controller unit 101 controls the entire MFP 100. The controller unit 101 also controls communication with external devices such as a management cloud system 121. The operation unit 102 accepts operations from a user and displays information to the user. The operation unit 102 is provided with a display unit such as an LCD panel that displays the operating status of the MFP 100 and a setting screen (user interface screen), and operation keys for setting the operating mode of the MFP 100, copy settings, and other operations. The display unit and buttons may be realized as a touch-operable touch panel that uses an electrostatic or pressure-sensitive system. By associating input coordinates on the touch panel with display coordinates, a GUI can be configured that makes it appear as if the user can directly operate the screen displayed on the touch panel.
[0012] The printer unit 103 outputs electronic data to a paper medium. For example, the printer unit 103 forms an image according to a received print job and outputs it on paper, or outputs an image read by the scanner unit 104 on paper. The scanner unit 104 optically reads an original placed on a platen or ADF (Auto Document Feeder), not shown, and converts it into electronic data. The operation unit 102, printer unit 103, and scanner unit 104 are connected to the controller unit 101, and function as a multifunction peripheral under the control of the controller unit 101.
[0013] Management cloud system 121 provides a service for managing MFP 100. Management cloud system 121 provides a service for managing multiple information processing devices including MFP 100, for example, by using a cloud service or a management application. In order to manage MFP 100, management cloud system 121 collects information from MFP 100 and remotely monitors the status of MFP 100. Management cloud system 121 may be realized by one or more information processing devices, a virtual machine (cloud service) that uses resources provided by a data center that includes information processing devices, or a combination of these.
[0014] The MFP 100 and the management cloud system 121 are connected via a network. For example, the MFP 100 and the management cloud system 121 are connected via a network, a LAN 110 and the Internet 120, and a gateway 111 that relays communication between the LAN 110 and the Internet 120. The gateway 111 is a network router that relays communication from the MFP 100 to the Internet 120. Note that the network 100 may be configured to enable data transmission and reception, and any communication method may be used. For example, the network 100 may be configured as a LAN, a WAN, a cellular network such as LTE or 5G, a wireless network, a telephone line, a dedicated digital line, or a combination of these.
[0015] 2 is a diagram illustrating the configuration of the controller unit 101 of the MFP 100. The controller unit 101 of the MFP 100 has a CPU 201, a DRAM 202, an I / O controller 203, a Flash ROM 211, and various I / Fs. The various I / Fs include a network I / F 204, a SATA I / F 205, a panel I / F 206, a printer I / F 207, and a scanner I / F 208.
[0016] A CPU 201 (Central Processing Unit) performs the main arithmetic processing within the controller section 101. The CPU 201 is connected to a DRAM 202 via a bus. The DRAM 202 is used by the CPU 201 as a working memory for temporarily storing program data representing arithmetic instructions during the calculation process of the CPU 201 and data to be processed. The CPU 201 is also connected to an I / O controller 203 via a bus.
[0017] The I / O controller 203 controls input and output to and from various devices, such as the operation unit 102, printer unit 103, and scanner unit 104, as well as external devices, in accordance with instructions from the CPU 201. The I / O controller 203 is connected to a flash ROM 211, which is a storage device, via a serial advanced technology attachment (SATA) interface 205. The flash ROM 211 stores data such as programs and document files for implementing the functions of the MFP 100. Examples of data stored in the flash ROM 211 include image data such as PDF and JPEG. Note that a large-capacity storage device, such as a hard disk drive (HDD) or a solid state drive (SSD), may be connected to the SATA interface 205 instead of the flash ROM 211.
[0018] A network I / F 204, a panel I / F 206, a printer I / F 207, and a scanner I / F 208 are connected to the I / O controller 203. A wired LAN device is connected to the network I / F 204. A network such as the LAN 140 is connected to the network I / F 204. The CPU 201 communicates with external devices such as the management cloud system 121 connected to the LAN 110 via the network I / F 204 and the network. The network I / F 204 may be connected to a wired LAN or a wireless LAN.
[0019] The CPU 201 implements user-oriented input and output to the operation unit 102 via the panel I / F 206. The CPU 201 implements printing processing using the printer unit 103 via the printer I / F 207. For example, to perform a copy function, the CPU 201 loads program data from the Flash ROM 211 into the DRAM 202 via the SATA I / F 205. The CPU 201 detects a copy instruction from the user via the operation unit 102 via the panel I / F 206 in accordance with the program loaded into the DRAM 202. Upon detecting the copy instruction, the CPU 201 receives an original as electronic data from the scanner unit 104 via the scanner I / F 208 and stores the data in the DRAM 202. The CPU 201 performs color conversion processing suitable for output on the image data stored in the DRAM 202. The CPU 201 transfers the image data stored in the DRAM 202 to the printer unit 103 via the printer I / F 207, and performs output processing onto paper media. The CPU 201 realizes scan processing using the scanner unit 104 via the scanner I / F 208 .
[0020] 3 is a diagram illustrating the software structure of MFP 100. The software configuration of MFP 100 is realized by CPU 201 of controller unit 101 reading a program stored in Flash ROM 211 into DRAM 202 and executing it. MFP 100 has an operation control unit 301, a data storage unit 302, a job control unit 303, an image processing unit 304, a print processing unit 305, a reading processing unit 306, and a network control unit 307. MFP 100 also has a PCT / IP control unit 308, a security setting control unit 309, a packet acquisition control unit 310, an environment estimation control unit 311, and a management system communication unit 312.
[0021] The operation control unit 301 controls the display and operation reception on the operation unit 102. Specifically, the operation control unit 301 displays a screen image for the user on the operation unit 102. The operation control unit 301 also detects user operations and executes processing associated with screen components such as buttons displayed on the screen. The data storage unit 302 stores data by controlling recording to and reading from the Flash ROM 211, which is a storage device. For example, when a user changes device settings, the data storage unit 302 stores setting values corresponding to the user's input in the Flash ROM 211 based on a request from the operation control unit 301, which has detected the content entered by the user on the operation unit 102. In this embodiment, communication trend data (packet features) and an audit log are also stored in the data storage unit 302. The audit log is a log that stores security-related information when security-related operations are performed. The audit log is saved in CSV (comma separated values) format.
[0022] The job control unit 303 controls the execution of jobs. The image processing unit 304 processes image data into a format suitable for the intended use in accordance with instructions from the job control unit 303. The print processing unit 305 controls the print processing by the printer unit 103. Specifically, the print processing unit 305 prints and outputs an image on a paper medium or the like via the printer I / F 207 in accordance with instructions from the job control unit 303. The read processing unit 306 controls the scan processing by the scanner unit 104. Specifically, the read processing unit 306 reads a specified document via the scanner I / F 208 in accordance with instructions from the job control unit 303.
[0023] A network control unit 307 performs network settings such as an IP address on a TCP / IP control unit 308 when the MFP 100 is started or when a setting change is detected, in accordance with the setting values stored in the data storage unit 302. The TCP / IP (Transmission Control Protocol / Internet Protocol) control unit 308 performs processing for sending and receiving network packets via the network I / F 204.
[0024] The security setting control unit 309 manages the security settings of the MFP 100. As a specific example, the security setting control unit 309 identifies and manages the correspondence between security-related setting values and setting items, and the correspondence between each setting item and security threats, among the setting values stored in the data storage unit 302. The security setting control unit 309 also manages the correspondence between the usage environment of the MFP 100 and the security setting items corresponding to the usage environment. When the user specifies the usage environment, the security setting control unit 309 can set the corresponding security-related settings all at once. The security setting control unit 309 uses the data storage unit 302 to refer to and change the security-related setting values.
[0025] The usage environment of the MFP 100 will now be described. The vendor predefines multiple usage environment types based on factors such as the MFP 100 configuration environment, the usage environment of the network to which the MFP 100 is connected, and whether confidential information is included in the information expected to be used by the MFP 100. Examples of usage environments include a company intranet environment, an internet-prohibited environment, a direct internet connection environment, a public space environment, a home environment, and a highly confidential information management environment. The security settings that should be configured on the MFP 100 differ depending on the usage environment. For example, the file sharing function is a function for sharing files over a network within the environment. In an environment where unspecified users share the network within the environment, it is desirable to disable this function to prevent information leaks. In other words, it is recommended to disable the file sharing function except in a private network environment where specified users share the network within the environment. Private network environments include a company intranet environment, an internet-prohibited environment, and a home environment. Therefore, it is recommended to disable the file sharing function in the direct internet connection environment, public space environment, and highly confidential information management environment, excluding these. The above definition of the usage environment does not limit the present invention, and some or other usage environments may be defined as illustrated in this embodiment. For example, assuming installation within a company, usage environments may be categorized by industry, such as finance or government agencies. The administrator of the MFP 100 can select one usage environment to set for the MFP 100 from a selection of usage environments defined by the vendor. Furthermore, the MFP 100 has a function for estimating the usage environment to support appropriate security settings even when a user who does not have specialized security knowledge and cannot determine the usage environment manages the MFP 100.
[0026] The packet acquisition control unit 310 acquires data (packets, network packet information) transmitted and received by the MFP 100. Network packet information (packets) is collected when the network control unit 307 starts network communication. The network packet information is composed of information from other information processing devices connected to the same network. The packet acquisition control unit 310 uses the network control unit 307 to collect packets transmitted and received by the MFP 100 by performing communication in accordance with the corresponding protocols. The acquired packets (network packet information) may be broadcast or multicast only, or may also include unicast. The longer the packet acquisition period, the higher the accuracy of environment estimation; however, the longer the period, the longer the resource load. The appropriate packet acquisition period depends on the environment to which the MFP 100 is connected. In an environment with a high packet flow rate, a short packet acquisition period will provide sufficient accuracy, but in an environment with a low packet flow rate, a longer packet acquisition period will not provide sufficient accuracy. Even if the acquisition period is set to a short period, such as 60 seconds, environment estimation is possible. When the collection of network packet information is completed, the packet acquisition control unit 310 stores the network packet information collected during the current acquisition period in the data storage unit 302. When the currently acquired network packet information is saved, if the network packet information acquired two times previously is stored in the data storage unit 302, this information is deleted, thereby optimizing the storage area. Therefore, the data storage unit 302 stores the network packet information acquired during the current acquisition period and the network packet information acquired during the previous acquisition period. In this embodiment, the packet acquisition control unit 310 acquires the network packet information currently connected in accordance with an instruction from the environment estimation control unit 311.
[0027] The environment estimation control unit 311 collects network packet information during connection, generates and saves communication trend data, and performs environment estimation and saves the estimation results in an audit log. When the network control unit 307 starts network communication, the environment estimation control unit 311 instructs the packet acquisition control unit 310 to collect network packet information during connection, thereby collecting packets sent and received by the MFP 100. Upon completing packet collection, the environment estimation control unit 311 identifies features from the collected network packet information, generates communication trend data, and saves the data in the data storage unit 302. The communication trend data is data indicating the features identified from the packets sent and received by the MFP 100. More specifically, the communication trend data is statistical information indicating the features generated from the collected packets, such as the source IP address in the IP header of the packets acquired during the packet acquisition period, the source port number in the TCP header, and the number of receptions by type. The environment estimation control unit 311 generates the communication trend data by extracting, for example, the source IP address, IP header information, port number, and the number of receptions from information associated with the packets. When generating the communication tendency data, the content portion (payload) of the packet is excluded. The environment estimation control unit 311 stores the generated communication tendency data (feature amounts of packets) in the data storage unit 302. In this way, the environment estimation control unit 311 functions as an identification unit that identifies and stores the communication tendency data (feature amounts of packets).
[0028] Furthermore, the environment estimation control unit 311 estimates the network environment (usage environment) to which the MFP 100 is connected, using a learning model for performing a usage environment estimation process. The learning model used by the environment estimation control unit 311 is a learned model that models communication trends (communication trend data, packet feature amounts) for a generated usage environment. The learning model may be installed in the MFP 100 at the time of shipment, for example, or may be installed by distributing it to the MFP 100 from the management cloud system 121. The learning model installed in the MFP 100 is updated by the management cloud system 121. When estimating the usage environment of the MFP 100 using the learning model, communication trend data (feature amounts) is used as input data for machine learning, and the estimation result is used as the output of the machine learning. The estimation result is information about the usage environment to which the MFP is connected, such as an in-house LAN, a home, or a public space. The environment estimation control unit 311 records and manages the estimation result of the usage environment in an audit log. The audit log is a log that is stored when a security-related operation is performed. The audit log can be exported and referenced by the user. The audit log information is stored in the data storage unit 302. In this way, the environment estimation control unit 311 functions as an estimation unit that estimates the usage environment and saves the usage environment information that is the estimation result in the audit log.
[0029] The management system communication unit 312 controls communication between the management cloud system 121 and the MFP 100. The management system communication unit 312 has a function of detecting when an audit log is written and transmitting the contents of the audit log to the management cloud system 121. The format of data that the management cloud system 121 can receive is determined, and the management system communication unit 312 manages the transmission format of data to be transmitted to the management cloud system 121. The format of data that the management cloud system 121 can receive is specified, for example, by the management cloud system 121. The management system communication unit 312 exchanges information with the management cloud system 121 using the network control unit 307. Specifically, the management system communication unit 312 processes the audit log and communication tendency data that the environment estimation control unit 311 has stored in the data storage unit 302 into transmission data in a format that the management cloud system 121 can receive, and transmits the transmission data to the management cloud system 121. In this way, the management system communication unit 312 functions as a transmission means that generates transmission data from the feature amounts (communication tendency data) of the packets used for the estimation and the estimation results, and transmits the data to the management cloud system 121. The combination of the estimation results of the usage environment collected by the management cloud system 121 from multiple MFPs including the MFP 100 and the communication tendency data used for the estimation is used to generate a new estimation model or to re-train an existing learning model used by the MFP 100.
[0030] In order for the management cloud system 121 to use the usage environment estimation results and communication tendency data collected from the MFP 100 for purposes such as relearning the learning model, the usage environment estimation results and the communication tendency data used for the estimation must be associated with each other. If the usage environment estimation results and the communication tendency data are transmitted from the MFP 100 as separate events, they are stored separately in the management cloud system 121, and processing to link them in the management cloud system 121 is required. If the number of devices managed by the management cloud system 121 is large, the search processing to link the usage environment estimation results and the communication tendency data takes time. Therefore, in this embodiment, the MFP 100 generates an event that brings together the usage environment estimation results and the communication tendency data, and transmits the usage environment estimation results and the communication tendency data to the management cloud system 121 in a linked state.
[0031] 4 and 5, a process in which MFP 100 transmits communication tendency data and estimation results together as one event to management cloud system 121, which is an external server. First, a series of processes in which packets are acquired, communication tendency data and estimation results are generated based on the acquired packets, and the data are stored in MFP 100 will be described using FIG. 4. In this case, the communication tendency data and the estimation results of the usage environment are saved separately in different data formats, but information linking the communication tendency data and the estimation results of the usage environment is recorded in both. In this embodiment, an example in which the communication tendency data and the estimation results of the usage environment are linked at the estimation start time will be described.
[0032] Fig. 4 is a flowchart showing the process of generating and storing communication tendency data and estimation results. Each process shown in Fig. 4 is realized in MFP 100 by CPU 201 reading a program stored in Flash ROM 211 into DRAM 202 and executing the program as arithmetic processing. This process is performed, for example, when network control unit 307 of MFP 100 starts network communication.
[0033] In S401, the environment estimation control unit 311 issues an instruction to the packet acquisition control unit 310 to acquire packets. Upon receiving the instruction from the environment estimation control unit 311, the packet acquisition control unit 310 acquires packets transmitted and received by the MFP 100. In S402, the environment estimation control unit 311 generates feature amounts (communication tendency data) from the packets (network packet information) acquired in S401.
[0034] In S403, the environment estimation control unit 311 uses the feature amount (communication tendency data) generated in S402 as input data for machine learning to estimate the usage environment of MFP 100 using a learning model. In S404, the environment estimation control unit 311 generates an estimation result of the usage environment of MFP 100 as output data of the machine learning in S403. The environment estimation control unit 311 generates information about the usage environment of MFP 100 as the estimation result of the usage environment using the learning model.
[0035] In S405, the environment estimation control unit 311 creates a file of the packet feature amounts (communication tendency data) generated in S402 in JSON format and stores it in the data storage unit 302. In this embodiment, the environment estimation control unit 311 saves the packet feature amounts (communication tendency data) generated in S402 using the estimation start time as information linking the packet feature amounts (communication tendency data) to the estimation result, in a file name. An example of the packet feature amounts (communication tendency data) saved in the data storage unit 302 will be described later with reference to FIG. 7. Note that, in this embodiment, an example has been described in which a feature amount file is created and saved after the usage environment estimation result is generated in S404, but the feature amount file can be created and saved (S405) as long as it is after the usage environment estimation (S403) has started.
[0036] In S406, the environment estimation control unit 311 stores the estimation start time and the estimation result of the usage environment of the MFP 100 generated in S404 by writing them in the audit log. The audit log is stored in the data storage unit 302. The environment estimation control unit 311 also writes information related to the estimation other than the estimation result, along with the estimation result of the usage environment, to the audit log. In this embodiment, the environment estimation control unit 311 writes the estimation start time, along with the estimation result, to the audit log as information linking the packet feature amount (communication tendency data) to the estimation result. An example of the estimation result of the usage environment recorded in the audit log will be described later with reference to FIG. 6. Through the above processing, the communication tendency data and the estimation result of the usage environment can be linked by the estimation start time and saved.
[0037] Next, referring to FIG. 5, a process in which management system communication unit 312 of MFP 100 transmits the usage environment estimation result and the communication tendency data used for the estimation to management cloud system 121 in the same event will be described. FIG. 5 is a flowchart showing the process of transmitting the usage environment estimation result and the communication tendency data. Each process shown in FIG. 5 is realized in MFP 100 when CPU 201 loads a program stored in Flash ROM 211 into DRAM 202 and executes the program as arithmetic processing. This process is performed when environment estimation control unit 311 of MFP 100 saves the usage environment estimation result in the audit log. That is, the process shown in FIG. 5 is performed following the process of S406 shown in FIG. 4.
[0038] In S501, the management system communication unit 312 detects an audit log write event. The audit log write event includes an event (S406) in which the estimation result of the usage environment is saved in the audit log. In S502, the management system communication unit 312 determines whether the operation target of the audit log corresponding to the audit log write event detected in S501 is environment estimation. In other words, it determines whether the content written in the audit log is the estimation result of the usage environment. If the operation target of the audit log is usage environment estimation, the processing of S503 is performed. If the operation target of the audit log is not environment estimation, this flow ends.
[0039] In S503, the management system communication unit 312 acquires an audit log corresponding to the audit log write event detected in S501. The audit log acquired by the management system communication unit 312 here is the result of an estimation of the usage environment. The acquired monitoring log includes an estimated start time. In S504, the management system communication unit 312 acquires, from the data storage unit 302, communication tendency data having the estimated start time acquired in S503 as the file name.
[0040] In S505, the management system communication unit 312 generates transmission data in a data format that can be received by the management cloud system 121, based on the usage environment estimation result acquired in S503 and the communication tendency data acquired in S504. The transmission data includes the usage environment estimation result and estimation start time acquired from the audit log, and packet feature quantities (communication tendency data) acquired from the data storage unit 302. The transmission data also includes information necessary for transmission. The format of data that the management cloud system 121 can receive is determined, and the management system communication unit 312 determines the transmission format for communication with the management cloud system 121. The management system communication unit 312 includes the information necessary for transmission in the transmission data according to the transmission format specified by the management cloud system 121. As information necessary for transmission, the transmission data also includes an event ID as information that uniquely identifies the event, an event name, the time the event occurred, and information for identifying the MFP 100 that is the source of the transmission data. The event occurrence time is, for example, the date and time when an audit log write event is detected, that is, the date and time when the usage environment estimation result is stored in the audit log. In this embodiment, the serial number of the MFP 100, which is information that uniquely identifies the MFP 100, is included in the transmission data as information for identifying the information processing device that is the transmission source. The management system communication unit 312 generates the transmission data in a format that can be received by the management cloud system 121. In this embodiment, the management system communication unit 312 generates the transmission data in JSON format. The communication tendency data created in S405 is in JSON format, and the transmission data created in S505 is also in JSON format. An example of the transmission data will be described later with reference to FIG. 8. In S506, the management system communication unit 312 transmits the transmission data generated in S505 to the management cloud system 121. By the processing of S505 and S506, the MFP 100 can transmit the feature amount (communication tendency data) of the packet used to estimate the usage environment and the usage environment information that is the estimation result to the management cloud system 121 in the same event.
[0041] Through the above processing, the communication tendency data and the estimation result of the usage environment linked by the estimation start time can be collected into the same event (one transmission data) and transmitted from MFP 100 to management cloud system 121. By combining the communication tendency data and the estimation result of the usage environment into one transmission data in advance, it becomes unnecessary for management cloud system 121 to perform processing to identify the combination of the communication tendency data and the estimation result of the usage environment that have been transmitted separately.
[0042] A specific example of the processing will be described using the monitoring log shown in Fig. 6, the communication tendency data shown in Fig. 7, and the transmission data shown in Fig. 8 as examples. Fig. 6 is a diagram showing an example of an audit log. The audit log is stored in the data storage unit 302. The audit log includes, for example, a log number 601, a date and time 602, a user name 603, a result 604, an operation type 605, an operation target 606, a free description A 607, and a free description B 608.
[0043] The log number 601 is the log number. The date and time 602 is the time when the audit log was stored. The user name 603 is the name of the user who performed the operation recorded in the management log. The result 604 indicates whether the operation was OK or NG. For example, if the operation was completed successfully, OK is stored in the result 604, and if the operation was not completed successfully, NG is stored in the result 604. The operation type 605 is the type of operation. End, Start, etc. are stored in the operation type 605.
[0044] The operation target 606 indicates the target of the operation. In the case of an audit log of environment estimation, "estimation" is stored in the operation target 606. Free description A 607 and free description B 608 store different information depending on the operation target. For example, in the case of an audit log of environment estimation, information on the usage environment that is the estimation result of the usage environment is stored in free description A 607, and the estimation start time is stored in free description B 608. The estimation start time is, for example, the time when the estimation process started in S403, expressed as numbers indicating the year, month, day, hour, minute, and second.
[0045] In FIG. 6, log number 1 is an audit log of environment estimation indicating that estimation is complete. Log number 2 is an audit log indicating that IPSec communication failed. As in log number 2, security-related information other than the estimation result of the usage environment is also written to the audit log. The audit log of environment estimation indicated by log number 1 is written to the audit log and stored in the process of S406 in FIG. 4. In the audit log of environment estimation indicated by log number 1, free text A607 indicating the estimation result of the usage environment is "Intranet," which indicates the company LAN. Furthermore, free text B608 indicating the estimation start time is 20230905T194217, which indicates 19:42:17 on September 5, 2023. Because the estimation result is written to the audit log immediately after the estimation of the usage environment is completed, in the audit log of environment estimation, the date and time 602 indicating the audit log writing time is the estimation end time. Therefore, it is possible to determine whether the usage environment estimation process has been completed within the specified time from the time in free description B 608 indicating the estimated start time and the time in date and time 602 indicating the estimated end time.
[0046] FIG. 7 is a diagram showing an example of communication tendency data. The communication tendency data is in JSON format. The file name of the communication tendency data is given with the estimated start time of the usage environment. The communication tendency data includes an estimated start time 701, an IP header 702, a source IP address 703, a TCP header 704, and a source port number 705. The estimated start time 701 is the estimated start time of the usage environment and is the same as the file name. Therefore, to link the estimation result with the communication tendency data, the estimated start time 701 may be used instead of the file name of the communication tendency data. The estimated start time 701 and the file name of the communication tendency data correspond to the estimated start time in the free description B608 of log number 1 in the monitoring log shown in FIG. 6.
[0047] In this embodiment, the packet feature amount (communication tendency data) and the estimation result are linked by the estimation start time. The estimation start time is unique information. Furthermore, since the estimation start time is determined when the usage environment estimation starts in S403, it is determined before the packet feature amount (communication tendency data) is stored in S405, and can be used when storing the packet feature amount (communication tendency data) in S405. On the other hand, if an attempt is made to link the estimation result and the communication tendency data using the audit log number, the environment estimation control unit 311 writes in S406 without considering the log number, and therefore cannot use the log number to generate a file of the packet feature amount (communication tendency data) (S405). Furthermore, the log number has a maximum value, and if it exceeds the maximum value, it will loop and lack uniqueness. Therefore, in this embodiment, the estimation start time is used as information for linking the packet feature amount (communication tendency data) and the estimation result. Furthermore, by writing the estimated start time to the audit log, it is possible to compare the estimated end time recorded as the audit log writing time with the estimated start time, making it possible to verify whether the estimation was completed within a specified time. Furthermore, by using the estimated start time as the file name of the packet feature (communication tendency data), it is possible to delete old files based on the file name to prevent the folder area (memory) from becoming full with files of packet feature (communication tendency data). Furthermore, by including the estimated start time in the transmission data, it becomes possible for the management cloud system 121 to grasp the trend of the time period when analyzing the transmission data. In this way, by recording the estimated start time in each of the packet feature (communication tendency data) and the estimation result, it is possible to link the two and also to verify whether the estimation was completed within a specified time and to delete old files.
[0048] IP header 702 indicates an IP header. Source IP address 703 indicates the IP address of the source of the packet. Note that the IP addresses are not specific IP addresses, but rather indicate types with 1, 2, and 3. The example shown in FIG. 7 indicates that 100 packets were acquired during the packet acquisition period, with 80 packets having IP address 1, 15 having IP address 2, and 5 having IP address 3.
[0049] TCP header 704 indicates a TCP header. Source port number 705 indicates the port number of the packet sender. Source port number 705 indicates the type using a specific port number. The example shown in FIG. 7 indicates that 100 packets were acquired during the packet acquisition period, with 80 having a port number of 10080, 15 having a port number of 57397, and 5 having a port number of 57396. Note that as long as network packets are used, the communication trend data may be the header portion or the data portion, or may be the packets themselves rather than statistical information.
[0050] FIG. 8 is a diagram showing an example of transmission data. The transmission data of the usage environment estimation result is in JSON format. The transmission data of the usage environment estimation result includes an event ID 801, device information 802, event name 803, event occurrence time 804, estimation result 805, estimated start time 806, and communication tendency data 807. The event ID 801 is information that uniquely identifies the current event. The device information 802 is the serial number of the MFP. The event name 803 is the name of the event. For an event that transmits the usage environment estimation result, the event name 803 is "EstimationCompleted."
[0051] The event occurrence time 804 is the time when the transmission data was generated. For an event that transmits an estimation result of the usage environment, the event occurrence time 804 is the same as the date and time 602 recorded in the audit log. That is, the event occurrence time 804 is the same as the estimated end time and the audit log writing time. The estimation result 805 is information about the usage environment that serves as the estimation result of the usage environment. The estimation result 805 has the same content as the free description A 607 recorded in the audit log. The estimation start time 806 is the time when the estimation result of the usage environment started. The estimation start time 806 has the same content as the free description B 608 recorded in the audit log, the file name of the file of the packet feature amount (communication tendency data), and the estimation start time 701 recorded in the file of the packet feature amount (communication tendency data). The packet feature amount (communication tendency data) shown in FIG. 7 is described in the communication tendency data 807.
[0052] Assume that the packet feature quantities (communication tendency data) shown in FIG. 7 were recorded in S405, and the audit log shown in audit log 1 in FIG. 6 was recorded in S406. In this case, in S501, the management system communication unit 312 detects the audit log write event of log number 1 in FIG. 6. In S502, the management system communication unit 312 acquires the audit log of log number 1 in FIG. 6 that corresponds to the detected audit log write event, and determines whether the operation target of the audit log is environment estimation. Since the operation target of audit log 1 is environment estimation, the management system communication unit 312 performs the process of S503. In S503, the management system communication unit 312 acquires the audit log including the estimated start time (free description B608) and the estimation result (free description A607) of log number 1 in FIG. 6. In S504, the management system communication unit 312 acquires communication tendency data (FIG. 7) having the estimated start time acquired in S503 as its file name. In step S505, the management system communication unit 312 generates transmission data ( FIG. 8 ) in JSON format based on the acquired estimation results and communication tendency data. The format of data that the management cloud system 121 can receive is predetermined, and the management system communication unit 312 determines the transmission format for the management cloud system 121. The communication tendency data shown in FIG. 7 includes only data related to the environment estimation created by the environment estimation control unit 311, and is not in a format that the management cloud system 121 can receive as is. Therefore, the management system communication unit 312 creates transmission data in a format that the management cloud system 121 can receive, including the information required for transmission defined in the transmission format for the management cloud system 121, the communication tendency data, and the estimation results. The information required for transmission includes, for example, device information 802 of the MFP 100, event occurrence time 804, event name 803, event ID 801, etc.
[0053] As described above, according to this embodiment, MFP 100 can identify feature amounts (communication tendency data) from packets, estimate the usage environment based on the feature amounts, and transmit the estimation results and communication tendency data together as a single transmission data to management cloud system 121. By transmitting the estimation results and communication tendency data together from MFP 100 to management cloud system 121, it becomes unnecessary for management cloud system 121 to link information in the audit log with information in the communication tendency data. This eliminates the time required for search processing, etc., to link information in the audit log with information in the communication tendency data in management cloud system 121, thereby reducing the processing load on management cloud system 121. In this way, the information processing device can transmit the estimation results of the usage environment of the information processing device and the information used for the estimation (packet feature amounts, communication tendency data) in a form that is easily usable by an external server.
[0054] The disclosure of this embodiment includes the following configuration of an information processing device. (Configuration 1) Identification means for identifying a feature from a packet transmitted or received by the information processing device; an estimation means for estimating a usage environment of the information processing device using a learning model with the feature amount as input data; an information processing apparatus comprising: a transmitting means for transmitting the feature amount used in estimating the usage environment and information on the usage environment, which is an estimation result of the usage environment estimation, to an external server in the same event; (Configuration 2) the feature amount used for estimating the usage environment and the information on the usage environment that is the estimation result are linked using a start time of the estimation of the usage environment; The information processing device according to configuration 1, wherein the transmitting means creates and transmits transmission data according to a transmission format specified by the external server based on the linked feature and the usage environment information that is the estimation result. (Configuration 3) the estimation means records an estimation result of the usage environment estimation in an audit log that records information related to security; 3. The information processing device according to configuration 2, wherein the transmission means acquires the estimation result recorded from the audit log, and creates the transmission data using the acquired estimation result. (Configuration 4) 4. The information processing device according to configuration 3, wherein when recording the estimation result of the usage environment estimation in the audit log, the information processing device also records the start time of the usage environment estimation. (Configuration 5) 4. The information processing device according to configuration 3, wherein the audit log also records information related to security other than the estimation result of the usage environment estimation. (Configuration 6) The specifying means creates and stores a file of the specified feature amount, 6. The information processing apparatus according to any one of configurations 2 to 5, wherein the transmission means acquires a file of the feature amount, and creates the transmission data using the acquired file of the feature amount. (Configuration 7) 7. The information processing apparatus according to configuration 6, wherein the start time of the estimation of the usage environment using the feature is used as the file name of the file of the feature. (Configuration 8) 8. The information processing device according to configuration 6 or 7, wherein the information recorded in the file of the feature amount includes a start time of estimation of the usage environment using the feature amount. (Configuration 9) 9. The information processing device according to any one of configurations 6 to 8, wherein the feature file and the transmission data are in JSON format. (Configuration 10) The information processing device according to any one of configurations 1 to 9, wherein the external server re-learns the learning model using the feature values transmitted from the information processing device and the usage environment information that is the estimation result.
[0055] (Other embodiments) The present invention can also be realized by supplying a program that realizes one or more functions of the above-described embodiments to a system or device via a network or a storage medium, and having one or more processors in the computer of the system or device read and execute the program.The present invention can also be realized by a circuit (e.g., ASIC) that realizes one or more functions.
[0056] Although the preferred embodiments of the present invention have been described above, the present invention is not limited to these embodiments and various modifications and changes are possible within the scope of the gist of the present invention.
Claims
1. Identification means for identifying a feature from a packet transmitted or received by the information processing device; an estimation means for estimating a usage environment of the information processing device using a learning model with the feature amount as input data; an information processing apparatus comprising: a transmitting means for transmitting the feature amount used in estimating the usage environment and information on the usage environment, which is an estimation result of the usage environment estimation, to an external server in the same event;
2. the feature amount used for estimating the usage environment and the information on the usage environment that is the estimation result are linked using a start time of the estimation of the usage environment; The information processing device according to claim 1, characterized in that the transmitting means creates and transmits transmission data in accordance with a transmission format specified by the external server based on the linked feature and the usage environment information that is the estimation result.
3. the estimation means records an estimation result of the usage environment estimation in an audit log that records information related to security; 3. The information processing apparatus according to claim 2, wherein the transmission means acquires the recorded estimation result from the audit log, and creates the transmission data using the acquired estimation result.
4. 4. The information processing apparatus according to claim 3, wherein when the estimation result of the usage environment estimation is recorded in the audit log, the start time of the estimation of the usage environment is also recorded.
5. 4. The information processing apparatus according to claim 3, wherein the audit log also records information related to security other than the estimation result of the usage environment estimation.
6. The specifying means creates and stores a file of the specified feature amount, 3. The information processing apparatus according to claim 2, wherein the transmitting means acquires a file of the feature amount, and creates the transmission data using the acquired file of the feature amount.
7. 7. The information processing apparatus according to claim 6, wherein a start time of the estimation of the usage environment using the feature is used as a file name of the file of the feature.
8. 7. The information processing apparatus according to claim 6, wherein the information recorded in the file of the feature amount includes a start time of estimation of the usage environment using the feature amount.
9. The information processing apparatus according to claim 6 , wherein the feature file and the transmission data are in JSON format.
10. The information processing device according to claim 1 , wherein the external server re-learns the learning model using the feature amount transmitted from the information processing device and the usage environment information that is the estimation result.
11. A control method for an information processing device, comprising: identifying a feature from a packet transmitted and received by the information processing device; a step of estimating a usage environment of the information processing device using a learning model with the feature amount as input data; a step of transmitting the feature used to estimate the usage environment and information on the usage environment, which is an estimation result of the usage environment estimation, to an external server in the same event.
12. A program that causes a computer of an information processing device to execute each step of the process according to claim 11.
Citation Information
Patent Citations
Printing device, control method of printing device, and program
JP2022131233A