Security system, security method, and program
The security system verifies hardware authenticity and redirects communication to a decoy network if compromised, effectively preventing and observing attacks on initialization firmware and BIOS.
Patent Information
- Application Number
- JP2024078627
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-05-14
- Publication Date
- 2025-11-27
Smart Images

Figure 2025173175000001_ABST
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to a security system, a security method, and a program. [Background technology]
[0002] If an attacker gains administrative privileges over the operating system (OS) of an information processing device, security features such as EDR (Endpoint Detection and Response) may be disabled. Furthermore, attacks on hardware, such as firmware rewriting, may also be launched. In this case, it may become difficult to detect and respond to attacks.
[0003] Patent Document 1 describes a method for verifying initialization firmware and a basic input output system (BIOS) in response to at least one of power-on and reset. If verification of either the initialization firmware or the BIOS fails, the method of Patent Document 1 performs at least one of the following: not executing the BIOS, starting a repair, reporting a verification failure, halting, shutting down, or executing the BIOS and booting an OS with limited functionality. [Prior art documents] [Patent documents]
[0004] [Patent Document 1] Special Publication No. 2014-518428 Summary of the Invention [Problem to be solved by the invention]
[0005] The technology of Patent Document 1 can detect an attack on at least one of the initialization firmware and the BIOS. The technology of Patent Document 1 cannot lead an attack to an environment where an attacker can observe an attack while preventing the attack.
[0006] One of the objectives of the present disclosure is to provide a security system, a security method, and a program that can guide an attack into an environment where an attack by an attacker can be observed while preventing the attack by the attacker. [Means for solving the problem]
[0007] A security system according to one aspect of the present disclosure includes a device verification means for verifying device authenticity, which is the authenticity of the hardware of an information processing device that realizes a virtual computer, using verification information generated from startup information of the information processing device, and a control instruction means for instructing a communication control device that controls communication from the virtual computer, if the device authenticity is not verified, to make the communication partner of the virtual computer a decoy network that imitates the connection destination of the virtual computer.
[0008] A security method according to one aspect of the present disclosure verifies device authenticity, which is the authenticity of the hardware of an information processing device that realizes a virtual computer, using verification information generated from startup information of the information processing device, and if the device authenticity is not verified, instructs a communication control device that controls communication from the virtual computer to make the communication partner of the virtual computer a decoy network that imitates the connection destination of the virtual computer.
[0009] A program according to one aspect of the present disclosure causes a computer to execute a device verification process that verifies device authenticity, which is the authenticity of the hardware of an information processing device that realizes a virtual computer, using verification information generated from startup information of the information processing device, and a control instruction process that, if the device authenticity is not verified, instructs a communication control device that controls communication from the virtual computer to make the communication partner of the virtual computer a decoy network that mimics the connection destination of the virtual computer.
[0010] A security system according to one aspect of the present disclosure includes a device verification execution means for verifying device authenticity, which is the authenticity of the hardware of an information processing device that realizes a virtual computer, using verification information generated from startup information of the information processing device, and a communication control means for, if the device authenticity is not verified, in a communication control device that controls communication from the virtual computer, making the communication partner of the virtual computer a decoy network that imitates the connection destination of the virtual computer. [Effects of the Invention]
[0011] The present disclosure has an effect of guiding an attack to an environment where an attack by an attacker can be observed while preventing the attack by the attacker. [Brief explanation of the drawings]
[0012] [Figure 1] FIG. 1 is a block diagram illustrating an example of the configuration of a security system according to the present disclosure. [Figure 2] FIG. 2 is a flowchart illustrating an example of the operation of the security system according to the present disclosure. [Figure 3] FIG. 3 is a block diagram illustrating an example of the configuration of a security system according to the present disclosure. [Figure 4] FIG. 4 is a block diagram illustrating an example of the configuration of an information processing device according to the present disclosure. [Figure 5] FIG. 5 is a block diagram illustrating an example of the configuration of a security system according to the present disclosure. [Figure 6] FIG. 6 is a block diagram illustrating an example of the configuration of a security system according to the present disclosure. [Figure 7] FIG. 7 is a flowchart illustrating an example of the operation of the security system according to the present disclosure. [Figure 8] FIG. 8 is a flowchart illustrating an example of the operation of a device startup process of a security system according to the present disclosure. [Figure 9] FIG. 9 is a flowchart illustrating an example of the operation of the monitoring start process of the security system according to the present disclosure. [Figure 10] FIG. 10 is a flowchart illustrating an example of the operation of the authentication process of the security system according to the present disclosure. [Figure 11] FIG. 11 is a flowchart illustrating an example of the operation of the monitoring determination process of the security system according to the present disclosure. [Figure 12] FIG. 12 is a flowchart illustrating an example of the operation of a process for storing OS information in the security system according to the present disclosure. [Figure 13] FIG. 13 is a flowchart illustrating an example of the operation of the security system according to the present disclosure in a process of restoring OS information. [Figure 14] FIG. 14 is a block diagram illustrating an example of the configuration of a security system according to the present disclosure. [Figure 15] FIG. 15 is a block diagram schematically illustrating an example of the configuration of a security system according to the present disclosure. [Figure 16] FIG. 16 is a block diagram illustrating an example of the configuration of a security system according to the present disclosure. [Figure 17] FIG. 17 is a flowchart illustrating an example of the operation of the security system according to the present disclosure. [Figure 18] FIG. 18 is a diagram illustrating an example of a hardware configuration of a computer capable of realizing a security system according to an embodiment of the present disclosure. DETAILED DESCRIPTION OF THE INVENTION
[0013] Hereinafter, embodiments of the present disclosure will be described in detail with reference to the drawings. In the drawings of the present disclosure, lines connecting components indicate that data is exchanged between those components. The components that exchange data are not limited to those connected by lines. Data may also be exchanged between components that are not connected by lines.
[0014] First Embodiment First, a first embodiment of the present disclosure will be described in detail with reference to the drawings.
[0015] <Configuration> First, the configuration of the first embodiment of the present disclosure will be described in detail with reference to the drawings.
[0016] FIG. 1 is a block diagram illustrating an example of the configuration of a security system according to the present disclosure.
[0017] The configuration of a security system according to a first embodiment of the present disclosure will be described in detail below with reference to FIG.
[0018] In the example shown in FIG. 1, the security system 10 according to the first embodiment of the present disclosure includes a device verification unit 122 and a control instruction unit 123.
[0019] <Device Verification Unit 122> The device verification unit 122 verifies device authenticity, which is the authenticity of the hardware of an information processing device that realizes a virtual machine, by using verification information generated from information on the startup of the information processing device.
[0020] <Control instruction unit 123> If the authenticity of the device cannot be verified, the control instruction unit 123 instructs the communication control device that controls communication from the virtual computer to make the communication partner of the virtual computer a decoy network that imitates the connection destination of the virtual computer.
[0021] <Supplementary explanation> The startup information of the information processing device is, for example, software such as a boot loader and firmware executed when the information processing device is started up. The startup information of the information processing device may include, for example, parameters of the software such as a boot loader and firmware executed when the information processing device is started up. The startup information of the information processing device may include, for example, a boot sequence when the information processing device is started up (for example, information on the order of software such as a boot loader and firmware executed). The startup information of the information processing device may include other information related to software (in other words, processes) executed when the information processing device is started up.
[0022] The verification information generated from the information on the startup of the information processing device is, for example, a hash value of the information on the startup of the information processing device.
[0023] The device verification unit 122 may verify device authenticity by comparing verification information (hereinafter referred to as target verification information) generated from startup information of the information processing device obtained when the information processing device is started with the registered verification information. The registered verification information is verification information generated from startup information of the information processing device when the information processing device is normal. The startup information of the information processing device when the information processing device is normal is, for example, startup information of the information processing device at the time of shipment. The startup information of the information processing device when the information processing device is normal may be, for example, startup information of an information processing device that has been confirmed to be normal.
[0024] The registration verification information is prepared in advance.
[0025] The device verification unit 122 may determine that the device authenticity of the information processing device has been verified if the object verification information and the registration verification information are the same. In this case, the device verification unit 122 determines that the device authenticity of the information processing device has not been verified if the object verification information and the registration verification information are different. Verifying the device authenticity means, for example, confirming that the software executed when the information processing device starts up has not been tampered with.
[0026] The device verification unit 122 may verify the device authenticity of the information processing device, for example, by transmitting the generated verification information to a verification device. The verification device is configured, for example, to verify the device authenticity of the information processing device using the received object verification information in response to receiving the object verification information. In this case, the verification device may determine that the device authenticity of the information processing device has been verified if the object verification information and the registration verification information are the same. If the object verification information and the registration verification information are different, the verification device determines that the device authenticity of the information processing device has not been verified. The device verification unit 122 receives the result of the verification of the device authenticity of the information processing device from the verification device. In addition, the verification device previously stores the registration verification information of the information processing device.
[0027] The device verification unit 122 may verify the device authenticity of the information processing device by comparing the object verification information with the registration verification information. In this case, the device verification unit 122 holds the registration verification information of the information processing device in advance. The registration verification information of the information processing device may be stored in advance in a TPM (Trusted Platform Module) of the information processing device. Note that the information processing device is configured to include a TPM. Generally, a TPM includes a memory area with high tamper resistance. The registration verification information of the information processing device is specifically stored in a memory area with high tamper resistance included in the TPM. Then, if the object verification information and the registration verification information are the same, the device verification unit 122 may determine that the device authenticity of the information processing device has been verified. If the object verification information and the registration verification information are different, the device verification unit 122 determines that the device authenticity of the information processing device has not been verified.
[0028] The communication control device is, for example, a device (i.e., a gateway) that relays communication and is configured to be able to dynamically change the forwarding destination of data (e.g., packets). Technologies that enable dynamic changes to the forwarding destination include, for example, VPN (Virtual Private Network) and SDN (Software Designed Networking). That is, the communication control device is, for example, a VPN gateway or an SDN gateway.
[0029] The communication partner of a virtual machine (hereinafter also referred to as the communication destination of a virtual machine) refers to a communication network that includes network resources with which the virtual machine can communicate. In other words, the communication partner of a virtual machine (i.e., the communication destination of a virtual machine) is a network that is configured so that the virtual machine can access it.
[0030] Furthermore, the above-mentioned connection destination of a virtual computer is a network that is set as a communication network including network resources with which the virtual computer can communicate when the user of the virtual computer is a legitimate user of the virtual computer. In other words, the connection destination of a virtual computer is a network that is set as a communication destination of the virtual computer when the user of the virtual computer is a legitimate user of the virtual computer. When the user of the virtual computer is a legitimate user of the virtual computer, a communication network including network resources with which the virtual computer can communicate is referred to as a legitimate network.
[0031] In response to an instruction from the control instruction unit 123, the communication control device switches the network that the virtual computer realized in the information processing device can access between the regular network and the decoy network. The virtual computer is an emulated computer. An OS program is executed on the virtual computer. A user of the virtual computer can launch an application that runs on the OS. The virtual computer executes the application on the OS.
[0032] As described above, the authorized network includes network resources, such as other information processing devices and / or storage devices, that can be accessed by authorized users of the virtual computer, and a communication network to which the network resources are connected. An authorized user of the virtual computer is, for example, a user (also referred to as a registered user) who has been registered in advance as a user of the virtual computer.
[0033] A decoy network is a network that mimics a legitimate network. In the present disclosure, the decoy network is generated so that the configuration of the decoy network is the same as the configuration of the legitimate network. However, the information stored in the network resources of the legitimate network is not stored in the network resources of the decoy network.
[0034] The regular network and the decoy network are realized as VPNs. For example, an authentication device that authenticates a user logging in to a virtual computer is accessed by the virtual computer as one of the network resources in the network (i.e., the regular network or the decoy network) to which the virtual computer is connected.
[0035] Setting the decoy network as the communication partner of a virtual computer means setting the communication control device to a setting (hereinafter referred to as decoy setting) that sends packets from the virtual computer to a network resource in the regular network to the decoy network. When the communication control device is set to the decoy setting, the communication control device forwards packets from the virtual computer to a network resource in the regular network to a network resource corresponding to that network resource. The communication control device forwards packets from a network resource in the decoy network to the virtual computer as packets from a network resource in the regular network that corresponds to that network resource.
[0036] When the virtual computer's communication partner is a regular network, the communication control device forwards packets from the virtual computer to a network resource on the regular network to that network resource on the regular network. Also, the communication control device forwards packets from a network resource on the regular network to the virtual computer as packets from that network resource on the regular network. In this disclosure, a setting in which the virtual computer's communication partner is a regular network is also referred to as a regular setting.
[0037] <Operation> Next, the operation of the first embodiment of the present disclosure will be described in detail with reference to the drawings.
[0038] FIG. 2 is a flowchart illustrating an example of the operation of the security system according to the present disclosure.
[0039] The operation of the security system 10 according to the first embodiment of the present disclosure will be described in detail below with reference to FIG.
[0040] 2, first, the device verification unit 122 verifies the device authenticity, which is the authenticity of the hardware of the information processing device that realizes the virtual computer, using verification information generated from startup information of the information processing device (step S11). If the device authenticity is not verified (NO in step S12), the control instruction unit 123 instructs the communication control device that controls communication from the virtual computer to set the communication partner of the virtual computer to a decoy network (step S13). If the device authenticity is verified (YES in step S12), the security system 10 ends the operation shown in FIG.
[0041] If the communication partner of the virtual computer has not been determined, the control instruction unit 123 instructs the communication control device that controls communication from the virtual computer to set the communication partner of the virtual computer to the regular network. If the communication partner of the virtual computer is determined to be the regular network, the security system 10 may perform the operation shown in FIG.
[0042] <Effects> This embodiment has the effect of guiding an attack to an environment where an attack by an attacker can be observed while preventing the attack by the attacker.
[0043] This is because the device verification unit 122 verifies the device authenticity of the information processing device that realizes the virtual computer. If the device authenticity is not verified, the control instruction unit 123 instructs the communication control device that controls communication from the virtual computer to set the communication partner of the virtual computer to a decoy network. As a result, if the device authenticity is not verified, access from the virtual computer is limited to the decoy network. This makes it possible to prevent attacks on the legitimate network by attackers. Furthermore, the communication control device that controls communication from the virtual computer can observe attacks from the virtual computer to the decoy network. In other words, the security system of this embodiment can lead attacks to an environment where attacks by attackers can be observed while preventing attacks by attackers.
[0044] <Second embodiment> Next, a second embodiment of the present disclosure will be described in detail with reference to the drawings.
[0045] <Configuration> First, the configuration of the second embodiment of the present disclosure will be described in detail with reference to the drawings.
[0046] FIG. 3 is a block diagram illustrating an example of the configuration of a security system according to the present disclosure.
[0047] The configuration of a security system according to the second embodiment of the present disclosure will be described in detail below with reference to Fig. 3. Fig. 3 shows the functional configuration of a security system 1.
[0048] 3, the security system 1 includes an information processing device 100, a device verification execution unit 210, a communication control unit 320, an access monitoring unit 330, a range determination unit 340, a user verification unit 360, an authentication unit 420, a receiving unit 510, an information storage unit 520, and a transmitting unit 530. The user verification unit 360 includes a behavior verification unit 310 and an authentication verification unit 410.
[0049] FIG. 4 is a block diagram illustrating an example of the configuration of an information processing device according to the present disclosure.
[0050] 4, information processing device 100 includes a boot control unit 110, a hypervisor unit 120, a virtual machine 130, and a virtual machine information storage unit 140. Hypervisor unit 120 includes a verification information generation unit 121, a device verification unit 122, a control instruction unit 123, a hypervisor execution unit 124, an information extraction unit 125, and a restoration unit 126.
[0051] Fig. 5 is a block diagram showing an example of the configuration of a security system according to the present disclosure, in which the security system 1 shown in Fig. 3 is implemented using a plurality of devices.
[0052] In the example shown in FIG. 5, the security system 1 includes an information processing device 100, a verification device 200, a communication control device 300, an authentication device 400, and a restoration support device 500.
[0053] The verification device 200 includes a device verification execution unit 210 .
[0054] The communication control device 300 includes a behavior verification unit 310 , a communication control unit 320 , an access monitoring unit 330 , and a range determination unit 340 .
[0055] The authentication device 400 includes an authentication verification unit 410 and an authentication unit 420 .
[0056] The restoration support device 500 includes a receiving unit 510 , an information storage unit 520 , and a transmitting unit 530 .
[0057] The configuration of the devices in the security system 1 is not limited to the example shown in Fig. 5. The security system 1 may be configured so that the functions of the verification device 200, the communication control device 300, the authentication device 400, and the restoration support device 500 are realized by one or more devices each including at least some of these functions. The security system 1 may be realized by the information processing device 100 and one or more of the devices described above.
[0058] 6 is a block diagram showing an example of the configuration of a security system according to the present disclosure. FIG. 6 schematically shows an example of the configuration of security system 1 shown in FIG.
[0059] 6, the security system 1 includes an information processing device 100, a verification device 200, a communication control device 300, an authentication device 400, and a restoration support device 500. Fig. 6 further shows that the communication control device 300 can set the communication partner of the virtual computer implemented in the information processing device 100 to a regular network 600 or a decoy network 700.
[0060] Next, the components of the security system 1 of the present disclosure will be described in detail.
[0061] <Information processing device 100> 4, the information processing device 100 includes a boot control unit 110, a hypervisor unit 120, a virtual machine 130, and a virtual machine information storage unit 140. The hypervisor unit 120 includes a verification information generation unit 121, a device verification unit 122, a control instruction unit 123, a hypervisor execution unit 124, an information extraction unit 125, and a restoration unit 126.
[0062] <Activation control unit 110> The boot control unit 110 executes processing at the time of booting up the information processing device 100 in response to the power-on of the information processing device 100 and the reset of the information processing device 100. The boot control unit 110 is, for example, a boot loader of the information processing device 100 and firmware such as UEFI (Unified Extensible Firmware Interface) or BIOS.
[0063] <Verification Information Generator 121> The verification information generation unit 121 generates the above-mentioned verification information from startup information of the information processing device obtained when the information processing device is started. The verification information generation unit 121 acquires the startup information of the information processing device, and generates the above-mentioned verification information from the acquired startup information of the information processing device. The verification information generation unit 121 may be realized by, for example, a TPM.
[0064] <Device Verification Unit 122> The device verification unit 122 verifies device authenticity, which is the authenticity of the hardware of the information processing device 100 that realizes the virtual machine 130, by using verification information generated from startup information of the information processing device 100. The device verification unit 122 is the same as the device verification unit 122 in the first embodiment.
[0065] The device verification unit 122 may verify the device authenticity of the information processing device 100, for example, by transmitting the generated verification information to the verification device 200. The verification device 200 corresponds to the verification device of the first embodiment. The verification device 200 is configured, for example, to verify the device authenticity of the information processing device 100 by using the received object verification information in response to receiving the object verification information. In this case, the verification device 200 (specifically, the device verification execution unit 210, as described below) may determine that the device authenticity of the information processing device 100 has been verified if the object verification information and the registration verification information are the same. If the object verification information and the registration verification information are different, the verification device 200 determines that the device authenticity of the information processing device 100 has not been verified. The device verification unit 122 receives the result of the verification of the device authenticity of the information processing device 100 from the verification device 200. The verification device 200 also stores the registration verification information of the information processing device 100 in advance.
[0066] The device verification unit 122 may verify the device authenticity of the information processing device 100 by comparing the object verification information with the registration verification information. In this case, the device verification unit 122 holds the registration verification information of the information processing device 100 in advance. The registration verification information of the information processing device 100 may be stored in advance in the TPM of the information processing device 100. The information processing device 100 is configured to include a TPM. Then, if the object verification information and the registration verification information are the same, the device verification unit 122 may determine that the device authenticity of the information processing device 100 has been verified. If the object verification information and the registration verification information are different, the device verification unit 122 determines that the device authenticity of the information processing device 100 has not been verified.
[0067] In the following description, the device verification unit 122 verifies the device authenticity of the information processing device 100 by, for example, transmitting the generated verification information to the verification device 200.
[0068] <Control instruction unit 123> When the device authenticity is not verified, the control instruction unit 123 instructs the communication control device 300, which controls communication from the virtual computer, to change the communication partner of the virtual computer to the decoy network 700. The control instruction unit 123 is the same as the control instruction unit 123 in the first embodiment. The communication control device 300 corresponds to the communication control device in the first embodiment. When the device authenticity is verified, the control instruction unit 123 instructs the communication control device 300, which controls communication from the virtual computer, to change the communication partner of the virtual computer to the regular network 600. The regular network 600 corresponds to the regular network in the first embodiment. The decoy network 700 corresponds to the decoy network 700 in the first embodiment.
[0069] The control instruction unit 123 instructs the communication control device 300 to set the decoy network 700 as the communication partner of the virtual computer, for example, by transmitting a decoy setting instruction to the communication control device 300. The decoy setting instruction is an instruction to set the decoy network 700 as the communication partner of the virtual computer. The control instruction unit 123 instructs the communication control device 300 to set the regular network 600 as the communication partner of the virtual computer, for example, by transmitting a regular setting instruction to the communication control device 300. The regular setting instruction is an instruction to set the regular network 600 as the communication partner of the virtual computer.
[0070] In response to an instruction from the control instruction unit 123, the communication control device 300 switches the network that the virtual computer realized in the information processing device 100 can access between the regular network 600 and the decoy network 700. For example, in response to receiving a decoy setting instruction, the communication control device 300 sets the network that the virtual computer realized in the information processing device 100 can access to the decoy network 700. For example, in response to receiving a regular setting instruction, the communication control device 300 sets the network that the virtual computer realized in the information processing device 100 can access to the regular network 600.
[0071] <Virtual Machine Information Storage Unit 140> The virtual computer information storage unit 140 stores information (referred to as virtual computer information) used to realize the virtual computer 130. The virtual computer information includes information on the OS of the virtual computer 130. The virtual computer information may also include information on applications that run on the OS of the virtual computer 130.
[0072] <Hypervisor execution unit 124> After the control instruction unit 123 transmits the decoy setting instruction or the normal setting instruction, the hypervisor execution unit 124 uses the virtual computer information to execute a process for realizing the virtual computer 130 on the information processing device 100. The method for realizing the virtual computer 130 on the information processing device 100 is one of various existing methods for realizing a virtual computer.
[0073] <Virtual Computer 130> The virtual computer 130 is a virtual computer that operates on the information processing device 100. The virtual computer 130 operates as a computer on which an OS is installed. The virtual computer 130 provides the user with the functions of a computer on which an OS is installed.
[0074] The communication control device 300 allows the virtual computer 130 to access network resources of a network (regular network 600 or decoy network 700) that is set as the communication destination of the virtual computer 130. As described above, the decoy network 700 imitates the regular network 600. The configuration of the regular network 600 is the same as the configuration of the decoy network 700. The communication control device 300 sets the network that is the communication destination of the virtual computer 130, without being involved with the virtual computer 130.
[0075] A user of the virtual computer 130 accesses the virtual computer 130 from a terminal device different from the information processing device 100. Specifically, for example, the user of the virtual computer 130 logs in to the virtual computer 130. If authentication accompanying the login is successful, the user of the virtual computer 130 is able to use the virtual computer 130. After authentication accompanying the login is successful, the user of the virtual computer 130 is able to access network resources of a network with which the virtual computer 130 communicates via the virtual computer 130. Access from the virtual computer 130 to network resources of a network with which the virtual computer 130 communicates is performed via the communication control unit 320 of the communication control device 300. Packets of communication between the virtual computer 130 and the network resources of a network with which the virtual computer 130 communicates are relayed by the communication control unit 320 of the communication control device 300.
[0076] <Information extraction section 125> The information extraction unit 125 extracts information about the OS of the virtual computer 130 from the virtual computer information stored in the virtual computer information storage unit 140. The information about the OS of the virtual computer 130 is information necessary for restoring (recovering) the OS of the virtual computer 130. In addition to the information about the OS of the virtual computer 130, the information extraction unit 125 may also extract information about applications running on the OS (i.e., information necessary for restoring (recovering) the applications).
[0077] The information extraction unit 125 transmits the extracted OS information to the restoration support device 500. When the information extraction unit 125 extracts application information, the information extraction unit 125 transmits the extracted OS information and application information to the restoration support device 500.
[0078] The restoration support device 500 stores the OS information and application information received from the information extraction unit 125 in the information storage unit 520. If the restoration support device 500 has not received the application information, it does not need to store the application information in the information storage unit 520.
[0079] The information extraction unit 125 extracts OS information from the virtual computer information stored in the virtual computer information storage unit 140 at a timing when it is determined that no attack has been made on the information processing device 100. When extracting application information, the information extraction unit 125 extracts OS information and application information from the virtual computer information stored in the virtual computer information storage unit 140. The timing when it is determined that no attack has been made on the information processing device 100 may be, for example, the timing when the information processing device 100 is first turned on. The timing when it is determined that no attack has been made on the information processing device 100 may be, for example, the timing immediately after an OS restoration and an OS update (e.g., a version upgrade or a security update). The timing when it is determined that no attack has been made on the information processing device 100 may be, for example, the timing immediately after an OS and application restoration and an OS and application update.
[0080] In the following description, the OS information includes application information when an application is restored in addition to the OS. When the OS information includes application information, the OS restoration may refer to the restoration of the OS and the application.
[0081] <Restore section 126> For example, in response to receiving a restoration instruction that is an instruction to restore the OS of the virtual machine 130 of the information processing device 100, the restoration unit 126 reads information about the OS of the virtual machine 130 of the information processing device 100 from the information storage unit 520 of the restoration support device 500. The restoration instruction may be input, for example, via an input device of the information processing device 100 and passed to the restoration unit 126. The restoration unit 126 restores the OS of the virtual machine 130 using the OS information read from the information storage unit 520 of the restoration support device 500. For example, the restoration unit 126 restores the OS information of the virtual machine information stored in the virtual machine information storage unit 140 using the OS information read from the information storage unit 520 of the restoration support device 500.
[0082] Specifically, in response to receiving the restoration instruction, the restoration unit 126 may transmit an instruction to transmit information about the OS to the restoration support device 500. In response to receiving the instruction to transmit information about the OS, the restoration support device 500 reads information about the OS of the virtual machine 130 of the information processing device 100 from the information storage unit 520. The restoration support device 500 transmits the read information about the OS of the virtual machine 130 of the information processing device 100 to the restoration unit 126.
[0083] The restoration unit 126 receives, from the restoration support device 500, information on the OS of the virtual machine 130 of the information processing device 100, which information has been read from the information storage unit 520 of the restoration support device 500. The restoration unit 126 restores the OS information of the virtual machine information stored in the virtual machine information storage unit 140, using the received information on the OS of the virtual machine 130 of the information processing device 100.
[0084] <Verification device 200> As described above, the verification device 200 includes a device verification execution unit 210 .
[0085] <Device Verification Execution Unit 210> The device verification execution unit 210 receives verification information generated from startup information of the information processing device 100 from the device verification unit 122 of the information processing device 100. Upon receiving the verification information of the information processing device 100, the device verification execution unit 210 compares the received verification information, that is, object verification information, with registration verification information to verify device authenticity, which is the authenticity of the hardware of the information processing device 100. As described above, the registration verification information is verification information generated from startup information of the information processing device 100 when the information processing device 100 is normal. The device verification execution unit 210 stores the registration verification information of the information processing device 100 in advance. If the object verification information and the registration verification information are the same, the device verification execution unit 210 may determine that the device authenticity of the information processing device 100 has been verified. If the object verification information and the registration verification information are different, the device verification execution unit 210 determines that the device authenticity of the information processing device 100 has not been verified.
[0086] The device verification execution unit 210 transmits the result of the verification of the device authenticity of the information processing device 100 to the device verification unit 122 of the information processing device 100 .
[0087] <User Verification Unit 360> The user verification unit 360 verifies user authenticity, which is the authenticity of the user, from the behavior of the user of the virtual computer. In the example shown in FIG. 5, the user verification unit 360 includes a behavior verification unit 310 included in the communication control device 300 and an authentication verification unit 410 included in the authentication device. The user verification unit 360 verifies user authenticity, which is the authenticity of the user, from the behavior of the user of the virtual computer, by at least one of the behavior verification unit 310 and the authentication verification unit 410. The behavior verification unit 310 and the authentication verification unit 410 will be described in detail later.
[0088] <Authentication device 400> As described above, the authentication device 400 includes an authentication verification unit 410 and an authentication unit 420 .
[0089] <Authentication Unit 420> The authentication unit 420 authenticates the user of the virtual machine 130 .
[0090] Specifically, for example, the virtual computer 130 transmits authentication data including, for example, a user ID (Identification) and data (for example, a password) for proving that the user of the virtual computer 130 is the user identified by the user ID to the authentication unit 420. The authentication unit 420 receives the authentication data from the virtual computer 130. The authentication unit 420 uses the authentication data to determine whether the user of the virtual computer 130 is the user indicated by the user ID. If the authentication unit 420 uses the authentication data to determine that the user of the virtual computer 130 is the user indicated by the user ID, it determines that authentication of the user of the virtual computer 130 has been successful. If the authentication unit 420 uses the authentication data to determine that the user of the virtual computer 130 is not the user indicated by the user ID, it determines that authentication of the user of the virtual computer 130 has failed.
[0091] The authentication method is not limited to the above-mentioned method using a password. The authentication method may be another authentication method. For example, the authentication method may be two-factor authentication using any two-factor authentication method. The authentication method may be multi-factor authentication using any multi-factor authentication method. This multi-factor authentication is authentication using three or more factors. The authentication method may be biometric authentication using biometric data such as at least one of a face image, an iris image, and a fingerprint image. The authentication method may be authentication using a personal certificate, etc.
[0092] The authentication unit 420 transmits the result of the authentication to the virtual computer 130. The result of the authentication transmitted to the virtual computer 130 may be information indicating whether or not the authentication was successful.
[0093] The authentication unit 420 further sends information about the authentication result to the authentication verification unit 410. The authentication result information sent to the authentication verification unit 410 includes, for example, information identifying the virtual computer 130, the user ID of the user who performed the authentication, and information indicating whether the authentication was successful.
[0094] <Authentication Verification Unit 410> The authentication verification unit 410 receives information on the authentication result from the authentication unit 420. The authentication verification unit 410 verifies the authenticity of the user using the result of the user authentication indicated by the information on the authentication result.
[0095] Specifically, if the user of the virtual computer 130 fails authentication a predetermined number of times or more consecutively, the authentication verification unit 410 determines that the user authenticity, which is the authenticity of the user, has not been verified. User authenticity means that the user is a legitimate user of the virtual computer 130. A lack of user authenticity means that the user is not a legitimate user of the virtual computer 130. A verification of user authenticity means that the user has been determined to be a legitimate user of the virtual computer 130. A failure to verify user authenticity means that the user has been determined to be not a legitimate user of the virtual computer 130.
[0096] The authentication verification unit 410 determines that the user authenticity cannot be verified if the user of the virtual computer 130 is not a registered user registered as a user of the virtual computer 130 and is successful in authentication. Note that the authentication verification unit 410 stores information on registered users of the virtual computer 130 in advance.
[0097] The authentication verification unit 410 determines that the user authenticity has been verified when the user of the virtual computer 130, who is a registered user registered as the user of the virtual computer 130, is successfully authenticated a predetermined number of times or more without failing authentication. Note that the user of the virtual computer 130 refers to the person operating the virtual computer 130 (in this case, the person performing the authentication operation to log in to the virtual computer 130).
[0098] If the user authenticity of the user of the virtual computer 130 cannot be verified, i.e., if it is determined that the user authenticity of the user of the virtual computer 130 cannot be verified, the authentication verification unit 410 sends a decoy setting instruction to the communication control unit 320 of the communication control device 300.
[0099] <Communication control device 300> The communication control device 300 includes a behavior verification unit 310 , a communication control unit 320 , an access monitoring unit 330 , and a range determination unit 340 .
[0100] <Communication control unit 320> The communication control unit 320 relays communications between the virtual computer 130 and a network that is set as the communication destination of the virtual computer (specifically, for example, network resources of the network that is set as the communication destination of the virtual computer).
[0101] In response to an instruction from the control instruction unit 123, the communication control unit 320 switches the network accessible by the virtual computer 130 implemented in the information processing device 100 between the regular network 600 and the decoy network 700. For example, in response to receiving a decoy setting instruction, the communication control unit 320 sets the network accessible by the virtual computer 130 implemented in the information processing device 100 to the decoy network 700. For example, in response to receiving a regular setting instruction, the communication control unit 320 sets the network accessible by the virtual computer 130 implemented in the information processing device 100 to the regular network 600. For example, when the communication control unit 320 has not received a decoy setting instruction, the communication control unit 320 may set the network accessible by the virtual computer 130 implemented in the information processing device 100 to the regular network 600. In other words, for example, when the information processing device 100 starts up, the communication control unit 320 may set the network accessible by the virtual computer 130 implemented in the information processing device 100 to the regular network 600. The communication control unit 320 may maintain the state in which the network that the virtual computer 130 realized in the information processing device 100 can access is the regular network 600 until it receives a decoy setting instruction from the information processing device 100.
[0102] <Access monitoring unit 330> The access monitor 330 monitors access from the virtual computer 130 to a network that is set as the communication destination of the virtual computer 130. That is, the access monitor 330 preserves packets of communication between the virtual computer 130 and the network that is the communication destination of the virtual computer 130 (specifically, for example, network resources of that network). In other words, the access monitor 330 captures and stores such packets.
[0103] The access monitor 330 further estimates, from the information of the captured packets, an access behavior, which is an action by the virtual computer 130 to access a network resource of a network with which the virtual computer 130 is communicating. The access behavior may be represented by the access destination and the content of the access (in other words, the type of access). The type of access may be, for example, read, write, rewrite, erase, etc. The type of access is not limited to these examples. The access monitor 330 estimates the access destination from, for example, information in the packet header. The access monitor 330 may reconstruct data sent by the packet from one or more captured packets. The access monitor 330 may then use the reconstructed data to determine the content of the access.
[0104] If the network with which the virtual computer 130 communicates is not the decoy network 700 and the authenticity of the user of the virtual computer 130 has been verified, the access monitoring unit 330 may estimate the access behavior from the stored packet and then discard the packet.
[0105] The access monitoring unit 330 stores, without discarding, packets received while the network with which the virtual computer 130 communicates is set as the decoy network 700. If the authenticity of the user of the virtual computer 130 is not verified, the access monitoring unit 330 stores, without discarding, packets received during communication between the virtual computer 130 and the network with which the virtual computer communicates while the user is using the virtual computer 130.
[0106] <Range Determining Unit 340> The range determination unit 340 determines the access behavior range, which is the range of access behavior of the virtual computer 130 used by the registered user, from the past access behavior of the virtual computer 130 while the registered user is using it (i.e., the access behavior determined from the stored packets). As described above, the registered user is a user who is registered as a user of the virtual computer 130.
[0107] The range determination unit 340 may determine, for example, the network resource accessed from the virtual computer 130 for each type of access behavior while the registered user is using the network resource as the access behavior range. The range determination unit 340 may determine, for example, the network resource accessed by the virtual computer 130 at a frequency equal to or higher than a predetermined frequency for each type of access behavior while the registered user is using the network resource as the access behavior range. The frequency of access may be, for example, the number of accesses per unit time.
[0108] <Behavior Verification Unit 310> The behavior verification unit 310 verifies the authenticity of the user of the virtual computer 130 using information on access behavior, which is behavior of the user of the virtual computer 130 accessing network resources (ie, network resources).
[0109] If the access behavior of the user of the virtual computer 130 does not satisfy the predetermined behavioral criteria, the behavior verification unit 310 determines that the user authenticity of the user is not verified. The predetermined behavioral criteria include, for example, not performing access behavior other than predetermined access behavior. The predetermined behavioral criteria may include, for example, not accessing network resources that are not predetermined network resources (e.g., network resources to which access is permitted). The predetermined behavioral criteria are not limited to these examples. The behavior verification unit 310 determines that the user authenticity of the user is verified while the access behavior of the user of the virtual computer 130 satisfies the predetermined behavioral criteria.
[0110] If the access behavior of the virtual computer 130 falls outside the above-mentioned access behavior range, the behavior verification unit 310 determines that the user authenticity of the user of the virtual computer 130 cannot be verified. As described above, the access behavior range is the range of access behavior determined from the past access behavior of the virtual computer 130 while it is being used by a registered user who is registered as the user of the virtual computer 130.
[0111] The behavior verification unit 310 determines that the access behavior of the virtual computer 130 is included in the access behavior range when the difference between the frequency of the access behavior of the virtual computer 130 and the frequency of the access behavior of the same type as the type of the access behavior in the access behavior range satisfies a criterion. The behavior verification unit 310 determines that the access behavior of the virtual computer 130 is outside the access behavior range (i.e., not included in the access behavior range) when the difference between the frequency of the access behavior of the virtual computer 130 and the frequency of the access behavior of the same type as the type of the access behavior does not satisfy a criterion. This criterion is that the frequency is greater than a threshold determined from the frequency of the access behavior of the same type as the type of the access behavior of the virtual computer 130 in the access behavior range. The threshold may be a value obtained by multiplying a predetermined positive number by the frequency of the access behavior of the same type as the type of the access behavior of the virtual computer 130 in the access behavior range. The threshold may be a value obtained by adding a predetermined positive number to the frequency of the access behavior of the same type as the type of the access behavior of the virtual computer 130 in the access behavior range.
[0112] The behavior verification unit 310 determines that the user authenticity of the user is verified as long as the access behavior of the virtual computer 130 does not deviate from the access behavior range and the access behavior of the virtual computer 130 satisfies the predetermined behavioral criteria. If the access behavior of the virtual computer 130 deviates from the access behavior range and does not satisfy the predetermined behavioral criteria, the behavior verification unit 310 determines that the user authenticity is not verified, regardless of whether the user of the virtual computer 130 is a registered user. In this case, a legitimate user of the virtual computer 130 is, for example, a user who uses the virtual computer 130 so that the access behavior of the virtual computer 130 does not deviate from the access behavior range and satisfies the predetermined behavioral criteria.
[0113] If the behavior verification unit 310 determines that the user authenticity of the user of the virtual computer 130 cannot be verified, the communication control unit 320 sets a network that the virtual computer 130 realized in the information processing device 100 can access (i.e., a network to which the virtual computer 130 communicates) as the decoy network 700.
[0114] When the behavior verification unit 310 determines that the user authenticity of the user of the virtual computer 130 cannot be verified, the behavior verification unit 310 may send a decoy setting instruction to the communication control unit 320. In response to receiving the decoy setting instruction, the communication control unit 320 sets a network that the virtual computer 130 can access (i.e., a network with which the virtual computer 130 communicates) as the decoy network 700.
[0115] <Restoration support device 500> As described above, the restoration support device 500 includes a receiving unit 510, an information storage unit 520, and a transmitting unit 530.
[0116] <Receiving section 510> The receiving unit 510 receives extracted information about the OS of the virtual machine 130 from the information extracting unit 125 of the information processing device 100. The receiving unit 510 stores the received information about the OS of the virtual machine 130 in the information storage unit 520. As described above, the OS information may include application information.
[0117] <Information storage unit 520> The information storage unit 520 stores the OS information received from the information extraction unit 125 of the information processing device 100 .
[0118] <Transmitter 530> In response to receiving an instruction to transmit information about the OS from the restoration unit 126 of the information processing device 100, the transmission unit 530 reads information about the OS of the information processing device 100 from the information storage unit 520. The transmission unit 530 transmits the information about the OS of the information processing device 100, which has been read from the information storage unit 520, to the restoration unit 126 of the information processing device 100.
[0119] <Operation> Next, the operation of the second embodiment of the present disclosure will be described in detail with reference to the drawings.
[0120] FIG. 7 is a flowchart illustrating an example of the operation of the security system according to the present disclosure.
[0121] The operation of the security system 1 according to the second embodiment of the present disclosure will be described in detail below with reference to FIG.
[0122] For example, when the information processing device 100 is powered on or when the information processing device 100 is restarted, the security system 1 starts the operation shown in FIG.
[0123] 7, the security system 1 performs device startup processing (step S101). The device startup processing will be described in detail later. Next, the hypervisor execution unit 124 of the information processing device 100 starts up the virtual machine 130 (step S102).
[0124] 7 until authentication of the user of the virtual computer 130 is performed. When authentication of the user of the virtual computer 130 is started, the security system 1 performs the operations from step S103 onwards.
[0125] In step S103, the security system 1 performs authentication processing (step S103). The authentication processing will be described in detail later. Then, the security system 1 performs monitoring and determination processing (step S104). The monitoring and determination processing will be described in detail later.
[0126] After the authentication process is executed, if the user logs out from the virtual computer 130, the security system 1 may continue the monitoring and determination process. If the user starts authentication for logging in to the virtual computer 130 while the security system 1 is continuing the monitoring and determination process, the security system 1 may perform operations from step S103 onwards.
[0127] When the information processing device 100 is powered on after being powered off, or when the information processing device 100 is restarted, the security system 1 restarts the operation from step S101.
[0128] Next, the operation of the device startup process will be described.
[0129] FIG. 8 is a flowchart illustrating an example of the operation of a device startup process of a security system according to the present disclosure.
[0130] The operation of the device startup process of the security system 1 according to the second embodiment of the present disclosure will be described in detail below with reference to FIG.
[0131] When the information processing device 100 is powered on or restarted, the security system 1 starts the device startup process shown in FIG. 7, that is, the operation shown in FIG.
[0132] 8, first, the start-up control unit 110 starts up the information processing device (step S111). That is, the start-up control unit 110 executes processing at the time of start-up of the information processing device 100. Next, the verification information generation unit 121 generates verification information from information on the start-up of the information processing device 100 (step S112).
[0133] Next, the device verification unit 122 verifies the device authenticity of the information processing device 100 using the verification information (step S113). As described above, the device verification unit 122 may verify the device authenticity of the information processing device 100 by transmitting the verification information to the verification device 200. Then, the device verification unit 122 may receive a verification result from the verification device 200. If the device authenticity is verified (YES in step S114), the security system 1 ends the operation shown in FIG.
[0134] If the device authenticity is not verified (NO in step S114), the control instruction unit 123 instructs the communication control device 300 to set the communication partner of the virtual computer 130 to a decoy network (step S115). Then, the security system 1 executes a monitoring start process (step S116). The monitoring start process will be described in detail below. Then, the security system 1 ends the operation shown in FIG. 8.
[0135] Next, the operation of the monitoring start process will be described.
[0136] FIG. 9 is a flowchart illustrating an example of the operation of the monitoring start process of the security system according to the present disclosure.
[0137] The operation of the monitoring start process of the security system 1 according to the second embodiment of the present disclosure will be described in detail below with reference to FIG.
[0138] 9, first, the communication control unit 320 of the communication control device 300 checks whether the communication destination of the virtual computer 130 is set to the decoy network 700 (step S121). If the communication destination is the decoy network (YES in step S122), the security system ends the operation shown in FIG.
[0139] If the communication destination is not a decoy network (NO in step S122), the communication control unit 320 sets the communication destination of the virtual computer 130 to the decoy network 700 (step S123). Then, the communication control unit 320 sets the access monitoring unit 330 to preserve packets of communication by the virtual computer 130 (step S124).
[0140] The access monitor 330 stores packets of communication by the virtual computer 130. However, if the access monitor 330 is not set to preserve packets of communication by the virtual computer 130, the access monitor 330 estimates access behavior from the stored packets and then discards the packets. If the access monitor 330 is set to preserve packets of communication by the virtual computer 130, the access monitor 330 does not discard packets after estimating access behavior from the stored packets.
[0141] Next, the operation of the authentication process will be described.
[0142] FIG. 10 is a flowchart illustrating an example of the operation of the authentication process of the security system according to the present disclosure.
[0143] The operation of the authentication process of the security system 1 according to the second embodiment of the present disclosure will be described in detail below with reference to FIG.
[0144] 10, first, the authentication unit 420 of the authentication device 400 authenticates the user of the virtual computer 130 (step S131). Next, the authentication verification unit 410 verifies the user authenticity using the authentication result (step S132). In step S132, the authentication verification unit 410 verifies the user authenticity of the user of the virtual computer 130. If the user authenticity is verified (YES in step S133), the security system 1 ends the operation shown in FIG.
[0145] If the user authenticity is not verified (NO in step S133), the authentication verification unit 410 instructs the communication control device 300 to set the communication destination of the virtual computer 130 to the decoy network (step S134). Next, the security system 1 executes a monitoring start process (step S135). Then, the security system 1 ends the operation shown in FIG. 10.
[0146] Next, the operation of the monitoring and determination process will be described.
[0147] FIG. 11 is a flowchart illustrating an example of the operation of the monitoring determination process of the security system according to the present disclosure.
[0148] The operation of the monitoring determination process of the security system 1 according to the second embodiment of the present disclosure will be described in detail below with reference to FIG.
[0149] 11, the access monitoring unit 330 monitors the access behavior of the virtual computer 130 (step S141). The behavior verification unit 310 verifies the user authenticity using information on the access behavior (step S142). If the user authenticity is verified (YES in step S143), the security system 1 repeats the operations from step S141 onwards.
[0150] If the user authenticity is not verified (NO in step S143), the security system 1 executes a monitoring start process (step S144), and then ends the operation shown in FIG.
[0151] Next, the operation of the process for storing information about the OS (that is, the process for storing information about the OS of the virtual machine 130) will be described.
[0152] FIG. 12 is a flowchart illustrating an example of the operation of a process for storing OS information in the security system according to the present disclosure.
[0153] The operation of the process of storing OS information in the security system 1 according to the second embodiment of the present disclosure will be described in detail below with reference to FIG.
[0154] 12, first, the information extraction unit 125 extracts information about the OS of the virtual machine 130 (step S201). The information extraction unit 125 transmits the extracted OS information to the receiving unit 510 of the restoration support device 500.
[0155] Next, the receiving unit 510 stores the information on the OS of the virtual computer 130 in the information storage unit 520. That is, the information storage unit 520 stores the information on the OS of the virtual computer 130 (step S202). Then, the security system 1 ends the operation shown in FIG.
[0156] Next, the operation of the process of restoring OS information (that is, the process of restoring OS information of the virtual machine 130) will be described.
[0157] FIG. 13 is a flowchart illustrating an example of the operation of the security system according to the present disclosure in a process of restoring OS information.
[0158] The operation of the process of restoring OS information in the security system 1 according to the second embodiment of the present disclosure will be described in detail below with reference to FIG.
[0159] 13, the restoration unit 126 receives a restoration instruction (step S211). If the restoration instruction is not received (NO in step S212), the security system 1 ends the operation shown in FIG.
[0160] If the restoration instruction is accepted (YES in step S212), the restoration unit 126 reads out information about the OS of the virtual machine (step S213). Specifically, the restoration unit 126 transmits an instruction to transmit the OS information to the transmission unit 530 of the restoration support device 500. Upon receiving the instruction to transmit the OS information, the transmission unit 530 reads out information about the OS of the virtual machine 130 from the information storage unit 520. Then, the transmission unit 530 transmits the read out information about the OS of the virtual machine 130 to the restoration unit 126. The restoration unit 126 receives the information about the OS of the virtual machine 130 from the transmission unit 530.
[0161] Next, the restoration unit 126 restores the OS of the virtual machine 130 using the received information about the OS of the virtual machine 130.
[0162] <Effects> The present embodiment described above has the same effects as the first embodiment, for the same reasons as those for the effects of the first embodiment.
[0163] <First Modification of Second Embodiment> The security system of FIG. 3 may be realized by devices having a different configuration from the example shown in FIG.
[0164] As described above, the security system 1 may be configured such that the functions of the verification device 200, the communication control device 300, the authentication device 400, and the restoration support device 500 are realized by one or more devices each including at least some of these functions. The security system 1 may be realized by the information processing device 100 and one or more of the above-mentioned devices. For example, in FIG. 3, all units other than the information processing device 100 may be implemented in the same device (e.g., referred to as a security device). For example, the access monitoring unit 330 may be included in a device (e.g., referred to as an access monitoring device) different from the device (e.g., a communication control device) that includes the communication control unit 320.
[0165] An example in which the configuration of the device is different from that described in the second embodiment will be specifically described below.
[0166] FIG. 14 is a block diagram illustrating an example of the configuration of a security system according to the present disclosure.
[0167] The configuration of a security system according to a modified example of the second embodiment will be described in detail below with reference to FIG.
[0168] 14, security system 1A includes information processing device 100, verification device 200, communication control device 300A, user verification device 350, authentication device 400A, and restoration support device 500. Information processing device 100, verification device 200, and restoration support device 500 are the same as information processing device 100, verification device 200, and restoration support device 500 of the second embodiment, respectively.
[0169] The communication control device 300A includes a communication control unit 320, an access monitoring unit 330, and a range determination unit 340. The communication control unit 320, the access monitoring unit 330, and the range determination unit 340 are the same as the communication control unit 320, the access monitoring unit 330, and the range determination unit 340 of the second embodiment, respectively.
[0170] The user verification device 350 includes a user verification unit 360. The user verification unit 360 includes a behavior verification unit 310 and an authentication verification unit 410. The behavior verification unit 310 and the authentication verification unit 410 are the same as the behavior verification unit 310 and the authentication verification unit 410 of the second embodiment, except that the behavior verification unit 310 and the authentication verification unit 410 are included in the user verification device 350.
[0171] The authentication device 400A includes an authentication unit 420. The authentication unit 420 is the same as the authentication unit 420 in the second embodiment.
[0172] FIG. 15 is a block diagram schematically illustrating an example of the configuration of a security system according to the present disclosure.
[0173] In the security system 1A illustrated in FIG. 15, an information processing device 100, a verification device 200, a communication control device 300A, a user verification device 350, an authentication device 400A, and a restoration support device 500 are connected to each other via a communication network 800 so that they can communicate with each other.
[0174] <Third embodiment> Next, a third embodiment of the present disclosure will be described in detail with reference to the drawings.
[0175] <Configuration> FIG. 16 is a block diagram illustrating an example of the configuration of a security system according to the present disclosure.
[0176] The configuration of the security system according to the third embodiment of the present disclosure will be described in detail below with reference to FIG.
[0177] In the example shown in FIG. 16, the security system 20 includes a device verification execution unit 210 and a communication control unit 320.
[0178] The device verification execution unit 210 verifies device authenticity, which is the authenticity of the hardware of an information processing device that realizes a virtual machine, by using verification information generated from startup information of the information processing device. The device verification execution unit 210 corresponds to the device verification execution unit 210 of the second embodiment.
[0179] If the device authenticity is not verified, the communication control unit 320 sets the communication partner of the virtual computer to a decoy network that imitates the connection destination of the virtual computer. The communication control unit 320 corresponds to the communication control unit 320 of the second embodiment.
[0180] <Operation> FIG. 17 is a flowchart illustrating an example of the operation of the security system according to the present disclosure.
[0181] The operation of the security system 20 according to the third embodiment of the present disclosure will be described in detail below with reference to FIG.
[0182] In the example shown in Fig. 17, first, the device verification execution unit 210 verifies the device authenticity, which is the authenticity of the hardware of the information processing device that realizes the virtual computer, using verification information generated from startup information of the information processing device (step S21). If the device authenticity is verified (YES in step S22), the security system 20 ends the operation shown in Fig. 17. If the device authenticity is not verified (NO in step S22), the communication control unit 320 sets the communication destination of the virtual computer to a decoy network (step S23).
[0183] <Effects> As with the first embodiment, this embodiment has the effect of being able to lead attacks into an environment where attacks by an attacker can be observed while preventing attacks by an attacker.
[0184] This is because the device verification execution unit 210 verifies the device authenticity of the information processing device that realizes the virtual computer. If the device authenticity is not verified, the communication control unit 320 sets the decoy network as the communication partner of the virtual computer. As a result, if the device authenticity is not verified, access from the virtual computer is limited to the decoy network. This makes it possible to prevent attacks on the legitimate network by attackers. Furthermore, attacks from the virtual computer to the decoy network can be observed in the decoy network. In other words, the security system of this embodiment can lead attacks to an environment where attacks by attackers can be observed while preventing attacks by attackers.
[0185] <Second Modification of Second Embodiment> The OS information of the virtual computer 130 may be created in advance by a management system of the virtualization platform. Then, the OS information of the virtual computer 130 may be distributed (deployed) to the virtual computer. Specifically, for example, the OS information of the virtual computer 130 created in advance by the management system of the virtualization platform may be stored in the information storage unit 520 of the restoration device. In this case, the receiving unit 510 receives the OS information of the virtual computer 130 from the management system of the virtualization platform and stores the received OS information of the virtual computer 130 in the information storage unit 520. Then, upon receiving an instruction to transmit the OS information from the restoration unit 126, the transmitting unit 530 reads the OS information of the virtual computer 130 from the information storage unit 520 and transmits the read OS information of the virtual computer 130 to the restoration unit 126. In this case, the hypervisor unit 120 may not include the information extraction unit 125. Furthermore, in this case, the restoration support device 500 may be part of the management system of the virtualization platform described above.
[0186] <Other embodiments> A security system according to an embodiment of the present disclosure (in other words, a device according to the security system according to an embodiment of the present disclosure) can be realized by a computer including a memory into which a program read from a storage medium is loaded and a processor that executes the program. A security system according to an embodiment of the present disclosure can also be realized by dedicated hardware. A security system according to an embodiment of the present disclosure can also be realized by a combination of the above-mentioned computer and dedicated hardware. Note that devices according to the security system according to an embodiment of the present disclosure include, for example, an information processing device, a verification device 200, a communication control device 300, a communication control device 300A, a user verification device 350, an authentication device 400, an authentication device 400A, a restoration support device 500, and a security device.
[0187] FIG. 18 is a diagram illustrating an example of a hardware configuration of a computer 1000 capable of implementing a security system according to an embodiment of the present disclosure. Using such a computer 1000, an apparatus according to the security system according to an embodiment of the present disclosure can be implemented. Referring to FIG. 18, the computer 1000 includes a processor 1001, a memory 1002, a storage device 1003, and an I / O (Input / Output) interface 1004. The computer 1000 can also access a storage medium 1005. The memory 1002 and the storage device 1003 are, for example, storage devices such as RAM (Random Access Memory) and a hard disk. The storage medium 1005 is, for example, a storage device such as RAM or a hard disk, a read-only memory (ROM), or a portable storage medium. The storage device 1003 may also be the storage medium 1005. The processor 1001 can read and write data and programs from and to the memory 1002 and the storage device 1003. The processor 1001 can access, for example, other devices via the I / O interface 1004. The processor 1001 can access a storage medium 1005. The storage medium 1005 stores a program that causes the computer 1000 to operate as a device related to a security system according to an embodiment of the present disclosure.
[0188] The processor 1001 loads a program stored in the storage medium 1005, which causes the computer 1000 to operate as a device related to the security system according to an embodiment of the present disclosure, into the memory 1002. Then, the processor 1001 executes the program loaded into the memory 1002, causing the computer 1000 to operate as a device related to the security system according to an embodiment of the present disclosure.
[0189] The device verification execution unit 210, the behavior verification unit 310, the communication control unit 320, the access monitoring unit 330, the range determination unit 340, the user verification unit 360, the authentication verification unit 410, the authentication unit 420, the receiving unit 510, and the transmitting unit 530 can be realized, for example, by the processor 1001 that executes a program loaded from the storage medium 1005 to the memory 1002. The start control unit 110, the hypervisor unit 120, the verification information generation unit 121, the device verification unit 122, the control instruction unit 123, the hypervisor execution unit 124, the information extraction unit 125, the restoration unit 126, and the virtual machine 130 can be realized, for example, by the processor 1001 that executes a program loaded from the storage medium 1005 to the memory 1002.
[0190] The information storage unit 520 can be realized by the memory 1002 included in the computer 1000 or a storage device 1003 such as a nonvolatile memory. The virtual machine information storage unit 140 can be realized by the memory 1002 included in the computer 1000 or a storage device 1003 such as a nonvolatile memory.
[0191] The device verification execution unit 210, the behavior verification unit 310, the communication control unit 320, the access monitoring unit 330, the range determination unit 340, the user verification unit 360, the authentication verification unit 410, the authentication unit 420, the receiving unit 510, the information storage unit 520, and the transmitting unit 530 can be partly or entirely realized by dedicated circuits that realize the functions of each unit. The boot control unit 110, the hypervisor unit 120, the verification information generation unit 121, the device verification unit 122, the control instruction unit 123, the hypervisor execution unit 124, the information extraction unit 125, the restoration unit 126, the virtual machine 130, and the virtual machine information storage unit 140 can be partly or entirely realized by dedicated circuits that realize the functions of each unit.
[0192] Furthermore, some or all of the above-described embodiments can be described as, but are not limited to, the following supplementary notes.
[0193] (Appendix 1) a device verification means for verifying device authenticity, which is the authenticity of the hardware of an information processing device that realizes a virtual machine, by using verification information generated from information on the startup of the information processing device; a control instruction means for instructing a communication control device that controls communication from the virtual computer, when the device authenticity is not verified, to set a communication partner of the virtual computer as a decoy network that imitates a connection destination of the virtual computer; A security system comprising:
[0194] (Appendix 2) a user verification means for verifying the authenticity of the user from the user's behavior on the virtual computer; Equipped with If the user authenticity of the user is not verified, the communication control device sets the communication partner of the virtual computer to the decoy network. 1. A security system as described in Appendix 1.
[0195] (Appendix 3) The user verification means is an authentication verification means that verifies the user authenticity of the user using a result of the authentication of the user. 10. The security system of claim 2, comprising:
[0196] (Appendix 4) The authentication verification means determines that the user authenticity is not verified if the user of the virtual computer fails the authentication, and if the user who is not a registered user registered as a user of the virtual computer succeeds in the authentication, and determines that the user authenticity is verified if the user who is a registered user registered as a user of the virtual computer succeeds in the authentication. 1. A security system as described in Appendix 3.
[0197] (Appendix 5) The user verification means is a behavior verification means that verifies the authenticity of the user using information on access behavior, which is behavior of the virtual computer accessing a network resource. 10. The security system of claim 2, comprising:
[0198] (Appendix 6) The behavior verification means determines that the user authenticity of the user is not verified if the access behavior of the virtual computer does not satisfy a predetermined behavioral standard, and determines that the user authenticity of the user is verified if the access behavior of the virtual computer satisfies the predetermined behavioral standard. 1. A security system as described in Appendix 5.
[0199] (Appendix 7) The behavior verification means determines that the user authenticity of the user is not verified if the access behavior of the virtual computer is outside an access behavior range that is a range of access behavior determined from the past access behavior of a registered user who is registered as a user of the virtual computer, and determines that the user authenticity of the user is verified if the access behavior of the virtual computer is not outside the access behavior range. 1. A security system as described in Appendix 5.
[0200] (Appendix 8) range determination means for determining the access behavior range from the history of past access behavior of the virtual computer used by the registered user; 8. The security system of claim 7, further comprising:
[0201] (Appendix 9) access monitoring means for monitoring access behavior, which is behavior of the virtual computer accessing a network resource; 4. The security system according to claim 2 or 3, comprising:
[0202] (Appendix 10) The access monitoring means records a record of access behavior of the virtual computer used by a registered user who is registered as a user of the virtual computer as the access history of the virtual computer used by the registered user. 9. A security system as described in Appendix 9.
[0203] (Appendix 11) The access monitoring means records a record of an access action from the virtual computer to the decoy network as a record of an attack. 9. A security system as described in Appendix 9.
[0204] (Appendix 12) The access monitoring means records packets of communication from the virtual computer to the decoy network as a record of the attack. 12. The security system described in Appendix 11.
[0205] (Appendix 13) information extraction means for extracting OS information, which is information about an OS (Operating System) of the virtual machine; an information storage means for storing the OS information; a restoration means for restoring the OS of the virtual machine by using the OS information read from the information storage means in response to receiving a restoration instruction that is an instruction to restore the OS when it is determined that the device authenticity cannot be verified; 3. The security system according to claim 1 or 2, further comprising:
[0206] (Appendix 14) information extraction means for extracting OS information, which is information about an OS (Operating System) of the virtual machine; an information storage means for storing the OS information; a restoration means for restoring the OS of the virtual machine by using the OS information read from the information storage means in response to receiving a restoration instruction that is an instruction to restore the OS when it is determined that at least one of the device authenticity and the user authenticity cannot be verified; 3. The security system of claim 2, further comprising:
[0207] (Appendix 15) the information processing device, the verification device, and the communication control device; The verification device a device verification execution means for verifying the device authenticity of the information processing device by comparing the received verification information with registered verification information, which is verification information registered in advance in the information processing device, in response to receiving the verification information; Equipped with The information processing device includes: Hypervisor means for realizing the virtual machine Equipped with The hypervisor means verification information generating means for generating the verification information of the information processing device from startup information of the information processing device; a device verification means for transmitting the verification information to the verification device; a control instruction means for transmitting a decoy setting instruction to the communication control device that controls communication from the virtual computer when the device authenticity is verified, the decoy setting instruction being an instruction to control setting a communication partner of the virtual computer to the decoy network; a hypervisor execution means for executing a process to realize the virtual machine after the decoy setting instruction is transmitted if the authenticity of the device is verified; Including, The communication control device a communication control means for setting the decoy network as a communication partner of the virtual computer in response to receiving the decoy setting instruction; Equipped with 3. The security system of claim 1 or 2.
[0208] (Appendix 16) The information processing device, the verification device, the communication control device, and the authentication device are included, The verification device a device verification execution means for verifying the device authenticity of the information processing device by comparing the received verification information with registered verification information, which is verification information registered in advance in the information processing device, in response to receiving the verification information; Equipped with The information processing device includes: Hypervisor means for realizing the virtual machine Equipped with The hypervisor means verification information generating means for generating the verification information of the information processing device from startup information of the information processing device; the device verification means; a control instruction means for transmitting a decoy setting instruction to the communication control device that controls communication from the virtual computer when the device authenticity is verified, the decoy setting instruction being an instruction to control setting a communication partner of the virtual computer to the decoy network; a hypervisor execution means for executing a process to realize the virtual machine after the decoy setting instruction is transmitted if the authenticity of the device is verified; Equipped with the device verification means verifies the device authenticity of the information processing device by transmitting the verification information to the verification device; The authentication device an authentication verification means for verifying the user authenticity of the user using a result of the user authentication, and transmitting the decoy setting instruction to the communication control device when it is determined that the user authenticity is not verified; Equipped with The communication control device a behavior verification means for verifying the authenticity of the user using information on the user's access behavior, which is the user's behavior in accessing a network resource; a communication control means for setting the decoy network as a communication partner of the virtual computer when it is determined that the user authenticity is not verified; Equipped with the communication control means, in response to receiving the decoy setting instruction, sets the decoy network as a communication partner of the virtual computer; 4. A security system according to claim 2 or 3.
[0209] (Appendix 17) a device verification means for verifying device authenticity, which is the authenticity of the hardware of an information processing device that realizes a virtual machine, by using verification information generated from information on the startup of the information processing device; a control instruction means for instructing a communication control device that controls communication from the virtual computer to set a communication partner of the virtual computer to a decoy network when the device authenticity is not verified; A control device comprising:
[0210] (Appendix 18) the device verification means transmits the verification information of the information processing device to a verification device, and receives information indicating whether the device authenticity has been verified from the verification device; In response to receiving the verification information of the information processing device, the verification device compares the received verification information with registered verification information, which is verification information registered in advance in the information processing device, thereby verifying the device authenticity of the information processing device. 18. The control device of claim 17.
[0211] (Appendix 19) verifying device authenticity, which is the authenticity of the hardware of an information processing device that realizes a virtual machine, using verification information generated from information on the startup of the information processing device; If the device authenticity is not verified, instruct a communication control device that controls communication from the virtual computer to set a communication partner of the virtual computer to a decoy network that imitates a connection destination of the virtual computer. Security methods.
[0212] (Appendix 20) verifying user authenticity, which is the authenticity of the user, from the behavior of the user of the virtual computer; If the user authenticity of the user is not verified, the communication control device sets the communication partner of the virtual computer to the decoy network. 19. The security method described in Appendix 19.
[0213] (Appendix 21) Using the result of the user's authentication, verify the user authenticity of the user. 20. The security method described in Appendix 20.
[0214] (Appendix 22) If the user of the virtual computer fails the authentication, and if the user who is not a registered user registered as a user of the virtual computer succeeds in the authentication, it is determined that the user authenticity is not verified, and if the user who is a registered user registered as a user of the virtual computer succeeds in the authentication, it is determined that the user authenticity is verified. 21. The security method described in Appendix 21.
[0215] (Appendix 23) The authenticity of the user is verified using information on access behavior, which is behavior of the virtual machine accessing a network resource. 20. The security method described in Appendix 20.
[0216] (Appendix 24) If the access behavior of the virtual computer does not satisfy a predetermined behavioral criterion, it is determined that the user authenticity of the user is not verified, and if the access behavior of the virtual computer satisfies the predetermined behavioral criterion, it is determined that the user authenticity of the user is verified. 2. The security method described in Appendix 23.
[0217] (Appendix 25) If the access behavior of the virtual computer falls outside an access behavior range that is a range of access behavior determined from the past access behavior of a registered user who is registered as a user of the virtual computer, it is determined that the user authenticity of the user is not verified, and if the access behavior of the virtual computer does not fall outside the access behavior range, it is determined that the user authenticity of the user is verified. 2. The security method described in Appendix 23.
[0218] (Appendix 26) The access behavior range is determined from the history of the past access behavior of the virtual computer used by the registered user. 2. The security method described in Appendix 25.
[0219] (Appendix 27) Monitoring access behavior, which is behavior of the virtual computer accessing a network resource. 22. The security method of claim 20 or 21.
[0220] (Appendix 28) A record of the access behavior of the virtual computer used by a registered user who is registered as a user of the virtual computer is recorded as the access history of the virtual computer used by the registered user. 2. The security method described in Appendix 27.
[0221] (Appendix 29) A record of the access behavior from the virtual computer to the decoy network is recorded as a record of the attack. 2. The security method described in Appendix 27.
[0222] (Appendix 30) A packet of communication from the virtual computer to the decoy network is recorded as a record of the attack. 29. The security method described in Appendix 29.
[0223] (Appendix 31) extracting OS information, which is information about the OS (Operating System) of the virtual machine; storing the OS information in an information storage unit; if it is determined that the device authenticity cannot be verified, in response to receiving a restore instruction that is an instruction to restore the OS, restore the OS of the virtual machine using the OS information read from the information storage unit; 21. The security method of claim 19 or 20.
[0224] (Appendix 32) extracting OS information, which is information about the OS (Operating System) of the virtual machine; storing the OS information in an information storage unit; when it is determined that at least one of the device authenticity and the user authenticity cannot be verified, in response to receiving a restoration instruction that is an instruction to restore the OS, restoring the OS of the virtual machine using the OS information read from the information storage unit; 20. The security method described in Appendix 20.
[0225] (Appendix 33) The verification device In response to receiving the verification information, verifying the device authenticity of the information processing device by comparing the received verification information with registered verification information, which is verification information registered in advance in the information processing device; The information processing device, generating the verification information of the information processing device from startup information of the information processing device; transmitting the verification information to the verification device; When the authenticity of the device is verified, a decoy setting instruction is sent to the communication control device that controls communication from the virtual computer, the decoy setting instruction being an instruction to control setting a communication partner of the virtual computer to the decoy network; If the authenticity of the device is verified, after the decoy setting instruction is transmitted, a process for realizing the virtual computer is executed; The communication control device In response to receiving the decoy setting instruction, set the communication partner of the virtual computer to the decoy network. 21. The security method of claim 19 or 20.
[0226] (Appendix 34) The verification device In response to receiving the verification information, verifying the device authenticity of the information processing device by comparing the received verification information with registered verification information, which is verification information registered in advance in the information processing device; The information processing device, generating the verification information of the information processing device from startup information of the information processing device; When the authenticity of the device is verified, a decoy setting instruction is sent to the communication control device that controls communication from the virtual computer, the decoy setting instruction being an instruction to control setting a communication partner of the virtual computer to the decoy network; If the authenticity of the device is verified, after the decoy setting instruction is transmitted, a process for realizing the virtual computer is executed; verifying the device authenticity of the information processing device by transmitting the verification information to the verification device; The authentication device verifying the user authenticity of the user using a result of the authentication of the user, and if it is determined that the user authenticity is not verified, transmitting the decoy setting instruction to the communication control device; The communication control device Verifying the authenticity of the user using access behavior information, which is the user's behavior of accessing resources of a network; If it is determined that the authenticity of the user is not verified, the decoy network is set as the communication partner of the virtual computer; In response to receiving the decoy setting instruction, set the communication partner of the virtual computer to the decoy network. 22. The security method of claim 20 or 21.
[0227] (Appendix 35) verifying device authenticity, which is the authenticity of the hardware of an information processing device that realizes a virtual machine, using verification information generated from information on the startup of the information processing device; If the authenticity of the device is not verified, instruct a communication control device that controls communication from the virtual computer to control setting a communication partner of the virtual computer to a decoy network. Control method.
[0228] (Appendix 36) transmitting the verification information of the information processing device to a verification device, and receiving information indicating whether the device authenticity has been verified from the verification device; In response to receiving the verification information of the information processing device, the verification device compares the received verification information with registered verification information, which is verification information registered in advance in the information processing device, thereby verifying the device authenticity of the information processing device. 36. The control method of claim 35.
[0229] (Appendix 37) a device verification process for verifying device authenticity, which is the authenticity of the hardware of an information processing device that realizes a virtual machine, by using verification information generated from information on the startup of the information processing device; a control instruction process for instructing a communication control device that controls communication from the virtual computer to set a communication partner of the virtual computer to a decoy network that imitates a connection destination of the virtual computer when the device authenticity is not verified; A program that causes a computer to execute the following.
[0230] (Appendix 38) The device verification process includes transmitting the verification information of the information processing device to a verification device, and receiving information indicating whether the device authenticity has been verified from the verification device; In response to receiving the verification information of the information processing device, the verification device compares the received verification information with registered verification information, which is verification information registered in advance in the information processing device, thereby verifying the device authenticity of the information processing device. 37. The program described in Appendix 37.
[0231] (Appendix 39) a device verification execution means for verifying device authenticity, which is the authenticity of the hardware of an information processing device that realizes a virtual machine, by using verification information generated from information on the startup of the information processing device; a communication control means for, when the authenticity of the device is not verified, changing a communication partner of the virtual computer to a decoy network that imitates a connection destination of the virtual computer; A security system comprising:
[0232] (Appendix 40) verifying device authenticity, which is the authenticity of the hardware of an information processing device that realizes a virtual machine, using verification information generated from information on the startup of the information processing device; If the authenticity of the device is not verified, a communication partner of the virtual computer is set to a decoy network that imitates a connection destination of the virtual computer. Security methods.
[0233] (Appendix 41) a device verification execution process for verifying device authenticity, which is the authenticity of the hardware of an information processing device that realizes a virtual machine, by using verification information generated from information on the startup of the information processing device; a communication control process for changing a communication partner of the virtual computer to a decoy network that imitates a connection destination of the virtual computer when the device authenticity is not verified; A program that causes a computer to execute the following.
[0234] Although the present disclosure has been described above with reference to the embodiments, the present disclosure is not limited to the above embodiments. Various modifications that can be understood by those skilled in the art can be made to the configuration and details of the present disclosure within the scope of the present disclosure. [Explanation of symbols]
[0235] 1. Security System 1A Security System 10. Security Systems 20. Security Systems 100 Information processing device 110 Start control unit 120 Hypervisor 121 Verification information generation unit 122 Equipment Verification Department 123 Control Instruction Section 124 Hypervisor Execution Unit 125 Information extraction section 126 Restoration Department 130 Virtual Machine 140 Virtual machine information storage unit 200 Verification Device 210 Equipment Verification Execution Unit 300 Communication control device 300A Communication Control Device 310 Behavioral Verification Department 320 Communication Control Unit 330 Access Monitoring Department 340 Range determination unit 350 User Verification Device 360 User Verification Department 400 Authentication Device 400A Authentication Device 410 Authentication Verification Department 420 Authentication Department 500 Restoration Support Device 510 Receiving Department 520 Information storage section 530 Transmitter 600 Regular Network 700 Decoy Network 800 Communications Network 1000 computers 1001 processor 1002 memory 1003 Storage device 1004 I / O interface 1005 Storage medium
Claims
1. a device verification means for verifying device authenticity, which is the authenticity of the hardware of an information processing device that realizes a virtual machine, by using verification information generated from information on the startup of the information processing device; a control instruction means for instructing a communication control device that controls communication from the virtual computer, when the device authenticity is not verified, to set a communication partner of the virtual computer as a decoy network that imitates a connection destination of the virtual computer; A security system comprising:
2. a user verification means for verifying the authenticity of the user from the user's behavior on the virtual computer; Equipped with If the user authenticity of the user is not verified, the communication control device sets the communication partner of the virtual computer to the decoy network.
10. The security system of claim 1.
3. The user verification means is an authentication verification means that verifies the user authenticity of the user using a result of the authentication of the user.
3. The security system of claim 2, comprising:
4. The authentication verification means determines that the user authenticity is not verified if the user of the virtual computer fails the authentication, and if the user who is not a registered user registered as a user of the virtual computer succeeds in the authentication, and determines that the user authenticity is verified if the user who is a registered user registered as a user of the virtual computer succeeds in the authentication.
4. The security system of claim 3.
5. The user verification means is a behavior verification means that verifies the authenticity of the user using information on access behavior, which is behavior of the virtual computer accessing a network resource.
3. The security system of claim 2, comprising:
6. The behavior verification means determines that the user authenticity of the user is not verified if the access behavior of the virtual computer does not satisfy a predetermined behavioral standard, and determines that the user authenticity of the user is verified if the access behavior of the virtual computer satisfies the predetermined behavioral standard.
6. The security system of claim 5.
7. The behavior verification means determines that the user authenticity of the user is not verified if the access behavior of the virtual computer is outside an access behavior range that is a range of access behavior determined from the past access behavior of a registered user who is registered as a user of the virtual computer, and determines that the user authenticity of the user is verified if the access behavior of the virtual computer is not outside the access behavior range.
6. The security system of claim 5.
8. range determination means for determining the access behavior range from the history of past access behavior of the virtual computer used by the registered user; The security system of claim 7 further comprising:
9. the information processing device, the verification device, and the communication control device; The verification device a device verification execution means for verifying the device authenticity of the information processing device by comparing the received verification information with registered verification information, which is verification information registered in advance in the information processing device, in response to receiving the verification information; Equipped with The information processing device includes: Hypervisor means for realizing the virtual machine Equipped with The hypervisor means verification information generating means for generating the verification information of the information processing device from startup information of the information processing device; a device verification means for transmitting the verification information to the verification device; a control instruction means for transmitting a decoy setting instruction to the communication control device that controls communication from the virtual computer when the device authenticity is verified, the decoy setting instruction being an instruction to control setting a communication partner of the virtual computer to the decoy network; a hypervisor execution means for executing a process to realize the virtual machine after the decoy setting instruction is transmitted if the authenticity of the device is verified; Including, The communication control device a communication control means for setting the decoy network as a communication partner of the virtual computer in response to receiving the decoy setting instruction; Equipped with 3. The security system according to claim 1 or 2.
10. The information processing device, the verification device, the communication control device, and the authentication device are included, The verification device a device verification execution means for verifying the device authenticity of the information processing device by comparing the received verification information with registered verification information, which is verification information registered in advance in the information processing device, in response to receiving the verification information; Equipped with The information processing device includes: Hypervisor means for realizing the virtual machine Equipped with The hypervisor means verification information generating means for generating the verification information of the information processing device from startup information of the information processing device; the device verification means; a control instruction means for transmitting a decoy setting instruction to the communication control device that controls communication from the virtual computer when the device authenticity is verified, the decoy setting instruction being an instruction to control setting a communication partner of the virtual computer to the decoy network; a hypervisor execution means for executing a process to realize the virtual machine after the decoy setting instruction is transmitted if the authenticity of the device is verified; Equipped with the device verification means verifies the device authenticity of the information processing device by transmitting the verification information to the verification device; The authentication device an authentication verification means for verifying the user authenticity of the user using a result of the user authentication, and transmitting the decoy setting instruction to the communication control device when it is determined that the user authenticity is not verified; Equipped with The communication control device a behavior verification means for verifying the authenticity of the user using information on the user's access behavior, which is the user's behavior in accessing a network resource; a communication control means for setting the decoy network as a communication partner of the virtual computer when it is determined that the user authenticity is not verified; Equipped with the communication control means, in response to receiving the decoy setting instruction, sets the decoy network as a communication partner of the virtual computer; 4. The security system according to claim 2 or 3.
11. verifying device authenticity, which is the authenticity of the hardware of an information processing device that realizes a virtual machine, using verification information generated from information on the startup of the information processing device; If the device authenticity is not verified, instruct a communication control device that controls communication from the virtual computer to set a communication partner of the virtual computer to a decoy network that imitates a connection destination of the virtual computer. Security methods.
12. a device verification process for verifying device authenticity, which is the authenticity of the hardware of an information processing device that realizes a virtual machine, by using verification information generated from information on the startup of the information processing device; a control instruction process for instructing a communication control device that controls communication from the virtual computer to set a communication partner of the virtual computer as a decoy network that imitates a connection destination of the virtual computer when the device authenticity is not verified; A program that causes a computer to execute the following.
13. a device verification execution means for verifying device authenticity, which is the authenticity of the hardware of an information processing device that realizes a virtual machine, by using verification information generated from information on the startup of the information processing device; a communication control means for, when the authenticity of the device is not verified, changing a communication partner of the virtual computer to a decoy network that imitates a connection destination of the virtual computer; A security system comprising:
Citation Information
Patent Citations
Protection and notification against BIOS flash attacks
JP2014518428A