Suspicious access countermeasure system, suspicious access countermeasure method, electronic device, and suspicious access countermeasure program
The suspicious access countermeasure system dynamically adjusts log detail and protects networked devices by transitioning to an alert state upon detection of suspicious access, addressing the trade-off between log detail and storage capacity, and enabling rapid response to security threats.
Patent Information
- Application Number
- JP2024080405
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-05-16
- Publication Date
- 2025-11-28
AI Technical Summary
Existing systems fail to provide effective preventative protection for electronic devices on a network when a security attack occurs, and there is a trade-off between log detail and storage capacity that is not dynamically balanced.
A suspicious access countermeasure system that includes electronic devices capable of transitioning to an alert state upon detection of suspicious access, increasing log detail and sending instructions to other devices on the network to do the same, with automatic restoration of settings upon administrator action.
The system automatically enhances log detail and protects networked devices from security threats, balancing log detail and storage capacity, and allows for rapid response to security attacks.
Smart Images

Figure 2025174251000001_ABST
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to a suspicious access countermeasure system, a suspicious access countermeasure method, an electronic device, and a suspicious access countermeasure program when a suspicious access to an electronic device is detected. [Background technology]
[0002] Multiple electronic devices (e.g., image forming devices) are connected to a network such as an in-house network. In the event of a security attack on an electronic device connected to a network (e.g., an in-house network), it is desirable to take preventative measures to protect all electronic devices on the same network that are at risk of the attack. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Japanese Patent Publication No. 2020-149245 Summary of the Invention [Problem to be solved by the invention]
[0004] According to Patent Document 1, an electronic device (image forming device) and a network device are connected via a network, and the network device sends its own log to the electronic device, which then stores the received network device log within the electronic device. The electronic device and the network device each have a log storage unit and a log processing control unit. For example, if a user sets the security level of the electronic device to high or low, the electronic device instructs the network device to change the log processing mode, and the network device receives the instruction and adjusts the amount of logs and the frequency with which logs are sent to the electronic device. This adjusts the trade-off between log detail and the load on the electronic device. According to Patent Document 1, the log processing mode is fixed according to settings such as security settings.
[0005] In view of the above circumstances, an object of the present disclosure is to, when a security attack occurs on an electronic device connected to a certain network (such as an internal company network), provide preventative protection for electronic devices on the same network that are also at risk of the attack. In addition, since there is a trade-off between the detail of logs and the degree of pressure on the storage capacity, it is desirable to strike a balance between the two. [Means for solving the problem]
[0006] A suspicious access countermeasure system according to an embodiment of the present disclosure includes: a first electronic device; a second electronic device connected to the first electronic device via a network; Equipped with The first electronic device includes: a first alert state setting unit that transitions from a normal state to an alert state when a suspicious access to the first electronic device is detected; a first instruction transmitting / receiving unit that transmits an alert state transition instruction to a second electronic device connected to the first electronic device via a network, the second electronic device transitioning to an alert state; It has.
[0007] The second electronic device includes: a second instruction transceiver that receives the alert state transition instruction from the first electronic device; a second alert state setting unit that transitions from the normal state to the alert state when the alert state transition instruction is received; It has.
[0008] A method for dealing with suspicious access according to an embodiment of the present disclosure includes: The first electronic device is When a suspicious access to the first electronic device is detected, the device transitions from a normal state to an alert state, An alert state transition instruction is transmitted to a second electronic device connected to the first electronic device via a network, the second electronic device instructing the second electronic device to transition to an alert state.
[0009] An electronic device according to an embodiment of the present disclosure includes: an alert state setting unit that functions as the first alert state setting unit and the second alert state setting unit; an instruction transmitting / receiving unit that functions as the first instruction transmitting / receiving unit and the second instruction transmitting / receiving unit; Equipped with It functions as the first electronic device and the second electronic device.
[0010] A suspicious access countermeasure program according to an embodiment of the present disclosure includes: Electronic equipment computers, an alert state setting unit that functions as the first alert state setting unit and the second alert state setting unit; an instruction transmitting / receiving unit that functions as the first instruction transmitting / receiving unit and the second instruction transmitting / receiving unit; Operate as. [Effects of the Invention]
[0011] According to the present disclosure, when a security attack occurs on an electronic device connected to a network (such as an internal company network), it is possible to preventatively protect electronic devices on the same network that are at risk of the attack. In addition, since there is a trade-off between the detail of logs and the degree of pressure on the storage capacity, it is possible to strike a balance between these two.
[0012] The effects described here are not necessarily limited to those described herein, and may be any of the effects described in this disclosure. [Brief explanation of the drawings]
[0013] [Figure 1] 1 illustrates a suspicious access countermeasure system according to an embodiment of the present disclosure. [Figure 2] 1 shows a hardware configuration of an image forming apparatus when the electronic device is an image forming apparatus. [Figure 3] 1 shows the functional configuration of an electronic device. [Figure 4] The functional configuration of the suspicious access prevention system is shown below. [Figure 5] 10 is a flowchart showing the operation flow of the suspicious access countermeasure system. [Figure 6] 10 is a schematic diagram showing the operational flow of the suspicious access prevention system when alerting begins. [Figure 7] 10 shows a schematic diagram of the operation flow when the suspicious access prevention system is deactivated. DETAILED DESCRIPTION OF THE INVENTION
[0014] Hereinafter, embodiments of the present disclosure will be described with reference to the drawings.
[0015] 1. Suspicious Access Prevention System
[0016] FIG. 1 shows a suspicious access countermeasure system according to one embodiment of the present disclosure.
[0017] The suspicious access countermeasure system 1 includes a plurality of electronic devices 10 connected to a specific network N such as an in-house network. The electronic devices 10 may be, for example, image forming devices (MFP, Multifunction Peripheral). Hereinafter, the electronic devices 10 may be referred to as image forming devices 10.
[0018] 2. Image forming equipment
[0019] FIG. 2 shows the hardware configuration of an image forming apparatus when the electronic device is an image forming apparatus.
[0020] The image forming apparatus 10 includes a control circuit 100 that constitutes a computer. The control circuit 100 is composed of a processor, such as a CPU 11a (Central Processing Unit), a RAM 11b (Random Access Memory), a ROM 11c (Read Only Memory), and dedicated hardware circuits, and is responsible for overall operational control of the image forming apparatus 10. The CPU 11a loads an information processing program stored in the ROM 11c into the RAM 11b and executes it to perform the operations described in the operational flow below and control the display and operational input of the touch panel 17. The ROM 11c permanently stores the programs and data executed by the CPU 11a. The ROM 11c is an example of a non-transitory computer-readable recording medium.
[0021] The control circuit 100 is connected to an image reading unit 12 (image scanner), an image processing unit 14 (including a GPU (Graphics Processing Unit)), an image memory 15, an image forming unit 16 (printer), a touch panel (front panel) 17 which is an operation unit equipped with a display unit 17a, a large-capacity non-volatile storage device 18 such as an HDD (Hard Disk Drive) or an SSD (Solid State Drive), a facsimile communication unit 19, and a network communication interface 13 (communication unit). The control circuit 100 controls the operation of each of the above-mentioned connected units and transmits and receives signals or data to and from each unit. The operation unit of the touch panel 17 is one form of input device, and a voice input device including a microphone may be provided as the input device.
[0022] 3. Functional configuration of electronic devices
[0023] FIG. 3 shows the functional configuration of the electronic device.
[0024] In the control circuit 100 constituting the computer of the electronic device 10, the CPU 11a operates as an alert state setting unit 101, an instruction transmission / reception unit 102, and a countermeasure execution unit 103 by loading a log management program recorded in the ROM 11c into the RAM 11b and executing it.
[0025] 4. Functional configuration of the suspicious access prevention system
[0026] Figure 4 shows the functional configuration of the suspicious access prevention system.
[0027] Hereinafter, the electronic device 10 that has detected suspicious access to itself will be referred to as the first electronic device 110, and all electronic devices 10 connected to the first electronic device 110 via the network N (which have not detected suspicious access to themselves) will be referred to as the second electronic devices 120. Each of the multiple electronic devices 10 can function as both the first electronic device 110 and the second electronic device 120.
[0028] The alert state setting unit 101, instruction transmission / reception unit 102, and countermeasure execution unit 103 of the first electronic device 110 function as a first alert state setting unit 111, a first instruction transmission / reception unit 112, and a first countermeasure execution unit 113.
[0029] The alert state setting unit 101, the instruction transmission / reception unit 102, and the countermeasure execution unit 103 of the second electronic device 120 function as a second alert state setting unit 121, a second instruction transmission / reception unit 122, and a second countermeasure execution unit 123.
[0030] 5. Operation flow of the suspicious access prevention system
[0031] Fig. 5 is a flowchart showing the operation flow of the suspicious access countermeasure system. Fig. 6 is a schematic diagram showing the operation flow of the suspicious access countermeasure system when alerting begins.
[0032] The first electronic device 110 detects suspicious access to its own device (step S1). Suspicious access includes, for example, panel operation or network access at unexpected times such as late at night, or network access from a country other than the usual one. Information about usual access and expected access may be stored in settings or may be analyzed from logs.
[0033] When suspicious access to the first electronic device 110 is detected, the first alert state setting unit 111 of the first electronic device 110 transitions from the normal state to the alert state (step S2). Upon transitioning to the alert state, the first alert state setting unit 111 changes, for example, the log output level to a high level (recording a more detailed log for later investigation and analysis) (step S3). In short, the normal state is a state in which the log output level is low, and the alert state is a state in which the log output level is high. For example, logs that require detailed information for analyzing suspicious access, such as logs of network communication, data input / output, and panel operation, are recorded in detail. Alternatively, the entire log may be made detailed, although this may consume storage space.
[0034] The first instruction transmitting / receiving unit 112 of the first electronic device 110 transmits an instruction to transition to an alert state to all second electronic devices 120 connected to the first electronic device 110 via the network N (step S4). The instruction to transition to an alert state is an instruction to transition from a normal state to an alert state.
[0035] The second instruction transmitting / receiving unit 122 of the second electronic device 120 receives the alert state transition instruction from the first electronic device 110 (step S5). When the alert state transition instruction is received, the second alert state setting unit 121 of the second electronic device 120 transitions from the normal state to the alert state (step S6) and changes the log output level to high (step S7).
[0036] In addition to the change in the log output content (step S3), other content may be added as specific content of the transition from the normal state to the alert state (step S2). For example, the triggered suspicious access may be denied, remote access functions may be disabled, and functional and access restrictions such as prohibiting access to and printing of stored data such as image data and address books may be imposed. In this case, the first electronic device 110 transmits suspicious access information (e.g., the IP address of the communication source) in addition to an instruction to transition to the alert state to the second electronic device 120 (step S4). The second electronic device 120 receives the suspicious access information in addition to the instruction to transition to the alert state (step S5). The second electronic device 120 transitions from the normal state to the alert state (step S6) and imposes functional and access restrictions (step S7).
[0037] FIG. 7 shows a schematic diagram of the operation flow when the suspicious access prevention system is deactivated.
[0038] Next, the operation when the alert state of the first electronic device 110 is released will be described. First, the first countermeasure execution unit 113 of the first electronic device 110 executes countermeasures against suspicious access through an operation by the administrator (step S8, YES). Specifically, the administrator applies security countermeasures to the first electronic device 110 in the alert state using a panel of the first electronic device 110 or an application or web application for managing the first electronic device 110. The security countermeasures may, for example, be to reject the IP address of the suspicious access that triggered the alert state. Alternatively, the first electronic device 110 may automatically reject the IP address of the suspicious access when the first electronic device 110 transitions to the alert state. In this case, the administrator may then confirm the action taken by the first electronic device 110 or cancel the rejection and set an exception as an exceptional, non-problematic access, and input to the first electronic device 110 that the confirmation for releasing the alert state has been completed.
[0039] When the first countermeasure execution unit 113 executes the countermeasure, the first alert state setting unit 111 of the first electronic device 110 transitions from the alert state to the normal state (step S9). That is, the first alert state setting unit 111 returns the log output content from the alert state (high level) to the normal state (low level) before the change (step S10). The first instruction transmitting / receiving unit 112 of the first electronic device 110 transmits an alert state cancellation instruction to the second electronic device 120, instructing the second electronic device 120 to cancel the alert state and including information on the countermeasure (contents of the change in settings of the first electronic device 110) (step S11).
[0040] The second instruction transmitting / receiving unit 122 of the second electronic device 120 receives an alert state cancellation instruction from the first electronic device 110 (step S12, YES). Then, the second countermeasure execution unit 123 of the second electronic device 120 executes countermeasures in accordance with the alert state cancellation instruction. That is, the second countermeasure execution unit 123 applies the same setting changes to the first electronic device 110 using the setting changes included in the alert state cancellation instruction (step S13). When the countermeasures are executed by the second countermeasure execution unit 123, the second alert state setting unit 121 of the second electronic device 120 transitions from the alert state to the normal state (step S14). That is, the second alert state setting unit 121 returns the log output content from the alert state (high level) to the normal state (low level) before the change (step S15).
[0041] In addition, a display may be displayed in step S8 so that the administrator can select whether to also release the security alert state of the second electronic device 120 with the same settings as the first electronic device 110, and if the administrator selects individual response, the operation may be such that instructions to other second electronic devices 120 from step S11 onwards or the process of propagating setting changes as a countermeasure is not carried out.
[0042] 6. Conclusion
[0043] Multiple electronic devices (e.g., image forming devices) are connected to a network such as an in-house network. In the event of a security attack on an electronic device connected to a network (e.g., an in-house network), it is desirable to take preventative measures to protect all electronic devices on the same network that are at risk of the attack.
[0044] According to Patent Document 1, an electronic device (image forming device) and a network device are connected via a network, and the network device sends its own log to the electronic device, which then stores the received network device log within the electronic device. The electronic device and the network device each have a log storage unit and a log processing control unit. For example, if a user sets the security level of the electronic device to high or low, the electronic device instructs the network device to change the log processing mode, and the network device receives the instruction and adjusts the amount of logs and the frequency with which logs are sent to the electronic device. This adjusts the trade-off between log detail and the load on the electronic device. According to Patent Document 1, the log processing mode is fixed according to settings such as security settings.
[0045] In contrast, according to this embodiment, when the first electronic device 110 detects suspicious access to its own device, it transitions to a security alert state for security purposes and changes the contents of the log it stores to be more detailed. Furthermore, it also sends an instruction to other second electronic devices 120 on the same network to set their security levels higher, causing the other second electronic devices 120 to transition to the same state. The first electronic device 110 that has transitioned to the security alert state is released when an administrator checks the situation and takes measures, such as rejecting the IP address from which the suspicious access occurred. An instruction to release the security alert state and information about the measures taken, i.e., the setting change, are also sent to the other second electronic devices 120 on the same network, and the other second electronic devices 120 similarly change their settings before releasing the security alert state and returning the log contents to the state before the alert state.
[0046] That is, according to this embodiment, if there is suspicious access, the stored contents of the log are automatically changed, and if the administrator takes measures against the suspicious access, the changed log output level is automatically restored to its original state. That is, the difference from Patent Document 1 is that the log output level is temporarily and automatically changed using suspicious access as a trigger. This makes it possible to respond to temporary security threats automatically, without relying on pre-settings.
[0047] According to this embodiment, since there is a trade-off between the detail of logs and the degree of storage area pressure, it is possible to strike a balance. In the event of a security attack on a network, it is possible to preventatively protect multiple electronic devices on the same network that are at risk of the attack. For example, if suspicious access is received in the middle of the night, the system automatically switches to a security alert state, and the next morning an administrator can check the logs of the electronic devices in the alert state, take action, and then cancel the alert.
[0048] Although the embodiments and modified examples of the present technology have been described above, the present technology is not limited to the above-described embodiments, and it goes without saying that various modifications can be made within the scope of the gist of the present technology. [Explanation of symbols]
[0049] 1. Suspicious Access Prevention System 10 Electronic equipment 100 control circuit 101 Alert status setting unit 102 Instruction transmitting / receiving unit 103 Countermeasures Implementation Department 110 First Electronic Device 111 First alert state setting unit 112 First instruction transmitting / receiving unit 113 First Countermeasures Implementation Department 120 Secondary Electronic Device 121 Second alert state setting unit 122 Second instruction transmitting / receiving unit 123 Second Countermeasures Implementation Department
Claims
1. a first electronic device; a second electronic device connected to the first electronic device via a network; Equipped with The first electronic device includes: a first alert state setting unit that transitions from a normal state to an alert state when a suspicious access to the first electronic device is detected; a first instruction transmitting / receiving unit configured to transmit an alert state transition instruction to a second electronic device connected to the first electronic device via a network, the second electronic device transitioning to an alert state; have Suspicious access prevention system.
2. The suspicious access countermeasure system according to claim 1, The second electronic device includes: a second instruction transmitting / receiving unit that receives the alert state transition instruction from the first electronic device; a second alert state setting unit that transitions from the normal state to the alert state when the alert state transition instruction is received; have Suspicious access prevention system.
3. The suspicious access countermeasure system according to claim 2, the first electronic device further includes a first countermeasure execution unit that executes countermeasures against the suspicious access; the first alert state setting unit transitions from the alert state to the normal state when the first countermeasure execution unit executes the countermeasure; The first instruction transmitting / receiving unit transmits an instruction to cancel an alert state to the second electronic device, the instruction including information on the countermeasure. Suspicious access prevention system.
4. The suspicious access countermeasure system according to claim 3, the second instruction transmitting / receiving unit receives the alert state cancellation instruction from the first electronic device; the second electronic device further includes a second countermeasure execution unit that executes the countermeasure in accordance with the alert state cancellation instruction; The second alert state setting unit transitions from the alert state to the normal state when the second countermeasure execution unit executes the countermeasure. Suspicious access prevention system.
5. The suspicious access countermeasure system according to any one of claims 1 to 4, The normal state is a state in which the log output level is low, and the alert state is a state in which the log output level is high. Suspicious access prevention system.
6. a first electronic device, When a suspicious access to the first electronic device is detected, the device transitions from a normal state to an alert state, An alert state transition instruction is sent to a second electronic device connected to the first electronic device via a network, the second electronic device being instructed to transition to an alert state. How to prevent suspicious access.
7. an alert state setting unit that functions as the first alert state setting unit according to claim 1 and the second alert state setting unit according to claim 2; an instruction transmitting / receiving unit that functions as the first instruction transmitting / receiving unit according to claim 1 and the second instruction transmitting / receiving unit according to claim 2; Equipped with The electronic device functions as the first electronic device according to claim 1 and the second electronic device according to claim 2. electronic equipment.
8. Electronic equipment computers, an alert state setting unit that functions as the first alert state setting unit according to claim 1 and the second alert state setting unit according to claim 2; An instruction transmitting / receiving unit that functions as the first instruction transmitting / receiving unit according to claim 1 and the second instruction transmitting / receiving unit according to claim 2. A suspicious access prevention program that operates as a
Citation Information
Patent Citations
Network device, network communication system, and network control program
JP2020149245A