Relay device
The relay device addresses the delay in notifying network administrators by generating infection notifications and restricting data communication, ensuring swift action against malware infections.
Patent Information
- Application Number
- JP2024113415
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-07-16
- Publication Date
- 2026-01-28
AI Technical Summary
Existing malware infection response technologies fail to promptly notify network administrators and other relevant parties of the status of malware infections, leading to delays in initiating countermeasures and increased risk of infection spread.
A relay device that monitors data communication, identifies infected terminals, and generates infection notification emails or web pages to notify administrators and other relevant parties, while restricting data communication and providing signature updates to infected terminals.
Enables rapid notification of malware infections to administrators and other relevant parties, facilitating quick countermeasures and effectively preventing the spread of infections.
Smart Images

Figure 2026013167000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to an infection response technique when a malware infection is detected in a communication terminal connected to a LAN (Local Area Network). [Background technology]
[0002] As one of the conventional technologies for responding to malware infection detected on any communication terminal connected to a LAN, Patent Document 1 proposes a technology that automatically restricts communication of the infected terminal and automatically notifies the user of the infected terminal that unauthorized communication has been detected by sending HTTP data or email data to the infected terminal. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Japanese Patent Application Laid-Open No. 2007-264990 Summary of the Invention [Problem to be solved by the invention]
[0004] In order to prevent the spread of malware infection, it is important to start countermeasures as soon as possible. According to the conventional technology described above, it is possible to automatically notify the user of an infected communication terminal that their own communication terminal is infected with malware.
[0005] However, this type of notification is only sent to the user of the infected device, and it is not possible to notify the network administrator who actually takes measures to deal with the malware infection, or other parties who are likely to become infected secondary from the infected device, of the status of the detected malware infection and warn them. This causes a delay in starting measures to deal with the malware infection, which increases the possibility of the infection spreading.
[0006] The present invention is intended to solve these problems, and aims to provide an infection response technology that can quickly notify specific users, such as administrators, of the status of malware infection. [Means for solving the problem]
[0007] In order to achieve this objective, the relay device of the present invention comprises a relay unit configured to relay and connect multiple communication terminals connected thereunder to a communication network via a LAN, and a control unit that controls communication between the multiple communication terminals, and the control unit comprises an infection processing unit configured to monitor data communication between the multiple communication terminals, identify a communication terminal in which malware infection is detected as an infected terminal, and restrict data communication including email transmission and web access by the infected terminal, and an email processing unit configured to generate an infection notification email to notify the malware infection status of the infected terminal in response to the detection of malware infection by the infection processing unit, and send the email to a predetermined notification email address.
[0008] In one example configuration of the relay device according to the present invention, when a request to send an email is sent from the infected terminal, the email processing unit generates a proxy email based on the email content obtained from the sent email and sends it to the network administrator, receives a proxy reply email to the proxy email returned by the network administrator in response, and then, when a request to receive an email is sent from the infected terminal, generates a received email including the email body of the proxy reply email and returns it to the infected terminal.
[0009] In one example configuration of the relay device according to the present invention, the control unit further includes a web processing unit configured to generate a web page for notifying the infected terminal of the malware infection status and deliver it to the infected terminal, and to acquire the contents of an inquiry sent from the infected terminal using an input form provided on the web page, and the email processing unit is configured to generate an email including the contents of the inquiry acquired by the web processing unit and send it to the administrator terminal of the network administrator.
[0010] In one example configuration of the relay device according to the present invention, the control unit further includes a signature update unit configured to, when a request for updating a signature related to malware is sent from the infected terminal, obtain the latest signature from a signature distribution server via the communication network and return it to the infected terminal. [Effects of the Invention]
[0011] According to the present invention, it is possible to promptly notify a specific user, such as an administrator, of the status of a malware infection. [Brief explanation of the drawings]
[0012] [Figure 1] FIG. 1 is a block diagram illustrating a configuration of a relay device according to a first embodiment. [Figure 2] FIG. 2 is an explanatory diagram showing an example of the structure of an infection notification email. [Figure 3] FIG. 3 is a sequence diagram illustrating an operation of the relay device according to the first embodiment. [Figure 4] FIG. 4 is a sequence diagram illustrating an operation of the relay device according to the second embodiment. [Figure 5] FIG. 5 is a block diagram illustrating a configuration of a relay device according to the third embodiment. [Figure 6] FIG. 6 is an explanatory diagram showing an example of the configuration of an infection notification web page. [Figure 7] FIG. 7 is a sequence diagram illustrating an operation of the relay device according to the second embodiment. [Figure 8] FIG. 8 is an explanatory diagram showing another example of the configuration of the infection notification web page. DETAILED DESCRIPTION OF THE INVENTION
[0013] Next, an embodiment of the present invention will be described with reference to the drawings. [First embodiment] First, a relay device 10 according to a first embodiment will be described with reference to the block diagram of FIG.
[0014] [Repeater] The relay device 10 as a whole is composed of relay devices such as a gateway or a UTM (Unified Threat Management) device, and is configured to relay and connect multiple communication terminals 20 connected thereunder via a LAN (Local Area Network) to a communication network NW such as the Internet, and to control data communication of the communication terminals 20.
[0015] In addition, in order to respond to malware infection, the relay device 10 is configured to monitor data communications at each communication terminal 20, identify a communication terminal in which unauthorized communications by malware are detected as an infected terminal, and restrict data communications, including email transmissions and web accesses, by the infected terminal.
[0016] [Communication terminal] The communication terminals 20 are composed of communication terminals such as PCs, smartphones, tablets, etc., and are configured to perform data communication with each other via a LAN, and to perform data communication with the communication network NW via the LAN and relay device 10. In the following, among the communication terminals 20, a communication terminal 20 infected with malware will be referred to as an infected terminal (communication terminal) A, a communication terminal 20 not infected with malware will be referred to as a normal terminal (communication terminal) B, and a communication terminal 20 used by a network administrator who manages the LAN will be referred to as an administrator terminal X.
[0017] [Storage Server] The storage server 21 is configured to communicate with internal devices such as the relay device 10 and communication terminal 20 connected to the LAN, thereby enabling these internal devices to store and acquire various data, and to transfer various data and send and receive emails between the internal devices. A mail server (not shown) connected to the communication network may be used to send and receive emails between the internal devices. Note that the relay device 10 acts as a proxy to restrict the sending and receiving of emails and web access by infected terminals.
[0018] [Principle of the Invention] The relay device 10 not only relays and connects a plurality of communication terminals 20 connected thereunder to the communication network NW via a LAN, but also performs data communication with these communication terminals 20. This data communication includes providing mail services using mail protocols and web services using the Hypertext Transfer Protocol (HTTP). Furthermore, because the relay device 10 itself controls communication restrictions on infected terminals, even infected terminals can perform data communication with the communication terminals 20.
[0019] The present invention focuses on the communication restriction function and data communication function that are originally provided in such a relay device 10, and is configured so that when the relay device 10 identifies any of the communication terminals 20 connected thereto via a LAN as an infected terminal, it generates an infection notification email including the malware infection status of the infected terminal and sends it to a pre-set notification email address.
[0020] This means that by setting the email addresses of the network administrator who manages the LAN and other relevant parties who are likely to be further infected from an infected device as notification email addresses, you can quickly notify them of the status of the malware infection when an infection is detected.
[0021] [Detailed configuration of relay device] Next, with reference to the block diagram of FIG. 1, the configuration of the relay device 10 according to the present embodiment will be described in detail. The relay device 10 includes a network I / F 11, a LAN I / F 12, a relay unit 13, a storage unit 14, and a control unit 15 as main circuit units.
[0022] [Network I / F] The network I / F 11 is connected to the communication network NW via a communication line L and is configured to perform data communication with various server devices such as a signature distribution server 30 connected to the communication network NW. The signature distribution server 30 is a server device that distributes signatures used by security software installed in the communication terminal 20, i.e., configuration data for identifying malware.
[0023] [LAN I / F] The LAN I / F 12 is configured to be connected to a LAN and to perform data communication with a communication terminal 20 connected to the LAN. At this time, the LAN I / F 12 is configured to take in various communication data transmitted from the communication terminal 20 and transfer it to the control unit 15. [Relay section] The relay unit 13 is connected to the network I / F 11 and the LAN I / F 12, and is configured to control the relay connection of the communication terminal 20 to the communication network NW in response to an instruction from the control unit 15.
[0024] [Storage] The memory unit 14 is made up of a storage device such as a semiconductor memory or a hard disk, and is configured to store various data and programs 14P used in the malware infection processing executed by the control unit 15. The main processing data stored in the memory unit 14 are a notification destination email address 14A and email data 14B.
[0025] [Recipient email address] The notification destination email address 14A is an email address used when notifying the malware infection status by email, and is set in advance in the storage unit 14. Specific examples of the notification destination email address 14A include email addresses of a network administrator who manages the LAN, and related parties who are likely to be further infected by an infected terminal. Of these, the email addresses of related parties differ depending on the user of the infected terminal, so they may be set for each user or department.
[0026] [Email data] The email data 14B is standard data for an infection notification email that notifies the user of the malware infection status. As shown in Fig. 2, the infection notification email contains standard content indicating that a malware infection has been detected, that communication restrictions have been implemented, the contact information of the network administrator, the format of the email as a whole, and the like, and this standard content is stored in advance in the storage unit 14 as email data 14B. When the infection notification email is generated, content that differs for each malware infection, such as the infected terminal and the date and time of infection detection, is sequentially embedded in this email data 14B.
[0027] [program] The program 14P is a program that realizes various processing units that execute malware infection processing in the control unit 15 by working in cooperation with the CPU of the control unit 15. The program 14P is read from an external device or a recording medium (neither of which is shown) and stored in the storage unit 14 in advance.
[0028] [Control Unit] The control unit 15 has a CPU and its peripheral circuits, and is configured to realize various processing units that execute malware infection processing by having the CPU cooperate with the program 14P in the storage unit 14. The main processing units realized by the control unit 15 are an infection processing unit 15A, an email processing unit 15B, and a signature update unit 15C.
[0029] [Infection Control Department] The infection processing unit 15A is configured to monitor each data communication from the communication terminal 20 transferred from the LANI / F12, identify the communication terminal 20 in which unauthorized communication by malware is detected as an infected terminal, restrict various data communications including email transmission and web access by the infected terminal, and block various data communications between the infected terminal and other communication terminals 20.
[0030] [Email processing section] When the infection processing unit 15A detects a malware infection and identifies an infected terminal, the email processing unit 15B is configured to generate an infection notification email to notify the malware infection status of the infected terminal based on the email data 14B in the memory unit 14, and to send it to a pre-set email address based on the notification destination email address 14A in the memory unit 14.
[0031] In addition, the email processing unit 15B is configured to return the saved infection notification email to the infected terminal when an email reception request is sent from the infected terminal using an email protocol such as POP (Post Office Protocol) or IMAP (Internet Message Access Protocol).
[0032] In addition, when an email sending request is sent from an infected terminal using an email protocol such as SMTP (Simple Mail Transfer Protocol), the email processing unit 15B is configured to check the destination email address of the email, and if the destination email address matches the pre-set administrator email address, send the email to the administrator email address.
[0033] [Signature Update Section] The signature update unit 15C is configured to, when an update request for a signature related to malware is sent from an infected terminal, access the signature distribution server 30 on behalf of the infected terminal to acquire the signature and return it to the infected terminal. This allows even an infected terminal with data communication restrictions to run security software based on the latest signature, thereby strengthening malware countermeasures.
[0034] [Operation of the first embodiment] Next, the operation of the relay device 10 according to the first embodiment will be described with reference to the sequence diagram of Fig. 3. Here, the description will be made taking as an example a case where, among the communication terminals 20 connected to a LAN, communication terminal A is an infected terminal that has been infected with malware, and communication terminal B is a normal terminal that is not infected with malware.
[0035] In the control unit 15 of the relay device 10, the infection processing unit 15A constantly monitors data communication from the communication terminal 20 that is transferred from the LAN I / F 12. When the infection processing unit 15A detects unauthorized communication caused by malware (step 101) from any communication request sent from the communication terminal A (step 100), the infection processing unit 15A identifies the communication terminal A that is the sender of the communication request as the infected terminal A that is infected with malware (step 102), and starts restricting various data communications including email transmission and web access by the infected terminal A, and starts blocking various data communications between the infected terminal A and other communication terminals 20 (step 103).
[0036] When the infection processing unit 15A detects a malware infection and identifies the infected terminal A, the email processing unit 15B generates an infection notification email to notify the infected terminal A of the malware infection status based on the email data 14B in the memory unit 14 (step 104) and stores it in the storage server 21 (step 105).
[0037] Next, the email processing unit 15B acquires the notification destination email addresses 14A from the storage unit 14 (step 106), and sends infection notification emails addressed to the notification destination email addresses 14A. As a result, the infection notification email is received by the communication terminal B (step 107), and also by the administrator terminal X (step 108), the relevant parties and the network administrator who are set in the notification destination email addresses 14A are automatically notified that the communication terminal A is infected with malware.
[0038] On the other hand, if the email reception request sent from communication terminal 20 (step 110) is sent from infected terminal A (step 111), email processing unit 15B acquires an infection notification email from storage server 21 (step 112) and returns it to infected terminal A (step 113). As a result, the user of infected terminal A is notified by the infection notification email shown in Fig. 2 that their own terminal is infected with malware.
[0039] [Advantages of the first embodiment] In this way, in this embodiment, when the relay device 10 identifies any of the communication terminals 20 connected thereto via the LAN as an infected terminal, the relay device 10 generates an infection notification email including the malware infection status of the infected terminal and sends it to each of the pre-set notification destination email addresses 14A.
[0040] As a result, if the email addresses of the network administrator who manages the LAN and other related parties who are likely to be infected secondary to an infected terminal are set as notification email addresses 14A, the malware infection status can be promptly notified by infection notification email upon infection detection. Therefore, countermeasures for the malware infection can be started quickly, and the spread of infection can be effectively suppressed.
[0041] [Second embodiment] Next, a relay device 10 according to a second embodiment of the present invention will be described. In this embodiment, a configuration in which a user of an infected terminal contacts other users such as a network administrator using an infected terminal with restricted data communication by email will be described as one configuration. In the relay device 10 according to the second embodiment, a new configuration is added to the mail processing unit 15B of the control unit 15, but the other configuration is the same as that shown in FIG. 1, and detailed description thereof will be omitted here.
[0042] [Email processing section] The email processing unit 15B is configured such that, when an email sending request is sent from an infected terminal, it generates a proxy email based on the email content obtained from the sent email and sends it to the network administrator, receives a proxy reply email in response to the proxy email returned by the network administrator, and then, when an email receiving request is sent from the infected terminal, it generates a received email based on the email content obtained from the proxy reply email and returns it to the infected terminal.
[0043] [Operation of the second embodiment] Next, the operation of the relay device 10 according to the second embodiment will be described with reference to the sequence diagram of FIG.
[0044] In the control unit 15 of the relay device 10, if the email sending request sent from the communication terminal 20 (step 120) is sent from the infected terminal A (step 121), the email processing unit 15B assumes that the sent email is an inquiry email from the user of the infected terminal A to the network administrator, obtains the email content (e.g., text data) from the sent email, generates a proxy email (step 122), and sends it to the email address of the network administrator set in the notification destination email address 14A in the memory unit 14 (step 123).
[0045] As a result, when the proxy email is received by the administrator terminal X and a proxy reply email is returned from the network administrator (step 124), the email processing unit 15B receives the proxy reply email (step 124) and stores it in the storage server 21 (step 125). After this, if the email reception request sent from the communication terminal 20 (step 130) is sent from the infected terminal A (step 131), the email processing unit 15B acquires a proxy reply email from the storage server 21 (step 132), generates a reply email based on the email content (e.g., text data) acquired from the proxy reply email (step 133), and returns it to the infected terminal A (step 134).
[0046] [Advantages of the second embodiment] In this way, in this embodiment, when an email sending request is sent from an infected terminal, the relay device 10 generates a proxy email based on the email content of the sent email and sends it to the network administrator, receives a proxy reply email in response to the proxy email sent back from the network administrator, and then, when an email reception request is sent from the infected terminal, generates a reply email including the email body of the proxy reply email and returns it to the infected terminal.
[0047] Generally, users of infected devices can make inquiries about malware infections by phone or in person, but these methods have the problem of placing a heavy burden on users of infected devices who cannot use the network and are unable to look up phone numbers or administrators.
[0048] According to this embodiment, even an infected terminal with data communication restrictions can send an inquiry about the malware infection to a network administrator via email, and can receive appropriate advice from the network administrator without imposing a heavy burden on the user of the infected terminal. This makes it possible to quickly start countermeasures against the malware infection and effectively prevent the spread of infection.
[0049] [Third embodiment] Next, a relay device 10 according to a third embodiment of the present invention will be described with reference to the block diagram of Fig. 5. In the first embodiment described above, an example was given in which a user of an infected terminal is notified of the malware infection status by an infection notification email. In this embodiment, an example is given in which a user of an infected terminal is notified of the malware infection status by an infection notification web page.
[0050] 5, compared to the configuration of the first embodiment described above, relay device 10 according to this embodiment has a Web processing unit 15D added to control unit 15 and Web page data 14C added to storage unit 14. The other configuration of relay device 10 according to this embodiment is the same as that of the first embodiment described above, and detailed description thereof will be omitted.
[0051] [Web page data] Web page data 14C is standard data for an infection notification web page that notifies the user of the malware infection status. As shown in Fig. 6, the infection notification web page includes standard content indicating that a malware infection has been detected, that communication restrictions have been implemented, the network administrator's contact information, the overall email format, and the like, and these standard contents are stored in advance in storage unit 14 as web page data 14C. When the infection notification web page is generated, content that differs for each malware infection, such as the infected terminal and the date and time of infection detection, is sequentially embedded in this web page data 14C.
[0052] 6, the infection notification web page also includes an input form for making an inquiry to the network administrator about the malware infection, with input fields for inputting, for example, the inquirer's name, department, email address, inquiry content, attachments, etc. Web page data 14C also includes this type of input.
[0053] [Web Processing Unit] When an access request to any web page is sent from an infected terminal using a protocol such as HTTP, the web processing unit 15D is configured to generate an infection notification web page including the malware infection status based on the web page data 14C in the memory unit 14, and deliver the infection notification web page to the infected terminal instead of the requested web page.
[0054] In addition, the Web processing unit 15D is configured to acquire the content of an inquiry regarding a malware infection sent from an infected terminal using an input form provided on the infection notification Web page, acquire the content of a response to the inquiry from the response email received by the email processing unit 15B, add it to the infection notification Web page, and redistribute it to the infected terminal.
[0055] [Email processing section] The email processing unit 15B is configured to generate an inquiry email including the text data acquired by the Web processing unit 15D, send it to the administrator email address preset in the notification destination email address 14A in the memory unit 14, and receive a reply email returned by the administrator in response to this.
[0056] [Operation of the third embodiment] Next, the operation of the relay device 10 according to the third embodiment will be described with reference to the sequence diagram of FIG.
[0057] In control unit 15 of relay device 10, when a request to access an arbitrary web page is sent from communication terminal 20 using a protocol such as HTTP (step 140), web processing unit 15D checks the sender of the request. If the sender is infected terminal A (step 141), an infection notification web page including the malware infection status is generated based on web page data 14C in storage unit 14 (step 142), and the infection notification web page is delivered to infected terminal A instead of the requested web page (step 143). As a result, the user of infected terminal A is notified that their terminal is infected with malware using the infection notification web page as shown in FIG. 6 described above.
[0058] Thereafter, when the user of infected terminal A inputs the inquiry content into the input form on the infection notification web page and performs a send operation, an inquiry request including the inquiry content is sent from infected terminal A to relay device 10 (step 150).
[0059] The Web processing unit 15D of the relay device 10 acquires the inquiry content (for example, text data) from the inquiry request from the infected terminal A (step 151).
[0060] The mail processing unit 15B generates an inquiry mail including the inquiry content acquired by the Web processing unit 15D (step 152) and sends it to the administrator terminal X of the network administrator (step 153). At this time, if the inquiry content includes an attachment file, the mail processing unit 15B attaches the attachment file to the inquiry mail and sends it.
[0061] Thereafter, the inquiry mail is received by the administrator terminal X (step 153), and the administrator creates a reply mail including the reply content and returns it from the administrator terminal X to the relay device 10 (step 154).
[0062] The email processing unit 15B receives the reply email from the administrator terminal X (step 154), and the web processing unit 15D obtains the reply content from the reply email received by the email processing unit 15B, adds the reply content to the infection notification web page to update it (step 155), and re-distributes it to the infected terminal A (step 156).
[0063] As a result, as shown in FIG. 8, the administrator's response to the inquiry about the malware infection is notified to the user of infected terminal A via the infection notification web page.
[0064] [Advantages of the third embodiment] In this way, in this embodiment, the relay device 10 generates an infection notification web page for notifying the infected terminal of the malware infection status, distributes it to the infected terminal, acquires the inquiry content sent from the infected terminal using an input form provided on the infection notification web page, generates an email including the inquiry content, and sends it to a pre-set administrator email address. This allows the status of a malware infection to be promptly notified on the infection notification web page upon detection, allowing countermeasures to be initiated quickly and effectively preventing the spread of infection.
[0065] In addition, while users of infected devices typically make inquiries about malware infections by phone or in person, these methods impose a significant burden on users of infected devices who are unable to use the network and are unable to look up phone numbers or administrators.
[0066] According to this embodiment, even if an infected terminal has data communication restrictions, it is possible to inquire about a malware infection to a network administrator using the input form on the infection notification web page, and the user of the infected terminal can receive appropriate advice from the network administrator very easily without imposing a heavy burden on the user.
[0067] [Extended embodiment] Although the present invention has been described above with reference to the embodiments, the present invention is not limited to the above embodiments. Various modifications that can be understood by those skilled in the art can be made to the configuration and details of the present invention within the scope of the present invention. Furthermore, the respective embodiments can be implemented in any combination within a consistent range. [Explanation of symbols]
[0068] 10...Relay device, 11...Network I / F, 12...LAN I / F, 13...Relay unit, 14...Memory unit, 14A...Notification destination email address, 14B...Email data, 14P...Program, 15...Control unit, 15A...Infection processing unit, 15B...Email processing unit, 15C...Signature update unit, 15D...Web processing unit, 20, A, B, X...Communication terminal, A...Infected terminal, X...Administrator terminal, 21...Storage server, 30...Signature distribution server, L...Communication line, LAN...Local network, NW...Communication network.
Claims
1. a relay unit configured to relay and connect a plurality of communication terminals connected thereunder via a LAN to a communication network; a control unit for controlling communications among the plurality of communication terminals; The control unit an infection processing unit configured to monitor data communications in each of the plurality of communication terminals, identify a communication terminal in which malware infection is detected as an infected terminal, and restrict data communications, including email transmission and web access, by the infected terminal; and an email processing unit configured to generate an infection notification email for notifying the malware infection status of the infected terminal in response to the detection of the malware infection by the infection processing unit, and to send the email to a preset notification destination email address. A relay device characterized by:
2. The mail processing unit When an email transmission request is sent from the infected terminal, a proxy email is generated based on the email content obtained from the transmitted email and sent to the network administrator, and a proxy reply email is received in response to the proxy email returned from the network administrator. After that, when an email reception request is sent from the infected terminal, a received email including the email body of the proxy reply email is generated and sent back to the infected terminal. The relay device according to claim 1 .
3. The control unit a web processing unit configured to generate a web page for notifying the infected terminal of a malware infection status and deliver it to the infected terminal, and to acquire an inquiry sent from the infected terminal using an input form provided on the web page; The email processing unit is configured to generate an email including the inquiry content acquired by the Web processing unit and transmit the email to an administrator terminal of the network administrator. The relay device according to claim 2 .
4. The control unit The computer further includes a signature update unit configured to, when a request for updating a signature related to malware is transmitted from the infected terminal, obtain the latest signature from a signature distribution server via the communication network and return the signature to the infected terminal. The relay device according to any one of claims 1 to 3.
Citation Information
Patent Citations
Automatic notification device of illegal communication and automatic notification program of unauthorized communication
JP2007264990A