Information processing device and information processing system
Patent Information
- Application Number
- JP2025034395
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-03-05
- Publication Date
- 2026-09-17
AI Technical Summary
【0009】 本発明によれば、自身の装置に対するネットワーク攻撃を受けるリスクを自身の装置の処理により低減させることができる。
Smart Images

Figure 2026146946000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to an information processing apparatus and an information processing system. [Background Art]
[0002] In organizations such as companies, it has become common for employees to connect business equipment used for work to a network. By connecting business equipment to a network, business data and business applications can be used via the network. On the other hand, connecting business equipment to a network involves the risk of adverse effects such as unauthorized access to network-connected devices and malware infection, caused by factors such as vulnerabilities in programs running on the business equipment or inadequate program settings. For example, when a business equipment that has not been used for a long period of time is connected to a network, there are cases where the business equipment is illegally accessed from outside via the network due to unpatched vulnerabilities in programs running on the equipment, resulting in the execution of malware.
[0003] As one of the methods for reducing such security risks, there is a quarantine network system. A quarantine network checks the status of business equipment when it connects to the network, and connects the relevant business equipment to an isolated network as necessary, thereby suppressing adverse effects on other network-connected devices. Patent Document 1 proposes a method of isolating an unauthorized terminal device by operating an L2 switch in a wireless LAN environment. [Prior Art Literature] [Patent Literature]
[0004] [Patent Document 1] Japanese Unexamined Patent Publication No. 2013-207642 [Summary of the Invention] [Problem to be Solved by the Invention]
[0005] However, prior art such as Patent Document 1 aims to suppress adverse effects on other network-connected devices caused by networking business equipment, and is not sufficient to prevent adverse effects on the connected business equipment itself. In this regard, it is conceivable that adverse effects on the business equipment itself can be prevented by special programs within the business equipment, but this cannot adequately address adverse effects that may occur immediately after network connection, after the business equipment has started up but before the special programs are started. Furthermore, there was a problem that adverse effects caused by network connection could not be addressed when a new version of the program with vulnerabilities fixed in the program within the business terminal was not provided (a state where patches were not provided).
[0006] This invention has been made in view of these circumstances, and its purpose is to provide an information processing device and an information processing system that can reduce the risk of being subjected to network attacks on its own device through the processing of its own device. [Means for solving the problem]
[0007] One of the present inventions for solving the above problems is an information processing device comprising: a storage device that stores information indicating a process for restricting or disabling a process performed using a communication network connected by a predetermined communication device; and a computing device that performs a confirmation process to check the risk of the communication device connecting to the communication network before connecting to the communication network, and a self-defense process that, if it is determined that there is a risk, executes a process indicated by the information stored in the storage device.
[0008] Another aspect of the present invention for solving the above problems is an information processing system comprising: a management device equipped with a computing device that receives input of information indicating a process for restricting or disabling a process performed using a communication network connected by a predetermined communication device; a storage device that stores the information acquired from the management device; and a user device equipped with a computing device that performs a confirmation process to check the risk of connecting to the communication network by the communication device before connecting to the communication network, and a self-defense process that, if it is determined that there is a risk, executes the process indicated by the information stored in the storage device. [Effects of the Invention]
[0009] According to the present invention, the risk of a network attack on the device itself can be reduced by processing the device itself.
[0010] Other configurations and effects will be clarified by the following description of the embodiments. [Brief explanation of the drawing]
[0011] [Figure 1] This figure shows an example of the configuration of the communication system according to this embodiment. [Figure 2] This figure shows an example of the hardware and functions of a management device. [Figure 3] This diagram shows an example of the hardware and functions that a terminal device possesses. [Figure 4] This figure shows an example of the hardware and functions of a recommended data provider. [Figure 5] This figure shows an example of self-defense processing item data. [Figure 6] This figure shows an example of self-defense level data. [Figure 7] This figure shows an example of basic self-defense level data. [Figure 8] This figure shows an example of the verification item data. [Figure 9]FIG. 1 is a diagram showing an example of operation suppression application data. [Figure 10] FIG. 2 is a diagram showing an example of self-protection state data. [Figure 11] FIG. 3 is a sequence diagram illustrating an example of terminal termination processing. [Figure 12] FIG. 4 is a sequence diagram illustrating an example of terminal startup processing. [Figure 13] FIG. 5 is a diagram showing an example of a first confirmation result notification screen. [Figure 14] FIG. 6 is a diagram showing an example of a second confirmation result notification screen.
Mode for Carrying Out the Invention
[0012] Hereinafter, embodiments of the present invention will be described with reference to the drawings.
[0013] FIG. 1 is a diagram showing an example configuration of a communication system 1 according to the present embodiment. The communication system 1 is an information processing system including: one or more terminal devices 11 (terminal apparatuses) that are information processing apparatuses used by respective users belonging to a predetermined organization and that execute a self-protection processing program described below; a management device 10 (management apparatus) that is an information processing apparatus configured to manage a program (self-protection processing program) for performing processing (hereinafter referred to as self-protection processing) for each terminal device 11 to prevent damage (network attack) from the outside by itself and related data of the program; and a recommended data providing device 12 that is an information processing apparatus configured to provide the self-protection processing program and related data to the management device 10.
[0014] The management device 10 is used by an organization administrator 14 who is an administrator in the communication system 1. The organization administrator 14 is authorized to operate the management device 10 to view and edit data and programs in the management device 10.
[0015] The recommended data providing device 12 is used by a recommended data administrator 16 who is an administrator in the communication system 1. The recommended data administrator 16 is authorized to view and edit data and programs in the recommended data providing device 12.
[0016] The terminal device 11, the management device 10, and the recommended data providing device 12 are communicatively connected via a wired or wireless communication network 13 such as the Internet, a LAN (Local Area Network), a WAN (Wide Area Network), or a dedicated line, for example.
[0017] FIG. 2 is a diagram illustrating an example of hardware included in the management device 10 and functions of the management device 10. First, the management device 10 includes: an arithmetic device 21 such as a CPU (Central Processing Unit) or a GPU (Graphics Processing Unit); a memory 22 such as a RAM (Random Access Memory) or a ROM (Read Only Memory); a storage device 25 such as an HDD (Hard Disk Drive) or an SSD (Solid State Drive); an input / output device 24 connected to a keyboard 28, a mouse 29, and a monitor 27; and a communication device 23 configured of a NIC (Network Interface Card), a wireless communication module, a USB (Universal Serial Bus) module, a serial communication module, or the like, which is connected to the communication network 13 to perform data communication. These devices are connected to each other via internal signal lines 26.
[0018] In addition, the management device 10 stores self-defense processing item data 204, self-defense level data 205, basic application self-defense level data 206, confirmation item data 207, and operation suppression application data 208.
[0019] The self-defense processing item data 204 is data that stores each self-defense processing, the content of these processings, and the like. The self-defense processing item data 204 is based on self-defense processing item recommendation data 404 received from the recommended data providing device 12. The self-defense processing item data 204 is data obtained by modifying the self-defense processing item recommendation data 404 by an organization administrator 14 in accordance with the organization's policies and environment. The modified self-defense processing item data 204 is transmitted to the terminal device 11.
[0020] The self-defense level data 205 is data that stores the contents of multiple patterns (hereinafter referred to as "self-defense levels") set according to the risk of network attacks that the terminal device 11 may receive via the communication network 13 (for example, patterns of self-defense actions to be taken). The self-defense level data 205 is based on the self-defense level recommendation data 405 received from the recommendation data providing device 12. The self-defense level data 205 is data that has been modified by the organization administrator 14 according to the organization's policies and environment, based on the self-defense level recommendation data 405. The modified self-defense level data 205 is transmitted to the terminal device 11.
[0021] The basic self-defense level data 206 defines the self-defense level at the end of operation of the terminal device 11 and the self-defense level when there is no risk of network attack on the terminal device 11. The basic self-defense level data 206 is based on the recommended basic self-defense level data 406 received from the recommended data providing device 12. The basic self-defense level data 206 is data modified by the organization administrator 14 according to the organization's policies and environment from the recommended basic self-defense level data 406. The modified recommended basic self-defense level data 406 is transmitted to the terminal device 11.
[0022] The verification item data 207 is data that records the timing for checking the self-defense level (risk of network attack). The verification item data 207 is based on the recommended verification item data 407 received from the recommended data providing device 12. The verification item data 207 is data that has been modified by the organization administrator 14 according to the organization's policies and environment, based on the recommended verification item data 407. The modified verification item data 207 is transmitted to the terminal device 11.
[0023] The operational restriction application data 208 is data that stores applications (application programs 302, described later) stored in the terminal device 11 whose operation is restricted based on self-defense procedures (operation restriction applications) and methods for restricting their operation (restriction methods). The operational restriction application data 208 is based on the operational restriction application recommendation data 408 received from the recommendation data providing device 12. The operational restriction application data 208 is data that has been modified by the organization administrator 14 according to the organization's policies and environment from the operational restriction application recommendation data 408. The modified operational restriction application data 208 is transmitted to the terminal device 11.
[0024] Furthermore, the management device 10 stores the management OS program 201, the management program 202, and the self-defense program 203.
[0025] The management OS program 201 controls the input / output device 24, loads data from the storage device 25 into memory 22, and controls the communication device 23. The management OS program 201 also loads the management program 202 from the storage device 25 into memory 22 and executes it.
[0026] The management program 202 manages the data and programs stored in the management device 10. Specifically, the management program 202 receives requests from the organization administrator 14 using the management device 10 to view or edit data and programs in accordance with the organization's policies and environment. For example, the management program 202 receives data and programs provided by the recommendation data providing device 12 (self-defense treatment recommendation program 403, self-defense treatment item recommendation data 404, self-defense level recommendation data 405, basic applicable self-defense level recommendation data 406, confirmation item recommendation data 407, operation suppression application recommendation data 408) according to input from the organization administrator 14, and accepts input from the organization administrator 14 for modifications to the received data and programs. In this case, the organization administrator 14 inputs the data and programs while referring to the organization's recommendation policy. The modified data and programs are stored as the self-defense treatment program 203, self-defense treatment item data 204, self-defense level data 205, basic applicable self-defense level data 206, confirmation item data 207, and operation suppression application data 208, respectively.
[0027] The self-defense program 203 is based on the self-defense recommendation program 403 received from the recommendation data providing device 12. The self-defense program 203 is a modified version of the self-defense recommendation program 403, modified by the organization administrator 14 according to the organization's policies and environment. The modified self-defense program 203 is transmitted to the terminal device 11.
[0028] Figure 3 shows an example of the hardware and functions of the terminal device 11. First, the terminal device 11, like the management device 10, includes a computing device 31 such as a CPU (Central Processing Unit) or GPU (Graphics Processing Unit), memory 32 such as RAM (Random Access Memory) or ROM (Read Only Memory), storage device 35 such as an HDD (Hard Disk Drive) or SSD (Solid State Drive), input / output devices 34 connected to a keyboard 38, mouse 39, and monitor 37, and a communication device 33 that connects to a communication network 13 to perform data communication, consisting of a NIC (Network Interface Card), wireless communication module, USB (Universal Serial Interface) module, or serial communication module. These devices are connected to each other by internal signal lines 36.
[0029] Furthermore, the terminal device 11 stores self-defense status data 304, self-defense processing item data 204, self-defense level data 205, basic applicable self-defense level data 206, confirmation item data 207, and operation suppression application data 208.
[0030] The self-defense status data 304 is data that stores the current state of the terminal device 11 related to the self-defense process.
[0031] Furthermore, the terminal device 11 stores the terminal OS program 301, the application program 302, and the terminal self-defense program 303.
[0032] The terminal OS program 301 controls the input / output device 34, loads data from the storage device 35 into memory 32, and controls the communication device 33, among other things.
[0033] The application program 302 is a program for various applications stored in the terminal device 11. The user 15 using the terminal device 11 can perform their duties using this application program 302.
[0034] The terminal self-defense program 303 communicates with the management program 202 of the management device 10 to acquire the self-defense processing program 203, self-defense processing item data 204, self-defense level data 205, basic applicable self-defense level data 206, confirmation item data 207, and operation suppression application data 208 of the management device 10, which have been set by the organization administrator 14, via the communication network 13, and stores these acquired data in the storage device 35.
[0035] Figure 4 shows an example of the hardware and functions of the recommended data provider 12. First, the recommended data provider 12, like the management device 10 and terminal device 11, includes a computing device 41 such as a CPU (Central Processing Unit) or GPU (Graphics Processing Unit), memory 42 such as RAM (Random Access Memory) or ROM (Read Only Memory), storage device 45 such as an HDD (Hard Disk Drive) or SSD (Solid State Drive), input / output devices 44 connected to a keyboard 48, mouse 49, and monitor 47, and a communication device 43 that connects to a communication network 13 to perform data communication, consisting of a NIC (Network Interface Card), wireless communication module, USB (Universal Serial Interface) module, or serial communication module. These devices are connected to each other by internal signal lines 46.
[0036] Furthermore, the recommended data providing device 12 stores recommended self-defense processing item data 404, recommended self-defense level data 405, recommended basic applicable self-defense level data 406, recommended confirmation item data 407, and recommended operation suppression application data 408.
[0037] The self-defense procedure recommendation data 404 is created or modified based on input by the recommendation data administrator 16. The self-defense procedure recommendation data 404 is transmitted to the management device 10.
[0038] The self-defense level recommendation data 405 is created or modified based on input from the recommendation data administrator 16. The self-defense level recommendation data 405 is transmitted to the management device 10.
[0039] The recommended basic self-defense level data 406 is created or modified based on input from the recommendation data administrator 16. The recommended basic self-defense level data 406 is transmitted to the management device 10.
[0040] The recommended verification item data 407 is created or modified based on input from the recommendation data administrator 16. The recommended verification item data 407 is transmitted to the management device 10.
[0041] The operational suppression application recommendation data 408 is created or modified based on input from the recommendation data administrator 16. The operational suppression application recommendation data 408 is transmitted to the management device 10.
[0042] Furthermore, the recommended data providing device 12 stores the provided OS program 401, the provided program 402, and the self-defense treatment recommendation program 403.
[0043] The provided OS program 401 controls the input / output device 44, loads data from the storage device 45 into memory 42, and controls the communication device 43. The provided OS program 401 also loads the provided program 402 from the storage device 45 into memory 42 and executes it.
[0044] The providing program 402 edits the data and programs stored in the recommended data providing device 12 to match the latest status based on input from the recommended data administrator 16. For example, when a new application program 302 for which a patch program has not yet been provided is discovered, the providing program 402 receives input of information about that application program 302 from the recommended data administrator 16 and adds the input information to the operational suppression application recommendation data 408. Also, for example, when the self-defense level confirmation items to be checked on the terminal device 11 are changed, the providing program 402 receives input of information about those confirmation items from the recommended data administrator 16 and updates the confirmation item recommendation data 407 with the input information. Furthermore, for example, when new self-defense processing information is added, the providing program 402 receives input of that self-defense processing information from the recommended data administrator 16 and updates the self-defense processing recommendation program 403 and the self-defense processing item recommendation data 404 with the input information.
[0045] The self-defense recommendation program 403 is created or modified based on input from the recommendation data administrator 16. The self-defense recommendation program 403 is transmitted to the management device 10.
[0046] (Self-defense procedure data, recommended self-defense procedure data) Next, Figure 5 shows an example of the self-defense processing item data 204. The self-defense processing item data 204 has the following fields: a self-defense processing ID 501 in which an ID (self-defense processing ID) assigned to each self-defense processing performed by the terminal device 11 is set; a self-defense processing content 502 in which the content of the self-defense processing is set; a self-defense start processing function 503 in which a function related to the self-defense processing to be executed when the terminal device 11 is started (startup self-defense processing) is set; and a self-defense end processing function 504 in which a function related to the self-defense processing to be executed when the terminal device 11 is shut down (shutdown self-defense processing) is set.
[0047] Self-defense processing content 502 contains the details of processing to restrict or disable processing using the communication network 13. For example, self-defense processing content 502 contains the details of processing such as suppressing the operation of an application (an application that is suppressed from operation as registered in the operation suppression application data 208), disabling the communication device 33 (disabling the connection function), blocking all communication necessary except for communication with the management program 202 of the management device 10, and suppressing the operation of an application that is waiting to connect to the communication network 13. The self-defense processing item recommendation data 404 has the same data structure as the self-defense processing item data 204.
[0048] (Self-defense level data, recommended self-defense level data) Figure 6 shows an example of self-defense level data 205. The self-defense level data 205 has the following fields: self-defense level ID 601, which is set to the self-defense level ID, which is an ID assigned to each self-defense level; self-defense level value 602, which is set to the self-defense level value, which is a parameter representing the risk of the self-defense level; applicable self-defense process ID list 60), which is set to a list of IDs of self-defense processes corresponding to the self-defense level; and implementable tasks 604, which is set to implementable tasks that the user can perform, which are associated with the self-defense level. The self-defense level recommendation data 405 has the same data structure as the self-defense level data 205.
[0049] (Basic self-defense level data, recommended basic self-defense level data) Figure 7 shows an example of the basic self-defense level data 206. The basic self-defense level data 206 has the following fields: setting item ID 701, which contains the ID assigned to each setting item; setting item name 702, which contains the name of the setting item; and setting value 703, which contains the self-defense level corresponding to the setting item. The recommended basic self-defense level data 406 has the same data structure as the basic self-defense level data 206.
[0050] (Data on items to be checked, recommended data on items to be checked) Figure 8 shows an example of the confirmation item data 207. The confirmation item data 207 consists of the following fields: confirmation item ID 801, which is set to an ID assigned to each confirmation item (confirmation item ID); confirmation content 802, which is set to the content of the confirmation item; and applicable self-defense level 803, which is set to the ID of the self-defense level that will be applied if the content of the confirmation item is met (self-defense level ID).
[0051] The confirmation details 802 include information such as whether a predetermined period has passed since the last self-defense procedure was performed, whether a predetermined period has passed since the last confirmation of a confirmation item was performed, whether a predetermined period has passed since the application program 302 was updated, whether encryption is not set on the storage device of the terminal device 11, and whether the terminal device 11 is locked due to the passage of a predetermined period. The recommended confirmation item data 407 has the same data structure as the confirmation item data 207.
[0052] (Data from apps that suppress operation, recommended data from apps that suppress operation) Figure 9 shows an example of the operation suppression application data 208. The operation suppression application data 208 consists of the following fields: operation suppression application ID 901, which contains an identifier (operation suppression application ID) assigned to the application whose operation is suppressed; application name 902, which contains the name of the application; application program path 903, which contains the path to the application; and operation suppression method 904, which contains the operation suppression process to be performed on the application. Note that the operation suppression application recommendation data 408 has a data structure similar to that of the operation suppression application data 208.
[0053] (Self-defense status data) Figure 10 shows an example of self-defense status data 304. The self-defense status data 304 consists of the following fields: a status item ID 1001, which is set to an identifier (status item ID) assigned to each state of the terminal device 11; a status item name 1002, which is set to the name of that state (status item name); and a status value 1003, which is set to the self-defense level applied in that state or the time when that state was reached. In the example shown in the figure, the ID of the currently applied self-defense level (applied self-defense level ID), the time when the self-defense program or data related to the self-defense program was last updated (last self-defense data and program update date and time), and the time when confirmation of the confirmation item was last performed (last confirmation processing date and time) are set.
[0054] Each program in each information processing device in the communication system 1, as described above, is executed by the arithmetic units 21, 31, and 41 of each information processing device reading it from memory 22, 32, 32 or storage devices 25, 35, and 45. These programs can be distributed, for example, by recording them on a portable or fixed recording medium. Furthermore, each program, in whole or in part, may be implemented using virtual information processing resources provided using virtualization technology, process space isolation technology, etc., such as a virtual server provided by a cloud system. Also, all or part of these programs may be implemented by services provided by a cloud system via an API (Application Programming Interface), etc.
[0055] <Processing when terminal ends> Figure 11 is a sequence diagram illustrating an example of the processing (terminal shutdown processing) performed when terminal equipment 11 shuts down in the communication system 1. This processing starts, for example, after terminal equipment 11 is started up.
[0056] The terminal OS program 301 of terminal device 11 waits for input from user 15 to stop the operation of terminal device 11. When the terminal OS program 301 receives a shutdown instruction (S1101), it transmits the input shutdown instruction to terminal self-defense program 303 (S1102).
[0057] When the terminal self-defense program 303 of the terminal device 11 receives a termination instruction, it performs termination self-defense processing according to the risk of connecting to the communication network 13, based on the basic applicable self-defense level data 206 (S1103).
[0058] Specifically, the terminal self-defense program 303 first obtains the status value 1003 of the record in the self-defense status data 304 where the status item name 1002 is "Applied Self-Defense Level ID," and then obtains the contents (current contents) of the applied self-defense processing ID list 603 of the record in the self-defense level data 205 where the obtained status value 1003 is set to self-defense level ID 601, thereby identifying the function related to the self-defense processing for the currently set self-defense level.
[0059] Furthermore, the terminal self-defense program 303 obtains the setting value 703 of the record in the basic applicable self-defense level data 206 where the status item name 1002 is "Applicable self-defense level ID at terminal termination", and obtains the contents of the applicable self-defense processing ID list 603 of the record in the self-defense level data 205 where the obtained setting value 703 is set to self-defense level ID 601 (termination contents), thereby identifying the function related to the self-defense processing at startup.
[0060] The terminal self-defense program 303 then identifies a self-defense process (applicable self-defense process ID) that is currently present but not in the end-of-service content, and retrieves the self-defense termination processing function 504 of the record in the self-defense process item data 204 where the identified applicable self-defense process ID is set to self-defense process ID 501, thereby identifying the function related to the termination self-defense process that should be executed this time. The terminal self-defense program 303 then sends a request to the self-defense processing program 203 to execute the identified function (S1104).
[0061] The self-defense processing program 203 of the terminal device 11 executes a function corresponding to the received request and transmits the execution result to the terminal self-defense program 303 (S1105).
[0062] The terminal self-defense program 303 updates the current self-defense level by changing the status value 1003 of the record in the self-defense status data 304 where the status item name 1002 is "Applied Self-Defense Level ID" to the setting value 703 of the record in the basic applied self-defense level data 206 where the status item name 1002 is "Applied Self-Defense Level ID at Terminal Termination" (S1106). After that, the terminal self-defense program 303 terminates (S1107).
[0063] Meanwhile, the terminal OS program 301 monitors the termination of the terminal self-defense program 303 (S1108), and upon confirming the termination of the terminal self-defense program 303, the processing of the terminal OS program 301 also terminates (S1109).
[0064] As a result of the above processing, the next time the terminal device 11 is started, it will start with the shutdown protection process already executed. For example, by starting it in a state where the communication device is disabled or all communication except that necessary for communication with the management program is blocked (disabling the connection function), it is possible to prevent adverse effects (such as network attacks) that may occur immediately after the terminal device 11 starts up and connects to the network.
[0065] <Processing during terminal startup> Figure 12 is a sequence diagram illustrating an example of the process (terminal startup process) that enables the user 15 to perform tasks using the terminal device 11 that utilize the communication network 13, after the terminal device 11 has started up and the self-defense process has been deactivated. The terminal startup process starts, for example, after the terminal device 11 has finished starting up (or has finished operating).
[0066] The terminal OS program 301 of terminal device 11 is waiting for input from user 15 to start the terminal device 11. When the terminal OS program 301 receives a start command (S1201), it transmits the input start command to the terminal self-defense program 303 (S1202).
[0067] When the terminal self-defense program 303 receives a startup command, it detects that the terminal device 11 has started up and determines whether the self-defense process was correctly executed when the terminal device 11 was last shut down (S1203). Specifically, the terminal self-defense program 303 determines whether the setting value 703 of the record in the basic applicable self-defense level data 206 where the setting item name 702 is set to "Applied self-defense level ID at terminal shutdown" is the same as the status value 1003 of the record in the self-defense status data 304 where the status item name 1002 is set to "Applied self-defense level ID".
[0068] If it is determined that the self-defense process was successfully executed when the terminal device 11 was last terminated (S1203: none), the terminal self-defense program 303 executes the self-defense process according to the risk of connecting to the communication network 13, similar to S1103 to S1105 (S1204 to S1206). After that, the process in S1207 is performed.
[0069] If it is determined that the self-defense process was not properly executed when the terminal device 11 was last terminated (S1203: Yes), the terminal self-defense program 303 executes the process in S1207.
[0070] In S1207, the terminal self-defense program 303 attempts to connect to the management program 202 of the management device 10. If successful, it updates the self-defense processing program and related data (S1207-S1209).
[0071] Specifically, the terminal self-defense program 303 checks whether any of the self-defense processing program 203, self-defense processing item data 204, self-defense level data 205, basic applicable self-defense level data 206, confirmation item data 207, and operation suppression application data 208 stored in the management device 10 have been updated since the last connection. If any of the data or programs have been updated, the terminal self-defense program 303 retrieves the updated data and program from the management device 10. Then, the terminal self-defense program 303 sets the current date and time to the status value 1003 of the record in the self-defense status data 304 where the status item name 1002 is set to "Last self-defense data and program update date and time".
[0072] Subsequently, the terminal self-defense program 303 obtains the confirmation item data 207, thereby acquiring each confirmation item related to self-defense processing in the terminal device 11 (S1210). Then, the terminal self-defense program 303 updates the status value 1003 of the record in the self-defense status data 304 where the status item name 1002 is set to "Previous confirmation processing date and time" to the current date and time.
[0073] The terminal self-defense program 303 checks whether each verification item obtained in S1210 is applicable. Specifically, the terminal self-defense program 303 refers to the verification content 802 of each record in the verification item data 207 obtained in S1210 and checks whether the content of verification content 802 is currently met.
[0074] Then, if there are any relevant verification items, the terminal self-defense program 303 identifies the self-defense level corresponding to those verification items as the self-defense level to be applied. Specifically, the terminal self-defense program 303 obtains the applicable self-defense level 803 from the record of the verification item data 207 related to the relevant verification item. If there are multiple relevant verification items, the terminal self-defense program 303 identifies each record from the self-defense level data 205 in which the value of each of the obtained applicable self-defense levels 803 is set in the self-defense level ID 601, and by comparing the values of 602 in each identified record with each other, it identifies the self-defense level of the verification item with the highest self-defense level.
[0075] Then, the terminal self-defense program 303 identifies the difference in self-defense processing between the self-defense processing related to the identified self-defense level (the self-defense level to be applied) and the self-defense processing related to the current self-defense level, thereby identifying and executing the function for the self-defense processing to be executed (S1211).
[0076] Specifically, the terminal self-defense program 303 retrieves the status value 1003 of the record in the self-defense status data 304 where the status item name 1002 is set to "Applied Self-Defense Level ID," and retrieves the list of applicable self-defense processing IDs 603 (self-defense processing IDs) of the record in the self-defense level data 205 where the retrieved status value 1003 is set to self-defense level ID 601, thereby identifying the self-defense processing for the current self-defense level.
[0077] Furthermore, the terminal self-defense program 303 identifies the self-defense process to be applied by obtaining the list of applicable self-defense process IDs 603 (self-defense process IDs) for records in the self-defense level data 205 where the self-defense level ID 601 is set to the above-mentioned applicable self-defense level 803.
[0078] The terminal self-defense program 303 then identifies the ID of the self-defense procedure to be executed by identifying all self-defense procedures (self-defense procedure IDs) that exist in the applicable self-defense procedure ID list 603 for the current self-defense level but do not exist in the applicable self-defense procedure ID list 603 for the self-defense level to be applied.
[0079] The terminal self-defense program 303 identifies the self-defense function to be executed by obtaining the self-defense termination processing function 504 for each record in the self-defense processing item data 204 where each identified self-defense processing ID is set to self-defense processing ID 501.
[0080] The terminal self-defense program 303 then instructs the self-defense processing program 203 to execute the function for each identified self-defense process (S1212). The self-defense processing program 203 executes the corresponding function and sends the execution result of each function back to the terminal self-defense program 303 (S1213).
[0081] Furthermore, the terminal self-defense program 303 updates the currently applied self-defense processing level registration data by updating the status value 1003 of records in the self-defense status data 304 where the status item name 1002 is set to "Applied Self-Defense Level ID" with the content of the self-defense level ID related to the self-defense processing to be applied, as identified above.
[0082] The terminal self-defense program 303 checks whether there was a corresponding confirmation item in S1210 (S1214). If there was no corresponding confirmation item (S1214: Yes), the terminal self-defense program 303 executes the process in S1219. If there was a corresponding confirmation item (S1214: No), the terminal self-defense program 303 executes the process in S1215.
[0083] In S1215, the terminal self-defense program 303 displays information on the relevant verification items on the first verification result notification screen 1300, which will be described later.
[0084] User 15 checks the first confirmation result notification screen 1300 and instructs the terminal OS program 301 to execute the corresponding processing for the confirmation item (for example, updating the terminal OS program 301, updating a predetermined anti-malware program, or encrypting the storage device 35 of the terminal device 11) (S1216). The terminal self-defense program 303 may execute these processes automatically.
[0085] Subsequently, the terminal self-defense program 303 receives an instruction from the user 15 to re-execute the process from S1207 onwards via the first confirmation result notification screen 1300. Upon receiving this instruction (S1217), it performs the re-execution (S1218).
[0086] Meanwhile, in S1214, the terminal self-defense program 303 displays the second confirmation result notification screen 1400, which will be described later (S1219). As a result, user 15 can perform tasks using the communication network 13 in an environment where sufficient self-defense processing (for example, the self-defense processing for the "self-defense level ID applicable when no problem is determined" in the basic applicable self-defense level data 206) has been applied.
[0087] The above processing for terminal device 11 is performed before terminal device 11 connects to the communication network 13.
[0088] In this way, user 15 will be able to perform network-based tasks in an environment where the necessary self-protection measures are applied.
[0089] (First confirmation result notification screen) Figure 13 shows an example of the first confirmation result notification screen 1300. The first confirmation result notification screen 1300 includes a title display area 1301 where the screen title is displayed, a notification information display area 1302 where various information is displayed, and a reconfirmation request button 1303 that accepts instructions from the user 15 to re-execute the process from S1207 onwards.
[0090] The notification information display area 1302 includes a confirmation result display area 1304 that displays the relevant confirmation item and its contents, and a self-defense status display area 1305 that displays the self-defense level currently applied to the terminal device 11, the self-defense processing corresponding to that self-defense level, and the tasks that the user 15 can perform for that self-defense level. The information in the self-defense status display area 1305 is based on the tasks 604 that can be performed in the record where the self-defense level ID corresponding to the relevant confirmation item is set as self-defense level ID 601 in the self-defense level data 205.
[0091] (Second confirmation result notification screen) Figure 14 shows an example of the second confirmation result notification screen 1400. The second confirmation result notification screen 1400 includes a title display area 1401 where the screen title is displayed, a notification information display area 1402 where various information is displayed, and a close button 1403 which is specified when closing the second confirmation result notification screen 1400.
[0092] The title display area 1401 includes a message 1404 indicating that there are no problems with the terminal device 11 and that work can be performed safely, and a self-defense status display area 1405 which displays the self-defense level currently applied to the terminal device 11, the self-defense process corresponding to that self-defense level, and the tasks that the user 15 can perform for that self-defense level.
[0093] As described above, before connecting to the communication network 13, the terminal device 11 of this embodiment performs a confirmation process to check the risk of connecting to the communication network 13 by the communication device 33. If it determines that there is a risk, it executes each self-defense process in the self-defense process item data 204, which stores self-defense processes to restrict or disable processes using the communication network 13.
[0094] Thus, in this embodiment, the terminal device 11 determines whether or not there is a communication risk to the terminal device 11 itself before connecting to the communication network 13, and performs self-protection processing if it determines that there is a risk.
[0095] Thus, according to the terminal device 11 of this embodiment, the risk of being subjected to network attacks on its own device can be reduced by processing the device itself.
[0096] Furthermore, the terminal device 11 in this embodiment receives an instruction to terminate its operation, and upon receiving the instruction, disables the function to connect to the communication network 13.
[0097] This makes it possible to avoid network attacks that could occur immediately after the terminal device 11 is powered on and connected to the network.
[0098] Furthermore, in this embodiment, when the terminal device 11 detects that the terminal device 11 has been activated, it determines whether a predetermined period has elapsed since the confirmation process executed immediately before, and if it determines that the predetermined period has elapsed, it executes each self-defense process in the self-defense process item data 204.
[0099] If terminal device 11 has not been started for a long period of time, terminal device 11 may be vulnerable to network attacks. Even when terminal device 11 is started in such a situation, it is possible to prevent network attacks on terminal device 11 itself by the communication network 13.
[0100] Furthermore, the terminal device 11 of this embodiment identifies a self-defense action corresponding to the risk confirmed in the confirmation process based on information (self-defense level data 205, basic applicable self-defense level data 206, confirmation item data 207) that associates the risk of connecting to the communication network 13 (self-defense level) with a self-defense action ID corresponding to that risk, and executes the identified self-defense action.
[0101] In this way, by performing self-defense measures corresponding to the level of self-defense required for the risk of connecting to the communication network 13, the risk of a network attack on one's own device can be effectively reduced depending on the situation.
[0102] Furthermore, if the terminal device 11 of this embodiment determines that there is a risk of connecting to the communication network 13, it executes self-defense processing based on information (self-defense processing item data 204, operation suppression application data 208) indicating processing to restrict or disable processing executed by the operation suppression application.
[0103] This allows you to suppress or disable the execution of applications that pose a risk, such as those for which patches are not yet available, thereby reducing the risk of network attacks against your device.
[0104] Furthermore, in the communication system 1 of this embodiment, the management device 10 stores the self-defense processing item data 204, and the terminal device 11 executes each self-defense processing item data 204 received from the management device 10.
[0105] In this configuration, the management device 10 manages the information on self-defense procedures, and the terminal devices 11 receive this information and perform self-defense procedures. This effectively reduces the risk of network attacks on each terminal device 11 depending on the case.
[0106] It should be noted that the present invention is not limited to the embodiments described above, and in the implementation stage, the components can be modified and implemented without departing from the gist of the invention, or the multiple components disclosed in the embodiments can be appropriately combined.
[0107] For example, some of the hardware components of each device in this embodiment may be provided in other devices. For instance, in this embodiment, the management device 10 is configured as a single unit, but it may be configured to operate with one or more management devices 10. Alternatively, the management device 10 and the recommended data providing device 12 may operate using the same single management device.
[0108] Furthermore, each program of each device may be provided in other devices, a program may consist of multiple programs, or multiple programs may be integrated into a single program.
[0109] Furthermore, the confirmation of whether or not to perform self-defense procedures is not limited to when the terminal device 11 is started up; it may also be configured to perform this confirmation at a specified time, taking into consideration measures for terminal devices 11 that are running for extended periods.
[0110] Furthermore, while the management device 10 is configured to allow customization according to the organization's policies and environment, it is also possible to configure the system without the management device 10, allowing the terminal device 11 to directly obtain data and programs for self-defense procedures from the recommended data provision device 12. [Explanation of Symbols]
[0111] 11 Terminal equipment, 13 Communication network, 31 Processing unit, 33 Communication device, 35 Storage device, 303 Terminal self-defense program, 203 Self-defense processing program
Claims
1. A storage device that stores information indicating a process for restricting or disabling a process performed using a communication network connected by a predetermined communication device, and Before connecting to the aforementioned communication network, a verification process is performed to confirm the risks of connecting to the aforementioned communication network by the communication device, A computing device that, when it determines that there is a risk, performs a self-defense process that executes the process indicated by the information stored in the memory device. An information processing device equipped with the following features.
2. The aforementioned computing device is The system receives an instruction to terminate the operation of the information processing device, and if such instruction is received, it disables the function to connect to the communication network. The information processing apparatus according to claim 1.
3. The aforementioned computing device is When the information processing device detects that it has started up, it determines whether a predetermined period has elapsed since the confirmation process that was executed immediately before, and if it determines that the predetermined period has elapsed, it executes the process indicated by the information. The information processing apparatus according to claim 1.
4. The storage device stores information that associates the risk of connecting to the communication network with the information that indicates the processing corresponding to the risk. The computing device identifies a process corresponding to the risk identified in the verification process from the stored information and executes the identified process. The information processing apparatus according to claim 1.
5. The storage device stores information indicating a process to restrict or disable the process, which is executed by a predetermined program stored therein. If the computing device determines that the risk exists, it executes a self-defense process that causes the predetermined program to execute the process indicated by the information. The information processing apparatus according to claim 1.
6. A management device equipped with a computing unit that accepts input of information indicating a process for restricting or disabling a process performed using a communication network connected by a predetermined communication device, A storage device for storing the information acquired from the management device, and Before connecting to the aforementioned communication network, a verification process is performed to confirm the risks of connecting to the aforementioned communication network by the communication device, A terminal device equipped with a computing device that performs self-defense processing, which involves executing processing indicated by the information stored in the memory device when it determines that there is a risk. An information processing system comprising the above.
7. The computing device of the aforementioned terminal device is Upon receiving an instruction to terminate the operation of the terminal device, and upon receiving such instruction, the function to connect to the communication network is disabled. The information processing system according to claim 6.
8. The computing device of the aforementioned terminal device is When the terminal device is detected to have started up, it is determined whether a predetermined period has elapsed since the confirmation process that was executed immediately before, and if it is determined that the predetermined period has elapsed, the process indicated by the information is executed. The information processing system according to claim 6.
9. The storage device of the terminal device stores information that associates the risk of connecting to the communication network with the information that indicates the processing corresponding to the risk. The computing device of the terminal device identifies a process corresponding to the risk identified in the verification process from the stored information and executes the identified process. The information processing system according to claim 6.
10. The storage device of the terminal device stores information indicating a process to restrict or disable the process, which is executed by a predetermined program stored therein. When the computing device of the terminal device determines that the risk exists, it performs a self-defense process that causes the predetermined program to execute the process indicated by the information. The information processing system according to claim 6.
Citation Information
Patent Citations
Connection management device, terminal device, connection management method, and program
JP2013207642A