Inspection device, inspection program, and inspection method
By first performing OS scanning in vulnerability detection and targeted vulnerability inspection based on the results, the problems of long detection time, high load and high misjudgment rate in the existing technology are solved, and efficient and accurate vulnerability detection and fraud detection are achieved.
Patent Information
- Application Number
- JP2021125165
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-07-30
- Publication Date
- 2025-05-09
- Estimated Expiration
- 2041-07-30
AI Technical Summary
When improving the accuracy of vulnerability detection of network equipment, the prior art faces the problems of long detection time, high load and high misjudgment rate, especially when non-standard ports and applications use non-recommended ports.
The method of first performing operating system (OS) scanning, determining the OS type and then performing targeted vulnerability checks. At the same time, the storage of device identification results and the priority use of the latest results is reduced to reduce misjudgment and improve detection accuracy.
It effectively reduces the time and load of vulnerability detection, improves the accuracy and efficiency of detection, and can detect potential vulnerabilities and fraud in the early stage.
Smart Images

Figure 0007673553000001 
Figure 0007673553000002 
Figure 0007673553000003
Abstract
Description
[Technical field]
[0001] The present invention relates to an inspection device, an inspection program, and an inspection method, and can be applied to an inspection device that remotely monitors terminals on a network, detects unauthorized terminals, and inspects vulnerabilities, for example. [Background technology]
[0002] Computer operating systems (OS) and applications (software) have vulnerability issues, which are information security flaws that can occur due to program malfunctions or design errors. If a computer is continued to be used with vulnerabilities remaining, there is a risk that it may be used for unauthorized access or become infected with a virus.
[0003] As such, vulnerabilities have become one of the major issues in terms of information security for computers connected to networks (such as the Internet).
[0004] As software for detecting vulnerabilities, for example, there are vulnerability testing tools as disclosed in Non-Patent Documents 1 to 3. By using a vulnerability testing tool to detect and remove vulnerabilities, it is possible to reduce the risk of virus infection, etc. As vulnerability testing means, for example, the following tests are available.
[0005] A port scan sends data specifying a port to a target terminal connected to the network and checks the response. By sending and receiving data packets for the number of ports to be inspected, it is possible to investigate the services and OS used by the target terminal.
[0006] Password vulnerability testing involves preparing a database of password strings in advance, such as initial passwords stored by applications, passwords with a small number of characters, or passwords consisting of common nouns that are easily leaked.The system then attempts to log in to a target device connected to the network using a string from this database, and if the user is able to log in, it can be determined that a vulnerability exists. [Prior art documents] [Non-patent literature]
[0007] [Non-Patent Document 1] “Nmap Changelog” [Retrieved July 20, 2021], [Online], INTERNET,<URL: https: / / nmap.org / changelog.html> [Non-Patent Document 2] “NESSUS” [Retrieved July 20, 2021], [Online], INTERNET,<URL: https: / / www.tenable.com / products / nessus> [Non-Patent Document 3] “OWASP ZAP(Zed Attack Proxy)” [Searched on July 20, 2021], [Online], INTERNET,<URL: https: / / owasp.org / www-project-zap / > Summary of the Invention [Problem to be solved by the invention]
[0008] However, while the above-mentioned vulnerability testing can improve the accuracy of vulnerability detection related to the services used, the OS, passwords, etc. by storing large amounts of target device information, port information, and passwords, there is a problem in that the testing takes a long time and places a very high load on the terminal being tested.
[0009] To address the above issue, the testing time can be reduced by first performing an OS scan and then performing a vulnerability test on the OS determined by the OS scan, but the OS scan does not necessarily return correct results.
[0010] In addition, when a port number other than the standard port number is set or an application that uses a port number that is not recommended is installed, it is prone to false positives. The problem of reduced accuracy occurs when vulnerability testing is performed on the wrong OS.
[0011] Therefore, there is a demand for an inspection device, an inspection program, and an inspection method that can perform inspections for unauthorized terminals and vulnerabilities while reducing the load and performing early detection. [Means for solving the problem]
[0012] The first invention is an inspection device that inspects vulnerabilities and / or frauds of one or more inspection target devices connected via a network, (1) detecting each of the inspection target devices newly connected to the network, and performing an identification process for each of the inspection target devices based on packets transmitted and received by each of the inspection target devices on the network. Multiple times a first inspection means for performing the above-mentioned inspection and determining the type of the device; (2) a device identification result storage means for storing a device identification result including a device type of each of the test target devices determined by the first test means; (3) a judgment information storage means for storing vulnerability judgment information describing the inspection content for judging the vulnerability and / or fraud of each of the test target devices for each device type; and (4) the device identification result stored in the device identification result storage means. and a second inspection means for determining inspection contents for detecting vulnerability and / or fraud of the equipment by transmitting and receiving data between the inspection device and the inspection target equipment using the information of the above, and inspecting the inspection target equipment based on the determined inspection contents, (5) The second inspection means determines the corresponding inspection content from the vulnerability determination information based on the device type of the device identification result, and further, when the device type contents of the multiple device identification results related to the same test target device are different, the second inspection means uses the latest result or the result of the device type that is most frequently used as the device identification result. It is characterized by:
[0013] A second inspection program of the present invention includes a computer installed in an inspection device that inspects vulnerabilities and / or fraud of one or more inspection target devices connected via a network, the computer (1) detecting each of the inspection target devices newly connected to the network, and performing an identification process for each of the inspection target devices based on packets transmitted and received by each of the inspection target devices on the network. Multiple times a first inspection means for performing the above-mentioned inspection and determining the type of the device; (2) a device identification result storage means for storing a device identification result including a device type of each of the test target devices determined by the first test means; (3) a judgment information storage means for storing vulnerability judgment information describing the inspection content for judging the vulnerability and / or fraud of each of the test target devices for each device type; and (4) the device identification result stored in the device identification result storage means.a second inspection means for determining inspection contents for detecting vulnerability and / or fraud of the equipment by transmitting and receiving data between the inspection device and the inspection target equipment using the information of the above, and inspecting the inspection target equipment based on the determined inspection contents; (5) the second inspection means determines the corresponding inspection content from the vulnerability determination information based on the device type of the device identification result, and further, when the device type contents of the multiple device identification results related to the same test target device are different, the second inspection means uses the latest result or the result of the device type that is used most frequently as the device identification result. It is characterized by:
[0014] The third aspect of the present invention is a testing method for use in a testing device that tests vulnerabilities and / or fraud in one or more test target devices connected via a network, comprising: The inspection device includes: First inspection method , device identification result storage means, determination information storage means, and The second inspection means detects each of the inspection target devices newly connected to the network, and performs an identification process for each of the inspection target devices based on packets transmitted and received by each of the inspection target devices on the network. Multiple times to determine the device type, (2) the device identification result storage means stores a device identification result including a device type of each of the inspection target devices determined by the first inspection means, (3) stores vulnerability determination information for each device type, the vulnerability determination information describing the inspection content for determining the vulnerability and / or fraud of each of the inspection target devices, and (4) The second inspection means includes: The device identification result stored in the device identification result storage means Using the information, determine the inspection content for detecting vulnerability and / or fraud of the equipment by transmitting and receiving data between the inspection device and the inspection target equipment, and inspect the inspection target equipment based on the determined inspection content; (5) The second inspection means determines the corresponding inspection content from the vulnerability determination information based on the device type of the device identification result, and (6) further, when the device type contents of the multiple device identification results related to the same test target device are different, the second inspection means uses the latest result or the result of the device type that is most frequently used as the device identification result. It is characterized by: Effect of the Invention
[0015] According to the present invention, it is possible to reduce the load and perform early detection while inspecting for unauthorized terminals and vulnerabilities. [Brief description of the drawings]
[0016] [Figure 1] 1 is a block diagram showing an internal configuration of an active scan device according to an embodiment; [Diagram 2] 1 is an overall configuration diagram showing the overall configuration of a vulnerability testing system according to an embodiment; [Diagram 3] FIG. 11 is an explanatory diagram illustrating an example of a regular terminal information storage unit according to the embodiment; [Figure 4] FIG. 11 is an explanatory diagram illustrating an example of a device identification result storage unit according to the embodiment. [Diagram 5] FIG. 11 is an explanatory diagram illustrating an example of a determination information storage unit according to the embodiment. [Figure 6] 11 is an explanatory diagram illustrating an example of a vulnerability test result storage unit according to the embodiment; FIG. [Figure 7] 4 is a flowchart showing a vulnerability check in a vulnerability check system (mainly an active scan device) according to an embodiment. [Figure 8] 10 is a flowchart showing detailed processing of an OS scan in a vulnerability testing unit according to the embodiment. [Figure 9] 10 is a flowchart showing detailed processing of a vulnerability test in a vulnerability test unit according to the embodiment; [Figure 10] FIG. 11 is an explanatory diagram illustrating an example of a vulnerability inspection result according to the embodiment. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0017] (A) Main embodiment DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS Hereinafter, an embodiment of an inspection device, an inspection program, and an inspection method according to the present invention will be described in detail with reference to the drawings.
[0018] (A-1) Configuration of the embodiment (A-1-1) Overall composition FIG. 2 is a diagram showing the overall configuration of a vulnerability testing system according to an embodiment.
[0019] In FIG. 2, the vulnerability testing system 100 includes an active scanning device 1, an equipment identification device 2, a vulnerability result output device 3, and multiple test target terminals 4 (4-1 to 4-n), and each device (terminal) is connected via a network N.
[0020] In the example of Figure 2, the vulnerability inspection device is composed of three devices: an active scan device 1, an equipment identification device 2 as a first inspection means, and a vulnerability result output device 3.However, the functions of each device may be implemented in device 1 or 2.
[0021] The network N may be any communication network to which each device can be connected, and the type of the network is not limited. In addition, there may be multiple types of networks between each device, and the network N may be composed of multiple types of networks (Ethernet, Internet, etc.).
[0022] The active scanning device 1 has a function of inspecting whether or not a target terminal 4, which is a terminal to be inspected, contains vulnerabilities.
[0023] The device identification device 2 has a function of monitoring packets sent and received by the test target terminal 4 on the network N, and determining the device type from the packet sending and receiving behavior (a wide variety of methods and algorithms can be applied to determine the device type). The device identification device 2 also has a function of notifying the active scan device 1 if the test target terminal 4 is determined to be a vulnerability assessment target. Since device identification is a static determination, it does not impose a load on the test target terminal 4. The device identification device 2 may be a function within a device that can manage the connection of the test target terminal 4 within the network N, such as a gateway.
[0024] The vulnerability result output device 3 has a function of outputting and displaying the results of the vulnerability test. For example, the vulnerability result output device 3 has a web browser in the device, and can use the browser to display information (the results of the vulnerability test) sent from the active scan device 1 on a screen, or can send input information to the active scan device 1 by inputting information on the displayed screen.
[0025] The inspection target terminal 4 is a communication terminal that is assigned an IP (Internet Protocol) address and a MAC (Media Access Control) address and is connectable to the network N. For example, the inspection target terminal 4 is an information processing terminal having a communication function, such as a PC (Personal Computer), a tablet, or a smartphone. In this embodiment, it is assumed that the inspection target terminal 4 is a "PC."
[0026] (A-1-2) Detailed configuration of active scan device 1 Fig. 1 is a block diagram showing the internal configuration of an active scanning device according to an embodiment. In Fig. 1, the active scanning device 1 includes a data receiving unit 11, a vulnerability testing unit 12 as a second testing means, a scan data generating unit 13, a test result generating unit 14, a control unit 15, a regular terminal information storage unit 16, a device identification result storage unit 17, a determination information storage unit 18, and a vulnerability test result storage unit 19.
[0027] The active scanning device 1 may be configured entirely in hardware (for example, using a dedicated semiconductor chip), or may be configured partially or entirely in software.
[0028] The data receiving unit 11 has a function of receiving the device identification result (device identification result data) of the test target terminal 4 transmitted by the device identification device 2. In addition, the data receiving unit 11 has a function of receiving the result of the active scan performed on the test target terminal 4.
[0029] The vulnerability inspection unit 12 has a function of determining the vulnerability inspection contents for performing an active scan on the inspection target terminal 4 that is the inspection target. The inspection contents are determined using the new connection data received from the equipment identification device 2 and the information in the authorized terminal information storage unit 16, the judgment information storage unit 18, and the vulnerability inspection result storage unit 19. The vulnerability inspection unit 12 uses, for example, a port scan, a password scan, etc. as the active scan.
[0030] The scan data generating unit 13 has a function of generating scan data for the vulnerability test contents determined by the vulnerability testing unit 12 using the data in the determination information storage unit 18 and transmitting the data to the test target terminal 4 .
[0031] The test result generating unit 14 has a function of generating results from the vulnerability test results in a format that can be displayed by the vulnerability result output device 3 and transmitting the results to the vulnerability result output device 3.
[0032] The control unit 15 has a function of determining the timing to start a vulnerability test, and when the timing to start a vulnerability test arrives, sending a test execution request to the vulnerability test unit 12. It is also possible to acquire the CPU utilization rate and load of the test target terminal 4, and delay the vulnerability start timing if there is a load.
[0033] The authorized terminal information storage unit 16 stores information about terminals (test target terminals 4) that are permitted to connect to the network.
[0034] Fig. 3 is an explanatory diagram showing an example of a regular terminal information storage unit according to an embodiment. As shown in Fig. 3, the regular terminal information storage unit 16 has the following items: "ID (Identification)" for identifying a terminal (test target terminal 4) permitted to connect to the network, "IP address" indicating the IP address of each test target terminal 4, "MAC address" indicating the MAC address of each device, and "device type" indicating the type (OS, etc.) of each device. Note that Fig. 3 is an example, and various configurations can be applied to the regular terminal information storage unit 16.
[0035] The above-mentioned device type is used to determine the vulnerability test contents as described below, and may be registered in advance for each device to be tested, or may be registered after the vulnerability results are obtained.
[0036] The device identification result storage section 17 stores the determination result of the device identification device 2.
[0037] Fig. 4 is an explanatory diagram showing an example of a device identification result storage unit according to an embodiment. As shown in Fig. 4, the device identification result storage unit 17 has items of "ID" for identifying the device identification result, "IP address" indicating the IP address of each test target terminal 4, "device type" indicating the type of each device (OS, etc.), and "timestamp" indicating the time of determination. Note that Fig. 4 is only an example, and various configurations can be applied to the configuration of the device identification result storage unit 17. Also, the "device type" here is the device type determined by the device identification device 2.
[0038] When the device identification device 2 of the active scanning device 1 performs device identification on the test target terminal 4 and receives the device identification result, the device identification device 2 assigns a new ID and additionally stores the result in the device identification result storage unit 17. The device identification result may be overwritten and stored instead of additionally stored. Also, if the device identification result cannot be determined, the device identification result may not be stored in the device identification result storage unit 17.
[0039] The determination information storage unit 18 stores (describes) a determination method related to vulnerability testing. For example, a password list is described in the determination information storage unit 18 for a password scan, and a port to be inspected is described in the determination information storage unit 18 for a port scan.
[0040] Fig. 5 is an explanatory diagram showing an example of a determination information storage unit according to an embodiment. In Fig. 5, the determination information storage unit 18 has the following items: "Test ID" for identifying the test contents, "Device Type" indicating the type of each device (OS, etc.), "Test Type" indicating a predetermined test type (password scan, port scan), "Test Command" which is a command for executing the predetermined test, "Test File Name" indicating a file name in which data, parameters, etc. required for the predetermined test are defined, and "Regular Result Output File" indicating a file in which a regular test result based on a predetermined test method is described. Note that Fig. 5 is an example, and various configurations can be applied to the configuration of the determination information storage unit 18.
[0041] 5, the target device type, test type, test command, test file name, and normal result output file are written for each test content in the determination information storage unit 18. If the initial password or port number used for each device is different, the accuracy of vulnerability testing is improved by writing each of them.
[0042] Regarding the method of using the judgment information storage unit 18, for example, when the vulnerability inspection unit 12 specifies the device (device type) to be inspected, all the corresponding inspection IDs are returned (notified). On the other hand, when an inspection ID is specified, it is possible to know what to inspect from the inspection type, and to obtain the inspection execution format from the inspection command and inspection file name. In addition, the vulnerability inspection unit 12 can compare the inspection result with the above-mentioned regular result output file and use it as a reference for vulnerability judgment.
[0043] Test ID1 (device type: unknown) and test ID6 (device type: unknown) shown in Figure 5 are test contents common to all terminals. Test ID5 and test ID8 are test contents for smart taps. Test ID2 can be common to all PCs, or test ID4 can be changed depending on the PC version.
[0044] By configuring the judgment information storage unit 18 as shown in Fig. 5, it is possible to respond flexibly, such as performing inspections with different port numbers used for each device type, or performing more detailed inspections than smart taps for PCs. The inspection file is created in advance and specified as the inspection file name, with the port numbers to be scanned described if a port scan is performed, or with a password list described if a password scan is performed.
[0045] The vulnerability test result storage unit 19 stores (describes) the results of the vulnerability test. FIG. 6 is an explanatory diagram showing an example of the vulnerability test result storage unit according to the embodiment. As shown in FIG. 6, the vulnerability test result storage unit 19 has the following items: "Test ID" for identifying the executed test, "Terminal ID" indicating an identifier (IP address or MAC address) for identifying the test target terminal 4, "Test time" indicating the time of the test, "OS" indicating the type of OS of the test target terminal 4, "Permitted OS" indicating whether the OS is permitted, "Password" indicating the password scan result, "Genuine terminal" indicating whether the terminal is genuine, and "Score" indicating the score of the vulnerability test. The above-mentioned permitted OS, password scan result, and genuine terminal items may be described by referring to, for example, a log file of the vulnerability test.
[0046] The vulnerability test result storage unit 19 records the above items for each vulnerability judgment. If a new vulnerability test is performed on the same terminal ID, the previous vulnerability result is overwritten or a new test ID is assigned and additionally saved. If additionally saved, the result is judged using multiple results from the same terminal, similar to the device identification result.
[0047] (A-2) Operation of the embodiment Next, characteristic operations in the vulnerability testing system 100 according to the embodiment will be described in detail with reference to the drawings.
[0048] FIG. 7 is a flowchart showing a vulnerability check in the vulnerability check system (mainly the active scan device 1) according to the embodiment.
[0049] <s101> The device identification device 2 monitors packets of the test target terminal 4 flowing through the network N, and when a determination is made, transmits device determination information (device determination result) to the active scanning device 1. The active scanning device 1 stores the device determination result acquired via the data receiving unit 11 in the device identification result storage unit 17.
[0050] The following vulnerability inspection will start at the saved timing. Alternatively, the control unit 15 of the active scanning device 1 may independently monitor the time elapsed since the previous inspection and determine the necessity of an unauthorized terminal inspection, instead of at the timing when the device identification information is received by the active scanning device 1. In any case, the timing of the vulnerability inspection is not particularly limited.
[0051] <s102> The active scanning device 1 (vulnerability inspection unit 12 ) extracts the IP address and the device type of the device identification result from the device identification result storage unit 17 .
[0052] When the vulnerability inspection unit 12 performs device identification multiple times for the same terminal and the device type is different, the latest result is prioritized. Also, when the vulnerability inspection unit 12 performs device identification three or more times, the most frequently performed device type result may be used as the result for the terminal.
[0053] For example, in the above-mentioned FIG. 4 (device identification result storage unit 17), a total of three sets of data, ID2, ID6, and ID8, are stored for a device with an IP address of "2.2.2.2." The device type is "PC OS ver1" twice and "PC OS ver2" once, so the device type is assumed to be "PC OS ver1" and used. Also, the data for a device with an IP address of "3.3.3.3" has two different device types. In this case, the device type is assumed to be the latest (data for ID7), "PC OS Ver3."
[0054] <s103> The vulnerability inspection unit 12 extracts regular terminal information of the corresponding terminal from the regular terminal information storage unit 16 and extracts past vulnerability inspection results of the corresponding terminal from the vulnerability inspection result storage unit 19 .
[0055] <s104> The vulnerability inspection unit 12 judges whether a vulnerability inspection (or an unauthorized terminal inspection) is necessary based on the device identification result, the authorized terminal information, and the past vulnerability inspection result. The vulnerability inspection unit 12 performs an inspection when a new inspection target terminal 4 is connected to the network, when the device type of the device identification result and the authorized terminal information is different, or when a vulnerability exists or the score is low in the past vulnerability inspection result.
[0056] 3 (authorized terminal information storage unit 16) and 4 (device identification result storage unit 17) are taken as examples. Since the device type of the IP address "1.1.1.1" is "PC gateway" in the authorized terminal information storage unit 16 and "PC OS ver1" in the device identification result storage unit 17, which are different, a vulnerability check is performed. Also, since the device type of the IP address "5.5.5.5" is not registered in the authorized terminal information (for example, because it has been connected to a new network), a vulnerability check is performed.
[0057] Furthermore, when the active scan device 1 independently monitors the time elapsed since the previous inspection and judges the necessity of inspection for unauthorized terminals, it determines that inspection is compulsorily necessary. If inspection is necessary, the vulnerability inspection unit 12 proceeds to step S105 described later, whereas if it determines that inspection is not necessary, it proceeds to step S107 described later.
[0058] <s105> If the vulnerability testing unit 12 determines in the processing of step S104 described above that testing is necessary, it performs an OS scan to determine the device for vulnerability testing, using the device identification result from the device identification device 2 (the device identification result stored in the device identification result storage unit 17).
[0059] FIG. 8 is a flowchart showing detailed processing of an OS scan in the vulnerability testing unit according to the embodiment.
[0060] <s105-1> The vulnerability inspection unit 12 extracts parameters (inspection file, etc.) required for the OS scan from the determination information storage unit 18 for the relevant address (the IP address of the device determined to require inspection in the process of step S104 described above).
[0061] For example, in the case of FIG. 5, the vulnerability test unit 12 extracts test parameters for test ID 7, in which the test type is "port" and the device type is "PC", in the OS scan.
[0062] <s105-2> The vulnerability inspection unit 12 performs an OS scan on the terminal at the address (test target terminal 4), performs a port scan, checks the port number in use, and determines the OS in use from the port in use.
[0063] <s105-3> The vulnerability inspection unit 12 outputs a device candidate list based on the result of the OS scan.
[0064] For example, the vulnerability inspection unit 12 outputs candidates 1 to 3 and calculates the device score for each. For the IP address "1.1.1.1", it is assumed that an OS scan has yielded three (OS, score) pairs, such as (PC gateway, 90), (PC OS ver2, 89), and (PC OS ver1, 88).
[0065] <s105-4> The vulnerability inspection unit 12 checks whether the OS scan result having the highest score, which is equal to or higher than a predetermined score, matches the OS of the device candidate in the device identification result.
[0066] If the two match, the vulnerability inspection unit 12 determines the matching OS as the device type. On the other hand, if the two do not match, the vulnerability inspection unit 12 returns to the above-mentioned S105-3 and similarly checks whether the result with the next highest score matches the determined device in the device identification result.
[0067] For example, in the example shown in step S105-3 above, with a score threshold of 80, the first time, the device identification result is "PC gateway", which is different from "PC OS ver1", so the process returns to S105-3. The second highest score, "PC OS ver2", is also different. Then, the third time, the third highest score, "PC OS ver1", is selected and is the same as the device identification result, so the vulnerability inspection unit 12 determines "PC OS ver 1" to be the device type.
[0068] If the device identification result does not determine the version but only determines that the device is a "PC," the process proceeds to the next step S105-5 with the highest score being "PC OS ver. 2."
[0069] <s105-5> The vulnerability inspection unit 12 determines the OS determination result. If there is no match even after checking up to five candidates (the number of candidates is not limited to five and is various) with a predetermined score or more, the vulnerability inspection unit 12 selects the device type with the highest score. In addition, the device type may be prioritized based on the device identification result.
[0070] <s105-6> The vulnerability testing unit 12 updates the data in the “OS” item of the relevant terminal in the vulnerability testing result storage unit 19 .
[0071] <s106> The vulnerability inspection unit 12 performs a vulnerability inspection on the determined device. After the vulnerability inspection, the vulnerability inspection unit 12 updates the contents of the corresponding terminal in the authorized terminal information storage unit 16 and the vulnerability inspection result storage unit 19.
[0072] Although a vulnerability test is performed in step S104 described above, if there is no corresponding vulnerability test as a result of step S105, it does not need to be performed.
[0073] FIG. 9 is a flowchart showing detailed processing of the vulnerability test in the vulnerability test section according to the embodiment (detailed processing of S106).
[0074] <s106-1> The vulnerability inspection unit 12 acquires, from the determination information storage unit 18, parameters for the vulnerability inspection to be performed for the relevant address using the device type determined in step S105 described above.
[0075] For example, for the IP address "1.1.1.1," a password scan with test ID 4, which is "PC OS ver 1," and a port scan with test ID 7, which is "PC," are selected.
[0076] In the example shown in step S105-3 above, if only the OS scan was performed, a password scan of test ID 3 would be selected, but by taking the device identification result into consideration, a password scan of test ID 4 would be selected.
[0077] <s106-2> The active scan device 1 (vulnerability inspection unit 12) performs vulnerability inspection. The active scan device 1 transmits data from the scan data generation unit 13 to the test target terminal 4, inputs response data from the test target terminal 4 to the vulnerability inspection unit 12 via the data reception unit 11, and judges vulnerabilities after transmitting and receiving all the scan data.
[0078] <s106-3> The vulnerability inspection unit 12 checks whether or not there are any tests that have not yet been performed among the vulnerability inspections that should be performed on the target device. If there are any tests that have not yet been performed, the vulnerability inspection unit 12 returns to step S106-1 and performs a vulnerability inspection. On the other hand, if all the tests that should be performed have been performed, the vulnerability inspection unit 12 executes the next step S106-4.
[0079] <s106-4> The vulnerability inspection unit 12 determines the judgment result and updates the contents of the corresponding terminal in the authorized terminal information storage unit 16 and the vulnerability inspection result storage unit 19. The line (data) to be described (updated) is the same line as in S105-6.
[0080] In determining whether a terminal is unauthorized, the vulnerability inspection unit 12 determines that the terminal is unauthorized by detecting an open port used by an unauthorized OS or unauthorized software through a port scan, or by detecting an unauthorized user through a password scan, etc. Also, a terminal may be determined to be unauthorized when the result of the vulnerability inspection is different from the results of other terminals already present in the network.
[0081] For example, in a base where only terminals with Windows (registered trademark) or Linux (registered trademark) operating systems are permitted to be connected, a terminal may be deemed to be unauthorized if the results of an OS scan are not similar to those of existing terminals. Also, for example, when the results of an OS scan using an existing tool do not allow for strict OS version information to be obtained, a terminal may be deemed unauthorized if the OS of the terminal is estimated to be clearly different from that of other terminals already existing in the network based on the character strings in the scan results. The anomaly score is determined according to the degree of unauthorizedness.
[0082] The IP address "1.1.1.1" was determined to be a "PC gateway" by the OS scan, but by taking into account the device identification results and performing a scan for "PC OS Ver 1", it is possible to shorten the vulnerability scan time and improve the accuracy of the vulnerability scan.
[0083] <s107> The inspection result generating unit 14 generates inspection results for the vulnerability result output device 3 , and transmits the generated inspection results to the vulnerability result output device 3 .
[0084] <s108> The vulnerability result output device 3 displays the received vulnerability inspection results.
[0085] FIG. 10 is an explanatory diagram showing an example of a vulnerability inspection result according to the embodiment.
[0086] 10, vulnerability test result display screen 200 includes a display field 210 that displays a summary message of the vulnerability test result, a display field 220 that displays each item of the vulnerability test result, detail buttons 230 (230-1 to 230-3) that display detailed results of each item, a retest button 240 that immediately re-executes a vulnerability test, and a regular information update button 250 that updates the IP address and device type of regular terminal information storage unit 16. Note that Fig. 10 is an example, and the displayed contents and layout, etc. are not limited to this.
[0087] 10 shows a case where the device is not a registered official terminal (does not use the official OS) and the password scan shows a vulnerability. In display field 220, the device (OS) is not the official "PC gateway" but "PC OS Ver 1", and the password check shows "NG".
[0088] (A-3) Effects of the embodiment According to this embodiment, the following effects are obtained.
[0089] The active scan device 1 uses the device identification results to correct the active scan method and the test results. This makes it easier to determine the OS in an OS scan and to handle password scans when the initial password is different depending on the device type. As a result, it is possible to reduce the load on the terminal, achieve early detection, and improve accuracy.
[0090] In addition, by referring to information about normally functioning devices and correcting the results of the vulnerability test, it is possible to obtain the effect of further improving the accuracy of the vulnerability test.
[0091] (B) Other embodiments Although various modified embodiments have been mentioned in the above-described embodiment, the present invention can also be applied to the following modified embodiments.
[0092] (B-1) The data types handled in the device information, the determination information, and the vulnerability testing information may include content other than that described in the above-described embodiment. In addition, some of the above-described information may be omitted.
[0093] (B-2) In the above embodiment, the determination result of device identification is input to the active scanning device 1, but the present invention may also be applied to the case where the vulnerability inspection result is input to the device identification device 2. [Explanation of symbols]
[0094] 1...active scan device, 2...equipment identification device, 3...vulnerability result output device, 4...terminal to be tested, 5...candidate, 11...data receiving unit, 12...vulnerability testing unit, 13...scan data generation unit, 14...test result generation unit, 15...control unit, 16...genuine terminal information storage unit, 17...equipment identification result storage unit, 18...judgment information storage unit, 19...vulnerability testing result storage unit, 100...vulnerability testing system, 200...vulnerability testing result display screen, 210, 220...display column, 230...details button, 240...retest button, 250...genuine information update button.
Claims
1. An inspection device that inspects vulnerabilities and / or fraud of one or more inspection target devices connected via a network, a first inspection means for detecting each of the inspection target devices newly connected to the network and for performing an identification process for each of the inspection target devices a plurality of times based on packets transmitted and received by each of the inspection target devices on the network, thereby determining a device type; a device identification result storage means for storing a device identification result including a device type of each of the test target devices determined by the first test means; a determination information storage means for storing vulnerability determination information for each device type, the vulnerability determination information describing the test contents for determining the vulnerability and / or fraud of each of the test target devices; a second inspection means for determining inspection contents for detecting vulnerability and / or fraud of a device by transmitting and receiving data between the inspection device and the device to be inspected using information on the device identification result stored in the device identification result storage means, and inspecting the device to be inspected based on the determined inspection contents; The second inspection means determines a corresponding inspection content from the vulnerability determination information based on the device type of the device identification result, Furthermore, when the contents of the device type of the plurality of device identification results related to the same test target device are different, the second inspection means uses the latest result or the result of the device type that is identified most frequently as the device identification result. An inspection device characterized by:
2. The second inspection means determines inspection contents from the vulnerability determination information using the device type determined by the first inspection means and the device type of each of the inspection target devices determined by operating system determination by transmitting and receiving data between the inspection device and the inspection target devices.
2. The inspection apparatus according to claim 1 .
3. retaining genuine terminal information, which is information on the inspection target device that has been permitted to connect to a network and determined to be a genuine terminal; The second inspection means determines the inspection contents taking into account the regular terminal information.
3. The inspection apparatus according to claim 1 or 2.
4. storing inspection result information which is information on the results of an inspection performed based on the inspection content determined by the second inspection means; The apparatus further includes an inspection result generating means for converting the inspection result information into a predetermined display format and outputting the converted information.
4. The inspection device according to claim 1, wherein the inspection device is a semiconductor laser.
5. 5. The inspection device according to claim 4, wherein the second inspection means determines inspection contents taking into account information on past inspection results stored in the inspection result information.
6. A computer installed in an inspection device that inspects vulnerabilities and / or fraud of one or more inspection target devices connected via a network, a first inspection means for detecting each of the inspection target devices newly connected to the network and for performing an identification process for each of the inspection target devices a plurality of times based on packets transmitted and received by each of the inspection target devices on the network, thereby determining a device type; a device identification result storage means for storing a device identification result including a device type of each of the test target devices determined by the first test means; a determination information storage means for storing vulnerability determination information for each device type, the vulnerability determination information describing the test contents for determining the vulnerability and / or fraud of each of the test target devices; using information on the device identification result stored in the device identification result storage means, determining inspection contents for detecting vulnerability and / or fraud of the device by transmitting and receiving data between the inspection device and the device to be inspected, and functioning as a second inspection means for inspecting the device to be inspected based on the determined inspection contents; The second inspection means determines a corresponding inspection content from the vulnerability determination information based on the device type of the device identification result, Furthermore, when the contents of the device type of the plurality of device identification results related to the same test target device are different, the second inspection means uses the latest result or the result of the device type that is identified most frequently as the device identification result. An inspection program characterized by:
7. 1. A testing method for use in a testing device that tests vulnerabilities and / or fraud in one or more test target devices connected via a network, comprising: The inspection device includes a first inspection means, an equipment identification result storage means, a determination information storage means, and a second inspection means, The first inspection means detects each of the inspection target devices newly connected to the network, and performs an identification process for each of the inspection target devices multiple times based on packets transmitted and received by each of the inspection target devices on the network, thereby determining the device type; The device identification result storage means stores a device identification result including a device type of each of the test target devices determined by the first test means, Vulnerability determination information is stored for each device type, the information describing the inspection content for determining the vulnerability and / or fraud of each of the inspection target devices; The second inspection means uses the information of the device identification result stored in the device identification result storage means to determine inspection contents for detecting vulnerability and / or fraud of the device by transmitting and receiving data between the inspection device and the inspection target device, and inspects the inspection target device based on the determined inspection contents; The second inspection means determines a corresponding inspection content from the vulnerability determination information based on the device type of the device identification result, Furthermore, when the contents of the device type of the plurality of device identification results related to the same test target device are different, the second inspection means uses the latest result or the result of the device type that is identified most frequently as the device identification result.
13. An inspection method comprising:
Citation Information
Patent Citations
Network connection management system
JP2006018766A
Virus detection system
JP2007226365A
Network quarantine system
JP2009169781A
Diagnostic program, diagnostic method and diagnostic apparatus
JP2017068691A