Information processing system, information processing method, and information processing program

By combining the collaborative work of high- and low-level network equipment in the information processing system, the problems of high cost and insufficient security of terminal equipment in the prior art are solved, and the effects of improving security and reducing costs are achieved.

JP7675148B2Active Publication Date: 2025-05-12NTT DOCOMO BUSINESS INC
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2023175593
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2023-03-03
Filing Date
2023-10-10
Publication Date
2025-05-12
Estimated Expiration
2043-06-30

AI Technical Summary

Technical Problem

The prior art has problems of high cost and insufficient security in the security measures of terminal devices such as computers and servers, especially in office automation equipment and Internet of Things equipment that cannot be deployed in EDR, there is a security risk and there is a possibility of false detection, and the terminal devices with normal functions are incorrectly detected as illegal terminals.

Method used

An information processing system consisting of an overlay network and a low-level network device is adopted. The system includes units and notification units for detecting illegal communications. By detecting illegal communications and notifying the subordinate network devices, the subordinate network devices analyze the communication information of the terminal equipment to determine whether the degree of communication variation exceeds a predetermined threshold, thereby determining whether it is an error detection and cutting off illegal communications based on the results.

Benefits of technology

The effect of improving security and reducing costs is achieved. By accurately analyzing and controlling the communication of terminal devices, the security risks brought about by mistake are avoided, and the effective cut-off of illegal communications is achieved without affecting the availability of the entire network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007675148000001
    Figure 0007675148000001
  • Figure 0007675148000002
    Figure 0007675148000002
  • Figure 0007675148000003
    Figure 0007675148000003
Patent Text Reader

Abstract

To achieve improved security and reduced costs.SOLUTION: An information processing system 1 is an information processing system including an upper-level NW device 100, which is a device that makes up an overlay network, and a lower-level NW device 200, which is a device that makes up an underlay network. The upper-level network device 100 detects unauthorized communication and notifies the lower-level network device 200 of information on the detected unauthorized communication. The lower-level NW device 200 acquires information about communication of a terminal connected to the lower-level NW device 200, determines the degree of variation between multiple pieces of flow data in the underlay network whose destination address is the same as the notified information on the unauthorized communication, and blocks the notified information on the unauthorized communication as unauthorized communication according to the determined degree of variation.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] The present invention relates to an information processing system, an information processing method, and an information processing program. [Background technology]

[0002] Conventionally, there are security countermeasure technologies for end terminals such as personal computers and servers. For example, a technology that detects suspicious communications and behaviors at the end terminals using EDR (Endpoint Detection and Response) is known. [Prior art documents] [Non-patent literature]

[0003] [Non-Patent Document 1] ICT Business Online What is EDR, a trending IT term that you may not know? [Searched June 20, 2023], Internet (https: / / www.ntt.com / bizon / glossary / ee / edr.html) Summary of the Invention [Problem to be solved by the invention]

[0004] Conventional technologies have had problems in terms of cost and security. For example, EDR is expensive because it needs to be installed on each terminal. Also, for OA (Office Automation) devices and IoT (Internet of Things) terminals that cannot be equipped with EDR, measures are not taken, and security risks remain. Furthermore, there are cases where a terminal that is functioning normally is mistakenly detected as an unauthorized terminal, or a normal communication destination from a terminal that is functioning normally is mistakenly detected as an unauthorized communication destination.

[0005] The present invention has been made in view of the above, and has an object to provide an information processing system, an information processing method, and an information processing program for improving security and reducing costs. [Means for solving the problem]

[0006] In order to solve the above-mentioned problems and achieve the object, the information processing system of the present invention is an information processing system consisting of an upper network device which is a device constituting an overlay network and a lower network device which is a device constituting an underlay network, wherein the upper network device has a detection unit which detects unauthorized communications and a notification unit which notifies the lower network device of information on the unauthorized communications detected by the detection unit, and the lower network device has a determination unit which calculates a degree of variation between multiple flow data in the underlay network which have the same destination address as the information on the unauthorized communications notified by the notification unit, determines whether the degree of variation is equal to or greater than a predetermined threshold, and determines that the detection is a false positive if the degree of variation is equal to or greater than the predetermined threshold, and a blocking unit which determines that the detection is not a false positive if the degree of variation determined by the determination unit is less than the predetermined threshold, and blocks the information on the unauthorized communications notified by the notification unit as unauthorized communications using information on communications of terminals connected to the lower network device. Effect of the Invention

[0007] According to the present invention, it is possible to improve security and reduce costs. [Brief description of the drawings]

[0008] [Figure 1] FIG. 1 is a diagram for explaining the prior art. [Diagram 2] FIG. 2 is a diagram illustrating an example of the configuration of the information processing system according to the embodiment. [Diagram 3] FIG. 3 is a diagram for explaining an example of the configuration of a higher-level NW device according to the embodiment. [Figure 4] FIG. 4 is a diagram for explaining an example of the configuration of a lower NW device according to the embodiment. [Diagram 5]FIG. 5 is a diagram for explaining an overview of the process performed by the information processing system according to the embodiment. [Figure 6] FIG. 6 is a diagram for explaining an example of the detection process and the determination process performed by the information processing system according to the embodiment. [Figure 7] FIG. 7 is a diagram for explaining an example of the detection process and the determination process performed by the information processing system according to the embodiment. [Figure 8] FIG. 8 is a diagram for explaining an example of the detection process and the determination process performed by the information processing system according to the embodiment. [Figure 9] FIG. 9 is a diagram for explaining an example of a blocking process performed by the information processing system according to the embodiment. [Figure 10] FIG. 10 is a diagram for explaining an example of a blocking process by the information processing system according to the embodiment. [Figure 11] FIG. 11 is a flowchart for explaining an example of the flow of processing by the information processing system according to the embodiment. [Figure 12] FIG. 12 is a diagram illustrating an example of a computer that executes an information processing program. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS

[0009] Hereinafter, an embodiment of an information processing system, an information processing method, and an information processing program according to the present application will be described in detail with reference to the drawings. Note that the present invention is not limited to the embodiment. In addition, in the description of the drawings, the same parts are denoted by the same reference numerals, and duplicated explanations will be omitted.

[0010] [Prior Art] First, the conventional technology will be described with reference to Fig. 1. Fig. 1 is a diagram for explaining the conventional technology.

[0011] In the following, the devices that make up the overlay network are referred to as upper network devices, and the devices that make up the underlay network are referred to as lower network devices. Here, the upper network devices refer to, for example, cloud proxy servers and UTM (Unified Threat Management). The lower network devices refer to, for example, network devices such as DPI (Deep Packet Inspection), routers, and switches.

[0012] Previous security measures divided networks into a trusted "inside" and an untrusted "outside," and measures were taken at the border between these two locations. For example, an internal network would be an in-house LAN (Local Area Network) or a data center connected via a VPN (Virtual Private Network), while an external network would be the Internet. For example, measures taken at the border include installing security devices such as firewalls, proxies, and IDS (Intrusion Detection System) / IPS (Intrusion Prevention System) at the border to block cyber attacks from outside by monitoring and controlling communications.

[0013] These conventional security measures are based on the premise that the data and systems to be protected are inside the network. However, with the spread of cloud computing, it is not uncommon to find that things to be protected are on the outside, on the Internet. As the objects to be protected are now scattered in various places, the boundaries have become blurred, and it is becoming difficult to take sufficient measures using conventional thinking.

[0014] This is why the idea of ​​zero trust is becoming more widespread. Zero trust security services implement various security measures based on the premise that all communications are not trusted. Specifically, this includes encrypting communication paths that are not related to whether they are inside or outside the network, strengthening user authentication by using multi-factor authentication, and comprehensive log monitoring of networks and the various devices connected to them. Many security solutions to realize zero trust have already appeared. For example, EDR is being installed, which enables early detection and response to cyber attacks by monitoring client devices and analyzing logs.

[0015] As a security measure for end-user devices such as PCs and servers, technology that uses EDR to detect suspicious communications and behavior at the end is known.

[0016] However, conventional technologies have problems in terms of cost and security. For example, EDR is expensive because it needs to be installed on each terminal. In addition, measures are not taken for office equipment or IoT terminals that cannot be equipped with EDR, and security risks remain. Furthermore, terminals that are functioning normally may be mistakenly detected as unauthorized terminals.

[0017] Therefore, the information processing system 1 of the present embodiment described below is an information processing system consisting of an upper network device 100, which is a device that constitutes an overlay network, and a lower network device 200, which is a device that constitutes an underlay network, in which the upper network device 100 detects unauthorized communication and notifies the lower network device 200 of information about the detected unauthorized communication, and the lower network device 200 acquires information about communication of a terminal connected to the lower network device 200, determines the degree of variation between the notified information about unauthorized communication and multiple flow data in the underlay network that have the same destination address, and blocks the notified information about unauthorized communication as unauthorized communication depending on the determined degree of variation.

[0018] Such an information processing system can reduce costs and improve security. In addition, by blocking communications from terminals that are conducting unauthorized communications, it is possible to control communications on a device-by-device basis without blocking the entire network, thereby ensuring network availability and achieving robust security.

[0019] In addition, information processing system 1 provides a zero trust security service unique to a line operator (carrier), in which the underlay network and overlay network work together to provide defense in an ICT (Information and Communication Technology) environment that is becoming increasingly complex and posing increasing cyber risks due to new working styles such as remote work and new business expansion through the use of IoT, etc.

[0020] The information processing system 1 provides a secure NaaS (Network as a Service) type ICT service in which the functions of the overlay network and the underlay network are closely integrated. Companies that use the services of this information processing system 1 can easily start, change, and cancel the services of this information processing system 1 instantly by applying through the management portal site, without having to spend costs on outsourcing to an IT (Information Technology) vendor or on network design, making it possible to reduce costs from design to operation.

[0021] In the information processing system 1, the overlay network and the underlay network are provided by the same company. Also, a user of the information processing system 1 can flexibly use the system by, for example, using only the overlay network and using another company's network for the underlay network.

[0022] [Information processing system configuration] Next, the configuration of the information processing system 1 will be described with reference to Fig. 2. As shown in Fig. 2, the information processing system 1 has an upper NW device 100 and a lower NW device 200. Each of these devices will be described below. Note that the information processing system 1 is not limited to having only one upper NW device 100 and one lower NW device 200, and may have multiple devices.

[0023] The upper network device 100 is a device that controls a higher-level network of the information processing system 1. The upper network device 100 detects unauthorized communication and notifies the lower network device 200 of the detection.

[0024] The lower NW device 200 is a device that controls a lower network of the information processing system 1. The lower NW device 200 determines whether the information on unauthorized communication notified from the upper NW device 100 is a false positive, and blocks the unauthorized communication if it is not a false positive. On the other hand, if it is a false positive, it deletes the information on the unauthorized communication used for the detection.

[0025] [Configuration of upper network device] Next, the configuration of the upper network device 100 will be described with reference to Fig. 3. As shown in Fig. 3, the upper network device 100 has a communication unit 110, a control unit 120, and a storage unit 130. These units may be held in a distributed manner in multiple devices. The processing of these units will be described below.

[0026] The communication unit 110 is realized by a NIC (Network Interface Card) or the like, and enables communication between an external device and the control unit 120 via an electric communication line such as a LAN (Local Area Network) or the Internet. For example, the communication unit 110 enables communication between the external device and the control unit 120.

[0027] The storage unit 130 is realized by a semiconductor memory element such as a random access memory (RAM) or a flash memory, or a storage device such as a hard disk or an optical disk. The information stored in the storage unit 130 includes, for example, terminal information managed by the upper NW device 100, terminal information managed by the lower NW device 200, information on unauthorized communication used for detection, information on unauthorized communication used for determining false detection, information on detected unauthorized communication, and other information necessary for blocking unauthorized communication. Here, the information on unauthorized communication used for detection includes information such as terminal information of the communication destination of the unauthorized communication and IP address of the communication destination of the unauthorized communication. Furthermore, the information on unauthorized communication used for determining false detection includes information such as the content of communication involving the lower NW device 200 and information on cyber attacks. Note that the information stored in the storage unit 130 is not limited to the above-mentioned examples.

[0028] Here, the information regarding unauthorized communications used to determine whether a communication is a false positive refers to multiple flow data in the underlay network that have the same destination address as the unauthorized communication detected in the overlay network.

[0029] The control unit 120 is realized using a CPU (Central Processing Unit), an NP (Network Processor), an FPGA (Field Programmable Gate Array), etc., and executes a processing program stored in a memory. As shown in Fig. 3, the control unit 120 has a detection unit 121 and a notification unit 122. Each unit of the control unit 120 will be described below.

[0030] The detection unit 121 detects unauthorized communication. For example, the detection unit 121 detects unauthorized communication by a security function. For example, the detection unit 121 detects unauthorized communication by a security function of a UTM.

[0031] For example, when the IP address of the destination of a packet matches the IP address of an unauthorized communication stored in advance in the storage unit 130, the detection unit 121 detects the communication as unauthorized communication and identifies the IP address of the destination as the IP address of the unauthorized communication destination. Note that the detection unit 121 may detect unauthorized communication not only by IP address but also by using the communication date and time, the behavior of packets observed in attacks such as a Distributed Denial of Service (DDoS) attack, a SYN flooding attack, a buffer overflow attack, or the like, or may use any other existing detection method.

[0032] The notification unit 122 notifies the downstream NW device 200 of information on unauthorized communication detected by the detection unit 121. For example, the notification unit 122 notifies the downstream NW device 200 of information on unauthorized communication detected by the detection unit 121, such as the detection date and time of the unauthorized communication, the detection type, the destination IP address and port, and the source IP address and port.

[0033] For example, the notification unit 122 uses information on unauthorized communication detected by the detection unit 121 to identify the destination of the unauthorized communication, and notifies the identified destination of the unauthorized communication to the downstream NW device 200. Note that the "destination IP address / port" refers to a destination IP address and a destination port, or both, and the "source IP address / port" refers to a source IP address and a source port, or both,.

[0034] [Configuration of lower level network devices] Next, the configuration of the lower NW device 200 will be described with reference to Fig. 4. As shown in Fig. 4, the lower NW device 200 has a communication unit 210, a control unit 220, and a storage unit 230. These units may be held in a distributed manner in a plurality of devices. The processing of each unit will be described below.

[0035] The communication unit 210 is realized by a NIC or the like, and enables communication between an external device and the control unit 220 via an electric communication line such as a LAN or the Internet. For example, the communication unit 210 enables communication between the external device and the control unit 220.

[0036] The storage unit 230 is realized by a semiconductor memory element such as a RAM or a flash memory, or a storage device such as a hard disk or an optical disk. Examples of information stored in the storage unit 230 include terminal information managed by the upper NW device 100, terminal information managed by the lower NW device 200, information on communication of terminals connected to the lower NW device 200, information on unauthorized communication used for detection, information on unauthorized communication used for determining false detection, information on detected unauthorized communication, and other information necessary for blocking unauthorized communication. Here, the information on unauthorized communication used for detection includes information such as terminal information of the communication destination of the unauthorized communication and IP address of the communication destination of the unauthorized communication. Furthermore, the information on unauthorized communication used for determining false detection includes information such as the content of communication involving the lower NW device 200 and information on cyber attacks. Note that the information stored in the storage unit 230 is not limited to the above-described examples.

[0037] The control unit 220 is realized using a CPU, an NP, an FPGA, or the like, and executes a processing program stored in a memory. As shown in Fig. 4, the control unit 220 has an acquisition unit 221, a determination unit 222, a blocking unit 223, and a deletion unit 224. Each unit of the control unit 220 will be described below.

[0038] The acquiring unit 221 acquires information related to communication of terminals connected to the lower NW device 200. For example, the acquiring unit 221 acquires information related to communication of OA devices and IoT devices connected to the lower NW device 200.

[0039] The determination unit 222 determines the degree of variation between a plurality of flow data in an underlay network having the same destination address as the information on unauthorized communication notified by the notification unit 122. For example, the determination unit 222 calculates the degree of variation between a plurality of flow data in an underlay network having the same destination address as the information on unauthorized communication notified by the notification unit 122, determines whether the degree of variation is equal to or greater than a predetermined threshold, and determines that a false detection has occurred if the degree of variation is equal to or greater than the predetermined threshold. The information on the flow data may be data acquired from each communication device in the underlay NW, or may be data stored in an external device.

[0040] Here, a specific example of a method for calculating the degree of variation by the determining unit 222 will be described. For example, the determining unit 222 acquires flow data containing information on unauthorized communication notified by the notifying unit 122, the destination IP address of which is the same.

[0041] Then, the determination unit 222 calculates the degree of variation based on one or more of the communication date and time between the flow data, the destination port number, the communication protocol, and the number of transferred bytes. For example, when the determination unit 222 calculates the degree of variation based on the destination port number, the communication protocol, and the number of transferred bytes, the determination unit 222 determines whether the ratio of records in which the destination port number, the communication protocol, and the number of transferred bytes do not match is equal to or greater than a predetermined threshold (e.g., 50%) for all acquired flow data, and if it is equal to or greater than the predetermined threshold, determines that the detection result in the overlay network is a false positive. Note that the determination unit 222 is not limited to this method of calculating the degree of variation, and may count the number of mismatched records instead of the ratio of mismatched records to determine whether it is equal to or greater than a predetermined threshold. Here, the information may match only partially or completely.

[0042] Also, for example, when the determination unit 222 calculates the degree of variation using the communication dates and times between flow data, the determination unit 222 may arrange the communication dates and times in order from oldest to newest, calculate the average value of the differences between the communication dates and times between data with close communication dates and times, and determine whether the average value is equal to or greater than a predetermined threshold value (e.g., one minute).If the average value is equal to or greater than the predetermined threshold value, the determination unit 222 may determine that the detection result in the overlay network is a false positive.

[0043] In other words, when unauthorized communication with, for example, a C2 server (Command and Control server) is detected in an overlay network, the judgment unit 222 judges the degree of variation among multiple flow data in an underlay network that has the same destination address as the communication in question, and if the variation is large, it is deemed to be a false positive rather than unauthorized communication with a C2 server.

[0044] The blocking unit 223 blocks the information of the unauthorized communication notified by the notification unit 122 as unauthorized communication, depending on the degree of variation determined by the determination unit 222. For example, when the determination unit 222 determines that the degree of variation is less than a predetermined threshold, the blocking unit 223 determines that the detection is not a false positive, and blocks the information of the unauthorized communication notified by the notification unit 122 as unauthorized communication.

[0045] For example, when the judgment unit 222 judges that the degree of variation is less than a predetermined threshold, the blocking unit 223 blocks communication to the destination of the unauthorized communication using information on the source IP address and port of the unauthorized communication notified by the notification unit 122 and information on the destination and source IP address and port of the terminal connected to the lower NW device 200 acquired by the acquisition unit 221.

[0046] Furthermore, for example, when the determination unit 222 determines that the degree of variation is less than a predetermined threshold, the blocking unit 223 blocks communication from the source of the unauthorized communication by using the information on the unauthorized communication notified by the notification unit 122. For example, when the determination unit 222 determines that the degree of variation is less than a predetermined threshold, the blocking unit 223 blocks communication from the terminal performing the unauthorized communication by using the information on the source IP address and port of the unauthorized communication notified by the notification unit 122 and the information on the destination and source IP address and port of the terminal connected to the lower NW device 200 acquired by the acquisition unit 221.

[0047] Furthermore, for example, when the determination unit 222 determines that the degree of variation is less than a predetermined threshold, the blocking unit 223 blocks communication from a NW including a source of the unauthorized communication, using the information on the unauthorized communication notified by the notification unit 122. For example, when the determination unit 222 determines that the degree of variation is less than a predetermined threshold, the blocking unit 223 blocks communication from a NW including a terminal performing unauthorized communication, using the information on the source IP address and port of the unauthorized communication notified by the notification unit 122 and the information on the destination and source IP address and port of the terminal connected to the lower NW device 200 acquired by the acquisition unit 221.

[0048] When the determination unit 222 determines that the degree of variation is equal to or greater than a predetermined threshold, the deletion unit 224 notifies the upper NW device 100 of an instruction to delete information related to unauthorized communications used for detection. For example, when the determination unit 222 determines that no action should be taken, the deletion unit 224 notifies the upper NW device 100 of an instruction to delete the content of communications involving the lower NW device 200 and information about cyber attacks as information related to unauthorized communications used for detection.

[0049] The information on unauthorized communications used for the false detection to be deleted by the deletion unit 224 may be stored in the upper network device 100 or an external device.

[0050] [Outline of processing by information processing system] Next, an overview of the processing by the information processing system 1 will be described with reference to Fig. 5. Fig. 5 is a diagram for explaining an overview of the processing by the information processing system 1.

[0051] First, the acquisition unit 221 of the lower NW device 200 acquires information on communication of a terminal connected to the lower NW device 200. For example, information on communication of an OA device, an IoT device, or the like connected to the lower NW device 200 is acquired.

[0052] Next, the detection unit 121 of the upper network device 100 detects unauthorized communication.

[0053] Next, the notification unit 123 of the upper network device 100 notifies the lower network device 200 of information on the unauthorized communication detected by the detection unit 121 .

[0054] Next, the determination unit 222 determines whether the unauthorized communication information notified by the notification unit 122 corresponds to the unauthorized communication information used to determine whether or not a false detection has occurred.

[0055] Then, when the determining unit 222 determines that a countermeasure should be taken, the blocking unit 223 blocks communication of the terminal performing the unauthorized communication based on the information of the unauthorized communication notified by the notifying unit 122 .

[0056] On the other hand, if the determination unit 222 determines that no action is taken, the deletion unit 224 notifies the upper network device 100 of an instruction to delete information related to the unauthorized communication.

[0057] In this manner, in the information processing system 1, the upper network device 100 and the lower network device 200 work closely together to detect, determine, and block unauthorized communications.

[0058] [Detection and judgment processing by information processing system] Next, the detection process and the determination process performed by the information processing system 1 will be described with reference to Fig. 6. Fig. 6 is a diagram for explaining the detection process and the determination process performed by the information processing system 1.

[0059] 6(1) shows information on unauthorized communications used for detection, such as the type of unauthorized communication destination and IP address. The location where the information on unauthorized communications used for detection is stored may be the storage unit 130 of the upper network device 100, in addition to the cloud proxy of the upper network device 100.

[0060] The detection unit 121 of the upper network device 100 detects unauthorized communication using information such as the type and IP address of the unauthorized communication destination stored in the cloud proxy, as shown in Fig. 6(2). Fig. 6(2) illustrates an example of information on communication detected as unauthorized communication by the detection unit 121.

[0061] Then, the determination unit 222 of the downstream NW device 200 determines the degree of variation among a plurality of flow data in the underlay network having the same destination address as the information on the unauthorized communication notified by the notification unit 122. In Fig. 6 (3), a plurality of flow data in the underlay network having the same destination address as the information on the unauthorized communication notified by the notification unit 122 is illustrated.

[0062] For example, the determination unit 222 calculates the degree of variation between multiple flow data in an underlay network that has the same destination address as the information on fraudulent communication notified by the notification unit 122, determines whether the degree of variation is greater than or equal to a predetermined threshold, and if the degree of variation is greater than or equal to the predetermined threshold, determines that it is a false positive.

[0063] For example, when calculating the degree of variation based on the destination port number, the communication protocol, and the number of transferred bytes, the judgment unit 222 judges whether the ratio of the number of records in which the destination port number, the communication protocol, and the number of transferred bytes do not all match for all the acquired flow data is a predetermined threshold value (e.g., 50%) or more, and if it is the predetermined threshold value or more, it judges that the detection result in the overlay network is a false positive.

[0064] 7, out of the 10 flow data, there is one record in which the destination port number, communication protocol, and number of transferred bytes all do not match, and the percentage is about "10%," so the determining unit 222 determines that the degree of variation is less than the predetermined threshold "50%. In other words, the determining unit 222 determines that the variation is not large, and the detection result in the overlay network is not considered to be a false detection. In this case, the blocking unit 223 blocks the unauthorized communication based on the information of the unauthorized communication notified by the notifying unit 122.

[0065] Also, for example, in the example of Fig. 8, out of the 10 flow data, there are 8 records in which the destination port number, communication protocol, and number of transferred bytes do not all match, which is about "80%". Therefore, the determining unit 222 determines that the degree of variation is equal to or greater than the predetermined threshold "50%". In other words, the determining unit 222 determines that the variation is large, and the detection result in the overlay network is considered to be a false detection. In this case, the deleting unit 224 notifies the upper NW device 100 to delete the information (Fig. 8(1)) related to unauthorized communication used for detection.

[0066] [Blocking by information processing system] Next, the cutoff process by the information processing system 1 will be described with reference to Fig. 9 and Fig. 10. Fig. 9 and Fig. 10 are diagrams for explaining the cutoff process by the information processing system 1.

[0067] The blocking unit 223 of the downstream NW device 200 uses the detection information of the unauthorized communication to block the unauthorized communication by DPI, as shown in FIG.

[0068] Figure 10(1), like Figure 6(1), shows information about unauthorized communications used for detection, such as the type of unauthorized communication destination and IP address. Also, Figure 10(2), like Figure 6(2), shows information about detected unauthorized communications.

[0069] 10(3), the blocking unit 223 of the downstream NW device 200 uses the detection information of the unauthorized communication destination (IP address and port of the connection destination of the unauthorized communication) to block the communication with the unauthorized communication destination by DPI. This allows the information processing system 1 to block the communication with the unauthorized communication destination early.

[0070] In other words, to explain using the example of FIG. 10(3), the blocking unit 223 blocks communication in which the destination IP address "203.0.113.15" transmitted from the upper network device 100 matches the destination IP address.

[0071] 10(4), the blocking unit 223 of the downstream NW device 200 uses detection information of the unauthorized communication destination (source IP address and port of the unauthorized communication) to block communication from the terminal performing the unauthorized communication by DPI. In this way, the information processing system 1 blocks the infected terminal and prevents the spread of infection.

[0072] In other words, to explain using the example of FIG. 10(4), the blocking unit 223 blocks communication in which the source IP address "192.0.2.118" transmitted from the upper network device 100 matches the source IP address.

[0073] 10(5), the blocking unit 223 of the downstream network device 200, for example, uses detection information of the unauthorized communication destination (source IP address and port of the unauthorized communication) to block communication from the network including the terminal performing the unauthorized communication by DPI. In this way, the information processing system 1 blocks the network to which the infected terminal belongs, and prevents the spread of infection.

[0074] 10(5) as an example, the notification unit 122 converts the source IP address "192.0.2.118" sent from the upper network device 100 to the IP address "192.0.2.0 / 24" masked with a subnet mask, and notifies the lower network device 200 of the source IP address "192.0.2.0 / 24". The blocking unit 223 then blocks communications where the source IP address corresponds to "192.0.2.0 / 24", thereby blocking not only the infected terminal but also the NW to which the infected terminal belongs.

[0075] In this manner, in the information processing system 1, the upper network device 100 and the lower network device 200 cooperate with each other to detect unauthorized communications and block each communication involving a terminal performing unauthorized communications.

[0076] [flowchart] Next, the flow of processing by the information processing system 1 will be described with reference to Fig. 11. Note that the steps below may be executed in a different order, and some processing may be omitted.

[0077] First, the acquisition unit 221 of the lower NW device 200 acquires information on communication of a terminal connected to the lower NW device 200 (step S101). For example, the acquisition unit 221 acquires information on communication of an OA device or an IoT device connected to the lower NW device 200.

[0078] Next, the acquiring unit 221 of the lower NW device 200 transmits the acquired information to the upper NW device 100 (step S102). Next, the detecting unit 121 of the upper NW device 100 detects unauthorized communication (step S103). For example, the detecting unit 121 detects unauthorized communication by a security function.

[0079] Next, the notification unit 122 of the upper NW device 100 notifies the lower NW device 200 of information on the unauthorized communication detected by the detection unit 121 (step S104). For example, the notification unit 122 notifies the lower NW device 200 of information on the unauthorized communication detected by the detection unit 121, such as the detection date and time of the unauthorized communication, the detection type, the destination IP address and port, and the source IP address and port.

[0080] Next, the determination unit 222 of the downstream NW device 200 calculates the degree of variation between the flow data having the same destination address as the information on the unauthorized communication notified by the notification unit 122 (step S105). For example, the determination unit 222 calculates the degree of variation based on one or more of the communication date and time, the destination port number, the communication protocol, and the number of transferred bytes between the flow data having the same destination address as the information on the unauthorized communication notified by the notification unit 122.

[0081] Next, the determination unit 222 of the lower NW device 200 determines whether the calculated degree of variation is equal to or greater than a predetermined threshold (step S106). If the determination unit 222 determines that the degree of variation is not equal to or greater than the predetermined threshold (step S106 "NO"), the cutoff unit 223 of the lower NW device 200 cuts off the unauthorized communication based on the information of the unauthorized communication notified by the notification unit 122 (step S107). For example, the cutoff unit 223 uses the information of the unauthorized communication notified by the notification unit 122 to cut off communication to a destination of the unauthorized communication.

[0082] On the other hand, if the determination unit 222 determines that the amount is less than the predetermined threshold ("YES" in step S106), the deletion unit 224 of the lower NW device 200 notifies the deletion of information related to unauthorized communications used for detection (step S108). For example, if the determination unit 222 determines that no action should be taken, the deletion unit 224 notifies the upper NW device 100 of an instruction to delete the content of communications involving the lower NW device 200 and information about cyber attacks as information related to unauthorized communications used for detection.

[0083] [effect] The information processing system 1 according to the embodiment is an information processing system including an upper network device 100 which is a device constituting an overlay network, and a lower network device 200 which is a device constituting an underlay network. The upper network device 100 has a detection unit 121 which detects unauthorized communications, and a notification unit 122 which notifies the lower network device 200 of information on unauthorized communications detected by the detection unit 121. The lower network device 200 has an acquisition unit 221 which acquires information on communications of a terminal connected to the lower network device 200, a determination unit 222 which determines the degree of variation between multiple flow data in an underlay network having the same destination address as the information on unauthorized communications notified by the notification unit 122, and a blocking unit 223 which blocks the information on unauthorized communications notified by the notification unit 122 as unauthorized communications depending on the degree of variation determined by the determination unit 222.

[0084] As a result, in the information processing system 1, the upper network device 100 detects unauthorized communication, the lower network device 200 determines the degree of variation, and the lower network device 200 blocks the communication according to the degree of variation, thereby improving security and reducing costs. Also, in the information processing system 1, by separating the detection point and the blocking point, for example, when an attack by a large-scale botnet occurs and the upper network device 100 detects communication of the C2 server of the botnet, it is possible to block the communication over a wide area with the underlay network even if an overlay network is not used, thereby minimizing damage.

[0085] Furthermore, the information processing system 1 achieves robust security while ensuring the availability of the network by controlling communications on a device-by-device basis, without cutting off communications from terminals performing unauthorized communications, without cutting off the entire network.

[0086] The determination unit 222 in the lower NW device 200 of the information processing system 1 according to the embodiment calculates the degree of variation between multiple flow data in the underlay network having the same destination address as the information of the unauthorized communication notified by the notification unit 122, determines whether the degree of variation is equal to or greater than a predetermined threshold, and if the degree of variation is equal to or greater than the predetermined threshold, determines that it is a false positive. If the determination unit 222 determines that the degree of variation is less than the predetermined threshold, the blocking unit 223 determines that it is not a false positive and blocks the information of the unauthorized communication notified by the notification unit 122 as unauthorized communication.

[0087] As a result, the information processing system 1 checks whether or not there has been a false positive based on whether or not the degree of variation in flow data having the same destination address as the information on unauthorized communication detected by the upper network device 100 exceeds a threshold, and by blocking communication to the destination of the unauthorized communication, it is possible to improve security and reduce costs.

[0088] The determining unit 222 in the lower NW device 200 of the information processing system 1 according to the embodiment calculates the degree of variation based on one or more of the communication date and time between flow data, the connection destination port number, the communication protocol, and the number of transferred bytes.

[0089] As a result, the information processing system 1 calculates the degree of variation of flow data that has the same destination address as the information of the unauthorized communication detected by the upper network device 100 based on the communication date and time between the flow data, the destination port number, the communication protocol, and the number of transferred bytes, and by blocking communication to the destination of the unauthorized communication depending on the degree of variation, it is possible to improve security and reduce costs.

[0090] The lower NW device 200 of the information processing system 1 according to the embodiment further has a deletion unit 224 that notifies the upper NW device 100 to delete information relating to unauthorized communications used for detection when the determination unit 222 determines that the degree of variation is equal to or greater than a predetermined threshold.

[0091] As a result, when the variation between the information on unauthorized communications detected by the upper network device 100 and flow data having the same destination address is equal to or greater than a threshold value, the information processing system 1 determines that it is a false positive and deletes the information on the unauthorized communications used for the detection, thereby improving security and reducing costs.

[0092] [program] It is also possible to create a program in which the processing executed by the information processing system 1 described in the above embodiment is written in a language executable by a computer. In this case, the same effect as in the above embodiment can be obtained by the computer executing the program. Furthermore, such a program may be recorded on a computer-readable recording medium, and the program recorded on the recording medium may be read and executed by a computer to realize the same processing as in the above embodiment.

[0093] Fig. 12 is a diagram showing an example of a computer that executes an information processing program. As shown in Fig. 12, a computer 1000 includes, for example, a memory 1010, a CPU 1020, a hard disk drive interface 1030, a disk drive interface 1040, a serial port interface 1050, a video adapter 1060, and a network interface 1070. These components are connected by a bus 1080.

[0094] The memory 1010 includes a ROM (Read Only Memory) 1011 and a RAM 1012. The ROM 1011 stores a boot program such as a BIOS (Basic Input Output System). The hard disk drive interface 1030 is connected to a hard disk drive 1090. The disk drive interface 1040 is connected to a disk drive 1100. A removable storage medium such as a magnetic disk or an optical disk is inserted into the disk drive 1100. The serial port interface 1050 is connected to a mouse 1110 and a keyboard 1120, for example. The video adapter 1060 is connected to a display 1130, for example.

[0095] 12, the hard disk drive 1090 stores, for example, an OS (Operating System) 1091, an application program 1092, a program module 1093, and program data 1094. The tables described in the above embodiments are stored in, for example, the hard disk drive 1090 or the memory 1010.

[0096] Furthermore, the information processing program is stored in the hard disk drive 1090, for example, as a program module in which instructions to be executed by the computer 1000 are written. Specifically, the hard disk drive 1090 stores a program module 1093 in which each process executed by the computer 1000 described in the above embodiment is written.

[0097] Furthermore, data used for information processing by the information processing program is stored as program data, for example, in the hard disk drive 1090. Then, the CPU 1020 reads out the program module 1093 and the program data 1094 stored in the hard disk drive 1090 into the RAM 1012 as necessary, and executes each of the above-mentioned procedures.

[0098] Note that the program module 1093 and program data 1094 relating to the information processing program are not limited to being stored in the hard disk drive 1090, and may be stored in, for example, a removable storage medium and read by the CPU 1020 via the disk drive 1100 or the like. Alternatively, the program module 1093 and program data 1094 relating to the control program may be stored in another computer connected via a network such as a LAN or a WAN (Wide Area Network), and read by the CPU 1020 via the network interface 1070.

[0099] [others] Although various embodiments have been described in detail herein with reference to the drawings, these embodiments are merely examples and are not intended to limit the present invention to these embodiments. The features described herein can be realized in various ways, including various modifications and improvements based on the knowledge of those skilled in the art.

[0100] Furthermore, the above-mentioned "module (-er suffix, -or suffix)" can be read as a unit, a means, a circuit, etc. For example, a communication module, a control module, and a storage module can be read as a communication unit, a control unit, and a storage unit, respectively. [Explanation of symbols]

[0101] 1. Information Processing Systems 100 Upper network device 110 Communications Department 120 Control section 121 Detection unit 122 Notification Department 130 Storage section 200 Lower NW device 210 Communications Department 220 Control section 221 Acquisition Department 222 Judgment section 223 Breaking section 224 Deleted section 230 Storage section

Claims

1. An information processing system including a higher-level network device that constitutes an overlay network and a lower-level network device that constitutes an underlay network, The upper network device includes: A detection unit that detects unauthorized communications; a notification unit that notifies the lower network device of information on the unauthorized communication detected by the detection unit; having The lower NW device a determination unit that calculates a degree of variation between a plurality of flow data in the underlay network having the same destination address as the information on the unauthorized communication notified by the notification unit, determines whether the degree of variation is equal to or greater than a predetermined threshold, and determines that the detection is a false positive if the degree of variation is equal to or greater than the predetermined threshold; a blocking unit that, when the degree of variation determined by the determining unit is less than a predetermined threshold, determines that the detection is not a false detection, and blocks the information of the unauthorized communication notified by the notifying unit as unauthorized communication, using information about communication of a terminal connected to the lower network device; An information processing system comprising:

2. The determination unit calculates the degree of variation based on one or more of the communication date and time between the flow data, the connection destination port number, the communication protocol, and the number of transferred bytes.

2. The information processing system according to claim 1 .

3. a deletion unit that notifies the upper network device of deletion of information related to unauthorized communication used for detection when the determination unit determines that the degree of variation is equal to or greater than a predetermined threshold value.

2. The information processing system according to claim 1, further comprising:

4. An information processing method executed by a higher-level network device that is a device constituting an overlay network and a lower-level network device that is a device constituting an underlay network, comprising: a detection step of the upper network device detecting unauthorized communication; a notification step of the upper network device notifying the lower network device of information on the unauthorized communication detected by the detection step; a determination step in which the lower network device calculates a degree of variation between a plurality of flow data in the underlay network having the same destination address as the information on the unauthorized communication notified by the notification step, determines whether the degree of variation is equal to or greater than a predetermined threshold, and determines that the detection is a false positive if the degree of variation is equal to or greater than the predetermined threshold; a blocking step of the lower network device determining that the detection is not an erroneous detection when the degree of variation determined in the determining step is less than a predetermined threshold, and blocking the information of the unauthorized communication notified in the notifying step as unauthorized communication by using information about communication of a terminal connected to the lower network device; 13. An information processing method comprising:

5. An information processing program to be executed by a computer as a higher-level NW device that is a device constituting an overlay network and a computer as a lower-level NW device that is a device constituting an underlay network, The computer as the upper network device, A detection step of detecting unauthorized communication; a notification step of notifying the downstream NW device of information on the unauthorized communication detected by the detection step; Run the command, The computer as the lower network device, a determination step of calculating a degree of variation between a plurality of flow data in the underlay network having the same destination address as the information on the unauthorized communication notified by the notification step, determining whether the degree of variation is equal to or greater than a predetermined threshold, and determining that the detection is a false positive if the degree of variation is equal to or greater than the predetermined threshold; a blocking step of determining that the detection is not an erroneous detection when the degree of variation determined in the determining step is less than a predetermined threshold, and blocking the information of the unauthorized communication notified in the notifying step as unauthorized communication using information about communication of a terminal connected to the lower network device. An information processing program characterized by causing the program to execute the above steps.

Citation Information

Patent Citations

  • Method, Apparatus, and System for Attack Data Packet Processing

    JP2018500830A

  • Information processing device, communication inspection method, and program

    JP2020014061A

  • Identifying a Denial-of-Service Attack in a Cloud-Based Proxy Service

    US20140109225A1