Input Software Security System and Security Method for a Closed Internal Network

The software security system for closed internal networks addresses the challenge of malicious code infections by using a kiosk and cloud-based quarantine processes to detect and block malicious code, ensuring a secure software integration environment.

JP7695813B2Active Publication Date: 2025-06-19SOFTCAMP
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2021063381
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2020-04-08
Filing Date
2021-04-02
Publication Date
2025-06-19
Estimated Expiration
2041-04-02

AI Technical Summary

Technical Problem

Existing security technologies for closed internal networks are inadequate in preventing malicious code infections during software integration and update processes, as they do not effectively cut off online connections between internal and external networks.

Method used

A software security system that includes a kiosk with a registration module, a vaccine module for detecting malicious code, and an authentication module for quarantining software, along with a client that verifies quarantine authentication and authorizes software execution, thereby creating a secure software integration environment.

Benefits of technology

The system effectively cuts off external communication, fundamentally blocking malicious code infections and ensuring a safe software integration environment by processing software through a kiosk and cloud-based quarantine processes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007695813000001
    Figure 0007695813000001
  • Figure 0007695813000002
    Figure 0007695813000002
  • Figure 0007695813000003
    Figure 0007695813000003
Patent Text Reader

Abstract

To provide a system and method for securing against input software to a closed internal network that shuts off malicious code-infected software from being inputted and incorporated into an internal network through an external network and builds up a safe security environment for the internal network.SOLUTION: A system for securing against input software to a closed internal network includes a kiosk including a registration module that reads out storage software for a connected portable storage medium, a vaccine module that detects a malicious code from the software, and an authentication module that sets a quarantine authentication to the portable storage medium in which a quarantine on the software has been completed, and a client including a check module that confirms the quarantine authentication for the portable storage medium and approves the execution of the storage software.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an input software security system and a security method for a closed internal network that blocks software infected with malicious code from being input and incorporated into the internal network through an external network and constructs a secure security environment for the internal network.

Background Art

[0002] Government agencies such as government offices and local governments, and various corporate bodies and research institutes that require other security (hereinafter referred to as the'security group') have constructed a closed internal network that is blocked from the external network such as the Internet in order to prevent unauthorized leakage of their own data and protect the constituent PCs and servers of the security group.

[0003] The developed security technology blocks direct penetration into the internal network through the external network. Therefore, existing malicious code technologies have limitations in attacking the internal network, and thus the unauthorized data leakage from the internal network and the internal network infection rate have decreased significantly.

[0004] However, as security technology has developed, hacking technology has also developed and the infection routes have become diversified. Therefore, attacks on software development companies and the like with relatively weak security have increased. Software development companies develop software such as source code, programs, update files, and patches to be incorporated into the internal network, and input the software into the internal network along a specified route.

[0005] In the communication environment between the software development company and the internal network, hackers penetrate the network of the software development company to modify the software to be transmitted to the internal network, insert new software with malicious purposes, or approach a separate server that distributes the software to change the software to be incorporated into the internal network. For reference, typical attack methods include build / update infrastructure forgery, forgery due to leakage of certificates and development accounts, forgery of hardware and firmware, and sale of online products infected with malicious code.

[0006] Software developed by a software development company that has been infected and modified (hereinafter referred to as 'infected') by hackers is incorporated into servers and PCs on the internal network, causing unauthorized leakage of internal network data or damaging the server so that it cannot achieve its original function.

[0007] Ultimately, there is an urgent need for security technology that can completely cut off the online connection between the internal network and the external network, neutralize malicious code in the software input into the internal network, and build a safe software integration environment.

Prior Art Documents

Patent Documents

[0008]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0009] Therefore, the present invention is for solving the above problems, and aims to provide a software security system and security method for a closed internal network that cuts off communication between the internal network and the external network to enhance the security of the internal network and fundamentally blocks the infection of malicious code occurring during the software integration and update process of the internal network.

Means for Solving the Problems

[0010] To achieve the above object, the present invention includes a kiosk including a registration module for reading saved software on a connected portable storage medium, a vaccine module for detecting malicious code from the software, and an authentication module for setting quarantine authentication on the portable storage medium for which the quarantine of the software has been completed, and a client including a check module for confirming the quarantine authentication of the portable storage medium and authorizing the execution of the saved software, which is a software security system for a closed internal network.

Advantages of the Invention

[0011] The present invention cuts off external communication of the internal network so that software is not input through the external network, and security processes the software input into the internal network via a kiosk and the cloud. Therefore, the inflow of malicious codes from the external network is fundamentally cut off, and there is an effect of constructing a safe software integration environment of the internal network with respect to the external network.

Brief Description of the Drawings

[0012]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Embodiments for Carrying Out the Invention

[0013] The features and effects of the present invention described above will become apparent from the following detailed description based on the accompanying drawings. Therefore, those with ordinary knowledge in the technical field to which the present invention pertains will be able to easily implement the technical idea of the present invention. The present invention can be subjected to various modifications and can have various forms. However, specific embodiments are illustrated in the drawings and will be described in detail in the text. However, this is not intended to limit the present invention to a specific disclosed form, and it must be understood that it includes all modifications, equivalents, and alternatives included in the idea and technical scope of the present invention. The terms used in this application are only used to explain specific embodiments and are not intended to limit the present invention.

[0014] Hereinafter, the specific content of the present invention will be described in detail based on the accompanying drawings.

[0015] FIG. 1 is a diagram schematically showing the communication relationship between the external network and the internal network of the kiosk configuration of the input software security system according to the present invention, and FIG. 2 is a block diagram showing the configurations of the kiosk, the cloud device, and the internal network client of the input software security system according to the present invention.

[0016] Referring to FIGS. 1 and 2, the security system of this embodiment has a communication function that can separate the internal network N2, which is the internal communication network of the security group, from the external network N1, which is a general communication network such as the Internet, and transmit the data of the external network N1 to the internal network N2. For this purpose, the security system of this embodiment includes a kiosk 100 that quarantines software (such as source code, programs, update files, patches, etc.) of the external network N1 for data communication between the internal network N2 and the external network N1 and stores it in a portable storage medium U that has been authenticated. For reference, the portable storage medium U can also be a storage means such as a USB, or can also be a computer system such as a notebook PC or a desktop PC.

[0017] The portable storage medium U registered and quarantined at the kiosk 100 is hardware-connected to the client C2, C2' or server S2 of the internal network N2, and the software stored on the portable storage medium U is incorporated into the client C2, C2' or server S2.

[0018] Ultimately, the software of the client C1 or servers S1, S1' communicating on the external network N1 is registered and quarantined at the kiosk 100, and the quarantined software accesses the internal network N2 through the offline connection of the portable storage medium U by the user.

[0019] For this purpose, the kiosk 100 of this embodiment includes a registration module 110 that reads the stored software of the connected portable storage medium U and registers a system image (embedded image), a vaccine module 140 that detects malicious code from the software, and an authentication module 160 that sets a quarantine authentication for the portable storage medium U for which the quarantine authentication of the software has been completed. Also, the client C2 of the closed internal network N2 separated from the external network N1 includes a check module 11 that confirms the quarantine authentication of the portable storage medium U and authorizes the execution of the stored software. For reference, the target to which the portable storage medium U is connected in the internal network N2 can be the server S2 in addition to the client C2, but in the detailed description and claims of this embodiment, it is generically referred to as the client C2. Therefore, the connection target of the portable storage medium U is not limited to only the client C2 and should be interpreted as being extended to the server S2 of the internal network N2.

[0020] Although FIGS. 1 and 2 described that the portable storage medium U is a USB memory, it is not limited thereto, and should be interpreted as being extended to the portable storage medium U as long as it is a medium having a storage function, such as a disk such as a CD (Compact Disc) or a DVD (Digital Versatile Disc), or an SD memory card.

[0021] The registration module 110 hardware - connects the portable storage medium U, reads the software stored in the portable storage medium U, and stores it in the memory 120 of the kiosk 100. Also, it generates a disk image from the system image of the portable storage medium U, that is, a snapshot, stores it in the memory 120, and transmits it to the clients C2 and S2.

[0022] The vaccine module 140 detects malicious code from the software stored in the memory 120. Also, it deletes or disables the malicious code that has infected the software. The vaccine module 140 can exemplify normal vaccine application software such as V3, HAURI, Bitdefender, etc., and preferably includes two or more different types of vaccine application software. Therefore, in the vaccine module 140 of this embodiment, two or more types of vaccine application software will prevent the software from being infected, enhancing the reliability for preventing malicious code. In addition, the vaccine module 140 can check for the presence of malicious code infection, such as programs for the processing of the kiosk 100, and perform detection and prevention.

[0023] On the other hand, the vaccine module 140 can be managed, such as updated, by the security management server 300 of the corresponding vaccine application software.

[0024] The kiosk 100 of this embodiment communicates with the security management server 300 and other management center servers (not shown) via the external network N1. By the way, unreasonable communication of the kiosk 100 via the external network may cause malicious code infection of the kiosk 100, so the kiosk 100 interfaces in the VPN (Virtual Private Network) mode and communicates with the designated security management server 300. Here, the kiosk 100 connects to the communication network in the VPN mode and connects to the security management server 300 only at a specified time, and the security management server 300 transmits update information for the security of the kiosk 100.

[0025] Therefore, the vaccine module 140 of this embodiment only causes a VPN communication device (not shown) to execute at a specified time to connect to the security management server 300, and the security management server 300 confirms the connection of the vaccine module 140 and transmits update information. The vaccine module 140 that receives the update information updates according to the setting process and cuts off the communication of the VPN communication device.

[0026] For reference, the VPN communication device and the kiosk 100 can communicate over a network, either wired or wirelessly. The kiosk 100 of this embodiment communicates wirelessly with the VPN communication device via an LTE base station.

[0027] The authentication module 160 sets a quarantine authentication on the portable storage medium U for which the software quarantine has been completed. The software is quarantined by various methods such as software verification and harmless treatment by reconstruction, as well as the aforementioned quarantine by the vaccine module 140. Therefore, once the software quarantine is completed, a quarantine authentication code for authenticating the security of the software is set. The quarantine authentication can be set on the software itself or on the portable storage medium U. Preferably, the quarantine authentication is set on the portable storage medium U so that the software that has not been verified is not further stored. Therefore, when the portable storage medium U with the quarantine authentication set is connected to the kiosk 100, the authentication module 160 checks whether the quarantine authentication is available and displays the result on the monitor configured in the kiosk 100.

[0028] The client C2 connected to the internal network N2 includes a check module 11 that checks the quarantine certification of the portable storage medium U and authorizes the execution of the storage software. Since the security system according to the present invention can quarantine the software of the external network N1 and input it to the internal network N2, the kiosk 100 completes the software quarantine and sets the quarantine certification. The check module 11 of the client C2 in the internal network N2 only receives the software for which the quarantine certification has been confirmed and is executed via the incorporation module 12. Of course, the software for which the quarantine certification has not been confirmed is ignored and the subsequent execution is aborted. In addition, the check module 11 registers the system image received from the client C2 and compares it with the system image of the portable storage medium U to determine whether they match. That is, if the software incorporated in the portable storage medium U is infected with malicious code, the sectors of the stored file change and the incorporated image, that is, the system image, changes. Therefore, the check module 11 can determine whether there is an infection with malicious code in the portable storage medium U and whether they match. Eventually, the client C2 accurately checks the portable storage medium U quarantined by the kiosk 100 and determines whether there is a subsequent infection with malicious code.

[0029] The kiosk 100 according to the present invention further includes a verification module 130 that classifies the software based on the type of the software and verifies it by a type-specific verification process.

[0030] The software input to the kiosk 100 via the portable storage medium U has various types depending on the format, execution program, extension, etc. By the way, if various types of software are quarantined in a unified process, the quarantine efficiency and reliability for each type will only decrease. Therefore, the verification module 130 classifies the type of the software and checks the type of the software of the portable storage medium U to classify it and perform the quarantine by a process suitable for the type. In this embodiment, the type of the software can include a firmware type, a patch type, a document type, etc.

[0031] For reference, the firmware type is a kind of microprogram that controls control devices such as computers, and is understood as software with hardware characteristics. The patch type is understood as software that updates windows or other various programs. The document type is a file generated by a word processor and has extensions such as *.hwp, *.docx, *.xlsx, *.pdf, etc. In addition, executable files with extensions such as *.exe, *.dll, *.com, *.bat, etc. can be classified by type.

[0032] The verification of the firmware type is performed by the verification module 130 analyzing the RDS (Reference Data Set) hash set of the software and checking the specified RDS hash set.

[0033] For reference, RDS is a data set used to improve the efficiency of digital forensic evidence data analysis. Normal files are excluded from the analysis target, and specific files are checked for existence. That is, the verification module 130 classifies the software generated by the system, font, and application program into known good code through RDS hash set analysis and excludes it from the analysis target, and includes software related to specific conditions of known malicious code such as rootkits, backdoors, and exploits as the analysis target.

[0034] The patch type verification is performed by the verification module 130 analyzing the code signature of the software to check if it is a valid code signature.

[0035] As is well known, software development companies not only produce software themselves, but also produce and supply patches for updating the software. Therefore, a code signature is set for the patch so that it can be confirmed that the patch is normal software of the software development company. Thereby, when the verification module 130 confirms that the software on the portable storage medium U is of the patch type, it checks whether the code signature of the software is set or whether the set code signature is complete.

[0036] The verification of the document type is performed by the verification module 130 analyzing the configuration macro of the software to check whether it is specified malicious code.

[0037] As is well known, a macro is a kind of record that binds several frequently used instruction words into a single key input operation, and a word processor sets a program to process the record. Therefore, the annoyance of the operator repeatedly using specific instruction words in a certain procedure during work using a word processor can be reduced by the macro function. By the way, it is common for macros to be distributed externally for general business use, and word processors such as EXCEL are frequently used in the fields of finance, accounting, and the financial circle, so it was frequent for hackers to load malicious code into the macro and use it maliciously.

[0038] Therefore, when the verification module 130 confirms that the type of software on the portable storage medium U is of the document type, it analyzes the format, extension, header structure, etc. of the software to detect whether it is a macro. As a result of the confirmation, since software without a macro set has a low possibility of being infected by a macro, the quarantine related to the macro is interrupted.

[0039] On the one hand, if the verification module 130 confirms a macro, it compares the macro with existing malicious code-related information to check whether it is infected. For reference, since a macro infected with malicious code is deformed into a specific function form, even if it has the same macro function, a normal macro and a malicious macro may have different function forms. Therefore, the verification module 130 checks for a macro with the same form as that of a macro infected with malicious code to determine whether the macro is infected.

[0040] The kiosk 100 according to the present invention further includes a detoxification module 150 that performs structure analysis, active content analysis, and software reconstruction of the software to detoxify the software.

[0041] When the quarantine of the software by the vaccine module 140 and the verification module 130 of the kiosk 100 is completed, the detoxification module 150 detects and detoxifies malicious code that leaked during the quarantine process of the vaccine module 140 and the verification module 130. For this purpose, the detoxification module 150 of this embodiment operates in the order of document format verification, document structure analysis, component extraction and verification, reconstruction and verification. More specifically, it scans the software to analyze the structure, detects and analyzes active content in the form of ActiveX controls or script code included in and distributed on a web page by software, removes the confirmed active content, and finally completes the detoxification of the software by content disarm and reconstruction (CDR) when the analysis and removal are completed.

[0042] Through the above-described process, the detoxification module 150 detoxifies the software on the portable storage medium U and finally completes the quarantine.

[0043] The kiosk 100 of this embodiment further includes a kiosk management module 170. The kiosk management module 170 manages the interlocking of the registration module 110, the memory 120, the verification module 130, the vaccine module 140, the inactivation module 150, and the authentication module 160, and also controls operations for the operation of the kiosk 100 itself.

[0044] To explain the operation in more detail, the kiosk 100 of this embodiment includes a reader for confirming the identity of the user and a display device for guiding the user about the overall operating state of the kiosk 100. In particular, the reader is arranged to be exposed on the housing of the kiosk 100 for reading authentication media such as identity cards, fingerprints, and eyeballs carried by the user, so as to facilitate the operation of the user. Also, this process and guiding comments are output via the display device, and the user operates the kiosk 100 according to the guiding comments. As described above, the kiosk management module 170 is included for controlling the operations of the reader and the display device of the kiosk 100, and the constituent modules 110 to 160, the reader, and the display of the kiosk 100 operate through normal management processes.

[0045] On the other hand, since there are limitations in the malicious code quarantine of the aforementioned vaccine module 140, verification module 130, and inactivation module 150, the quarantine process of the kiosk 100 is performed together with a separate cloud device 200. Here, the communication between the kiosk 100 and the cloud device 200 is performed via the external network N1, and communication technology in the VPN (Virtual Private Network) method can be applied.

[0046] The cloud device 200 of this embodiment includes a software management module 210 that analyzes the software of the portable storage medium U connected to the kiosk 100 to search for corresponding reference information, a history registration module 220 that registers and manages the history information due to the specification change of the software, and a comparison and analysis module 230 that compares the specification of the software with one or more selected from the reference information and the history information, confirms the change items equal to or higher than the reference value, and notifies them.

[0047] To describe each component in more detail, the software management module 210 analyzes the software carried in from the kiosk 100, and confirms specifications such as the registration number registered in the cloud device 200, the software (product) type, the software name, the current version, the memory, the configured compiler, the number of files, the capacity, the analysis date, the type and number of link URLs, and the number of IPs, and sets them as reference information. For this purpose, the software management module 210 pre-registers the software, and when new software is carried in, it registers and stores it in the cloud device 200 according to the regulations.

[0048] The history registration module 220 confirms the specification change of the software confirmed by the software management module 210 and registers it as history information. That is, it records the change of the software specification every time it is carried in with cumulative data so that the change can be grasped. Therefore, when the software is a patch, it is possible to grasp the version change of the patch, the change of the memory structure, and the existence of a new compiler for which the existing history information is not confirmed, and to determine whether the patch is normal from the history information.

[0049] The comparison and analysis module 230 compares the specification of the newly carried-in software with the corresponding reference information of the software confirmed by the software management module 210 or the history information of the history registration module 220. If a difference equal to or higher than the reference value is confirmed as a comparison result, it notifies the specified target.

[0050] In addition, if the comparison analysis module 230 confirms that changes such as changes in the configuration file size, changes in the memory usage, new link address configurations, generation of new executable files, changes in file versions, and changes in the memory structure are equal to or greater than the reference value, it notifies the specified target.

[0051] In addition, the comparison analysis module 230 checks whether the size difference between the Virtual Size and the Size of Raw Data for a section in the configuration code of the software on the portable storage medium U is equal to or greater than the reference value, analyzes and calculates the entropy for the section in the configuration code of the software on the portable storage medium U, checks whether the calculated value is equal to or greater than the reference value, searches for the signature of the specified packer in the configuration code of the software on the portable storage medium U, and if it confirms the execution of the corresponding packer, it notifies the specified target.

[0052] In addition, as a result of comparing the software specifications of the portable storage medium U with the historical information, if the comparison analysis module 230 extracts one or more types of codes selected from the keyboard or mouse hooking code, the access target elevation code for the client's saved information, the APC (Asynchronous Procedure Call) injection code, the DLL injection code, the execution process alternation code, and the service addition code from the software, it notifies the specified target. For reference, APC injection is also called an asynchronous procedure call and is executed by the PowerShell executed by the Invoke-Expression function. The asynchronous procedure call injection first allocates memory for a malicious DLL together with VirtualAllocEx and then copies and inserts the malicious DLL here, so it is used as a means for malicious code infection. In addition, DLL injection is a technique for executing code by forcibly loading a DLL within the address space of another process and is used as another means for malicious code infection.

[0053] As described above, if a change equal to or greater than a reference value is confirmed by software with respect to reference information, the software is made to presume that a function other than the original function has been added, so that the software can be suspected of being infected with malicious code. Therefore, the comparison analysis module 230 of the cloud device 200 can notify software in which a change equal to or greater than the reference value has been confirmed to a designated target so that an inspection can be performed. Here, the designated target can be a software development company that is the originator of the software or a professional program engineer. Therefore, the inspection information of the designated target for the software can be transmitted to the kiosk 100 and output via a display device, or transmitted to relevant persons via a communication medium such as email, MMS, or SMS.

[0054] FIG. 3 is a flowchart sequentially showing a security method based on the input software security system according to the present invention, FIG. 4 is an image sequentially showing an image of a software quarantine procedure displayed on a kiosk of the input software security system according to the present invention, and FIGS. 5 and 6 are images showing a simulation of a quarantine service processed by a cloud device of the input software security system according to the present invention.

[0055] Referring to FIGS. 1 to 6, the security system according to the present invention operates in the following process.

[0056] S11; Portable storage medium connection stage The user connects a portable storage medium U storing software to be carried into the internal network N2 to the kiosk 100. For the connection, the kiosk 100 of the present embodiment performs a user authentication procedure as shown in FIG. 4 and inputs the portable storage medium U into the kiosk 100 both hardware-wise and software-wise.

[0057] Since the user authentication technology and the connection of the portable storage medium U and the input technology of the stored software are already known technologies, the description thereof is omitted here.

[0058] S12; Identification number assignment stage The registration module 110 assigns an identification number for identifying the software input during the connection process, and identifies and registers the software based on this. Further, the registration module 110 takes a snapshot of the system image of the portable storage medium U connected to the kiosk 100, associates it with the identification number, registers it, and transmits it to be registered in the client C2.

[0059] As is well known, the system image is an embedded image of the software stored in the portable storage medium U, and is the content of the disk drive obtained by dividing and copying the stored file sector by sector. Therefore, if there is a change in the embedded file of the portable storage medium U or a new file is further stored, a change in the system image will occur.

[0060] The software with the assigned identification number undergoes a subsequent quarantine process at the kiosk 100, or is transmitted to the cloud device 200 for a subsequent quarantine process, or a subsequent quarantine process is performed on both the kiosk 100 and the cloud device 200.

[0061] S13; Software classification stage The software with the assigned identification number is classified by the verification module 130 according to its type. As described above, the types of software are diverse according to formats, execution programs, extensions, etc., and the verification module 130 classifies the software according to specified criteria.

[0062] S14; Software-specific verification stage The verification module 130 continues to verify the classified software according to the corresponding type. As described above, the software of this embodiment can be classified into types such as firmware type, patch type, document type, etc. For each type of software, in the case of the firmware type, an RDS hash set check is performed, in the case of the patch type, a code signature verification is performed, and in the case of the document type, verification is performed by macro detection and analysis.

[0063] For reference, the kiosk 100 outputs the file verification process by simulation as shown in FIG. 5, so that the user can recognize the current progress.

[0064] S15; Vaccine inspection stage The vaccine module 140 checks and treats whether the software is infected with malicious code using a normal vaccine program.

[0065] For reference, the verification technology and the vaccine technology do not necessarily follow the procedures described above. If necessary, the vaccine technology can be applied prior to the verification technology.

[0066] S16; Detoxification stage The detoxification module 150 utilizes the CDR processing technology of the software to perform, in order, document format verification (Format Verification) of the software, structure analysis (Structure Analysis), component extraction and verification (Component Extraction), and reconstruction and verification (Reconstruction Verification).

[0067] S17; Normal processing confirmation stage If it is confirmed that the above-mentioned quarantine process is completed and the software is normal, the subsequent process is carried out. However, if a problem occurs in any one of the above quarantine processes, the subsequent quarantine process is aborted and the user is notified of the matter.

[0068] S21; Confirmation stage of imported software On the other hand, the software management module 210 checks the specifications of the software imported from the kiosk 100 and outputs it as shown in FIG. 5. Here, if unregistered software is imported, the software management module 210 registers the software according to the specified procedure and sets the specifications of the software as reference information.

[0069] S22; History information registration stage The history registration module 220 checks the software specifications confirmed by the software management module 210 and registers them as history information. For reference, the history information includes not only the specifications that can be checked by the reference information, but also the specifications that cannot be checked by the reference information. That is, if a file or the like that cannot be checked by the reference information is found in the imported software specifications, it is added as history information.

[0070] S23; Change item comparison and analysis stage The comparison and analysis module 230 compares the reference information with the history information, and if a difference equal to or greater than the reference value is confirmed as shown in FIG. 6, if a specification such as a new file or link address that cannot be confirmed by the reference information is confirmed, if a change in the memory structure is confirmed, or if code for malicious code infection is confirmed, it notifies the relevant matter.

[0071] S24; Normal processing confirmation stage If it is confirmed that the quarantine result of the comparison and analysis module 230 and the software are normal, it notifies the kiosk, and if it is confirmed that they are abnormal, it issues a notice to reject the import to the designated target or the internal network N2.

[0072] S18; Authentication setting stage If it is determined that the software is integrity software based on the quarantine results of the kiosk 100 and the cloud device 200, the authentication module 160 sets quarantine authentication for the software or the portable storage medium U so that it can connect to the client C2 of the internal network N2.

[0073] In this embodiment, the authentication module 160 enables the quarantined software to be transmitted to the portable storage medium U or online, and produces and transmits the software as a result.

[0074] S32; Authentication check stage The check module 11 of clients C2 and S2 checks the quarantine authentication of the portable storage medium U connected offline to determine the safety of the software, and checks whether the system image of the portable storage medium U matches the system image registered on the portable storage medium U to determine whether there is subsequent infection.

[0075] If the quarantine authentication of the portable storage medium U is confirmed and the system images are confirmed to match, the check module 11 finally determines that the currently connected portable storage medium U and the software are safe, and the integration module 12 stores or integrates the software in the designated space of the internal network N2.

[0076] In the foregoing detailed description of the present invention, preferred embodiments of the present invention have been described. However, it will be understood that those skilled in the art or those with ordinary knowledge in the relevant technical field can make various modifications and changes to the present invention without departing from the spirit and technical scope of the present invention described in the claims below.

Claims

1. A kiosk including a registration module for reading the storage software of a connected portable storage medium, a vaccine module for detecting malicious code from the software, and an authentication module for setting quarantine authentication on the portable storage medium for which the quarantine of the software has been completed, A client including a check module for verifying the quarantine authentication of the portable storage medium and authorizing the execution of the storage software, Further including a cloud device including a software management module for analyzing the software of the portable storage medium connected to the kiosk and searching for corresponding reference information, a history registration module for registering and managing the history information due to the specification change of the software, and a comparison analysis module for comparing the specification of the software with one or more selected from the reference information and the history information, confirming the change items equal to or greater than the reference value, and notifying the specified target A closed internal network input software security system, characterized in that.

2. The kiosk Further including at least one or more modules among a verification module for classifying software based on the type of the software and verifying it by a type-specific verification process, and an inactivation module for performing software structure analysis, active content analysis, and software reconstruction to inactivate the software, the closed internal network input software security system according to claim 1.

3. The verification module classifies the software into at least one or more types among firmware type, patch type, and document type, the closed internal network input software security system according to claim 2.

4. For the verification of the firmware type, the verification module analyzes the RDS (Reference Data Set) hash set of the software to confirm whether it is a specified RDS hash set, The verification of the patch type is that the verification module analyzes the software code signature to confirm whether it is a valid code signature, The verification of the document type is characterized in that the verification module analyzes the software configuration macro to confirm whether it is specified malicious code. The input software security system for a closed internal network according to claim 3.

5. The comparison and analysis module As a result of comparing the software specification of the portable storage medium with the history information, if one or more codes selected from a keyboard or mouse hooking code, an access target elevation code for the client's stored information, an APC (Asynchronous Procedure Call) injection code, a DLL injection code, an execution process alternation code, and a service addition code are extracted from the software, it is characterized by notifying the specified target. The input software security system for a closed internal network according to claim 1.

6. The comparison and analysis module In the configuration code of the software of the portable storage medium, whether the size difference between the Virtual Size and the Size of Raw Data for a section is equal to or greater than a reference value, whether the calculated value obtained by analyzing and calculating the entropy for a section in the configuration code of the software of the portable storage medium is equal to or greater than a reference value, and whether the signature of a specified packer is searched for in the configuration code of the software of the portable storage medium to confirm the execution of the packer. If so, it is characterized by notifying the specified target. The input software security system for a closed internal network according to claim 1.

7. The kiosk is interfaced to perform network communication in a VPN (Virtual Private Network) manner. The input software security system for a closed internal network according to claim 1.

Citation Information

Patent Citations

  • Information acquisition system

    JP2002073905A

  • Information processing system, detection device, information processing device, security management method, and security management program

    JP2017151708A

  • Method for updating regular program

    KR1020020031500A

  • Apparatus and method for verifying file to be transmitted to internal network

    KR1020190011145A

  • System and method for implementing secure media exchange on a single board computer

    US20190220594A1