Quarantine network system, quarantine server, and security inspection program
The integration of a quarantine management table with a patch management server simplifies quarantine network operations by automating patch policy alignment, reducing manual registration and version-specific updates, thus enhancing operational efficiency.
Patent Information
- Application Number
- JP2022126631
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-08-08
- Publication Date
- 2025-06-25
- Estimated Expiration
- 2042-08-08
AI Technical Summary
Existing quarantine network systems face complexity in operations due to the need for manual registration of patch policies in both quarantine and patch management servers, leading to potential conflicts and increased operational burden.
A quarantine network system that integrates with a patch management server to manage patch application status, using a quarantine management table to determine pass/fail based on patch application states, simplifying the registration process and reducing the need for manual updates.
Facilitates easier operation of quarantine networks by aligning patch policies across servers, reducing manual registration requirements and ensuring consistent security policies without version-specific updates.
Smart Images

Figure 0007698611000001 
Figure 0007698611000002 
Figure 0007698611000003
Abstract
Description
Technical Field
[0001] The present invention relates to a quarantine network system, a quarantine server, and a security inspection program.
Background Art
[0002] Patent Document 1 discloses a quarantine network system that subjects devices applying security policies other than the security policies to which general-purpose computers should conform to quarantine. In this system, the quarantine server identifies the security policy to which the embedded device should conform based on the ID information received from the embedded device, and transmits an inspection request to the embedded device to inspect whether the identified security policy is complied with. The embedded device acquires inspection information for inspecting compliance with the security policy in response to the inspection request, performs its own inspection based on the inspection information, and transmits the inspection result to the quarantine server.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] Generally, a quarantine network system for inspecting, isolating, and treating a client device to be quarantined using a quarantine server is known. When the client device connects to the network, the quarantine server determines the pass / fail of quarantine, for example, by inspecting the patch status of the OS (Operating System) in the client device. Therefore, the system administrator needs to register in advance in the quarantine server a security policy representing, for example, the pass / fail for each patch.
[0005] On the one hand, enterprises and the like may use a patch management server such as a WSUS (Windows (registered trademark) Server Update Services) server to manage the patch application status in client devices. In this case, the system administrator needs to perform necessary registration operations so that the security policy of the patches in the quarantine server and the patch application policy in the patch management server do not conflict. As a result, there was a risk that the operation of the quarantine network would become complicated.
[0006] The present invention has been made in view of such circumstances, and one of its objects is to provide a quarantine network system, a quarantine server, and a security inspection program capable of facilitating the operation of the quarantine network.
[0007] The above and other objects and novel features of the present invention will become apparent from the description of this specification and the accompanying drawings.
Means for Solving the Problems
[0008] Among the inventions disclosed in the present application, the outline of a representative embodiment will be briefly described as follows.
[0009] A quarantine network system according to an embodiment includes a client device, a quarantine server, and a patch management server. The quarantine server is connected to the network, inspects the client device, and determines whether the quarantine of the client device is passed or failed based on the inspection result. The patch management server is connected to the network and manages the patch application status in the client device by communicating with the client device. Here, the quarantine server stores a quarantine management table that defines the correspondence between the patch application status managed by the patch management server and the pass / fail of the quarantine. Then, when the client device requests to connect to the network, the quarantine server acquires the patch application status managed by the patch management server, and refers to the quarantine management table using the acquired patch application status to determine whether the quarantine of the client device is passed or failed.
Advantages of the Invention
[0010] Among the inventions disclosed in the present application, the effects obtained by typical embodiments will be briefly described. It becomes possible to facilitate the operation of the quarantine network.
Brief Description of the Drawings
[0011]
Figure 1
Figure 2
Figure 3A
Figure 3B
Figure 4
Figure 5
Figure 6
Figure 7
Embodiments for Carrying Out the Invention
[0012] Hereinafter, embodiments of the present invention will be described in detail with reference to the drawings. In all the drawings for explaining the embodiments, the same members are basically denoted by the same reference numerals, and the repeated explanations thereof are omitted.
[0013] <Outline of the Quarantine Network System> FIG. 1 is a schematic diagram showing a configuration example of a quarantine network system according to an embodiment. The quarantine network system shown in FIG. 1 includes an internal network 11, a gateway 12, a business server 13, a quarantine server 14, a patch management server 15, an authentication server 16, an authentication switch SW, and client devices TM10 and TM20. The gateway 12, the business server 13, the quarantine server 14, the patch management server 15, and the authentication server 16 are connected to the internal network 11.
[0014] The authentication switch SW is connected between the client devices TM10 and TM20 and the internal network 11. In this example, the client device TM10 is connected to port P1 of the authentication switch SW and is used by the user 17a. Also, the client device TM20 is a tablet device used by, for example, the user 17b and is connected to port Pn of the authentication switch SW via a wireless LAN (Local Area Network) access point WAP. In the specification, the client devices TM10 and TM20 are collectively referred to as the client device TM, and the users 17a and 17b are collectively referred to as the user 17.
[0015] The authentication switch SW performs network authentication of the client device TM or the user 17 and controls the relay of frames or packets between the client device TM and the internal network 11 based on the authentication result. The internal network 11 is, for example, an in-house network or the like, and although not shown, has a layer 2 (L2) switch, a layer 3 (L3) switch, or the like that is responsible for the relay of frames or packets.
[0016] The gateway 12 is a router or the like and mediates communication between the internal network 11 and the external network 10. The external network 10 is the Internet or the like. The business server 13 is, for example, a file server, a Web server, or the like and provides various services required for business.
[0017] The quarantine server 14 inspects the client device TM and determines whether the quarantine of the client device TM is passed or failed based on the inspection result. Specifically, the quarantine server 14 inspects whether a specific patch, i.e., an update program or the like, is applied to the OS of the client device TM, whether the antivirus program is up-to-date, and the like. The quarantine server 14 stores a quarantine management table 21 in the memory 20, details of which will be described later.
[0018] The patch management server 15 manages the patch application status in the client device TM through communication with the client device TM. Specifically, the patch management server 15 is, for example, a WSUS server that manages the update status of the OS and the like. The patch management server 15 may also manage the update status of the antivirus program and the like. The WSUS server acquires the OS update program from the server of the OS supply company, for example, and distributes the acquired update program to a plurality of client devices TM within the internal network 11. The patch management server 15 stores a patch management table 23 in the memory 22, details of which will be described later.
[0019] The authentication server 16 performs network authentication of the client device TM or the user 17 in cooperation with the authentication switch SW. Specifically, the authentication server 16 stores an authentication table that defines the account information of the client device TM or the user 17 for which network authentication is permitted, although not shown in the figure. In response to an authentication determination request from the authentication switch SW, the authentication server 16 performs an authentication determination based on the authentication table and responds with the authentication determination result to the authentication switch SW. The authentication server 16 is, for example, a RADIUS (Remote Authentication Dial In User Service) server or the like.
[0020] As a modification of the configuration in FIG. 1, the authentication switch SW may be installed between the gateway 12 and the internal network 11. Also, the business server 13, the quarantine server 14, the patch management server 15, and the authentication server 16 may be installed in the external network 10 as cloud servers.
[0021] FIG. 2 is a schematic diagram showing an example of the hardware configuration of the client device TM in FIG. 1. The client device TM shown in FIG. 2 is realized by a computer system including a computer 30, a display 31, a user input interface 32, and the like. The computer 30 includes a processor 35 such as a CPU (Central Processing Unit), a memory 36, a communication interface (IF) 37, and a bus 38 connecting these components. The memory 36 is composed of, for example, a combination of a volatile memory such as a DRAM (Dynamic Random Access Memory) or an SRAM (Static Random Access Memory) and a non-volatile memory such as a flash memory, an SSD (Solid State Drive), or an HDD (Hard Disk Drive).
[0022] The memory 36 stores a security inspection program 39, details of which will be described later. The processor 35 realizes the quarantine function in the client device TM by executing the security inspection program 39. The communication interface 37 is, for example, a wired LAN interface or a wireless LAN interface. In the example of FIG. 1, the client device TM is connected to the authentication switch SW via the communication interface 37.
[0023] The display 31 is, for example, a liquid crystal display, an organic EL (Electro Luminescence) display, or the like, and displays information based on an image signal from the computer 30. The user input interface 32 is a keyboard, a mouse, a touch panel, or the like, and outputs an input signal based on the operation of the user 17 to the computer 30. Note that the business server 13, the quarantine server 14, the patch management server 15, and the authentication server 16 shown in FIG. 1 can also be realized using such a computer.
[0024] <Details of the Quarantine Management Table> FIG. 3A is a diagram showing an example of a part of a management screen by the patch management server 15 in FIG. 1. FIG. 3B is a diagram showing a partial configuration example of a patch management table 23 stored in the patch management server 15 in FIG. 1. The patch management screen 25 shown in FIG. 3A is displayed, for example, on a display of the patch management server 15 or a display of a management terminal connectable to the patch management server 15. Further, in this example, the patch management screen 25 is displayed by the function of the patch management server 15.
[0025] In FIG. 3A, four application states ST1 to ST4 are shown as a schematic application state of patches in the client device TM. In the specification, the application states ST1 to ST4 are collectively referred to as the application state ST or simply the state ST.
[0026] State ST1 represents a state where the installation of the update program has failed. State ST2 represents a state where the installation of the update program is necessary. Specifically, state ST2 represents a state (ST21) where the update program has not been downloaded or installed in the client device TM to which the update program is applicable, a state (ST22) where only the installation has not been performed, or a state (ST23) where the installation is incomplete.
[0027] State ST3 represents a state (ST31) where the installation of the update program is completed or a state (ST32) where the update program is not applicable. The state (ST32) where the update program is not applicable represents, for example, a state (ST321) where an OS outside the management target is used, or a state (ST322) where a more recent update program has been installed by some method. State ST4 represents a state where the application state of the update program is unknown. Specifically, state ST4 represents, for example, a state (ST41) where there has been no access from the client device TM after preparing the latest update program, or a state (ST42) where the application state could not be correctly recognized at the time of access.
[0028] In the patch management screen 25 shown in FIG. 3A, the number and ratio of client devices TM in a plurality of, in this example, nine client devices TM to be managed for each of the states ST1 to ST4 are shown. For example, the number of client devices TM managed as the state ST3 is six. In this way, the patch management server 15 manages the general application state ST of the patches in the client device TM by distinguishing them into four states ST1 to ST4.
[0029] The patch management table 23 shown in FIG. 3B represents the correspondence between the identifier of the client device TM and the application state ST of the patch in the client device TM. Specifically, the application state ST of the patch may be, for example, an identifier for distinguishing the application state. The patch management server 15 can create a patch management screen 25 as shown in FIG. 3A based on such a patch management table 23, for example.
[0030] In the example of the patch management table 23 shown in FIG. 3B, computer names CN10, CN20,... are used as the identifiers of the client devices TM. The computer names CN10, CN20 correspond to the client devices TM10, TM20 shown in FIG. 1, respectively, for example. In this case, for example, the application states ST of the patches in the client devices TM10, TM20 are managed as the states ST3, ST2, respectively. The patch management server 15 recognizes the application state ST and updates the patch management table 23 every time it is accessed from the client device TM, for example.
[0031] FIG. 4 is a diagram showing a configuration example of the quarantine management table 21 stored in the quarantine server 14 in FIG. 1. The quarantine management table 21 shown in FIG. 4 defines the correspondence between the application status ST of the patches managed by the patch management server 15 described above and the pass / fail of the quarantine. In this example, among the four states ST1 to ST4 described above, only the state ST3 is defined as a pass, and the remaining states ST1, ST2, and ST4 are defined as fails. The system administrator registers such a quarantine management table 21 in advance with the quarantine server 14. Note that the quarantine management table 21 is not limited to defining pass / fail for each of the four states ST1 to ST4, and for example, it may define only the state ST3 that is considered a pass.
[0032] The quarantine server 14 performs the following operations generally using such a quarantine management table 21. First, when the client device TM requests a connection to the internal network 11, the quarantine server 14 acquires the application status ST of the patches managed by the patch management server 15 for the client device TM. Then, the quarantine server 14 refers to the quarantine management table 21 using the acquired application status ST of the patches to determine the pass / fail of the quarantine for the client device TM.
[0033] For example, in the example described with reference to FIGS. 3B and 4, when the client device TM10 requests a connection to the internal network 11, the quarantine server 14 determines that the quarantine for the client device TM10 is a pass. On the other hand, when the client device TM20 requests a connection to the internal network 11, the quarantine server 14 determines that the quarantine for the client device TM20 is a fail.
[0034] When using such a method, when the system administrator registers the patch security policy for the quarantine server 14, it is not necessary to register one patch to be quarantined for each version of each OS. That is, conventionally, in the conventional quarantine management table in the quarantine server 14, for example, when the OS is "version xxx of Windows 10", the system administrator has to perform registration operations such as passing if the update program of version "yyy" is applied for each version of the OS. Furthermore, for example, when the update program is versioned up and accordingly the application policy in the patch management server 15 is changed, the system administrator has to change the security policy in the quarantine server 14, that is, the conventional quarantine management table, to reflect the change content.
[0035] On the other hand, when using the method of the embodiment, the system administrator only needs to register a quarantine management table 21 as shown in FIG. 4. The registration content determines pass or fail for each application state of the patch managed by the patch management server 15, and does not require the input of the OS or the version of the update program. Furthermore, the registration content does not particularly require a change even if the application policy in the patch management server 15 is changed. As a result, it becomes possible to facilitate the operation of the quarantine network.
[0036] <Operation of Quarantine Network System> FIG. 5 is a sequence diagram showing an example of the processing content of the quarantine network system in FIG. 1. First, as a premise, in the authentication switch SW, network restrictions are performed in advance so as to permit only access from the client device TM to the quarantine server 14 and the patch management server 15. Specifically, the authentication switch SW assigns, for example, a VLAN that permits only access to the quarantine server 14 and the patch management server 15 to a client device TM for which network authentication is not permitted by using the authentication VLAN (Virtual Local Area Network) function.
[0037] In addition, the system administrator registers a quarantine management table 21 as shown in FIG. 4 in the quarantine server 14 in advance. On such a premise, the quarantine network system executes the process as shown in FIG. 5.
[0038] First, in response to a network connection request from the client device TM, the quarantine server 14 requests the client device TM to execute the security inspection program 39 (step S11). Specifically, for example, the authentication switch SW connects the client device TM to the quarantine server 14 in response to a network connection request from the client device TM. In response to this, the quarantine server 14 requests the client device TM to execute the security inspection program 39.
[0039] At step S11, if the security inspection program 39 has not been downloaded in the client device TM, the quarantine server 14 causes the download to be performed. Specifically, the quarantine server 14 stores the security inspection program 39 in the memory 20. Then, the quarantine server 14 displays, for example, a link or button for downloading the security inspection program 39 in the memory 20 to the client device TM on the display 31 of the client device TM, for example, on a Web screen. When the user 17 selects the link or the like, the client device TM downloads the security inspection program 39 from the quarantine server 14 to its own memory 36.
[0040] Subsequently, the client device TM starts the security inspection program 39 stored in the memory 36 (step S12). At this time, after completing the download of the security inspection program 39 in step S11, the client device TM may automatically start the security inspection program 39. Also, the download and start of the security inspection program 39 in steps S11 and S12 are performed each time a network connection request occurs from the client device TM.
[0041] However, not limited to such a method, when the quarantine server 14 receives, for example, a first network connection request from the client device TM, it may cause the client device TM to install the security inspection program 39. In this case, when the quarantine server 14 receives a network connection request from the client device TM for the second time and later, it may cause the installed security inspection program 39 to be executed.
[0042] Thereafter, the client device TM, specifically, the processor 35 of the client device TM, performs the processing of the subsequent steps S13 to S15, S18-1a, S18-1b, and S18-2 by executing the security inspection program 39.
[0043] In step S13, the client device TM obtains the destination information for the patch management server 15, such as an IP address (Internet Protocol) or FQDN (Fully Qualified Domain Name), from the quarantine server 14 or from the information registered in the client device TM. The destination information is registered in the quarantine server 14 in advance in the former case and in the client device TM in advance in the latter case. In many cases, the destination information is registered in the client device TM in advance so that the patch management server 15 can manage the update program of the device itself.
[0044] Next, the client device TM sends a request to obtain the patch application status ST to the patch management server 15 represented by the destination information obtained in step S13 (step S14a). The patch application status ST at this time represents the application status managed by the patch management server 15 for the client device TM that is the request source. Then, in response to step S14a, the client device TM obtains from the patch management server 15 the patch application status ST in its own device, specifically, for example, an identifier for distinguishing the application status ST, etc. (step S14b).
[0045] Subsequently, the client device TM transmits a quarantine pass / fail determination request based on the patch application status ST acquired in step S14b to the quarantine server 14 (step S15). Specifically, the client device TM transmits, for example, a quarantine pass / fail determination request including an identifier for distinguishing the application status ST or the like.
[0046] On the other hand, the quarantine server 14 receives the pass / fail determination request from the client device TM, and determines the pass / fail of the quarantine in the client device TM by referring to the quarantine management table 21 using the patch application status ST acquired from the pass / fail determination request (step S16). Then, the quarantine server 14 transmits the quarantine pass / fail determination result to the client device TM (step S17).
[0047] If the quarantine pass / fail determination result received in step S17 is a pass, the client device TM displays a message indicating that "the quarantine has passed" on the display 31, for example, on a Web screen or on a screen displayed by the security inspection program 39. Thereafter, the user 17 inputs account information such as a user identifier and a password on the Web screen of the authentication switch SW or on a screen by the security inspection program 39. The client device TM transmits a network authentication request based on the account information to the authentication switch SW (step S18-1a).
[0048] In step S19, the authentication switch SW inquires of the authentication server 16 about the permission or non-permission of network authentication based on the received account information. As a result, when the authentication switch SW determines to permit network authentication, it releases the network restriction on the client device TM. Also, the authentication switch SW transmits the network authentication determination result to the client device TM (step S18-1b). Here, an authentication method using a user identifier and a password has been shown, but network authentication may be performed using a digital certificate applied to the authentication server 16, the client device TM, or both.
[0049] In step S19, specifically, the authentication switch SW assigns a VLAN with network restrictions removed to the client device TM using, for example, an authentication VLAN function. As a result, the client device TM is able to access, for example, the business server 13 and the external network 10 via the gateway 12. On the other hand, if the authentication switch SW determines that the network authentication is to be rejected, for example, the authentication switch SW requests the client device TM to re-enter account information.
[0050] On the other hand, if the quarantine pass / fail judgment result received in step S17 is a failure, the client apparatus TM displays, for example, a message stating "Quarantine has failed and connection to the network is denied" on a Web screen or a screen displayed by the security inspection program 39. Furthermore, the client apparatus TM displays, for example, a link or button for applying the update program from the patch management server 15 on the Web screen or a screen displayed by the security inspection program 39.
[0051] Here, when the user 17 of the client device TM selects the link, the client device TM transmits an update program acquisition request to the patch management server 15, and can acquire the latest update program from the patch management server 15 (step S18-2). That is, the patch management server 15 also functions as a treatment server in the quarantine network.
[0052] <A variant of the quarantine network system [1]> In the case of a failed quarantine network, various methods are available, such as the authentication switch method, the personal firewall method, and the authentication DHCP (Dynamic Host Configuration Protocol) method, depending on which part is to be denied free connection to the internal network 11. Figure 5 shows an example of the authentication switch method, in which a security inspection program 39 communicates with the authentication switch SW to restrict connection to the network.
[0053] That is, as described in steps S18-1a, S18-1b, and S18-2, when the quarantine fails, the security inspection program 39 controls so that a network authentication request is not sent to the authentication switch SW. As a result, network authentication by the authentication switch SW is not permitted, and thus, free connection to the internal network 11 is denied by the security inspection program 39.
[0054] On the other hand, the personal firewall method is one of the applicable methods when the authentication switch SW is not provided. In this case, according to the pass / fail determination result of the quarantine, the security inspection program 39 controls the personal firewall installed in the client device TM to control access to the internal network 11. In this case, the quarantine server 14 determines the pass / fail of the quarantine using the quarantine management table 21 as in the case of step S16, and in step S17, the pass / fail determination result may be transmitted to the client device TM.
[0055] When the client device TM receives a response from the quarantine server 14 indicating that the quarantine has failed, the security inspection program 39 controls the personal firewall of the client device TM. As a result, communication to the internal network 11 is denied, and free connection to the internal network 11 is denied. On the other hand, when the client device TM receives a response indicating that the quarantine has passed, the security inspection program 39 controls the personal firewall of the client device TM to permit communication to the internal network 11.
[0056] The authentication DHCP method is a method of denying free access to the internal network 11 by a DHCP server (not shown) when the quarantine fails. When using this method, the DHCP server assigns, for example, a pre-inspection IP address to the client device TM, and when the quarantine is successful, assigns an IP address with network restrictions lifted. At this time, similar to the case of step S16, the quarantine server 14 uses the quarantine management table 21 to determine whether the quarantine is passed or failed, and in step S17, it may send the pass / fail determination result to the DHCP server.
[0057] <Modification Example [2] of the Quarantine Network System> In FIG. 5, in steps S14a, S14b, and S15, the application state ST of the patch in the client device TM was obtained using the security inspection program 39 in the client device TM, and a pass / fail determination was requested from the quarantine server 14. Instead, for example, the client device TM may send a quarantine request to the quarantine server 14 using the security inspection program 39 in step S15 without making the acquisition requests in steps S14a and S14b.
[0058] In this case, the quarantine server 14 that has received the quarantine request checks the application state ST of the client device TM with the patch management server 15, and based on the response result, collates it with the quarantine management table 21 in step S16 to make a pass / fail determination. Regarding step S15, specifically, the client device TM may obtain, for example, the computer name of the client device TM using the security inspection program 39 at the startup stage in step S12. Then, in step S15, the client device TM may send a quarantine request including the computer name, etc. to the quarantine server 14.
[0059] <Modification Example [3] of the Quarantine Network System> In FIG. 5, the case where the patch management server 15 manages the application status of patches for the OS is taken as an example. However, the patch management server 15 is not limited to this, and may manage the application status of patches for antivirus programs. Also in this case, similar to the case of FIG. 5, the client device TM may use a security inspection program to obtain the application status of patches in the client device TM managed by the patch management server 15 and transmit it to the quarantine server 14. The application status of the patch at this time is, for example, the application status of an update program for an antivirus program, the version information of virus definition information, and the like.
[0060] <Details of the security inspection program> FIG. 6 is a block diagram showing a detailed functional configuration example of the main part of the client device TM in FIG. 1. The client device TM shown in FIG. 6 includes a status acquisition unit 40, a pass / fail determination request unit 41, a determination result reception unit 42, and a network authentication request unit 43. Each of these units is realized by the processor 35 of the client device TM executing the security inspection program 39 in the memory 36. That is, the security inspection program 39 is for causing the computer 30 to function as the status acquisition unit 40, the pass / fail determination request unit 41, the determination result reception unit 42, and the network authentication request unit 43.
[0061] As shown in steps S14a and S14b in FIG. 5, the status acquisition unit 40 acquires the patch application status ST from the patch management server 15 by transmitting a request to acquire the patch application status ST to the patch management server 15. The pass / fail determination request unit 41 transmits a quarantine pass / fail determination request based on the acquired patch application status ST to the quarantine server 14 as shown in step S15 in FIG. 5. Specifically, the pass / fail determination request unit 41 transmits a pass / fail determination request including, for example, an identifier for distinguishing the patch application status ST.
[0062] As shown in step S17 in FIG. 5, the determination result receiving unit 42 receives the pass / fail determination result of the quarantine from the quarantine server 14. As shown in steps S18-1a and S18-1b in FIG. 5, when the pass / fail determination result of the quarantine is a pass, the network authentication request unit 43 transmits a network authentication request to the authentication switch SW.
[0063] <Details of the Quarantine Server> FIG. 7 is a block diagram showing a detailed functional configuration example of the main part of the quarantine server 14 in FIG. 1. The quarantine server 14 shown in FIG. 7 includes a connection request receiving unit 45, a pass / fail determination unit 46, and a memory 20. Each of these units is realized, for example, when a processor of the quarantine server 14 executes a quarantine management program (not shown) in the memory 20. However, each of these units is not limited to such a software implementation form, and may be realized by hardware such as an FPGA (Field Programmable Gate Array) or an ASIC (Application Specific Integrated Circuit), or may be realized by a combination of software and hardware.
[0064] As shown in FIG. 4, the memory 20 stores a quarantine management table 21 that defines the correspondence between the application state ST of the patch managed by the patch management server 15 and the pass / fail of the quarantine. The memory 20 also stores a security inspection program 39 for causing the client device TM to perform a download. As shown in step S11 in FIG. 5, the connection request receiving unit 45 receives a network connection request from the client device TM via the authentication switch SW. Then, in response to the connection request, the connection request receiving unit 45 requests the client device TM to execute the security inspection program 39.
[0065] At this time, as described in step S11, if the security inspection program 39 has not been downloaded to the client device TM, the connection request reception unit 45 causes the client device TM to download the security inspection program 39. Specifically, the connection request reception unit 45 causes the client device TM to display, for example, a screen for downloading the security inspection program 39 in the memory 20 to the client device TM, for example, a screen including a link or a button to the security inspection program 39. When the user 17 selects the link or the like, the client device TM downloads and executes the security inspection program 39 from the quarantine server 14.
[0066] As shown in steps S15 and S16 in FIG. 5, the pass / fail determination unit 46 acquires the application state ST of the patch managed by the patch management server 15 from the client device TM. Then, the pass / fail determination unit 46 refers to the quarantine management table 21 using the acquired application state ST of the patch to determine the pass / fail of the quarantine in the client device TM, and transmits the pass / fail determination result to the client device TM.
[0067] Note that, as described in the modification [2], the pass / fail determination unit 46 may directly acquire the application state ST of the patch in the client device TM from the patch management server 15. Further, as described in the modification [1], the pass / fail determination unit 46 may transmit the pass / fail determination result to the DHCP server. Furthermore, in some cases, the pass / fail determination unit 46 may transmit the pass / fail determination result to the authentication switch SW and cause the authentication switch SW to perform network restriction.
[0068] <Main effects of the embodiment> As described above, in the method of the embodiment, based on the quarantine management table 21 that defines the correspondence between the patch application state ST in the client device TM managed by the patch management server 15 and the pass / fail of quarantine, the pass / fail of quarantine is determined. Thereby, it is possible to easily match the patch security policy in the quarantine server 14 and the patch application policy in the patch management server 15, and it becomes possible to facilitate the operation of the quarantine network. Also, by using the security inspection program 39 to cause the client device TM to acquire the patch application state ST and transmit it to the quarantine server 14, it is possible to appropriately and easily implement quarantine management based on the patch application state ST.
[0069] As described above, the invention made by the present inventor has been specifically described based on the embodiments. However, the present invention is not limited to the above-described embodiments, and various modifications can be made without departing from the gist thereof. For example, the above-described embodiments have been described in detail for easy understanding of the present invention, and are not necessarily limited to those having all the configurations described. Also, a part of the configuration of one embodiment can be replaced with the configuration of another embodiment, and the configuration of another embodiment can be added to the configuration of one embodiment. Also, for a part of the configuration of each embodiment, it is possible to add, delete, or replace other configurations.
[0070] For example, the various programs described above can be stored in a non-temporary tangible computer-readable recording medium and then supplied to a computer. Examples of such a recording medium include magnetic recording media typified by hard disk drives, optical recording media typified by DVDs (Digital Versatile Discs) and Blu-ray discs, and semiconductor memories typified by flash memories.
Explanation of Reference Numerals
[0071] 11: Internal network, 14: Quarantine server, 15: Patch management server, 20, 22, 36: Memory, 21: Quarantine management table, 30: Computer, 39: Security inspection program, 40: Status acquisition unit, 41: Pass / fail determination request unit, 42: Determination result reception unit, 43: Network authentication request unit, 46: Pass / fail determination unit, ST: Patch application status, SW: Authentication switch, TM: Client device
Claims
1. A client device, a quarantine server connected to a network, inspecting the client device, and determining whether the quarantine of the client device is passed or failed based on the inspection result, a patch management server connected to the network and managing the application status of patches in the client device by distinguishing them into a plurality of states through communication with the client device, A quarantine network system comprising: The quarantine server stores a quarantine management table that defines the correspondence between each state of the patch application status managed by the patch management server and the pass / fail of quarantine. When the client device requests to connect to the network, the patch management server acquires the patch application status it manages, and refers to the quarantine management table using the acquired patch application status to determine whether the quarantine of the client device is passed or failed. The client device is implemented by a computer. When the client device requests to connect to the network, the quarantine server requests the client device to execute a security inspection program. The client device, by executing the security inspection program, has a status acquisition unit that acquires the patch application status from the patch management server, a pass / fail determination request unit that transmits a pass / fail determination request for quarantine based on the acquired patch application status to the quarantine server, a determination result reception unit that receives a pass / fail determination result of quarantine from the quarantine server, functions as, a quarantine network system.
2. In the quarantine network system according to Claim 1, an authentication switch is connected between the client device and the network to perform network authentication of the client device. The client device, by executing the security inspection program, further functions as a network authentication request unit that transmits a network authentication request to the authentication switch when the pass / fail determination result of quarantine received by the determination result reception unit is a pass. A quarantine network system.
3. In the quarantine network system according to Claim 1, the patch management server is a WSUS (Windows Server Update Services) server. A quarantine network system.
4. A quarantine server applied to a quarantine network system having a patch management server that manages the patch application status in a client device by distinguishing it into a plurality of states, inspects the client device, and determines whether the quarantine of the client device is passed or failed based on the inspection result. A memory that stores a quarantine management table that defines the correspondence between each state of the patch application status managed by the patch management server and the pass / fail of quarantine. When the client device requests a connection to the network, the patch application status managed by the patch management server is acquired, and the quarantine management table is referred to using the acquired patch application status, and a pass / fail determination unit that determines whether the quarantine of the client device is passed or failed. A connection request reception unit that receives a connection request from the client device to the network and, in response to the connection request, requests the client device to execute a security inspection program. Comprising The security inspection program causes the client device to A status acquisition unit that acquires the patch application status from the patch management server. A pass / fail determination request unit that transmits a pass / fail determination request for quarantine based on the acquired patch application status to the quarantine server. A determination result reception unit that receives a pass / fail determination result for quarantine from the quarantine server. A program for causing it to function as Quarantine server.
5. In the quarantine server according to claim 4, The security inspection program causes the client device to When the pass / fail determination result for quarantine received by the determination result reception unit is a pass, a network authentication request unit that transmits a network authentication request to an authentication switch. A program for causing it to further function as Quarantine server.
6. In the quarantine server according to claim 4 or 5, The memory stores the security inspection program. The connection request reception unit causes the client device to display a screen for downloading the security inspection program in the memory to the client device in response to the connection request from the client device. Quarantine server.
7. A quarantine network system having a quarantine server that inspects a client device and determines whether the quarantine of the client device is passed or failed based on the inspection result, and a patch management server that manages the application state of patches in the client device by distinguishing them into a plurality of states, on the premise of which, a security inspection program applied to the client device realized by a computer, the computer is made to, a state acquisition unit that acquires the application state of the patch from the patch management server, a pass / fail determination request unit that transmits a pass / fail determination request for quarantine based on the acquired application state of the patch to the quarantine server, a determination result reception unit that receives a pass / fail determination result of quarantine from the quarantine server, for functioning as, a security inspection program.
8. In the security inspection program according to Claim 7, the quarantine network system has an authentication switch that performs network authentication of the client device, the security inspection program, the computer is made to, a network authentication request unit that transmits a network authentication request to the authentication switch when the pass / fail determination result of quarantine received by the determination result reception unit is a pass, for further functioning as, a security inspection program.
Citation Information
Patent Citations
Network connection control system
JP2006066982A
Network management system, method and program
JP2006252256A
Quarantine network system
JP2008077558A
Quarantine system, quarantine method, and quarantine program
JP2008084266A
Information processing system, information processing method, and control program
JP2012168710A