Information processing system, information processing method, and information processing program

The information processing system addresses the challenge of immediate detection and blockage of unauthorized communication by integrating upper and lower NW devices to enhance security in complex ICT environments, ensuring robust security and cost-effective service deployment.

JP7710549B2Active Publication Date: 2025-07-18NTT DOCOMO BUSINESS INC
View PDF 8 Cites 0 Cited by

Patent Information

Application Number
JP2024017964
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2023-03-03
Filing Date
2024-02-08
Publication Date
2025-07-18
Estimated Expiration
2043-06-30

AI Technical Summary

Technical Problem

Existing security measures struggle to handle immediate detection and block unauthorized communication on devices, especially after infection, particularly in complex ICT environments with remote work and IoT integration, where traditional boundary-based security is ambiguous.

Method used

An information processing system comprising an upper NW device and lower NW devices that collaborate to detect and block unauthorized communication, where the upper NW device blocks communication based on information from lower NW devices, utilizing a unified threat management system to manage and filter out unauthorized IP addresses.

Benefits of technology

The system achieves robust security by enhancing detection accuracy and enabling immediate response to unauthorized communication, supporting zero-trust security and reducing operational costs through flexible service deployment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007710549000001
    Figure 0007710549000001
  • Figure 0007710549000002
    Figure 0007710549000002
  • Figure 0007710549000003
    Figure 0007710549000003
Patent Text Reader

Abstract

To provide an information processing system, a method, and a program that achieve robust security.SOLUTION: An information processing system includes an upper-level NW (network) device and a plurality of lower-level NW devices. Each lower-level NW device collates information on communication of a terminal connected to the lower-level NW device, with information obtained by analyzing, together, contents of communication involving the lower-level NW device and information on past cyber-attacks stored in an external device, detects unauthorized communication, and notifies the upper-level NW device of information on the detected unauthorized communication. The upper-level NW device adds the information on the unauthorized communication that has been notified by each of the plurality of lower-level network devices that makes up respective underlay networks to a list of IP addresses that are not allowed to communicate, and uses the information added to the list to block unauthorized communication using security functions of UTM.SELECTED DRAWING: Figure 7
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an information processing system, an information processing method, and an information processing program.

Background Art

[0002] Conventionally, there are technologies for detecting unauthorized communication. For example, there are known technologies for identifying terminals that perform suspicious communication or behavior by installing firewalls and IPSs (Intrusion Prevention Systems) at gateways and monitoring communications.

Prior Art Documents

Non-Patent Documents

[0003]

Non-Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] In the prior art, there were security problems. For example, in some cases, it may not be possible to handle detections and blocks for PCs (Personal Computers) immediately after infection.

[0005] The present invention has been made in view of the above, and an object thereof is to provide an information processing system, an information processing method, and an information processing program for realizing robust security.

Means for Solving the Problems

[0006] In order to solve the above-described problems and achieve the object, an information processing system according to the present invention includes an upper NW (network) device that is a device constituting an overlay network, and a device provided by the same operator as the operator providing the device constituting the overlay network, and is an information processing system including a plurality of lower NW devices that are devices constituting each underlay network. The upper NW device adds information on unauthorized communication notified from each of the plurality of lower NW devices constituting each underlay network to a list of IP addresses that do not permit communication, and uses the information added to the list to block the unauthorized communication by a security function of UTM. The upper NW device has a blocking unit. Each of the lower NW devices collates information obtained by analyzing information on communication of a terminal connected to the lower NW device, communication content in which the lower NW device is involved, and information on past cyberattacks stored in an external device, and has a detection unit that detects the unauthorized communication, and a notification unit that notifies the upper NW device of the information on the unauthorized communication detected by the detection unit.

Effect of the Invention

[0007] According to the present invention, robust security can be realized.

Brief Description of the Drawings

[0008]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Mode for Carrying Out the Invention

[0009] Hereinafter, with reference to the drawings, embodiments of the information processing system, information processing method, and information processing program according to the present application will be described in detail. Note that the present invention is not limited by this embodiment. Also, in the description of the drawings, the same parts are denoted by the same reference numerals, and duplicate descriptions are omitted.

[0010] [Prior Art] First, the prior art will be described with reference to FIG. 1. FIG. 1 is a diagram for explaining the prior art.

[0011] Hereinafter, the device constituting the overlay network will be referred to as an upper NW device, and the device constituting the underlay network will be referred to as a lower NW device. Here, the upper NW device refers to, for example, a cloud proxy server or a UTM (Unified Threat Management). Also, the lower NW device refers to, for example, network devices such as DPI (Deep Packet Inspection), routers, and switches.

[0012] Previous security measures involved dividing the network into a trusted "inside" and an untrusted "outside" and taking countermeasures at the boundary. For example, the inside network could include an in-house LAN (Local Area Network) or a data center connected via a VPN (Virtual Private Network), while the outside network would be the Internet. For instance, as countermeasures taken at the boundary, security devices such as firewalls, proxies, IDS (Intrusion Detection System) / IPS (Intrusion Prevention System) are installed at the boundary to monitor and control communications, thereby blocking cyberattacks from the outside.

[0013] These previous security measures assume that the data and systems to be protected are inside the network. However, with the spread of the cloud, it is not uncommon for things to be protected on the outside Internet. Thus, as the objects to be protected are scattered in various locations, the boundary has become ambiguous, and it is becoming difficult to take sufficient countermeasures with the conventional way of thinking.

[0014] Therefore, the concept of zero trust is spreading. In zero-trust security services, various security measures are taken on the premise that all communications are not trusted. Specifically, it includes encryption of communication paths regardless of whether they are inside or outside the network, strengthening of user authentication by using multi-factor authentication, and integrated log monitoring of the network and various devices connected to it. Many security solutions for realizing zero trust have already emerged. For example, EDR (Endpoint Detection and Response) is provided to enable early detection and response to cyberattacks by monitoring client devices and analyzing logs.

[0015] In addition, there has been a technology for detecting unauthorized communication. For example, there is a technology for identifying a terminal that conducts suspicious communication or behavior by installing a firewall or an IPS in a gateway or by monitoring communication.

[0016] In the prior art, there were security problems. For example, as illustrated in FIG. 1, while it was possible to identify a terminal that conducts suspicious communication or behavior, when a normally functioning PC was infected with malware or the like, it was difficult for the detection block to handle it, and there were cases where suspicious communication was allowed.

[0017] Therefore, the information processing system 1 according to the embodiment described below is an information processing system including an upper NW device 100 which is a device constituting an overlay network and a lower NW device 200 which is a device constituting an underlay network. The upper NW device 100 cuts off unauthorized communication based on the information on unauthorized communication notified from the lower NW device 200. The lower NW device 200 acquires information on the communication of the terminal connected to the lower NW device 200, detects unauthorized communication based on the acquired information on the communication of the terminal connected to the lower NW device 200, and notifies the upper NW device 100 of the detected information on unauthorized communication.

[0018] By such an information processing system, effects such as realizing robust security can be obtained.

[0019] In addition, in the information processing system 1, in response to an ICT (Information and Communication Technology) environment that becomes more complex and has an increased cyber risk due to new work styles such as remote work and new business expansion through the use of IoT and the like, the underlay NW and the overlay NW cooperate to provide a zero-trust security service unique to a line operator (carrier).

[0020] The information processing system 1 provides a secure NaaS (Network as a Service)-type ICT service in which the functions of the overlay NW and the underlay NW are closely coordinated. Enterprises that receive the service of this information processing system 1 can easily start, change, and cancel the service of this information processing system 1 immediately by applying through the management portal site without incurring costs for IT (Information Technology) vendor commission or costs associated with NW design, and can reduce the costs related to the operation from design to operation.

[0021] [Configuration of the information processing system] Next, the configuration of the information processing system 1 will be described with reference to FIG. 2. As shown in FIG. 2, the information processing system 1 includes an upper NW device 100 and a lower NW device 200. Each of these devices will be described below. Note that in the information processing system 1, the upper NW device 100 and the lower NW device 200 are not limited to being one each, and a plurality of them may be provided.

[0022] The upper NW device 100 is a device that controls the upper network of the information processing system 1. The upper NW device 100 blocks unauthorized communications using the information on unauthorized communications notified from the lower NW device 200.

[0023] The lower NW device 200 is a device that controls the lower network of the information processing system 1. The lower NW device 200 acquires information related to the communication of terminals (for example, OA devices, IoT devices, etc.) connected to the lower NW device 200, detects unauthorized communications based on the acquired information, and notifies the upper NW device 100 of the information on unauthorized communications.

[0024] [Configuration of the upper NW device] Next, the configuration of the upper-level NW device 100 will be described with reference to FIG. 3. As shown in FIG. 3, the upper-level NW device 100 includes a communication unit 110, a control unit 120, and a storage unit 130. Note that these units may be held by a plurality of devices in a distributed manner. The processing of each of these units will be described below.

[0025] The communication unit 110 is realized by a NIC (Network Interface Card) or the like, and enables communication between the control unit 120 and an external device via a telecommunication line such as a LAN (Local Area Network) or the Internet. For example, the communication unit 110 enables communication between the external device and the control unit 120.

[0026] The storage unit 130 is realized by a semiconductor memory element such as a RAM (Random Access Memory) or a flash memory, or a storage device such as a hard disk or an optical disk. Information stored in the storage unit 130 includes, for example, terminal information managed by the upper-level NW device 100, terminal information managed by the lower-level NW device 200, information related to the communication of terminals connected to the lower-level NW device 200, information related to unauthorized communication, information on detected unauthorized communication, other information necessary for detecting unauthorized communication, and other information necessary for blocking unauthorized communication. Here, the information related to unauthorized communication includes information such as the type of communication destination of unauthorized communication, terminal information, and IP address. Note that the information stored in the storage unit 130 is not limited to the examples described above.

[0027] The control unit 120 is realized by using a CPU (Central Processing Unit), an NP (Network Processor), an FPGA (Field Programmable Gate Array), or the like, and executes a processing program stored in a memory. As shown in FIG. 3, the control unit 120 includes a blocking unit 121. Each unit included in the control unit 120 will be described below.

[0028] The blocking unit 121 blocks unauthorized communication based on the information of unauthorized communication notified by the lower-level NW device 200. For example, the blocking unit 121 uses the information of unauthorized communication notified by the lower-level NW device 200 to block communication to the communication destination of the unauthorized communication. For example, the blocking unit 121 uses the type of unauthorized communication and the IP address information notified by the notification unit 223 to block communication to the communication destination of the unauthorized communication.

[0029] For example, the blocking unit 121 adds the IP address information of the unauthorized communication destination notified by the notification unit 223 to the list of IP addresses that do not permit communication, and blocks communication to the communication destination of the unauthorized communication by filtering.

[0030] [Configuration of Lower-Level NW Device] Next, the configuration of the lower-level NW device 200 will be described with reference to FIG. 4. As shown in FIG. 4, the lower-level NW device 200 includes a communication unit 210, a control unit 220, and a storage unit 230. Note that each of these units may be held in a distributed manner by a plurality of devices. The processing of each of these units will be described below.

[0031] The communication unit 210 is implemented by a NIC or the like and enables communication between the control unit 220 and an external device via a telecommunication line such as a LAN or the Internet. For example, the communication unit 210 enables communication between the external device and the control unit 220.

[0032] The storage unit 230 is implemented by a semiconductor memory device such as a RAM or a flash memory, or a storage device such as a hard disk or an optical disk. Information stored in the storage unit 230 includes, for example, terminal information managed by the upper NW device 100, terminal information managed by the lower NW device 200, information related to the communication of terminals connected to the lower NW device 200, information related to unauthorized communication, information on detected unauthorized communication, and other information necessary for detecting unauthorized communication. Here, the information related to unauthorized communication stored in the storage unit 230 includes information obtained by analyzing together the communication content in which the lower NW device 200 is involved and information on past cyberattacks stored in an external device (integrated security analysis platform). Note that the information stored in the storage unit 230 is not limited to the examples described above.

[0033] The control unit 220 is implemented using a CPU, an NP, an FPGA, etc., and executes a processing program stored in a memory. As shown in FIG. 4, the control unit 220 includes an acquisition unit 221, a detection unit 222, and a notification unit 223. Hereinafter, each unit included in the control unit 220 will be described.

[0034] The acquisition unit 221 acquires information related to the communication of terminals connected to the lower NW device 200. For example, the acquisition unit 221 acquires information related to the communication of OA devices and IoT devices connected to the lower NW device 200.

[0035] For example, the acquisition unit 221 acquires flow data including communication date and time, destination IP address, source IP address, etc. as information related to communication.

[0036] The detection unit 222 detects unauthorized communication based on the information related to the communication of terminals connected to the lower NW device 200 acquired by the acquisition unit 221. For example, the detection unit 222 detects unauthorized communication by comparing the information related to the communication of terminals connected to the lower NW device 200 acquired by the acquisition unit 221 with the information related to unauthorized communication stored in the storage unit 230.

[0037] Further, the detection unit 222 may detect unauthorized communication by collating information regarding the communication of the terminal connected to the lower-level NW device 200 transmitted from the lower-level NW device 200 with information regarding unauthorized communication stored in an external device.

[0038] Note that the detection unit 222 may detect the information regarding unauthorized communication itself stored in the storage unit 230 as unauthorized communication. For example, the detection unit 222 may detect, as unauthorized communication, the information itself obtained by analyzing together the communication content in which the lower-level NW device 200 is involved and stored in the storage unit 130 and information such as past cyber attack information stored in an external device.

[0039] For example, the detection unit 222 performs detection according to the characteristics of communication, such as anomalies in fluctuations in traffic volume and abnormal traffic patterns, as data of an ISP (Internet Serves Provider) collected in the underlay NW. Note that the detection unit 222 may use any existing detection method.

[0040] The notification unit 223 notifies the upper-level NW device 100 of the information regarding the unauthorized communication detected by the detection unit 222. For example, the notification unit 223 notifies the upper-level NW device 100 of information such as the detection date and time of unauthorized communication, the detection type, the destination IP address, and the source IP address as the information regarding the unauthorized communication detected by the detection unit 222.

[0041] In this way, when the detection unit 222 detects unauthorized communication, the notification unit 223 immediately notifies the upper-level NW device 100 of the information regarding the unauthorized communication. For this reason, the upper-level NW device 100 can immediately reflect it in the overlay service by adding the unauthorized IP address to the list of IP addresses for which communication is not permitted, and the overlay NW and the underlay NW can cooperate to improve the detection accuracy of unauthorized communication.

[0042] [Overview of Processing by Information Processing System] Next, with reference to FIG. 5, the processing by the information processing system 1 will be described. FIG. 5 is a diagram for explaining the outline of the processing by the information processing system 1.

[0043] First, the acquisition unit 221 of the lower-layer NW device 200 acquires information regarding the communication of terminals connected to the lower-layer NW device 200. For example, it acquires information regarding the communication of OA devices, IoT devices, etc. connected to the lower-layer NW device 200.

[0044] Subsequently, the detection unit 222 of the lower-layer NW device 200 detects unauthorized communication based on the information regarding the communication of terminals connected to the lower-layer NW device 200 acquired by the acquisition unit 221.

[0045] Subsequently, the notification unit 223 of the lower-layer NW device 200 notifies the upper-layer NW device 100 of the information on the unauthorized communication detected by the detection unit 222.

[0046] Then, the blocking unit 121 of the upper-layer NW device 100 blocks communication to the communication destination of the unauthorized communication based on the information on the unauthorized communication notified by the notification unit 223.

[0047] The blocking unit 121 cooperates with an external device, adds the IP addresses of malicious terminals to a list, and performs filtering. For example, the blocking unit 121 uses a database storing the IP addresses of C2 (Command and Control server) servers discovered by analyzing flow data and DDoS (Distributed Denial of Service) analysis in the underlying NW, and performs access control according to the ACL (Access Control List) of the firewall, which is one of the security functions of the UTM that is the upper-layer NW device 100, to block communication to C2.

[0048] In this way, the upper-layer NW device 100 intensively collects the detection results of malicious flows detected in each underlay NW, adds them to the list of IP addresses that do not permit communication, and blocks unauthorized communication in the overlay NW, thereby making it possible to improve the detection accuracy. Furthermore, even when the user uses only the overlay NW and the underlay NW is provided by another company, the upper-layer NW device 100 can accurately provide a service that blocks unauthorized communication to such users by implementing the block in the overlay NW.

[0049] In the information processing system 1, the overlay NW and the underlay NW are provided by the same operator. In addition, users who use the information processing system 1 can use it flexibly, for example, by using only the overlay NW and using another company for the underlay NW.

[0050] In this way, in the information processing system 1, the upper-layer NW device 100 and the lower-layer NW device 200 closely cooperate to detect and block unauthorized communication.

[0051] [Detection and Blocking Processing by Information Processing System] Next, with reference to FIG. 6, the detection process and the blocking process by the information processing system 1 will be described. FIG. 6 is a diagram for explaining the detection process and the blocking process by the information processing system 1.

[0052] As shown in FIG. 6(1), the storage unit 230 of the lower-layer NW device 200 stores information related to unauthorized communication, such as the type of unauthorized communication destination and the IP address. Here, the information related to unauthorized communication stored in the storage unit 230 may be information obtained by analyzing the communication content in which the lower-layer NW device 200 is involved and the information on past cyberattacks stored in an external device.

[0053] For example, the storage unit 230 stores information related to unauthorized communication, such as the type of unauthorized communication destination and the IP address, obtained by analyzing the communication information of the terminal connected to the lower-layer NW device 200 and the past DDoS attack information.

[0054] The detection unit 222 of the lower NW device 200 detects unauthorized communication by comparing the information on the communication of the terminal connected to the lower NW device 200 acquired by the acquisition unit 221 with the information on unauthorized communication stored in the storage unit 230. At this time, the detection unit 222 may detect the information on unauthorized communication itself stored in the storage unit 130 as unauthorized communication. For example, the detection unit 222 detects, as unauthorized communication, a type of "C2 server" and an IP address of "203.0.113.15".

[0055] The notification unit 223 of the lower NW device 200 notifies the upper NW device 100 of the information on the unauthorized communication (type of "C2 server", IP address of "203.0.113.15") detected by the detection unit 222.

[0056] Then, the blocking unit 121 of the upper NW device 100 uses the information on the unauthorized communication notified from the lower NW device 200 to block the communication to the communication destination of the unauthorized communication. For example, as shown in FIG. 6(2), the blocking unit 121 adds the information on the notified unauthorized communication destination IP address of "203.0.113.15" to the list of IP addresses that do not permit communication, and blocks the communication to the communication destination of the unauthorized communication by filtering.

[0057] In this way, the information processing system 1 has the upper NW device 100 and the lower NW device 200 cooperate to detect unauthorized communication and block unauthorized communication.

[0058] [Flowchart] Next, with reference to FIG. 7, the processing flow by the information processing system 1 will be described. Note that the following steps can also be executed in a different order, and there may be omitted processing.

[0059] First, the acquisition unit 221 of the lower-layer NW device 200 acquires information regarding the communication of the terminals connected to the lower-layer NW device 200 (step S101). For example, the acquisition unit 221 acquires information regarding the communication of OA devices and IoT devices connected to the lower-layer NW device 200.

[0060] Next, the detection unit 222 of the lower-layer NW device 200 detects unauthorized communication based on the information regarding the communication of the terminals connected to the lower-layer NW device 200 acquired by the acquisition unit 221 (step S102). For example, the detection unit 222 detects unauthorized communication by comparing the information regarding the communication of the terminals connected to the lower-layer NW device 200 acquired by the acquisition unit 221 with the information regarding unauthorized communication stored in the storage unit 230.

[0061] The notification unit 223 of the lower-layer NW device 200 notifies the upper-layer NW device 100 of the information regarding the unauthorized communication detected by the detection unit 222 (step S103). For example, the notification unit 223 notifies the upper-layer NW device 100 of information such as the type and IP address as the information regarding the unauthorized communication detected by the detection unit 222.

[0062] The blocking unit 121 of the upper-layer NW device 100 blocks the unauthorized communication based on the information regarding the unauthorized communication notified by the notification unit 223 (step S104). For example, the blocking unit 121 uses the information regarding the unauthorized communication notified by the notification unit 223 to block the communication to the communication destination of the unauthorized communication.

[0063] [Effect] The information processing system 1 according to the embodiment is an information processing system including an upper NW device 100 which is a device constituting an overlay network and a lower NW device 200 which is a device constituting an underlay network. The upper NW device 100 has a blocking unit 121 that blocks unauthorized communication based on information on unauthorized communication notified from the lower NW device 200. The lower NW device 200 has an acquisition unit 221 that acquires information on communication of a terminal connected to the lower NW device 200, a detection unit 222 that detects unauthorized communication based on the information on communication of the terminal connected to the lower NW device 200 acquired by the acquisition unit 221, and a notification unit 223 that notifies the upper NW device 100 of the information on unauthorized communication detected by the detection unit 222.

[0064] Thereby, the information processing system 1 can realize robust security by detecting unauthorized communication from the information acquired by the lower NW device 200, notifying the upper NW device 100 of the detected information on unauthorized communication, and blocking it.

[0065] The detection unit 222 in the lower NW device 200 of the information processing system 1 according to the embodiment detects unauthorized communication by collating the information on communication of the terminal connected to the lower NW device 200 acquired by the acquisition unit 221 with the information on unauthorized communication stored in the storage unit 230.

[0066] Thereby, the information processing system 1 can realize robust security by collating the information on communication of the terminal connected to the lower NW device 200 with the information on unauthorized communication to detect unauthorized communication.

[0067] The blocking unit 121 in the upper NW device 100 of the information processing system 1 according to the embodiment blocks communication to the communication destination of unauthorized communication using the information on unauthorized communication notified from the lower NW device 200.

[0068] As a result, the information processing system 1 can achieve robust security by using the notified information of unauthorized communication to block communication to the communication destination of unauthorized communication.

[0069] [Program] It is also possible to create a program that describes the processing executed by the information processing system 1 described in the above embodiment in a language executable by a computer. In this case, by the computer executing the program, the same effects as those of the above embodiment can be obtained. Further, such a program may be recorded on a computer-readable recording medium, and the same processing as that of the above embodiment may be realized by causing the computer to read and execute the program recorded on this recording medium.

[0070] FIG. 8 is a diagram showing an example of a computer that executes an information processing program. As shown in FIG. 8, the computer 1000 includes, for example, a memory 1010, a CPU 1020, a hard disk drive interface 1030, a disk drive interface 1040, a serial port interface 1050, a video adapter 1060, and a network interface 1070. These components are connected by a bus 1080.

[0071] The memory 1010 includes a ROM (Read Only Memory) 1011 and a RAM 1012. The ROM 1011 stores a boot program such as a BIOS (Basic Input Output System), for example. The hard disk drive interface 1030 is connected to the hard disk drive 1090. The disk drive interface 1040 is connected to the disk drive 1100. A removable storage medium such as a magnetic disk or an optical disk is inserted into the disk drive 1100, for example. A mouse 1110 and a keyboard 1120 are connected to the serial port interface 1050, for example. A display 1130 is connected to the video adapter 1060, for example.

[0072] Here, as shown in FIG. 8, the hard disk drive 1090 stores, for example, an OS (Operating System) 1091, application programs 1092, program modules 1093, and program data 1094. Each table described in the above embodiment is stored, for example, in the hard disk drive 1090 or the memory 1010.

[0073] Also, the information processing program is stored in the hard disk drive 1090 as, for example, a program module in which instructions executed by the computer 1000 are described. Specifically, the program module 1093 in which each process executed by the computer 1000 described in the above embodiment is described is stored in the hard disk drive 1090.

[0074] Also, the data used for information processing by the information processing program is stored in the hard disk drive 1090 as program data. Then, the CPU 1020 reads out the program module 1093 and the program data 1094 stored in the hard disk drive 1090 into the RAM 1012 as needed, and executes each of the above-described procedures.

[0075] Note that the program module 1093 and the program data 1094 related to the information processing program are not limited to being stored in the hard disk drive 1090, and may be stored in a removable storage medium, for example, and read out by the CPU 1020 via a disk drive 1100 or the like. Alternatively, the program module 1093 and the program data 1094 related to the control program may be stored in another computer connected via a network such as a LAN or a WAN (Wide Area Network), and read out by the CPU 1020 via the network interface 1070.

[0076] [Others] Various embodiments have been described in detail herein with reference to the drawings. However, these multiple embodiments are examples, and it is not intended to limit the present invention to these multiple embodiments. The features described herein can be realized in various ways, including various modifications and improvements based on the knowledge of those skilled in the art.

[0077] Also, the above-mentioned "parts (module, -er suffix, -or suffix)" can be read as units, means, circuits, etc. For example, the communication part (communication module), control part (control module), and storage part (storage module) can be read as a communication unit, a control unit, and a storage unit, respectively.

Description of Reference Numerals

[0078] 1 Information processing system 100 Upper NW device 110 Communication part 120 Control part 121 Cut-off part 130 Storage part 200 Lower NW device 210 Communication part 220 Control part 221 Acquisition part 222 Detection part 223 Notification part 230 Storage part

Claims

1. An information processing system comprising a host NW device that is a device constituting an overlay network, and a plurality of lower NW devices that are devices provided by the same operator as the operator providing the devices constituting the overlay network and that are devices constituting each underlay network, wherein the host NW device adds information on unauthorized communication notified from each of the plurality of lower NW devices constituting each underlay network to a list of IP addresses that do not permit communication, and uses the information added to the list to block the unauthorized communication by a security function of a UTM; a blocking unit having, each of the lower NW devices collates information obtained by analyzing together information on communication of a terminal connected to the lower NW device, characteristics of abnormal traffic of communication of a plurality of packets in which the lower NW device is involved, and information on past cyber-attack flow data stored in an external device, and a detection unit that detects the unauthorized communication; a notification unit that notifies the host NW device of information on the unauthorized communication detected by the detection unit and characterized by an information processing system.

2. The blocking unit adds information on unauthorized communication notified from each of the plurality of lower NW devices to a list of IP addresses that do not permit communication, and uses the information added to the list to block communication to the communication destination of the unauthorized communication The information processing system according to claim 1, characterized by the above.

3. An information processing method executed by a host NW device that is a device constituting an overlay network, and a plurality of lower NW devices that are devices provided by the same operator as the operator providing the devices constituting the overlay network and that are devices constituting each underlay network, wherein each of the lower NW devices collates information obtained by analyzing together information on communication of a terminal connected to the lower NW device, characteristics of abnormal traffic of communication of a plurality of packets in which the lower NW device is involved, and information on past cyber-attack flow data stored in an external device, and a detection step of detecting unauthorized communication; each of the lower NW devices notifies the host NW device of the information on the unauthorized communication detected in the detection step The upper NW device adds the information on unauthorized communication notified from each of the plurality of lower NW devices constituting each underlay network to a list of IP addresses that do not permit communication, and uses the information added to the list to block the unauthorized communication by the security function of the UTM; a blocking step An information processing method characterized by including the above.

4. A computer as an upper NW device that is a device constituting an overlay network, and a plurality of computers as a plurality of lower NW devices that are devices provided by the same operator as the operator providing the device constituting the overlay network and that constitute each underlay network, an information processing program to be executed on the computers, on the computer as the upper NW device, add the information on unauthorized communication notified from each of the plurality of lower NW devices constituting each underlay network to a list of IP addresses that do not permit communication, and use the information added to the list to block the unauthorized communication by the security function of the UTM; a blocking step to execute, on each computer as each lower NW device, compare with the information obtained by analyzing together the information on the communication of the terminal connected to the lower NW device, the characteristics of abnormal traffic of the communication of a plurality of packets in which the lower NW device is involved, and the information on the flow data of past cyber attacks stored in an external device, and a detection step of detecting the unauthorized communication; a notification step of notifying the upper NW device of the information on the unauthorized communication detected by the detection step An information processing program characterized by causing the above to be executed.

Citation Information

Patent Citations

  • Network attach defense system

    JP2006325091A

  • Warning system, illegal access track method, illegal access detection system, security management method and attack protection method

    JP2007122749A

  • Method and apparatus for detecting unwanted traffic in one or more packet networks using string analysis

    JP2010508598A

  • SCALABLE DDoS PROTECTION OF SSL-ENCRYPTED SERVICES

    US20170070531A1

  • Counting SYN packets

    US20210067534A1