Countermeasure presentation device, countermeasure presentation method, and countermeasure presentation program

A system tailors security measure presentation to user characteristics, enhancing implementation rates by using user-specific interfaces and explanations, addressing the challenge of diverse user needs in security measure implementation.

JP7759861B2Active Publication Date: 2025-10-24KDDI CORP
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2022142025
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-09-07
Publication Date
2025-10-24
Estimated Expiration
2042-09-07

AI Technical Summary

Technical Problem

Existing security measure presentation methods fail to account for user characteristics such as age, gender, and IT literacy, leading to difficulties in implementation and increased risk of security breaches when family or acquaintances assist, especially for users with low IT literacy.

Method used

A system that includes a security countermeasure registration unit, application information acquisition, terminal information acquisition, requirements collection, and countermeasure presentation units to tailor security measure presentation to user characteristics and environment, using appropriate interfaces and explanations based on user responses and terminal data.

Benefits of technology

Enables effective presentation of security measures using user-specific interfaces, improving implementation rates and reducing the digital divide by providing clear procedures and explanations suited to individual user needs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007759861000001
    Figure 0007759861000001
  • Figure 0007759861000002
    Figure 0007759861000002
  • Figure 0007759861000003
    Figure 0007759861000003
Patent Text Reader

Abstract

To provide a measure presentation device which can present an execution procedure of a security measure by an appropriate user interface, according to characteristics and use environment of a user.SOLUTION: A Web server 10 includes: a security measure registration unit 111 for receiving input of items of a security measure, and information including a condition to be executed, an execution procedure and explanation of terms, and registering the item and the information in a database; an application information acquisition unit 112 for acquiring application information from an application management server 20; a terminal information acquisition unit 113 for acquiring terminal information; a requirement collection unit 114 for requiring a response of a user for a question relating to the type of a user terminal 30 and use service; a measure presentation unit 115 for extracting an item required to be executed among the items of the security measure on the basis of the collected response, and presenting the item to the user terminal 30; and a measure procedure presentation unit 116 for extracting the execution procedure and the explanation of the terms for the selected item from the database, and presenting the execution procedure and the explanation to the user terminal 30.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an apparatus, a method, and a program for presenting security measures that need to be implemented. [Background technology]

[0002] Conventionally, there has been a demand for a mechanism to notify users of security measures that need to be implemented on their terminals. For example, Patent Document 1 proposes a technology for managing the patch application status of software by comparing patch information provided by the development vendor with the application status, extracting and notifying the users of necessary security measures. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Japanese Patent Application Laid-Open No. 2004-234208 [Patent Document 2] Japanese Patent Publication No. 2022-56574 [Non-patent literature]

[0004] [Non-Patent Document 1] Kazuhiko Hamamoto, "Web Design and Usability Evaluation for the Elderly," Information Processing Society of Japan SIG Technical Report, 2004, vol. 106, pp. 13-18. [Non-patent document 2] HM Salman et al., "Usability Evaluation of the Smartphone User Interface in Supporting Elderly Users From Experts' Perspective," IEEE Access, 2018, vol. 6, pp. 22578-22591. [Non-patent document 3] A. Frik et al., "Privacy and Security Threat Models and Mitigation Strategies of Older Adults," Proceedings of the Fifteenth Symposium on Usable Privacy and Security (SOUPS2019), 2019, pp. 21-40. [Non-patent document 4] V. Garg et al., "Designing Risk Communication for Older Adults," Gerontechnology, vol. 11, no. 2. [Non-Patent Document 5] TJ McGill and N. Thompson, "Gender Differences in Information Security Perceptions and Behavior," Australasian Conference on Information Systems, 2018. Summary of the Invention [Problem to be solved by the invention]

[0005] However, in the past, when promoting security measures, the same method was used for all users, making it difficult for users with low IT literacy to implement security measures themselves. As a result, some users entrusted the implementation of security measures to family members or acquaintances, but there was a risk of encountering security damage, such as phishing attacks or attacks that exploit vulnerabilities, when family members or acquaintances were not at home.

[0006] Furthermore, as shown in Non-Patent Documents 3 and 5, it is known that security awareness and privacy awareness vary depending on the user's age, gender, level of IT literacy, etc. For this reason, as shown in Non-Patent Document 4, an appropriate presentation method is needed that suits the user's characteristics, such as making it easier for elderly people to recognize risks when presented with video rather than text. In particular, many efforts have been made in recent years to eliminate the digital divide, and for example, Non-Patent Documents 1 and 2 propose interfaces and designs that are easy for elderly people to use. However, the interfaces and designs for implementing security measures are uniform, and the interface design does not take into account the characteristics of users across a wide range of ages and levels of IT literacy.

[0007] An object of the present invention is to provide a countermeasure presentation device, a countermeasure presentation method, and a countermeasure presentation program that can present security countermeasure implementation procedures using an appropriate user interface according to the user's characteristics and usage environment. [Means for solving the problem]

[0008] The countermeasure presentation device of the present invention includes a security countermeasure registration unit that accepts input of information including security countermeasure items, conditions for implementing the items, implementation procedures, and explanations of terminology, and registers the information in a database; an application information acquisition unit that acquires, for each of a plurality of applications, application information including the type of application installed on a user terminal from an application management server that stores the type of the application; a terminal information acquisition unit that acquires terminal information related to the security countermeasure items on the user terminal; a requirements collection unit that collects user responses to questions related to the type of user terminal and the services used; a countermeasure presentation unit that extracts items that need to be implemented from the security countermeasure items based on the responses collected by the requirements collection unit and presents the items on the user terminal; and a countermeasure procedure presentation unit that accepts input of a selection of any of the security countermeasure items, extracts the implementation procedures and explanations of terminology for the selected item from the database, and presents them on the user terminal.

[0009] The requirement collection unit may present candidates for the service to be used based on the terminal information.

[0010] The countermeasure presentation unit may compare the application information with the terminal information to present the security countermeasure items excluding items for which countermeasures have already been taken.

[0011] The countermeasure procedure presentation unit may receive an input indicating the user's age or level of IT literacy, select a design according to the input, and present the implementation procedures and explanations of terms.

[0012] The countermeasure procedure presentation unit may determine the level of IT literacy based on the terminal information.

[0013] The countermeasure procedure presentation unit may determine the age of the user based on the services used included in the answers collected by the requirement collection unit.

[0014] The countermeasure presentation method of the present invention is performed by a computer, and includes the following steps: a security countermeasure registration step of accepting input of information including security countermeasure items, conditions for implementing the items, implementation procedures, and explanations of terminology, and registering the information in a database; an application information acquisition step of acquiring, for each of a plurality of applications, application information including the type of application installed on a user terminal from an application management server that stores the type of the application; a terminal information acquisition step of acquiring terminal information related to the security countermeasure items on the user terminal; a requirements gathering step of collecting user responses to questions related to the type of user terminal and the services used; a countermeasure presentation step of extracting items that need to be implemented from the security countermeasure items based on the responses collected in the requirements gathering step, and presenting the items on the user terminal; and a countermeasure procedure presentation step of accepting input of a selection of any of the security countermeasure items, extracting the implementation procedures and explanations of terminology for the selected item from the database, and presenting the items on the user terminal.

[0015] A countermeasure presentation program according to the present invention is for causing a computer to function as the countermeasure presentation device. [Effects of the Invention]

[0016] According to the present invention, it is possible to present security countermeasure implementation procedures using an appropriate user interface in accordance with the characteristics of the user and the usage environment. [Brief explanation of the drawings]

[0017] [Figure 1] FIG. 1 is a diagram illustrating a configuration of a management system according to an embodiment. [Figure 2] FIG. 2 is a diagram illustrating a functional configuration of a Web server according to an embodiment. [Figure 3] 10A and 10B are diagrams illustrating examples of screens that a requirement collection unit presents to a user in the embodiment. [Figure 4] 10A and 10B are diagrams illustrating examples of screens presented to a user by a countermeasure presentation unit in the embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0018] An example of an embodiment of the present invention will be described below. According to an interview survey conducted by the applicant, the reasons given for leaving security measures to family or acquaintances include difficulty with technical terms, not knowing what security measures to implement, and not knowing the procedures for implementing security measures. In this embodiment, a system is described that presents a list of security measures that each user should implement based on the device and service used by the user. The list includes links to the implementation procedures for the security measures and explanations of technical terms.

[0019] FIG. 1 is a diagram showing the configuration of a management system 1 according to this embodiment. The management system 1 includes a web server 10 (management device) equipped with a database, an application management server 20 that manages application information that requires security measures, and a user terminal 30.

[0020] The management system 1 executes security countermeasure registration processing (1), application information acquisition processing (2), terminal information acquisition processing (3), requirement collection processing (4), countermeasure presentation processing (5), and countermeasure procedure presentation processing (6) by having the web server 10 and the management software of the user terminal 30 operate in cooperation with each other. As a result, the Web server 10 presents security measures that need to be implemented in an appropriate user interface according to the user's characteristics and usage environment, and further provides explanations of implementation procedures and technical terms.

[0021] The application management server 20 receives information from application providers regarding various applications that can be installed on the user terminal 30, centrally manages the types of applications and update types for each application, and provides them in response to requests from the Web server 10.

[0022] The user terminal 30 is a device such as a personal computer (PC), smartphone, or tablet that can access the Web server 10. The user terminal 30 may execute functions provided on a website built on the Web server 10, or may have management software installed in advance that enables communication with the Web server 10. In this embodiment, a case where management software is used will be exemplified.

[0023] FIG. 2 is a diagram showing the functional configuration of the Web server 10 in this embodiment. The Web server 10 is an information processing device (computer) that includes a control unit 11, a storage unit 12, various data input / output devices, communication devices, and the like.

[0024] The control unit 11 is a part that controls the entire Web server 10, and realizes each function in this embodiment by appropriately reading and executing various programs stored in the storage unit 12. The control unit 11 may be a CPU.

[0025] The storage unit 12 is a storage area for various programs for causing the hardware group to function as the Web server 10, various data, and the like, and may be a ROM, RAM, flash memory, hard disk drive (HDD), or the like. Specifically, the storage unit 12 stores various databases in addition to a program (management program) for causing the control unit 11 to execute each function of this embodiment. The databases include security measure items 121, security measure requirements 122, security measure implementation procedures 123, technical terminology explanations 124, stage determination conditions 125, gender and age determination conditions 126, terminal information logs 127, user responses 128, and user attributes 129.

[0026] The control unit 11 includes a security countermeasure registration unit 111, an application information acquisition unit 112, a terminal information acquisition unit 113, a requirement collection unit 114, a countermeasure presentation unit 115, and a countermeasure procedure presentation unit .

[0027] The security countermeasure registration unit 111 is a functional unit that is responsible for the security countermeasure registration process (1), and accepts input of various information including security countermeasure items, conditions for implementing these countermeasures, implementation procedures for the countermeasures, and explanations of technical terms directly from the system administrator or via the system administrator's terminal, and registers this information in the database (security countermeasure items 121, security countermeasure requirements 122, security countermeasure implementation procedures 123, and technical terminology explanations 124) in the memory unit 12. Furthermore, the security countermeasure registration unit 111 may automatically collect procedure manuals and the like created by application developers from descriptions on websites related to the application in question, and similarly register them in the database.

[0028] The application information acquisition unit 112 is a functional unit that performs application information acquisition processing (2), and acquires application information and update information for all applications installed in the user terminal 30 from the application management server 20.

[0029] The app information includes the type of app, the latest version, etc. The type of app can be, for example, SNS, finance, membership service, game, usage status check (for electricity, communication, etc.), health, video streaming, news, education, etc. The update information also includes whether an update is available and the type of update, which may be, for example, a function improvement, security, or both a function improvement and security.

[0030] If the application management server 20 does not contain application information or update information for the application, the application information acquisition unit 112 may extract necessary information by analyzing a document such as a detailed description or privacy policy for the application and update. For example, the application information acquisition unit 112 extracts keywords related to the application information or update information from the document.

[0031] The terminal information acquisition unit 113 is a functional unit that performs the terminal information acquisition process (3), and periodically collects terminal information related to the security countermeasure status through software in the user terminal 30 and records it as a terminal information log 127 in the database of the memory unit 12. The terminal information includes the OS version, whether automatic updates are enabled, the name and version of the application used, whether user authentication means is enabled, and password change history.

[0032] Furthermore, the terminal information acquisition unit 113 may distribute a questionnaire to the user terminal 30, and acquire information on the characteristics of the user as further terminal information when the user answers the questionnaire. Knowledge gained from survey results, etc., includes, for example, behavioral change stages (see, for example, Patent Document 2) in which the user is defined as a period of indifference, interest, preparation, implementation, maintenance, etc. depending on the user's interest, concern, and awareness of security measures, as well as the implementation status of measures, as well as personality and risk perception.

[0033] The requirements collection unit 114 presents questions from the user terminal 30 regarding the type of device (PC, smartphone, tablet, IoT device, etc.) and the services used (Internet, Internet banking, used apps, etc.) as requirements for determining the necessary security measures, collects the user's answers, and records them as user answers 128 in the database of the memory unit 12. At this time, the requirement collection unit 114 may present candidates for available services based on the terminal information of the user terminal 30 collected by the terminal information acquisition unit 113.

[0034] FIG. 3 is a diagram illustrating an example of a screen that the requirement collection unit 114 in this embodiment presents to the user. In this example, the user can select and input, for example, a type based on the OS of a personal computer or a type based on the OS of a smartphone as the type of device (user terminal 30) used by the user. Note that the user may input answers for multiple devices used by the user.

[0035] The countermeasure presenting unit 115 extracts security countermeasures that need to be implemented based on the answers collected by the requirement collecting unit 114, and presents them to the user. At this time, the countermeasure presentation unit 115 compares the update information acquired by the application information acquisition unit 112 with the terminal information acquired by the terminal information acquisition unit 113, and if the OS or application is up to date, i.e., countermeasures have been taken, it determines that there is no need to implement countermeasures, and does not need to present the relevant information to the user. Furthermore, based on the password change history acquired by the terminal information acquisition unit 113, for example, if the password has not been changed for a long period of time, a recommendation to change the password periodically may be presented as one of the measures.

[0036] The countermeasure procedure presentation unit 116 accepts a request when a security countermeasure item presented on the user terminal 30 is selected (clicked), and presents to the user terminal 30 the procedure for implementing the countermeasure for the relevant item and an explanation of the technical terminology. The presentation data is registered in advance in a database of the Web server 10, and may include not only text information but also moving images, images, and the like.

[0037] The presentation method can be changed depending on the characteristics of the user. For example, by selecting the level of IT literacy, which is a user attribute, on the screen displayed on the user terminal 30, explanations of technical terms and the like may be hidden for users with a high level of IT literacy. On the other hand, for users with a low level of IT literacy, security measure implementation procedures may be shown using images or videos rather than text.

[0038] Furthermore, by selecting the user attributes of age or generation, a design and interface for the elderly may be applied, such as displaying larger text or presenting the content in a video format, for users over a certain age. Specifically, by using an XML document format or the like to explain the database implementation procedures and technical terms, it is possible to clearly indicate the changes and content of the presentation method according to the user's characteristics.

[0039] Furthermore, the correlation between the above-mentioned behavioral change stage classification and the level of IT literacy may be defined in advance in the stage determination condition 125 in the storage unit 12, and the countermeasure procedure presenting unit 116 may determine the level of IT literacy based on this classification.

[0040] Furthermore, it is known that the services used by users tend to differ depending on gender and age. Therefore, by registering in advance services that are frequently used by each age group and each gender in the gender and age determination conditions 126 of the storage unit 12, the countermeasure procedure presenting unit 116 may determine the gender and age based on the degree of agreement between the registered contents and the software used included in the terminal information acquired by the terminal information acquiring unit 113 and the services used acquired by the requirement collecting unit 114.

[0041] The determination of the level of IT literacy, gender, and age (generation) may be made when no input is received from the user, and the input information may be given priority.

[0042] FIG. 4 is a diagram illustrating an example of a screen that the countermeasure presenting unit 115 in this embodiment presents to the user. For example, in the case of a user who uses the Internet and spreadsheet software on a personal computer, the Web server 10 receives responses regarding the device and service used, acquires terminal information, and presents a list of necessary security measures. In addition, by selecting (clicking) each item on the list, the user can check the implementation procedures for the countermeasures in text, images, videos, etc.

[0043] According to this embodiment, the Web server 10 presents necessary security measures, implementation procedures, and explanations of technical terms according to the status of the user terminal 30 and based on pre-registered conditions. Therefore, the management system 1 can solve conventional problems such as "I don't know what security measures to implement" and "I don't understand how to implement security measures or the terminology," and can present the user with the procedures for implementing security measures using an appropriate user interface depending on the user's characteristics and usage environment.

[0044] For example, the management software periodically asks questions about the device type and services used, and once the user answers, a list of necessary security measures is displayed. The user can then easily click through the steps to implement the measures and complete them. As a result, it is possible to clearly show users which measures to implement and in what order, which is expected to encourage users to implement security measures themselves, leading to an increase in the implementation rate of security measures and elimination of the digital divide.

[0045] Furthermore, the Web server 10 presents candidates for services to be used by the user based on the terminal information, which improves convenience and allows for more reliable answers to be collected, thereby enabling security measures to be presented with high accuracy.

[0046] Furthermore, the Web server 10 may compare the application information with the terminal information and present the list excluding items of security measures for which measures have already been taken, in accordance with the security measure requirement conditions 122. This allows only the necessary items to be displayed concisely, and items for which measures have been completed are sequentially deleted from the list.

[0047] The Web server 10 may accept input indicating the user's age and level of IT literacy, select a design according to these inputs, and present an explanation of the implementation procedures and terminology. This allows the management system 1 to present more appropriate implementation procedures according to the characteristics of the user, such as by changing the design to conform to guidelines for the elderly.

[0048] At this time, the Web server 10 can determine the level of IT literacy based on terminal information (e.g., behavioral change stage, etc.), and can estimate user attributes and present appropriate design of countermeasure implementation procedures even when there is no input from the user. Furthermore, the Web server 10 can determine the age of the user based on the services used by the user, and can estimate the user's attributes and present an appropriate design for implementing countermeasures even when there is no input from the user.

[0049] In this embodiment, the case where management software is used in the user terminal 30 has been mainly described, but a similar function may be provided on the site of the Web server 10. In this case, the information that can be acquired in the above-mentioned terminal information acquisition process (3) is limited. Therefore, for example, the name and version of the application in use may be added to the questions in the requirement gathering process (4).

[0050] This embodiment will, for example, lead to an improvement in the implementation rate of security measures and the elimination of the digital divide, thereby contributing to Goal 9 of the United Nations-led Sustainable Development Goals (SDGs), which is to "Develop resilient infrastructure, promote sustainable industrialization and foster innovation."

[0051] Although the embodiments of the present invention have been described above, the present invention is not limited to the above-described embodiments. Furthermore, the effects described in the above-described embodiments are merely a list of the most preferable effects resulting from the present invention, and the effects of the present invention are not limited to those described in the embodiments.

[0052] The countermeasure presentation method by the management system 1 is realized by software. When realized by software, the programs constituting this software are installed in an information processing device (computer). These programs may be recorded on removable media such as CD-ROMs and distributed to users, or may be distributed by being downloaded to the user's computer via a network. Furthermore, these programs may be provided to the user's computer as a web service via a network without being downloaded. [Explanation of symbols]

[0053] 1 Management System 10 Web server (countermeasure presentation device) 11 Control section 12 Storage section 20 Application Management Server 30 User terminals 111 Security Measures Registration Department 112 Application information acquisition unit 113 Terminal information acquisition unit 114 Requirements Gathering Department 115 Countermeasures Presentation Department 116 Countermeasure Procedure Presentation Section 121 Security measures 122 Security Measures Requirements 123 Security Measures Implementation Procedures 124 Terminology Explanation 125 Stage Determination Conditions 126 Conditions for sex and age determination 127 Terminal Information Log 128 User Answers 129 User Attributes

Claims

1. a security measures registration unit that receives input of information including security measures, conditions for implementing the measures, implementation procedures, and explanations of terms, and registers the information in a database; an application information acquisition unit that acquires application information including the type of the application installed on the user terminal from an application management server that stores the type of each of the plurality of applications; a terminal information acquisition unit that acquires terminal information related to the security countermeasure items in the user terminal; a requirement collection unit that collects answers from users to questions regarding the type of user terminal and the services used; a countermeasure presentation unit that extracts items that need to be implemented from the security countermeasure items based on the answers collected by the requirement collection unit and presents the items to the user terminal; A countermeasure presentation device comprising: a countermeasure procedure presentation unit that accepts a selection input of any of the items that need to be implemented that are presented by the countermeasure presentation unit, extracts the implementation procedure and explanation of terms for the selected item from the database, and presents them on the user terminal.

2. The measure presentation device according to claim 1 , wherein the requirement collection unit presents the candidates for the service to be used based on the terminal information.

3. The countermeasure presentation device according to claim 1 , wherein the countermeasure presentation unit compares the application information with the terminal information to present the security countermeasure items excluding items for which countermeasures have already been taken.

4. The countermeasure presentation device according to claim 1 , wherein the countermeasure procedure presentation unit receives an input indicating a user's age or level of IT literacy, selects a design according to the input, and presents the implementation procedures and explanations of terms.

5. The countermeasure presentation device according to claim 4 , wherein the countermeasure procedure presentation unit determines the level of IT literacy based on the terminal information.

6. The countermeasure presentation device according to claim 4 , wherein the countermeasure procedure presentation unit determines the age of the user based on the services used included in the answers collected by the requirement collection unit.

7. a security measure registration step of accepting input of information including security measure items, conditions for implementing the items, implementation procedures, and explanations of terminology, and registering the information in a database; an application information acquisition step of acquiring application information including the type of the application installed on the user terminal from an application management server that stores the type of each of the plurality of applications; a terminal information acquisition step of acquiring terminal information relating to the security countermeasure items in the user terminal; a requirement gathering step of collecting answers from users to questions regarding the type of user terminal and the services used; a countermeasure presentation step of extracting items that need to be implemented from the security countermeasure items based on the answers collected in the requirement collection step and presenting the items to the user terminal; a countermeasure procedure presentation step of accepting a selection input of any of the items that need to be implemented that are presented in the countermeasure presentation step, extracting the implementation procedure and explanation of terms for the selected item from the database, and presenting them on the user terminal.

8. A countermeasure presentation program for causing a computer to function as the countermeasure presentation device according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • Security countermeasure operational management device

    JP2004234208A

  • Patch application system

    JP2010250749A

  • Information processor, information processing method, information processing system, and program

    JP2012173885A

  • Stage determination device, stage determination method, and stage determination program

    JP2022056574A

  • Evaluation device, evaluation method, and evaluation program

    WO2018216175A1