Information processing device, control method and program for information processing device
The information processing device automatically blocks unused ports and provides user intervention options, addressing the challenge of configuring minimal ports for security, thus enhancing security and convenience.
Patent Information
- Application Number
- JP2021196001
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-12-02
- Publication Date
- 2025-10-27
- Estimated Expiration
- 2041-12-02
AI Technical Summary
Users without security knowledge find it difficult to manually identify and configure information processing devices to use only the minimum number of ports necessary for their usage status, leading to potential security risks.
An information processing device with a port filtering function that automatically blocks communication using ports unused for a specific period, featuring settings for automatic blocking or user confirmation, and displays messages for user intervention when access occurs.
Enables convenient and secure configuration of port filtering settings, ensuring only necessary ports are used, thereby enhancing security and operational efficiency.
Smart Images

Figure 0007760351000001 
Figure 0007760351000002 
Figure 0007760351000003
Abstract
Description
[Technical Field]
[0001] The present invention relates to an information processing device that communicates with the outside. [Background technology]
[0002] Information processing devices connected to a network communicate using specific network ports for each protocol. Hereinafter, network ports will be simply referred to as ports. For example, if FTP (File Transfer Protocol) is used to transfer files, port 21 corresponding to FTP is used to send and receive files between the sending and receiving information processing devices. If HTTPS is used for web access, the corresponding port 443 is used, and so on. The ports to be used are predetermined according to the functions to be used.
[0003] Furthermore, Patent Document 1 discloses a technology in which users such as administrators are configured to use only ports deemed necessary, taking into consideration the balance between the functions they will use and the security risks, and then operating the firewall function based on this configuration. [Prior art documents] [Patent documents]
[0004] [Patent Document 1] Japanese Patent Application Laid-Open No. 2010-253724 Summary of the Invention [Problem to be solved by the invention]
[0005] In recent years, there has been an increase in cases where users without specialized security knowledge manage information processing devices. Users without security knowledge are likely unaware that the functions they use should be minimized. Furthermore, regardless of whether the management user is familiar with security knowledge, it is difficult to manually identify unused functions in an information processing device. Therefore, there is a problem in that it is difficult to appropriately configure each information processing device to use only the minimum number of ports in accordance with its usage status.
[0006] The present invention has been made in consideration of at least one of the above-mentioned problems. One aspect of the present invention aims to provide a mechanism for configuring port filtering so as to block communication using a port that has not been used for a specific period of time. Another aspect of the present invention aims to improve the convenience of port-related operation configuration. [Means for solving the problem]
[0007] In order to achieve at least one of the above objects, an information processing device according to one aspect of the present invention is an information processing device having a port filtering function, a setting means for setting whether or not communications using a port that has not been used for a specific period of time are to be automatically blocked without user operation; and a setting means for setting whether or not communications using a port that has not been used for a specific period of time are to be automatically blocked without user operation, Specific period Mato Ports that are not being transmitted To a display control means for displaying a message prompting confirmation of the target setting; and control means for automatically cutting off communications using ports that have not been used for communication for the specific period without user operation, when the setting means has set the automatic cutting off of communications using ports that have not been used for communication for the specific period without user operation.An information processing device according to another aspect of the present invention is an information processing device having a port filtering function, and includes: first display control means for displaying a message for a port that has not been used for communication for a specific period, prompting the user to confirm settings for the port, based on user operation; first setting means for making settings related to the port filtering function so as to cut off communications using the port, based on user operation; second display control means for displaying information indicating that access to the port has occurred when a communication packet using the port that has been set to cut off communication is received; and second setting means for making settings related to the port filtering function so as to cancel the cutting off of communications using the port from which the access has occurred, based on user operation. [Effects of the Invention]
[0008] According to one aspect of the present invention, it is possible to configure port filtering settings so as to block communication using ports that have not been used for a specific period of time. In addition, according to another aspect of the present invention, it is possible to improve the convenience of port-related operation settings. [Brief explanation of the drawings]
[0009] [Figure 1] FIG. 1 illustrates an example of an information processing system. [Figure 2] FIG. 2 is a diagram illustrating an example of the hardware configuration of an MFP 101. [Figure 3] FIG. 2 is a diagram illustrating an example of the software configuration of an MFP 101. [Figure 4] 10 is an example of a screen displayed on an operation unit 116 of the MFP 101. [Figure 5] 10 is a flowchart showing an example of control in the MFP 101. [Figure 6] 10 is a flowchart illustrating an example of control for identifying an unused port. [Figure 7] 10 is a flowchart illustrating an example of control regarding unused ports. [Figure 8] 10 is a flowchart illustrating an example of control regarding unused ports. [Figure 9] 10 is a flowchart showing an example of control relating to unused ports in the second embodiment. [Figure 10] 13 is a flowchart showing an example of control relating to unused ports in the third embodiment. [Figure 11] FIG. 11 is a sequence diagram illustrating control relating to ports in the third embodiment. [Figure 12] FIG. 10 is a sequence diagram for explaining a modified example. DETAILED DESCRIPTION OF THE INVENTION
[0010] The following describes embodiments of the present invention with reference to the drawings. Note that the following embodiments do not limit the scope of the invention as claimed, and not all of the combinations of features described in the embodiments are necessarily essential to the solution of the invention.
[0011] First Embodiment First, the configuration of the information processing system according to the present invention will be described using FIG. 1. The information processing system according to the present embodiment includes an MFP (Multi Function Peripheral) 101 and an external device (not shown). In the present embodiment, the MFP 101 will be described as an example of an information processing device. The MFP 101 is connected to a network 100. Also, external devices such as client devices (not shown) and servers are connected to the network 100. The MFP 101 can communicate with external devices such as client devices and servers via the network 100.
[0012] Specifically, the MFP 101 can transmit data based on an image obtained by scanning a client device or a server, or can transmit data collected by the MFP 101 to a client device or a server.
[0013] <Hardware Configuration of MFP101> Next, the hardware configuration of the MFP 101, which is the core of the information processing system, will be described. The MFP 101 has a reading function for reading an image on a sheet, a file transmission function capable of transmitting the read image to an external communication device, etc. It also has a printing function for printing an image on a sheet.
[0014] In the present embodiment, the MFP 101 is described as an example of an information processing device, but it is not limited thereto. For example, a scanner device such as an SFP (Single Function Peripheral) without a printing function may be used. It can also be applied to general-purpose computers such as PCs. Also, the present embodiment can be applied to various communication devices and IoT devices connected to a network, such as 3D printers, smartphones, digital cameras, and network cameras.
[0015] A control unit 110 including a central processing unit (CPU) 111 controls the overall operation of the MFP 101. The CPU 111 reads control programs stored in a read-only memory (ROM) 112 or storage 114 to perform various control operations, such as print control and read control. The ROM 112 stores control programs executable by the CPU 111. A random access memory (RAM) 113 is the main memory of the CPU 111 and is used as a work area or a temporary storage area for expanding various control programs. The storage 114 stores print data, image data, various programs, and various setting information. In this embodiment, an auxiliary storage device such as a solid-state drive (SSD) is assumed as the storage 114, but a non-volatile memory such as a hard disk drive (HDD) may be used instead of the SSD. In this manner, the hardware, such as the CPU 111, the ROM 112, and the RAM 113, constitutes a so-called computer.
[0016] In the MFP 101 of this embodiment, one CPU 111 executes each process shown in the flowcharts described below using one memory (RAM 113), but other modes are also possible. For example, multiple CPUs, RAMs, ROMs, and storages can work together to execute each process shown in the flowcharts described below. Also, some of the processes may be executed using hardware circuits.
[0017] An operation unit interface (I / F) 115 connects an operation unit 116 and the control unit 110. The operation unit 116 is equipped with a liquid crystal display unit with a touch panel function, various hard keys, etc. The operation unit 116 functions as a display unit that displays information and a reception unit that receives instructions from the user.
[0018] The reading unit I / F 117 connects the reading unit 118 and the control unit 110. The reading unit 118 reads an original placed on a platen or an ADF and generates a read image. The generated read image is stored in the storage 114 or the RAM 113. The read image generated by the reading unit 118 is transmitted to an external device via the network 100 or used to print an image on a sheet.
[0019] The printing unit I / F 119 connects the printing unit 120 and the control unit 110. The scanned image generated by the reading unit 118 and stored in the storage 114 or RAM 113 is transferred from the control unit 110 to the printing unit 120 via the printing unit I / F 119. The printing unit 120 receives the scanned image via the control unit 110 and prints the scanned image on a sheet. It is also possible to perform printing based on a print job received from an external device. The printing method of the printing unit 120 may be an electrophotographic method or an inkjet method. Other printing methods such as a thermal transfer method may also be applied.
[0020] The communication unit I / F 121 is a communication interface included in the MFP 101. The control unit 110 is connected to the network 100 via the communication unit I / F 121. The communication unit I / F 121 can transmit data to devices and servers on the network 100, or to a server on the Internet via a gateway (not shown) on the network 100.
[0021] In this embodiment, it is assumed that the communication unit I / F 121 is a communication interface that performs wired communication compliant with Ethernet (registered trademark), but it is not limited thereto. For example, it may be a wireless communication interface compliant with the IEEE802.11 series. Also, the communication interface may be a communication interface that connects to a cellular network (e.g., LTE, 5G, etc.). That is, the network 100 may be configured to enable communication based on the so-called TCP / IP (Transmission Control Protocol / Internet Protocol). That is, any communication method may be adopted for the communication method in the physical layer.
[0022] Also, the MFP 101 of this embodiment has a firewall function from the viewpoint of security. The user can perform settings such as port filtering and IP filtering using the firewall function. That is, the firewall function provides a port filtering function and an IP filtering function.
[0023] By the way, users without security knowledge are likely not to recognize that they should minimize the functions they use in order to maintain good security. Also, regardless of whether the user performing the management is proficient in security knowledge, there is a problem that it is difficult for the user to manually identify the functions that are not being used by the user in the information processing apparatus.
[0024] Therefore, in the conventional technology, there is a problem that it is difficult to perform port filtering settings that appropriately use only the minimum number of ports according to the usage status of each information processing apparatus. In view of at least one of the above problems, in this embodiment, control is performed to perform settings related to port filtering so as to block communication using ports in which communication has not been performed for a specific period. The following describes the specific mechanism.
[0025] <Software Configuration of MFP101> 2 shows an example of the software configuration of the MFP 101. The software in the MFP 101 is composed of three layers: an OS (Operating System) 200, 210 to 212 that function as middleware, and a communication application / server 213.
[0026] The OS 200 is basic software for controlling the overall operation of the MFP 101. The OS 200 includes a communication control unit 201. The communication control unit 201 controls the transmission and reception of packets via the communication unit I / F 121. When the communication application / server 213 communicates with an external device, the communication application / server 213 requests the communication control unit 201 of the OS 200 to transmit data. Upon receiving the data transmission request, the communication control unit 201 transmits the data to the external device. The communication control unit 201 also controls the forwarding of packets received by the communication unit I / F 121 to an internal communication application or server, or the discarding of received packets. The communication control unit 201 includes a firewall 202 that provides a firewall function that determines whether to pass or discard packets based on preset filtering conditions. Packets handled by the communication control unit 201 are inspected by the firewall 202. Specifically, the firewall 202 determines whether a packet that an upper layer application or server is about to send, or a packet received from outside, meets the conditions for discarding the packet. If it determines that the conditions for discarding are met, the firewall discards the packet. The firewall 202 also has a function for storing the occurrence of packet discard as a log. In this embodiment, the firewall 202 may be configured to store log information such as text data that combines information on the date and time when the discard occurred, the port number corresponding to the discarded packet, and information for distinguishing between received and transmitted packets. The log is saved in a predetermined storage area of the storage 114.
[0027] Next, a description will be given of the middleware of the MFP 101. A setting storage unit 212 stores settings made via the middleware, and setting values and data used by the middleware and the OS.
[0028] Static rule setting unit 210 has a function of setting and editing static filtering conditions (also called static port settings) to be set in firewall 202. When static rule setting unit 210 receives a user operation to edit the settings, it updates the static filtering list stored in setting storage unit 212.
[0029] The function of setting and editing static filtering conditions provided by the setting unit 210 will be described with reference to Fig. 3. Figs. 3(a) and (b) show examples of setting screens that the setting unit 210 displays on the operation unit 116 in cooperation with the OS 200. Fig. 3(a) illustrates an example of a setting screen when a Deny List format that lists ports that discard packets is selected as the control policy. A user with administrator privileges for the MFP 101 can log in to the MFP 101 and access the setting screen illustrated in Fig. 3. The operation unit 116 is divided into a first area 301, which is a display area that displays various setting screens and operation screens, and a second area 307, which is a status display area that displays errors and warnings. Fig. 3(a) illustrates an example of a case in which a status message, described later, is displayed in the second area 307, indicated by the dashed dotted line.
[0030] Area 302 displays a list of ports set as target ports. Radio button 303 is a display item used when changing the control policy. The user can select one of the options using radio button 303. The radio button functions as a selection item for selecting a user operation. When setting filtering conditions in the Deny List format exemplified in FIG. 3(a), the administrator sets port numbers for which packet communication is to be discarded as target ports. Therefore, there is a possibility that ports for functions that the user of MFP 101 does not use may remain open during operation.
[0031] New key 304 is a key used when adding a new target port, and edit key 305 is a key used when editing a port registered as a target port. Delete key 306 is a key used when deleting a port registered as a target port from filtering targets. A user can edit the static filtering conditions of a target port via keys 304 to 306. FIG. 3(b) illustrates an example of a setting screen when an Allow List format (also called an arrow list method) that lists ports through which packets are allowed to pass is selected as a control policy. In this case, a user such as an administrator sets port numbers corresponding to functions that may be used as target ports. Therefore, ports for functions that are not actually used by the user of MFP 101 may remain open.
[0032] Returning to the explanation of FIG. 2, the setting unit 210 updates the static filtering list stored in the setting storage unit 212 based on the settings made via the screens exemplified in FIG. 3(a) and FIG. 3(b).
[0033] Furthermore, the setting unit 210 sets port filtering conditions for the firewall 202 of the OS 200 based on the static filtering list stored in the setting storage unit 212 .
[0034] Next, unused port control unit 211 has the function of managing the last communication date and time for open ports, identifying unused ports, and closing unused ports. Control unit 211 stores the identified unused ports as an unused port list in setting storage unit 212. When the conditions for closing a specified unused port are met, control unit 211 sets port filtering conditions for firewall 202 of OS 200 and performs processing to close the specified unused port.
[0035] Furthermore, the unused port control unit 211 has a function of updating the discard list stored in the setting storage unit 212 based on the log generated by the firewall 202. The discard list is referred to as appropriate in the flowchart described below. Finally, the control unit 211 provides a management setting screen described below to a user such as an administrator. The user can close unused ports via the management setting screen, or reopen a port that has been closed but has been accessed. The user can also configure operation settings for control of unused ports via the management setting screen. The control unit 211 updates the operation settings recorded in the setting storage unit 212 based on the operation settings configured via the management setting screen.
[0036] Finally, the communication application / server 213 is an application layer module that allows the MFP 101 to exchange data with external devices. As an example, the MFP 101 has modules such as a network print application, a network scan application, and an HTTP server.
[0037] The network print application is an application that receives print data via ports 631, 443, and 9100, for example. The network print application works in cooperation with the printing unit 120 to print an image on a sheet based on a print job received from a print client of an external device. The network scan application is an application that transmits a file based on a scanned image obtained by scanning an original with the scanning unit 118 to a scan client of an external device via ports 631 and 443. The HTTP server is a web server that provides a setting screen or information confirmation screen for the MFP 101 to a web browser using port 80 or port 443. Although not shown for space reasons, the MFP 101 also has various other communication applications / servers. These various applications / servers communicate with the outside world via various ports according to their respective functions.
[0038] Next, a specific mechanism for configuring port filtering to block communication using ports that have not been used for a specific period of time will be described using the flowcharts shown in Figures 5 to 8 and the setting screen shown in Figure 4. Each operation (step) shown in the flowcharts of Figures 5 to 8 is realized by the CPU 111 loading into the RAM 113 a program for implementing each control module stored in the ROM 112 or storage 114 and executing it. Note that data transmission and reception processing, etc., is realized in cooperation with each communication unit I / F. In addition, in cases where it is necessary to clarify the subject of processing, the software module executed by the CPU 111 will be described as the subject.
[0039] The flowchart illustrated in Fig. 5 is an example of processing that is executed after the power of MFP 101 is changed from OFF to ON and the startup processing is completed. Note that, due to space limitations, only processing related to port filtering is illustrated in Fig. 5.
[0040] In S501, the communication control unit 201 determines whether packet transmission or reception has occurred in cooperation with the communication unit I / F 121. If packet transmission or reception has occurred, the process proceeds to S502, and if packet transmission or reception has not occurred, the process proceeds to S507.
[0041] In S502, the firewall 202 determines whether to discard the packet based on the packet filtering rules set therein. If it is determined that the packet should be discarded, the process proceeds to S506. If it is determined that the packet should not be discarded (i.e., if it is determined that the packet should be allowed to pass), the process proceeds to S503. Port filtering conditions are defined in the firewall 202 by the process described below. The firewall 202 obtains the destination port number, which is the destination, included in the packet header and determines whether the port filtering conditions are met. If the filtering conditions are met, the firewall 202 performs control in accordance with the control policy. If the Allow List format is selected and the packet filtering conditions are met, the firewall 202 allows the packet to pass. On the other hand, if the Allow List format is selected and the packet filtering conditions are not met, the firewall 202 discards the packet. Also, if the Deny List format is selected and the packet filtering conditions are met, the firewall 202 discards the packet. Furthermore, if the Deny List format is selected and the packet filtering conditions are not met, the firewall 202 allows the packet to pass. This process makes it possible to block communication to a specific port based on the packet filtering conditions.
[0042] In S506, firewall 202 stores a log indicating that the packet has been discarded. As described above, the log stores text data that combines information about the date and time the discard occurred, the port number corresponding to the discarded packet, and information distinguishing between received and transmitted packets. Unused port control unit 211 monitors the log, detects that new text data has been written, and adds the port number stored in the log, i.e., the port number corresponding to the discarded packet, to the discard list. Once the addition to the discard list is complete, CPU 111 advances the process to S501.
[0043] In S503, the communication control unit 201 determines whether the processing content is reception of a broadcast packet or a multicast packet. If it is determined that the processing content is reception of a broadcast packet or a multicast packet, the process proceeds to S504. If it is determined that the processing content is not reception of a broadcast packet or a multicast packet (i.e., if it is determined that the processing content is a unicast packet addressed to an IP address assigned to the MFP 101), the process proceeds to S505. In S504, the communication control unit 201 determines whether to respond to the packet. Specifically, if there is no upper application waiting for a packet at the port, the communication control unit 201 determines not to respond to the packet and proceeds to S501. On the other hand, if a request to send a response packet is received from an upper application waiting for a packet at the port, the communication control unit 201 determines to respond to the packet and proceeds to S505. By making the determination in S504, it is possible to configure the communication control unit 201 not to update the last communication date and time for multicast packets / broadcast packets circulating on the network and to which the MFP 101 does not respond.
[0044] In S505, the communication control unit 201 executes packet transmission and reception processing. When transmitting a packet to the outside, the communication control unit 201 cooperates with the communication unit I / F 121 to transmit the packet onto the network 100. When receiving a packet from the outside, the communication control unit 201 transfers the received packet to a higher-level communication application. Next, the communication control unit 201 records the date and time of the last communication of the port used for transmission and reception.
[0045] In S507, the CPU 111 determines whether the current time is a predetermined time. If it is determined that the current time is the predetermined time, the process proceeds to S508. If it is determined that the current time is not the predetermined time, the process proceeds to S509. In this embodiment, it is assumed that the unused port determination process shown in S508 is performed once a day, for example, at a predetermined time such as 11:00 PM, but this is not limited to this. For example, it may be configured to perform the unused port determination process every 12 hours using a timer or the like.
[0046] In S509, the CPU 111 determines whether a shutdown operation has been received. If a shutdown operation has been received, shutdown control (not shown) is performed, and the series of processes ends. If a shutdown operation has not been received, the process proceeds to S501.
[0047] In S508, unused port control unit 211 performs processing to identify unused ports. Specific control will be described with reference to FIG.
[0048] In S601, unused port control unit 211, in cooperation with firewall 202, identifies an open port for which filtering conditions are set to allow packets to pass. Subsequently, in S602, unused port control unit 211, in cooperation with communication control unit 201, acquires the last communication date and time associated with the identified open port. Once acquisition is complete, the process proceeds to S603.
[0049] In S603, the control unit 211 extracts open ports that have not had a communication record during a specific period of time. The control unit 211 then stores the extracted open ports that have not had a communication record during the specific period of time as an unused port list in the setting storage unit 212. If the number of extracted open ports that have not had a communication record during a specific period of time is zero, information such as NULL or None is stored in the unused port list. The specific period can be, for example, 30 days. In this embodiment, 30 days is used in consideration of the possibility that monthly processing may be performed once a month using the functions provided by the MFP 101. By using a period such as 30 days, it is possible to prevent ports used in such cases from being subject to warnings or being closed every time. Furthermore, a 30-day period is a period that prevents port closures and warnings from occurring due to the MFP not being used during long holidays such as the holiday season, while also allowing for appropriate periodic review for operational management purposes.
[0050] Furthermore, the specific period used as an extraction condition in S603 may be configured to be set based on a user operation by an administrator or the like. Information indicating the specific period is stored as an operation setting of the setting storage unit 212. In this case, in S603, information indicating the specific period may be acquired from the setting storage unit 212, and extraction may be performed based on the period corresponding to the acquired information.
[0051] In S604, the control unit 211 determines whether or not one or more unused ports have been found as a result of the extraction in S603. If one or more unused ports have been found, the process proceeds to S605, and if one or more unused ports have not been found (if the number of unused ports is 0), the process proceeds to S606.
[0052] In S605, the control unit 211 sets a control flag indicating that an unused port has been found to "True" and sets a notification issuance flag indicating the notification issuance status to "False", and proceeds to S501. Meanwhile, in S606, the control unit 211 sets a control flag indicating that an unused port has been found to "False", and proceeds to S501. The control flag is referenced as appropriate in the flowcharts described below to perform notification control and port close control.
[0053] Next, notification control and port auto-close control in MFP 101 will be described using the flowchart in Fig. 7. The flowchart in Fig. 7 is a flowchart excerpting processing related to notification control and port auto-close control executed by MFP 101. The processing shown in the flowchart in Fig. 7 is executed in response to the occurrence of an update event that requires updating the screen displayed on operation unit 116 of MFP 101. Specifically, an update event occurs when a return operation is performed in an off state in which no screen is displayed on operation unit 116. An update event also occurs when an event that requires updating a drawing occurs while an operation screen is displayed on operation unit 116.
[0054] In S701, the unused port control unit 211 determines whether a flag indicating that an unused port has been found is set and whether the notification issuance flag indicates that a notification has not been issued. Specifically, if the control flag indicating that an unused port has been found is set to True and the notification issuance flag is set to False, the process proceeds to S702. On the other hand, if the control flag indicating that an unused port has been found is set to False or the notification issuance flag is set to True, the process ends. In S702, the control unit 211 determines whether an operation setting for automatically closing an open port has been configured.
[0055] The operation settings will be explained using the management setting screen shown in Fig. 4. The user can instruct the opening and closing of unused ports and change the operation settings related to the opening and closing of unused ports via the screen shown in Fig. 4. Here, the operation settings related to the processing in Fig. 7 will be explained. The operation of instructing the opening and closing of ports will be explained together with the flowchart in Fig. 8, which will be described later.
[0056] Checkbox 404 is a display item for changing an operation setting for automatically closing an unused port when the port is detected. Checkbox 405 is a display item for changing an operation setting for not displaying a warning notification. Checkbox 406 is a display item for changing an operation setting for providing a detection exception port. Display item 407 is a display item used when configuring additional settings for a detection exception port. OK key 412 is a key used to confirm operation settings and port open / close operations. The control unit 211 changes the operation settings stored in the setting storage unit 212 based on the settings configured via the screen of FIG. 4. Specifically, when 404 is changed to a checked state, the operation setting for automatically closing an open port stored in the setting storage unit 212 is changed to ON. When 404 is changed to an unchecked state, the operation setting for automatically closing an open port stored in the setting storage unit 212 is changed to OFF.
[0057] Similarly, the control unit 211 changes the ON / OFF state of the operational setting for not displaying a warning notification, which is stored in the setting storage unit 212, according to the check state of 405. Furthermore, based on the check state of 406, the control unit 211 changes the ON / OFF state of the operational setting for whether to provide a detection exception port, which is stored in the setting storage unit 212. If the check box is checked, the control unit 211 changes the corresponding operational setting to ON, and if the check box is unchecked, the control unit 211 changes the corresponding operational setting to OFF.
[0058] When it is detected that display item 407 has been selected, control unit 211 displays an additional settings screen (not shown). Ports 80 and 443 are displayed as default exception ports on the additional settings screen. Default exception ports may be configured so that they cannot be deleted.
[0059] This additional settings screen provides the user with the ability to add and set detection exception ports on an application-by-application basis, such as a network print application or a scan print application. For example, when a network print application is selected, it is possible to configure the system to add ports corresponding to the print protocol supported by the print application to the exception ports. Specifically, in addition to ports 80 and 443, which are set as default exceptions, ports 631 and 9100 can be added to the detection exception ports.
[0060] Although the present embodiment illustrates an example in which detection exception ports are set on an application-by-application basis, the present invention is not limited to this. For example, an additional detection exception port may be set by the user inputting a number indicating a port number.
[0061] 6, in S702, if the operation setting for automatically closing an open port has been made, that is, if ON is stored in the setting storage unit 212 as the operation setting for automatically closing an open port, the control unit 211 proceeds to S703. On the other hand, if the operation setting for automatically closing an open port has not been made, that is, if OFF is stored in the setting storage unit 212 as the operation setting for automatically closing an open port, the control unit 211 proceeds to S707.
[0062] In S703, the control unit 211, in cooperation with the firewall 202, determines whether the firewall control policy is in the Deny List format. If it is determined that the firewall control policy is in the Deny List format, the process proceeds to S704. On the other hand, if it is determined that the firewall control policy is not in the Deny List format (i.e., if it is determined that it is in the Allow List format), the process proceeds to S707.
[0063] In S704, control unit 211 updates the port filtering conditions of firewall 202 based on the unused port list and the settings of the detection exception ports, and applies a port filter to the firewall. Specifically, when the operational setting for whether to set detection exception ports is OFF, control unit 211 updates the port filtering conditions of firewall 202 so as to close all ports included in the unused port list. When the operational setting for whether to set detection exception ports is ON, control unit 211 performs processing to exclude port 80, port 443, and the additionally set detection exception ports from the unused port list.
[0064] Next, control unit 211 updates the port filtering conditions of firewall 202 so as to close the ports included in the unused port list excluding the detection exception ports.
[0065] In S705, the control unit 211 sets a flag indicating that an unused port has been found to False. Subsequently, in S706, the control unit 211 cooperates with the operation unit 116 to display a status message in the second area 307 on the operation unit 116 indicating that automatic closure has been performed.
[0066] Meanwhile, in S707, the control unit 211 determines whether or not an operation setting has been made to not display a warning notification. If an operation setting to not display a warning notification has been made, that is, if ON is stored in the setting storage unit 212 as the operation setting to not display a warning notification, the control unit 211 ends the series of processes. On the other hand, if OFF is stored in the setting storage unit 212 as the operation setting to not display a warning notification, the control unit 211 advances the process to S708.
[0067] In S708, the control unit 211 cooperates with the operation unit 116 to display a status message in the second area 307 on the operation unit 116 informing the user that there is an unused port and prompting the user to confirm this.
[0068] In S709, the control unit 211 sets the notification issuance flag to True. Subsequently, when the CPU 111 detects that a predetermined time has elapsed since the message was displayed, or that a user operation on the message has been detected, it stops the display of the message displayed in S706 or S708. The detection of the passage of the predetermined time or the detection of a user operation on the message is a process for determining whether or not a condition for stopping the display of the message has been met. When the stopping is complete, the series of processes ends.
[0069] Finally, a method for controlling port closing and opening based on a user operation via the operation unit will be described using the flowchart of Fig. 8. The processing shown in the flowchart of Fig. 8 is executed in response to acceptance of a user operation for displaying a management setting screen for unused ports. A user operation for selecting a status message displayed in S706 or S708 is an example of a user operation for displaying a management setting screen. Also, a user operation for selecting an icon for displaying a management setting screen for unused ports, which is displayed in a setting menu not shown, is an example of a user operation for displaying a management setting screen.
[0070] In S800, the control unit 211 cooperates with the operation unit 116 to display the management setting screen shown in FIG. 4, and accepts a setting change operation by the user via the management setting screen.
[0071] The management setting screen will be described with reference to FIG. 4. Information 402 indicating the detection status of unused open ports is displayed on the management setting screen. When a flag indicating that an unused port has been found is set to True, the control unit 211 displays information indicating the detection status. Furthermore, when an unused port has been closed by the process of automatically closing an unused port described above, the control unit 211 displays information indicating that the port has been closed. Area 403 is an area for displaying a list of unused ports. The control unit 211 displays a list of ports included in the unused port list in this area. Specifically, the control unit 211 works in cooperation with the operation unit 116 to display a label indicating each port number in association with a display item in the form of a radio button indicating the open / closed state of the port. Furthermore, the control unit 211 displays information indicating that access has occurred for port numbers included in both the discard list and the unused port list in association with the port numbers.
[0072] When the operational setting for whether to set a detection exception port is ON, the control unit 211 performs control so that ports set as detection exception ports are not displayed in the unused port list, even if they are included in the unused port list. In other words, when the operational setting for whether to set a detection exception port is ON, ports set as detection exception ports are excluded from the unused port management targets (control targets).
[0073] The user can change whether each port is open or closed by operating the radio button. Key 410 is a key used to close all ports detected as unused ports. Key 411 is a key used to reopen a port that has been accessed after being closed, among ports that have been closed by a user operation via the management setting screen or by the process of automatically closing unused ports described above. As described above, OK key 412 is a key used to open or close a port and to apply changes to the operation settings. Users such as administrators can manage the opening and closing of unused ports via the setting screen.
[0074] Returning to the explanation of Fig. 8, in S801, the control unit 211 determines whether or not the OK key has been selected in cooperation with the operation unit 116. If the OK key has been selected, the process proceeds to S802, and if the OK key has not been selected, the process returns to S800 and waits for further setting change operations.
[0075] In S802, the control unit 211 determines whether a change operation related to port opening or closing has been performed in cooperation with the operation unit 116. If a change operation related to port opening or closing has been performed, the process proceeds to S805, and if no change operation related to port opening or closing has been performed, the process proceeds to S803.
[0076] In S803, the control unit 211 determines whether or not a user operation to change the operation settings has been performed in cooperation with the operation unit 116. If a change operation to change the operation settings has been performed, the process proceeds to S804, and if a change operation to change the operation settings has not been performed, the series of processes ends.
[0077] In S804, the control unit 211 changes (updates) the operation settings stored in the setting storage unit 212 so that the operation settings correspond to the operation for changing the operation settings performed via the management setting screen. When the change process is completed, the series of processes ends.
[0078] In S805, the control unit 211 executes processing when an operation related to opening is performed via the management setting screen. Note that if an operation related to opening is not performed, this processing is skipped. A more detailed explanation follows. The control unit 211 cooperates with the communication control unit 201 to update the last communication date and time corresponding to the port that has been opened with the current date and time. The control unit 211 also deletes the port from the unused port list and the discard list stored in the setting storage unit 212.
[0079] In S806, the control unit 211 updates the port filtering conditions of the firewall 202 based on the operation content, the unused port list, and the settings of the detection exception ports, and applies a port filter to the firewall 202. When an operation to close all unused ports is performed, the filtering conditions are updated so that all unused ports are closed. For example, if the control policy is in the Deny List format, an update process is performed to add a rule that rejects unused ports. On the other hand, if the control policy is in the Allow List format, an update process is performed to delete a rule that allows packets to pass for unused ports. Note that when the operational setting for whether to set detection exception ports is ON, it is sufficient to configure the system to close only unused ports that do not fall under the detection exception ports.
[0080] Furthermore, if an operation is performed to reopen all ports that have been accessed again after closing an unused port, the port filter conditions are updated to establish rules that allow packets to pass through the corresponding ports. Finally, if an operation is performed to change the settings for individual ports using the radio buttons, the port filter conditions are updated to establish port open / close states that correspond to the settings made via the management setting screen. Once the update is complete, the process proceeds to S807.
[0081] In S807, the control unit 211 sets a flag indicating that an unused port has been found to False, and the process proceeds to S803.
[0082] The above-described process makes it possible to configure port filtering settings so as to block communication using ports that have not been used for a specific period of time.
[0083] <Second embodiment> In the first embodiment, an example has been given of a case where the control policy is in the Deny List format and an operation setting for automatically closing an open port is configured, and processing for automatically closing the port is performed.
[0084] In the second embodiment, a mechanism for performing automatic closing processing regardless of a control policy and automatic opening processing based on a discard list when an operation setting for automatically closing an open port is made will be described. Note that the hardware configuration and software configuration of the MFP 101 in the second embodiment are the same as those in the first embodiment. Note that the same processing as in the first embodiment will be omitted as appropriate.
[0085] Fig. 9 is an example of a flowchart executed in the second embodiment in place of the flowchart of Fig. 7 in the first embodiment. The differences from Fig. 7 are that the determination process corresponding to S703 is not performed, that the processes shown in S921 and S922 are performed when it is determined that the automatic closing setting is set (Yes in S902), and that the process of S923 is performed instead of the process of S904.
[0086] The processing from S901 to S902 is the same as S701 and S702 in the first embodiment. In S902, if the unused port control unit 211 determines that automatic closure is set, the processing proceeds to S921; otherwise, the unused port control unit 211 proceeds to S907.
[0087] In S921, the control unit 211 acquires the discard list and the unused port list from the setting storage unit 212. Next, the control unit 211 removes the ports included in the discard list from the unused port list. Then, the control unit 211 updates the information on the last communication date and time of the ports managed by the communication control unit 201 so that the last communication date and time of the removed ports becomes the current date and time. When the update is complete, the process proceeds to S922.
[0088] Subsequently, in S922, the control unit 211 initializes the discard list stored in the setting storage unit 212. When the initialization is complete, the process proceeds to S923.
[0089] By performing the processes of S921 and S922, unused ports that have not sent or received packets for an unspecified period of time but have had packets discarded by the firewall can be excluded from the targets for automatic closure.
[0090] Next, in S923, the control unit 211 resets the filtering conditions of the firewall. Next, the control unit 211 sets port filter conditions for the firewall based on the settings of the static port filtering list, the unused port list, and the detection exception port list. Specifically, the control unit 211 applies a port filter based on the static port filtering list to the firewall 202. Next, if the operational setting for whether to set a detection exception port is OFF, the control unit 211 updates the port filtering conditions of the firewall 202 to close all ports included in the unused port list. On the other hand, if the operational setting for whether to set a detection exception port is ON, the control unit 211 performs processing to exclude port 80, port 443, and the additionally set detection exception port from the unused port list. Finally, the control unit 211 updates the port filtering conditions of the firewall 202 to close ports included in the unused port list excluding the detection exception ports. Once the updating of the filtering conditions is complete, the process proceeds to S905. Note that the processing of S905 to S909 is similar to the processing of S705 to S709 in the first embodiment, and therefore description thereof will be omitted.
[0091] The above-described process makes it possible to perform automatic port opening in addition to automatic port closing, regardless of whether an Allow List or a Deny List is used as the firewall control policy.
[0092] <Third embodiment> In the second embodiment, an example was given in which automatic port opening processing is performed in addition to automatic port closing processing. However, in the second embodiment, the port opening and closing processing is performed after the predetermined time is determined in the processing of S507, so the closed port cannot be opened when communication is attempted through the port. In view of this, the third embodiment provides a mechanism for opening a port when packet communication is attempted through an automatically closed port.
[0093] The hardware and software configurations of the MFP 101 in the second embodiment are the same as those in the first and second embodiments. Processing that is the same as in the first and second embodiments will be omitted as appropriate.
[0094] FIG. 10 shows an example of processing executed in the third embodiment when it is determined to discard a packet in the processing of S502 in the flowchart of FIG. 5 in the first embodiment.
[0095] In S1001, the unused port control unit 211 determines whether an automatic closing setting has been made. If an operation setting to automatically close an open port has been made, that is, if ON is stored in the setting storage unit 212 as the operation setting to automatically close an open port, the control unit 211 proceeds to S1002. On the other hand, if an operation setting to automatically close an open port has not been made, that is, if OFF is stored in the setting storage unit 212 as the operation setting to automatically close an open port, the control unit 211 proceeds to S506.
[0096] In S1002, control unit 211 determines whether the port corresponding to the packet determined to be discarded is included in the unused port list. If it is determined that the port is included in the unused port list, the process proceeds to S1003; if it is determined that the port is not included, the process proceeds to S506. Next, in S1003, control unit 211 updates the port filter conditions of firewall 202 so as to open the port corresponding to the discarded packet. Specifically, in the case of the Allow List format, update control is performed to add the port to the exception conditions that allow the packet to pass. In the case of the Deny List format, update control is performed to delete the condition corresponding to the port from the exception conditions that cause the packet to be discarded.
[0097] In S1004, the control unit 211 updates the last communication date and time associated with the port number opened in S1003 with the current date and time. The control unit 211 also deletes the opened port from the unused port list and the discard list.
[0098] Through the above process, communication is attempted to the automatically closed port, and after the packet is discarded, the port can be opened immediately.
[0099] The effect of the processing in Fig. 10 will be explained using the sequence diagram in Fig. 11. Fig. 11 shows an example of processing when a TCP connection is made from an external device to the MFP 101. For the sake of explanation, the following example will be explained, taking as an example a state in which TCP port 25 is identified as an unused port and is auto-closed.
[0100] First, the external device specifies TCP port 25 and attempts to establish a TCP connection with MFP 101 (sequence S1101). Firewall 202 of MFP 101 receives a packet attempting to establish the TCP session and determines to discard the packet. Then, the processes described in S1001 to S1004 are executed, and the port filtering condition that allows TCP packets addressed to the port corresponding to the packet, i.e., port 25, to pass is applied to the firewall (S1102).
[0101] At this point, the external device determines that a response to the packet has not been returned due to congestion on the communication path on the network 100, and retries to establish a TCP connection. At the time of the retry sequence, port 25 has been reopened. Therefore, the TCP connection can be established (S1103). After the connection is established, data can be exchanged as appropriate (S1104).
[0102] <Modification> In the first and second embodiments, examples have been given in which the MFP 101 determines unused ports, identifies closed or open ports based on user operations, or automatically closes open ports. However, the present invention is not limited to this. For example, control of unused ports can be achieved by cooperation between a management system including the MFP 101 and the management server 102. FIG. 12 shows an example of a communication sequence of a management system as a modified example. The management server 102 is a management server that collects and manages information about the MFP 101 and other MFPs. In this embodiment, some of the processing, such as displaying the screen illustrated in FIG. 4 and accepting setting change operations, is performed on the management server side. The hardware configuration of the management server 102 may be a configuration that excludes the hardware configuration related to printing and scanning from the hardware configuration of the MFP 101 illustrated in FIG. 2, i.e., a so-called von Neumann computer including a CPU, ROM, RAM, and storage.
[0103] The management server 102 may be configured to use multiple processors, RAM, ROM, and storage in cooperation to execute the processes described in the sequences below, or may use multiple server computers to execute the processes described in the sequences below.
[0104] The specific processing will be described below. The unused port control unit 211 of the MFP 101 periodically transmits information to the management server, such as once a day. This information includes the last communication date and time of the port used for sending and receiving, the discard list, and a list of open ports identified by processing similar to S601, as described in the first embodiment (S1200).
[0105] The management server that receives this information manages the received information as management information for MFP 101. Next, it performs processing to identify unused ports based on the stored information (S1201). This processing means that the same processing as S601 to S606 described in the first embodiment is performed on the management server 102 side. The management server 102 manages the unused port list and control flag information generated by the identification processing as management information for MFP 101.
[0106] Management server 102 issues accounts to administrators who manage multiple MFPs, such as MFP 101. The administrators who manage multiple MFPs access a web page provided by management server 102 via a web browser on their own client terminal, such as a PC. The administrators enter account information on the web page, log in to management server 102, and can view a page showing management information for MFPs 101 and the like that they manage. At this time, management server 102 executes processes equivalent to S701 to S708 of the first embodiment based on the management information stored in association with MFP 101, and can display the status message described in the first embodiment on the page showing the management information. However, the process of S704 is implemented in cooperation with MFP 101.
[0107] Furthermore, the page showing the management information is configured to include a display item for transitioning to the management setting screen. The user performs an operation to select a display item for transitioning to the management setting screen. The web browser, which accepts this operation, transmits an HTTP request to the management server 102 requesting the page of the management setting screen corresponding to the selection operation. The management server 102, which receives this request, responds to the web browser with the management setting screen corresponding to FIG. 4. Through the processing described above, the management server 102 can provide a management setting screen to a user such as an administrator. Subsequent processing for accepting setting change operations based on user operations is realized by cooperation between the client PC and the management server 102. Note that the processing of S806 is realized in cooperation with the MFP 101.
[0108] Next, a method for performing the port filter application process described in S704 of Fig. 7, S806 of Fig. 8, and S923 of Fig. 9 will be described. When closing or opening a port based on an operation via a Web page corresponding to the screen of Fig. 4, management server 102 performs a process of specifying the port to be closed or opened based on management information of MFP 101 and information received from the Web browser. Furthermore, when automatic closure is performed based on an operation setting for automatically closing an open port, management server 102 performs a process of specifying the port to be closed based on management information of MFP 101 (S1202).
[0109] Next, the MFP 101 is instructed to close or open the identified port (S1203). Upon receiving the instruction, the MFP 101 updates the port filtering conditions for the firewall 202 based on the instruction (S1204).
[0110] Finally, the MFP 101 updates the discard list and the last communication date and time as necessary for the port changed in the processing of step S1204. Specifically, when a port open instruction is given, the MFP 101 performs processing to delete the port for which the instruction is given from the discard list and to update the last communication date and time to the current time.
[0111] The above-described process of managing devices on the server side and remotely instructing the opening and closing of ports as appropriate can be applied not only to the MFP 101 but also to all devices registered as devices to be managed.
[0112] Therefore, when a single administrator manages many MFPs and other devices installed within a company, it becomes possible to easily check the port usage status of many devices. It also becomes possible to perform a process to remotely close unused ports on a specific device. Furthermore, it becomes possible to remotely reopen unused ports that have been closed on a specific device.
[0113] <Other embodiments> The present invention can also be realized by supplying a program that realizes one or more functions of each of the above-described embodiments to a system or device via a network or a storage medium, and having one or more processors in the computer of the system or device read and execute the program. It can also be realized by a circuit (e.g., ASIC or FPGA) that realizes one or more functions. [Explanation of symbols]
[0114] 101 MFP 111 CPU 121 Communication Unit I / F121
Claims
1. An information processing device having a port filtering function, a setting means for setting whether or not communications using a port that has not been used for a specific period of time will be automatically blocked without user operation; a display control means for displaying a message prompting confirmation of settings for ports that have not been used for communication during the specified period, when the setting means has not set a setting to automatically block communications using the ports that have not been used for communication during the specified period without user operation; and a control means for automatically cutting off, without user operation, communications using a port that has not been used for a specific period of time, when the setting means has set the automatic cutting off of communications using a port that has not been used for a specific period of time, without user operation; and An information processing device having the above.
2. A port setting means for setting whether to block communication using the port based on a user operation; a first storage means for storing a setting as to whether or not communication using the port is to be blocked, the setting being made based on the user operation; and The information processing device described in claim 1, characterized in that when the setting stored in the first storage means is an arrow list type setting, even if the setting means is set to automatically block communication using a port that has not been used for communication for the specific period without user operation, the control means will not automatically block communication without user operation.
3. When the information processing device receives a packet of communication using a port that has not been used for communication for the specific period and whose communication has been blocked by the control means, the control means controls the port filtering function so as not to block communication using the port.
3. The information processing apparatus according to claim 1, wherein the information processing apparatus is a computer.
4. The packet of communication using a port for which no communication has been performed during the specified period and for which communication has been blocked by the control means is a packet in which the destination port number included in the header of the packet is the number of a port for which no communication has been performed during the specified period.
4. The information processing apparatus according to claim 3,
5. An information processing device having a port filtering function, a first display control means for displaying a message for prompting a user to confirm the settings of a port when the port has not been used for communication for a specific period of time; a first setting means for setting the port filtering function based on a user operation so as to block communication using the port; a second display control means for displaying information indicating that an access to the port has occurred when a packet for communication using the port set to block communication is received; a second setting means for setting the port filtering function based on a user operation so as to release the blocking of communication using the port from which the access occurred; An information processing device having the above.
6. An information processing device as described in Claim 5, characterized in that it further has a third display control means for displaying a list of ports on which no communication has been performed during the specified period.
7. the third display control means displays a list of ports for which no communication has been performed during the specific period, together with a display item for blocking communication using the ports for which no communication has been performed during the specific period; The first setting means performs setting related to the port filtering function so as to block communication using the port based on a user operation on the display item.
7. The information processing apparatus according to claim 6,
8. The second display control means displays, together with a list of ports for which no communication has been performed during the specific period displayed by the third display control means, information indicating that access to the ports has occurred; The information is displayed in association with the port from which the access occurred among the ports included in the list.
8. The information processing device according to claim 6, wherein:
9. The third display control means further controls to display the list by associating a selection item for selecting whether to close or open each of the ports included in the list with each of the ports included in the list.
9. The information processing apparatus according to claim 6, wherein the information processing apparatus is a computer.
10. The packet of communication using the port set to block communication is a packet in which the destination port number included in the header of the packet is the number of a port that has not been used for communication during the specified period.
10. The information processing apparatus according to claim 5, wherein the information processing apparatus is a computer.
11. a first storage means for storing a list of ports that have not been used for communication for the specified period; a second storage means for storing information indicating that an access to the port has occurred when a packet of communication using the port set to block communication is received; 11. The information processing apparatus according to claim 5, further comprising:
12. The method further comprises: managing the last communication date and time for each port; and identifying a port that has not been in communication for the specified period based on the last communication date and time; An information processing device as described in any one of claims 1 to 11, characterized in that the identification means is a packet received by broadcast or multicast, and for a port that received a packet that did not perform processing based on the packet, the last communication date and time at which the communication was performed is not updated.
13. 13. The information processing apparatus according to claim 1, further comprising a change unit that changes the specific period based on a user operation.
14. The method further includes an exception port setting unit that sets an exception port to be excluded from the target of blocking, 14. The information processing apparatus according to claim 1, wherein a port corresponding to the information indicating the exception port is excluded from targets for blocking communication.
15. 15. The information processing apparatus according to claim 14, wherein the exception port setting means sets ports 80 and 443 as the exception ports.
16. 16. The information processing apparatus according to claim 14, wherein the information processing apparatus is a printing apparatus, and the exception port setting unit sets a port corresponding to a printing protocol supported by the printing apparatus as the exception port.
17. A method for controlling an information processing device having a port filtering function, comprising: a setting step of setting whether to automatically block communications using ports that have not been used for a specific period of time without user operation; a display control step of displaying a message prompting confirmation of settings for ports that have not been used for communication during the specified period, when the setting step does not include a setting to automatically block communications using the ports that have not been used for communication during the specified period without user operation; a control step of automatically cutting off, without user operation, communications using ports that have not been used for a specific period of time, when the setting step has been configured to automatically cut off communications using ports that have not been used for a specific period of time, without user operation; A control method comprising:
18. Computer, a setting means for setting whether or not communications using a port that has not been used for a specific period of time will be automatically blocked without user operation; a display control means for displaying a message prompting confirmation of settings for ports that have not been used for communication during the specified period, when the setting means has not set a setting to automatically block communications using the ports that have not been used for communication during the specified period without user operation; and a control means for automatically cutting off, without user operation, communications using a port that has not been used for a specific period of time, when the setting means has set the automatic cutting off of communications using a port that has not been used for a specific period of time, without user operation; A program to function as a 19. A method for controlling an information processing device having a port filtering function, comprising: a first display control step of displaying a message for prompting a user to confirm settings for a port when the port has not been used for communication for a specific period of time; a first setting step of setting the port filtering function based on a user operation so as to block communication using the port; a second display control step of displaying information indicating that access to the port has occurred when a packet of communication using the port set to block communication is received; a second setting step of setting the port filtering function based on a user operation so as to cancel the blocking of communication using the port from which the access occurred; A control method comprising:
20. A computer, a first display control means for displaying a message for prompting a user to confirm the settings of a port when the port has not been used for communication for a specific period of time; a first setting means for setting the port filtering function based on a user operation so as to block communication using the port; a second display control means for displaying information indicating that an access to the port has occurred when a packet for communication using the port set to block communication is received; a second setting means for setting the port filtering function based on a user operation so as to cancel the blocking of communication using the port from which the access occurred; A program to function as a
Citation Information
Patent Citations
Communication system and communication method
JP2009134430A
Image forming apparatus
JP2010253724A
Information processing device, control method of information processing device, and program
JP2018092230A