Information processing device, information processing method, and program

The information processing device and method distinguish between legitimate and fraudulent activities by detecting and evaluating disruptive security behaviors, effectively identifying fraudulent users.

JP7782767B2Active Publication Date: 2025-12-09MITSUBISHI ELECTRIC CORP
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2025557319
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2023-11-21
Publication Date
2025-12-09
Estimated Expiration
2043-11-21

AI Technical Summary

Technical Problem

Conventional techniques for detecting fraudulent behavior in user systems fail to distinguish between legitimate business operations and fraudulent activities, leading to false positives, which poses the risk of false positives.

Method used

The information processing device and method differentiate between legitimate business operations and fraudulent activities by detecting disruptive behaviors such as investigating or circumventing security measures, and evaluate users accordingly.

Benefits of technology

Effectively detects fraudulent activities by identifying disruptive behaviors, thereby appropriately identifying users who commit fraud.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007782767000001
    Figure 0007782767000001
  • Figure 0007782767000002
    Figure 0007782767000002
  • Figure 0007782767000003
    Figure 0007782767000003
Patent Text Reader

Abstract

An information processing device according to the present disclosure solves the following problem: business activities generally involve a wide variety of operations, and with conventional methods, operations performed to distinguish whether a user is engaging in legitimate business activities or fraudulent activities are not frequent enough, possibly resulting in erroneous detection. This information processing device comprises a detection unit that detects disruptive behavior, which is related to interference with security settings on equipment of an organization, performed by a user using the equipment, and includes a device capable of appropriately detecting whether the user is engaging in fraudulent activities.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to an information processing device, an information processing method, and a program. [Background technology]

[0002] In user systems with multiple terminals, users often commit fraud. To address fraud, systems are used to detect fraud and analyze the risk of fraud. Conventional technology effectively utilizes user logs managed in various locations, and uses the various logs to calculate a risk score for each user using a security management server, and detects users who engage in fraudulent behavior using the calculated risk score (see Patent Document 1). For example, the conventional technology tallies the average number of operations for each of multiple types of operations during a target period, and calculates each user's risk score based on the average number of operations, etc. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Japanese Patent Application Publication No. 2019-204389 Summary of the Invention [Problem to be solved by the invention]

[0004] However, business-related operations typically vary widely, and conventional techniques based on the frequency of operations make it difficult to distinguish whether a user is performing legitimate business or committing fraud, posing the risk of false positives.

[0005] The present disclosure has been made to solve the above-mentioned problems, and aims to appropriately evaluate whether a user of a terminal is committing fraud. [Means for solving the problem]

[0006] According to a first aspect of the present invention, an information processing device includes a detection unit that detects disruptive behavior, which is behavior related to disruption of security set in a device, by a user who uses a device in an organization. and, an evaluation unit that evaluates the user based on the detection of the disruptive behavior, the disruptive behavior includes behavior of investigating the security set in the device and behavior of circumventing the security set in the device; The evaluation unit performs different evaluations when the behavior to be investigated is detected and when the behavior to be avoided is detected. . According to a second aspect of the present invention, an information processing method of an information processing device includes a step of detecting, by a detection unit, a disruptive behavior, which is a behavior related to disruption of security set in a device, by a user who uses a device of an organization. and, and evaluating the user by an evaluation unit based on the detection of the disruptive behavior; the disruptive behavior includes behavior of investigating the security set in the device and behavior of circumventing the security set in the device; The step of making the evaluation makes different evaluations when the behavior to be investigated is detected and when the behavior to be avoided is detected. . According to a third aspect of the present invention, the program includes a process for detecting, in a computer, a disruptive behavior by a user who uses an organization's equipment, which is a behavior related to disrupting security set in the equipment. and, and performing a process of evaluating the user based on the detection of the disruptive behavior, the disruptive behavior includes behavior of investigating the security set in the device and behavior of circumventing the security set in the device; The evaluation is made differently when the behavior to be investigated is detected and when the behavior to be avoided is detected. . [Effects of the Invention]

[0007] According to the present disclosure, since interference with the security of an organization is detected by a user of a terminal that uses equipment in the organization, it is possible to appropriately detect whether a user is committing fraud. [Brief explanation of the drawings]

[0008] [Figure 1] FIG. 1 is a diagram showing an example of a system configuration according to an embodiment. [Figure 2] FIG. 1 is a diagram showing an entire system according to a first embodiment. [Figure 3] FIG. 1 is a diagram showing an example of a system configuration in a first embodiment. [Figure 4] FIG. 4 is a diagram showing an example of a user input log in the first embodiment. [Figure 5] FIG. 3 is a diagram showing an example of a user management database in the first embodiment. [Figure 6] FIG. 2 is a diagram showing the functional configuration of a server in the first embodiment. [Figure 7] FIG. 3 is a sequence diagram showing an example of the flow of processing executed by each device in the first embodiment. [Figure 8] FIG. 10 is a diagram showing an example of a system configuration in a second embodiment. [Figure 9] FIG. 10 is a sequence diagram showing an example of the flow of processing executed by each device in the second embodiment. [Figure 10] 10 shows an example of a screen displayed on a display unit in the second embodiment. [Figure 11] 10 shows an example of a screen displayed on a display unit in the second embodiment. [Figure 12] FIG. 11 is a diagram showing the functional configuration of a server in the third embodiment. [Figure 13] FIG. 11 is a diagram showing an example of a user management database in the third embodiment. [Figure 14] FIG. 11 is a sequence diagram showing an example of the flow of processing executed by each device in the third embodiment. [Figure 15] FIG. 13 is a diagram showing the functional configuration of a terminal in a fourth embodiment. [Figure 16] 13 is a flowchart showing an example of the flow of processing executed by a terminal in the fourth embodiment. [Figure 17] FIG. 13 is a diagram showing an example of a system configuration in a fifth embodiment. [Figure 18] FIG. 13 is a sequence diagram showing an example of the flow of processing executed by each device in the fifth embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0009] In order to explain the present disclosure in more detail, embodiments for carrying out the present disclosure will be described below with reference to the accompanying drawings. <System configuration> FIG. 1 is a diagram showing an example of a system configuration of a communication system 1 according to this embodiment. In the communication system 1, for example and not by way of limitation, a server 10 and a plurality of terminals 20 (terminal 20A, terminal 20B, terminal 20C, . . . ) are connected via a network 30.

[0010] The server 10 is connected via a network 30 to a terminal 20 used by a user. In Figure 1, the number of servers 10 connected to the network 30 is shown as one, and the number of terminals 20 is shown as three, but this number is not limited, and multiple servers 10 may be provided, and the number of terminals 20 may be one or multiple.

[0011] The network 30 serves to connect one or more terminals 20 and one or more servers 10. In other words, the network 30 refers to a communication network that provides a connection path so that the above-mentioned various devices can connect and then send and receive data.

[0012] One or more portions of network 30 may or may not be a wired or wireless network. Network 30 may include, by way of example and not limitation, an ad hoc network, an intranet, an extranet, a virtual private network (VPN), a local area network (LAN), a wireless LAN (WLAN), a wide area network (WAN), a wireless WAN (WWAN), a metropolitan area network (MAN), a portion of the Internet, a portion of the Public Switched Telephone Network (PSTN), a cellular network, integrated service digital networks (ISDN), wireless LAN, long term evolution (LTE), code division multiple access (CDMA), Bluetooth, satellite communications, etc., or a combination of two or more thereof. Network 30 may include one or more networks 30.

[0013] The server 10 may be any device capable of implementing the functions described in each embodiment. The server 10 may be, for example, but not limited to, a server device, a computer (for example, but not limited to, a desktop, laptop, tablet, etc.), a handheld computing device (for example, but not limited to, a PDA (personal digital assistant)), or any other type of computer or communication platform. The server 10 may also be referred to as an information processing device or an information management device.

[0014] The terminal 20 may be any device capable of implementing the functions described in each embodiment. The terminal 20 may include, but is not limited to, a computer (such as a desktop, laptop, or tablet), a handheld computing device (such as a personal digital assistant (PDA)), or other types of computers. The terminal 20 may also be referred to as an information processing device or an information management device.

[0015] [Hardware (HW) configuration of each device] The hardware configuration of each device included in the communication system 1 will be described.

[0016] (1) Server hardware configuration FIG. 1 shows an example of the hardware configuration of the server 10. As shown in FIG. The server 10 includes a control unit 11 (CPU: central processing unit), a memory unit 15, a communication I / F 14 (interface), an input / output unit 12, a display 13, and a clock unit 16. The hardware components of the server 10 are connected to each other via a bus, for example and not as a limitation. It is not essential that the hardware of the server 10 includes all of the components. For example and not as a limitation, the hardware of the server 10 may or may not be configured such that the display 13 and the clock unit 16 are detachable. The display 13 and other components may be installed outside the server, and information output via the communication I / F 14 (interface) may be received and displayed on the display 13 installed outside the server.

[0017] The control unit 11 has circuits physically structured to execute the functions realized by the codes or instructions contained in the program, and is realized by, for example and not by way of limitation, a data processing device embedded in hardware.

[0018] The control unit 11 is typically a central processing unit (CPU), but may or may not be a microprocessor, a processor core, a multiprocessor, an application-specific integrated circuit (ASIC), or a field programmable gate array (FPGA). Each process may or may not be implemented by a logic circuit (hardware) or a dedicated circuit formed in an integrated circuit (an integrated circuit (IC) chip, a large-scale integration (LSI)), etc. These circuits may or may not be implemented by one or more integrated circuits, and multiple processes described in each embodiment may or may not be implemented by a single integrated circuit. An LSI may also be referred to as a VLSI, a super LSI, an ultra LSI, or the like depending on the degree of integration. Therefore, the control unit 11 may or may not be referred to as a control circuit. In the present disclosure, the control unit 11 is not limited to these.

[0019] The storage unit 15 has a function of storing various programs and various data required for the operation of the server 10. The storage unit 15 is realized by various storage media such as a hard disk drive (HDD), a solid state drive (SSD), and a flash memory. However, in the present disclosure, the storage unit 15 is not limited to these. Furthermore, the storage unit 15 may or may not be expressed as a memory.

[0020] Server 10 stores program P in storage unit 15, and by executing this program P, control unit 11 executes the processes of each unit included in control unit 11. In other words, program P stored in storage unit 15 causes server 10 to realize each function executed by control unit 11. This program P may or may not be expressed as a program module.

[0021] The communication I / F 14 transmits and receives various data via the network 30. The communication may be performed either wired or wirelessly, and any communication protocol may be used as long as mutual communication is possible. The communication I / F 14 has a function of communicating with various devices such as the terminal 20 via the network 30. The communication I / F 14 transmits various data to various devices such as the terminal 20 in accordance with instructions from the control unit 11. The communication I / F 14 also receives various data transmitted from various devices such as the terminal 20 and transmits it to the control unit 11. The communication I / F 14 may also be simply referred to as a communication unit. When the communication I / F 14 is configured as a physically structured circuit, it may also be referred to as a communication circuit.

[0022] The input / output unit 12 includes a device for inputting various operations to the server 10 and a device for outputting the processing results processed by the server 10. The input / output unit 12 may be an integrated input unit and an output unit, or may be separated into the input unit and the output unit.

[0023] The input unit of the input / output 12 is realized by a device that inputs various operations to the server 10. The input unit is realized by any one or combination of all types of devices that can accept input from a user and transmit information related to the input to the control unit 11. The input unit is typically realized by hardware keys such as a keyboard or a pointing device such as a mouse. Note that the input unit may or may not include, but is not limited to, a touch panel, a camera (for inputting operations via video images), or a microphone (for inputting operations via voice). However, in the present disclosure, the input / output unit 12 is not limited to these. Note that the input unit may be detachable as appropriate or may be attached as needed. For example, in each embodiment, the configuration related to the input unit may be detached in its entirety or only a portion thereof may be attached as needed.

[0024] The output unit of the input / output 12 is realized by any one of or a combination of any type of device capable of outputting the processing results processed by the control unit 11. An example of the output unit is the display 13, which is typically realized by a monitor (for example, but not limited to, a liquid crystal display or an organic electroluminescence display (OLED)). The display 13 may or may not be a head-mounted display (HMD), a projection mapping device, a hologram, or a device capable of displaying images, text information, etc. in air (which may or may not be a vacuum). The display 13 may or may not be capable of displaying display data in 3D. In the present disclosure, the display 13 is not limited to these. The output unit is not limited to the display 13 like a display unit, but may be a touch panel, a touch display, a speaker, a printer, or any other device that notifies the user of information or notifies the user of processing results such as presenting information. The output unit may be detachable as appropriate or attached as needed. For example, in each embodiment, the configuration relating to the output section may be entirely removed or partly attached as needed.

[0025] The clock unit 16 is a built-in clock of the server 10, and outputs time information (timekeeping information). The clock unit 16 is configured to include, for example and without limitation, an RTC (Real Time Clock) as a hardware clock, a system clock, etc. The clock unit 16 can also be expressed as a timekeeping unit or a time information detection unit, for example and without limitation.

[0026] (2) Hardware configuration of the terminal FIG. 1 shows an example of the hardware configuration of the terminal 20. The terminal 20 includes a control unit 21 (CPU: central processing unit), a memory unit 28, a communication I / F 22 (interface), an input / output unit 23, a display unit 24, a microphone 25, a speaker 26, a camera 27, a clock unit 29A, and a position calculation information detection unit 29B. The hardware components of the terminal 20 are connected to each other via a bus, for example and not by way of limitation. It is not essential that the hardware configuration of the terminal 20 includes all of the components. For example and not by way of limitation, the terminal 20 may or may not be configured such that individual components, such as the microphone 25, the camera 27, or multiple components, are detachable.

[0027] The control unit 21 has circuits physically structured to execute the functions realized by the codes or instructions contained in the program, and is realized by, for example and not by way of limitation, a data processing device embedded in hardware.

[0028] The control unit 21 may include, but is not limited to, a central processing unit (CPU), a microprocessor, a processor core, a multiprocessor, an application-specific integrated circuit (ASIC), or a field programmable gate array (FPGA). Furthermore, each process may or may not be realized by a logic circuit (hardware) formed in an integrated circuit (IC chip, LSI (Large Scale Integration)), or a dedicated circuit. Furthermore, these circuits may be realized by one or more integrated circuits, and multiple processes shown in each embodiment may or may not be realized by a single integrated circuit. Furthermore, LSIs may be referred to as VLSIs, super LSIs, ultra LSIs, etc., depending on the degree of integration. Therefore, the control unit 21 may or may not be referred to as a control circuit.

[0029] The storage unit 28 has a function of storing various programs and various data required for the operation of the terminal 20. The storage unit 28 includes, but is not limited to, various storage media such as a hard disk drive (HDD), a solid state drive (SSD), a flash memory, a random access memory (RAM), and a read only memory (ROM). Furthermore, the storage unit 28 may or may not be expressed as a memory.

[0030] Terminal 20 stores program P in storage unit 28, and by executing this program P, control unit 21 executes the processing of each unit included in control unit 21. In other words, program P stored in storage unit 28 causes terminal 20 to realize each function executed by control unit 21. Furthermore, this program P may or may not be expressed as a program module.

[0031] The communication I / F 22 transmits and receives various data via the network 30. The communication may be performed either wired or wirelessly, and any communication protocol may be used as long as mutual communication is possible. The communication I / F 22 has a function of communicating with various devices such as the server 10 via the network 30. The communication I / F 22 transmits various data to various devices such as the server 10 in accordance with instructions from the control unit 21. The communication I / F 22 also receives various data transmitted from various devices such as the server 10 and transmits it to the control unit 21. The communication I / F 22 may also be simply referred to as a communication unit. When the communication I / F 22 is configured as a physically structured circuit, it may also be referred to as a communication circuit.

[0032] The input / output unit 23 includes a device for inputting various operations to the terminal 20 and a device for outputting processing results processed by the terminal 20. The input / output unit 23 may be an integrated input unit and an output unit, or may be separate input unit and output unit, or may not be so.

[0033] The input unit is realized by any one or combination of devices capable of receiving input from a user and transmitting information related to the input to the control unit 21. Examples of the input unit include, but are not limited to, hardware keys such as a touch panel, a touch display, and a keyboard, pointing devices such as a mouse, a camera (operation input via video images), and a microphone (operation input via voice). Note that a camera is, but is not limited to, an example of the imaging unit 27, and a microphone is, but is not limited to, an example of the sound input unit 26. Note that the input unit is not limited to the disclosure of this application, and individual components or multiple components may or may not be configured to be removable in each embodiment as needed. Furthermore, configurations not described in this disclosure may also be added as appropriate.

[0034] The output unit is realized by any one of or a combination of all types of devices that can output the processing results processed by the control unit 21. Examples of the output unit include, but are not limited to, a touch panel, a touch display, a speaker (a non-limiting example of a sound output unit), optical components (non-limiting examples include lenses, media, and other components for 3D (three dimensions) output, hologram output, etc.), and a printer. These output processing results, such as notifying the user of information or presenting information.

[0035] When the input / output unit 23 is a touch panel, the input / output unit 23 and the display unit 24 may be disposed opposite each other and have approximately the same size and shape.

[0036] The display unit 24 is realized by any one of all types of devices or a combination thereof that can display according to the display data written to the frame buffer. Examples of the display unit 24 include, but are not limited to, a touch panel, a touch display, a monitor (for example, but not limited to, a liquid crystal display or an organic electroluminescence display (OLED)), a head mounted display (HMD), projection mapping, a hologram, and a device that can display images, text information, etc. in air (which may or may not be a vacuum). Note that these display units 24 may or may not be capable of displaying display data in 3D.

[0037] The clock unit 29A is a built-in clock of the terminal 20, and outputs time information (timekeeping information). The clock unit 29A is configured to include, for example and not by way of limitation, a clock that uses a crystal oscillator. The clock unit 29A can also be expressed as a timekeeping unit or a time information detection unit, for example and not by way of limitation.

[0038] The clock unit 29A may or may not have a clock that conforms to the NITZ (Network Identity and Time Zone) standard or the like.

[0039] The position calculation information detection unit 29B is a functional unit that detects (measures) information (hereinafter referred to as "position calculation information") necessary for the control unit 21 to calculate (measure) the position of its own terminal 20. The position calculation information detection unit 29B can also be expressed as a position calculation sensor unit, for example and not by way of limitation.

[0040] The position calculation information detection unit 29B includes, by way of example and not limitation, a satellite positioning sensor (satellite positioning unit), which is a sensor or unit for calculating the position of the terminal 20 using a satellite positioning system such as GPS (Global Positioning System), and an inertial measurement sensor (inertial measurement unit (IMU (Inertial Measurement Unit))), which is a sensor or unit for calculating the position of the terminal 20 using an inertial navigation system.

[0041] The satellite positioning unit includes, by way of example and not limitation, an RF receiving circuit that converts RF (Radio Frequency) signals, including positioning satellite signals transmitted from positioning satellites and received by an antenna (not shown), into digital signals, and a baseband processing circuit that performs correlation calculation processing on the digital signals output from the RF receiving circuit to capture the positioning satellite signals, and outputs information such as satellite orbit data and time data extracted from the positioning satellite signals as information for position calculation.

[0042] The inertial measurement unit has an inertial sensor that is a sensor that detects information necessary for calculating the position of the terminal 20 by inertial navigation calculation. The inertial sensor includes, but is not limited to, a three-axis acceleration sensor and a three-axis gyro sensor, and outputs the acceleration detected by the acceleration sensor and the angular velocity detected by the gyro sensor as information for position calculation.

[0043] For example, but not by way of limitation, control unit 21 calculates the position of its own terminal 20 at regular intervals or specific intervals based on the position calculation information detected by position calculation information detection unit 29B. The terminal position is referred to as the "terminal position," and the calculated terminal position is referred to as the "calculated terminal position." Control unit 21 then associates the calculated terminal position with the date and time when the calculated terminal position was calculated, and stores the calculated terminal position history data in storage unit 28. (3) Other

[0044] Furthermore, the program P (for example, but not limited to, a software program, computer program, or program module) of each embodiment of the present disclosure may or may not be provided in a state stored in a computer-readable storage medium. The storage medium can store the program P in a "non-transitory tangible medium." The program P may or may not be intended to realize part of the functions of each embodiment of the present disclosure. Furthermore, the program P may or may not be a so-called difference file (difference program) that can realize the functions of each embodiment of the present disclosure in combination with a program P already recorded on a storage medium.

[0045] Storage media such as storage unit 15 and storage unit 28 may include any of the storage media described above, or a suitable combination of two or more of these. Storage media may be volatile, nonvolatile, or a combination of volatile and nonvolatile, as appropriate. Note that storage media are not limited to these examples and may be any device or medium capable of storing program P. Furthermore, storage media may or may not be referred to as memory.

[0046] Furthermore, the program P of the present disclosure may or may not be provided to the server 10 or the terminal 20 via any transmission medium capable of transmitting a program (such as a communication network or broadcast waves). The server 10 or the terminal 20, by way of example and not limitation, executes the program P downloaded via the Internet or the like to realize the functions of the multiple functional units shown in each embodiment. The same applies to other devices.

[0047] In addition, each embodiment of the present disclosure may also be realized in the form of a data signal in which the program P is embodied by electronic transmission. At least a part of the processing in the server 10 or the terminal 20 may or may not be realized by cloud computing configured by one or more computers. At least a part of the processing in the terminal 20 may or may not be performed by the server 10. In this case, at least a part of the processing of each functional unit of the control unit 21 of the terminal 20 may or may not be performed by the server 10. At least a part of the processing in the server 10 may or may not be performed by the terminal 20. In this case, at least a part of the processing of each functional unit of the control unit 11 of the server 10 may or may not be performed by the terminal 20. Unless explicitly stated otherwise, each determination in the embodiments of the present disclosure is not essential, and a predetermined process may or may not be performed when the determination condition is met, or when the determination condition is not met. Furthermore, unless explicitly stated otherwise, the configuration of each process in the embodiments of the present disclosure is not essential, and some of the processes disclosed in the embodiments may or may not be skipped.

[0048] The programs of the present disclosure are implemented using, for example and without limitation, scripting languages ​​such as ActionScript and JavaScript (registered trademark), compiler languages ​​such as Objective-C and Java (registered trademark), and markup languages ​​such as HTML5.

[0049] <Embodiment 1> The first embodiment discloses an example in which an information processing device such as a server 10 detects an obstruction to the security of an organization, which is performed by a user who uses a terminal 20 that is a device of the organization.

[0050] 2 shows an overall system diagram of the first embodiment. The overall system of the first embodiment includes the server 10, terminal 20, and display device 24 described above, and the server 10 and terminal 20 are capable of communicating with each other via a network 30. In the first embodiment, the server 10 is a server used by an organization, and the terminal 20 is a terminal used by a user belonging to the organization. Note that the organization in this embodiment may be an individual or a group of multiple people formed for a purpose. Examples of organizations are not limited to these, and may include facilities such as accommodation facilities, government agencies, companies, factories, schools, medical institutions such as hospitals, and other organizations. Therefore, the terminal 20 of the organization is a terminal used by a user belonging to the organization, and the server 10 communicates information with the terminal 20 of the organization via the network 30 to detect disruptive behavior of users against the organization's security, as described below.

[0051] Next, an example of functions realized by the server 10 and terminal 20 according to the first embodiment will be described with reference to Fig. 3. The server 10 includes the control unit 21, communication unit 22, input / output unit 23, and storage unit 28 described above. The storage unit 28 stores a user input log 281. The user input log 281 stores operations performed by a user who uses the terminal 20.

[0052] The data structure of the user input log 281 is composed of a user name, a user ID, an operation log, and other information, as shown in Fig. 4. The user name is the name of the user who uses the terminal 20, and may be, for example and without limitation, a name input by an administrator who manages an organization, or information input by the user who uses the terminal 20 himself.

[0053] The user ID may be information for identifying a user who uses the terminal 20, or information for identifying a terminal 20 that the user can use (has the right to use). The user input log 281 is expressed using alphabets and numbers as an example of a user ID, but is not limited to this. Alternatively, the user ID may be expressed using other languages ​​such as kanji, symbols, or the like.

[0054] Next, the operation log is an item for recording operations performed on terminal 20 by a user using terminal 20. For example, the operation log of user input log 281 records that on Nth month Nth day, the user of terminal 20 performed an operation to delete antivirus software, which is an action that interferes with the security of the organization.

[0055] Here, security is something set up by an organization to safely protect the organization. Security may be configured with hardware or software. Software-based security may include, but is not limited to, antivirus software to counter external attacks, a firewall set up in the organization, an intrusion detection system that detects external intrusions into the organization's system, or an intrusion prevention system that prevents external intrusions based on the detection. Security may also be something that protects the organization's network using the specific security systems described above.

[0056] Furthermore, security may be set uniformly for all terminals 20 in an organization. For example, an organization may have a plurality of terminals 20, each of which is distributed to a plurality of users. Antivirus software, firewalls, and the like are set uniformly for all of these terminals 20. In this manner, the same security may be set for the entire organization. Although the same security level is described above, the security level does not need to be the same for all terminals 20, and different security levels may be set. For example, a higher security level may be set for users with higher job responsibilities, and a lower security level may be set for users with lower job responsibilities. This is because users with higher job responsibilities are more likely to store important information on their terminals 20, so the security level may be set higher to strictly protect the information. Conversely, the security level may be set lower for users with higher job responsibilities and higher for users with lower job responsibilities.

[0057] Additionally, an action that disrupts the security of an organization is an action that a user takes to disrupt the above-mentioned security established by the organization using the terminal 20. By way of example and not limitation, an action that disrupts the security of an organization includes an action that investigates the security established by the organization, an action that circumvents the security established by the organization, and the like.

[0058] Actions to investigate the security of an organization include actions by a user of terminal 20 to investigate the security itself set up in the organization, and actions to investigate logs of operations performed on the security set up in the organization.

[0059] As a non-limiting example, the behavior of investigating the security set up in an organization includes the behavior of investigating the location where antivirus software installed on the terminal 20 available to the user is stored, the location where a firewall is installed, etc. Such behavior may later lead to circumvention of the set security (details will be described later, but as a non-limiting example, the deletion of antivirus software shown in the user input log 281 in FIG. 4), and therefore is treated as behavior that interferes with the security of the organization.

[0060] Furthermore, as will be described later, the behavior of investigating the log of operations performed on the security set for the organization may involve investigating the log or the operation log stored in the database, where the history of operations performed by the user of the terminal 20 is stored in the user input log 281 or the user management database 152. Such behavior may later lead to the deletion of the recorded security operation log (as an example, and not a limitation, the deletion of the operation log showing the removal of antivirus software shown in the user input log 281 in FIG. 4), and therefore may be included in the behavior that interferes with the security of the organization.

[0061] Actions to circumvent security set by an organization may include actions to disable security set by the organization or actions to delete operation logs that have performed operations against security set by the organization.

[0062] Examples of actions that disable security set by an organization include, but are not limited to, uninstalling security software that is security set by an organization, installing software that harms the security set by an organization, etc. These actions directly harm the security set by an organization, and therefore may be included in actions that disrupt the security of an organization.

[0063] Furthermore, the behavior of deleting an operation log in which an operation was performed against the security set by an organization is the behavior of deleting the above-mentioned user input log 281 and the operation log stored in the user management database 152. Such behavior is an behavior in which the user of the terminal 20 conceals his / her own behavior that interferes with security, and therefore may be included in the behavior that interferes with the security of an organization.

[0064] 4, the operation log of user input log 281 may not only record disruptive behavior that disrupts security set by an organization, but may also record operations that are normally performed using terminal 20 by the user of terminal 20. As an example, user input log 281 in Fig. 4 records an operation indicating that user A-A logged in to a community within the organization on month L, day L. Such information may be recorded, or the data may be configured not to store such information and to record only disruptive behavior that disrupts security.

[0065] The user input log 281 may also include other information. The other information is information related to user A·A. The information about user A·A may include, by way of example and not limitation, the date user A·A joined the company and the type of work the user does at the organization. User A·A's length of service can be calculated from the date user A·A joined the company, and since a user with a long length of service is generally a trustworthy user, this can be used to determine whether the actions recorded in user A·A's operation log were performed by mistake. Furthermore, based on the work that the user is engaged in at the organization, it can be used to determine whether the actions recorded in the operation log are work that user A-A must perform. Note that other information does not need to be included in the user input log 281, and it does not matter whether it is included or not. Other items may also be stored, such as location information for terminal 20. If terminal 20 is not located where normal business operations are performed, there is a possibility that fraudulent activity has been performed, and this information can be used to determine whether the actions stored in user A's operation log were performed by mistake. Note that location information can be detected using the location calculation detection unit 29B described in FIG. 1, or the like, and if necessary, may be attached to terminal 20 as appropriate to enable location detection.

[0066] In this way, the user input log 281 records the history of operations of the terminal 20 by the user of the terminal 20. The user input log 281 records operations of the user of the terminal 20 by input to the input / output unit 23 of the terminal 20.

[0067] The control unit 21 of the terminal 20 controls the communication unit 22 to transmit the information recorded in the user input log 281 to the server 10 via the network 30. Under the control of the control unit 21, the information recorded in the user input log 281 of the storage unit 28 is transmitted to the server 10. The information stored in the user input log 281 that is sent may or may not be all of the information contained in the user input log 281. For example, only the user ID and operation log information contained in the user input log 281 may be sent to the server 10. If the user's name has already been recorded on the receiving server side, the user name does not need to be sent. Although the case where the user ID is sent has been described, if the user can be uniquely identified by the user name, the user name may be sent together with the operation log instead of the user ID. Therefore, if the user can be uniquely identified by the user name, the user ID is not necessarily required. Furthermore, other information contained in the user input log 281 may not be transmitted if it is not used in subsequent processing by the server 10.

[0068] Next, the server 10 includes the control unit 11, communication unit 14, and storage unit 15 described above. The storage unit 15 includes a security processing program 151 and a user management database 152. The security processing program 151 is a program for executing a detection process, which will be described later, in the first embodiment, and the control unit 11 can execute the detection process by reading the security processing program 151. The user management database 152 stores, in a database format for each user, information on each user input log 281 transmitted from each user's terminal 20 via the network 30.

[0069] The communication unit 14 of the server 10 receives information based on the user input log 281 transmitted from the terminal 20. The control unit 11 of the server 10 controls the storage of the information based on the user input log 281 received by the communication unit 14 in the user management database 152 stored in the storage unit 15. Under the control of the control unit 11, operation logs performed by each user are stored in the user input log 281 in a database format.

[0070] FIG. 5 is a diagram showing the data configuration of the user management database 152 stored in the storage unit 15. The user management database 152 is configured based on the information in the user input log 281 transmitted from each user's terminal 20, and therefore, like the user input log 281, includes the user name, user ID, operation log, and other information. Note that the user management database 152 shown in FIG. 5 is illustrated as having the same configuration as the user input log 281, but they may or may not be the same. For example, unlike the input log 281, the user management database 152 may or may not include other information. On the other hand, even if the user management database 152 includes an item for other information, the input log 281 may not include such an item.

[0071] The user name, user ID, operation log, and other information are based on the input log 281 described above and may be the same information as the input log 281, or may be information added to or partially deleted from the information in the input log 281. The user management database 152 is information that aggregates the information in the input log 281 transmitted from each terminal 20, and therefore includes the user name, user ID, operation log, and other information for each user. For example, the user management database 152 in FIG. 5 stores in its operation log the deletion of antivirus software on Nth month and Nth day, which is included in the operation log of the input log 281 stored in the terminal 20 of user A·A. The user management database 152 also stores in its operation log the operation of the U application on Qth month and Qth day, which is included in the operation log of the input log 281 stored in the terminal 20 of user B·B. In this way, the user management database 152 is configured from information in which the information of the input log 281 sent from each terminal 20 is aggregated.

[0072] Next, the detection process according to the first embodiment of the present invention will be described with reference to Fig. 6. Fig. 6 shows functions included in the server 10, which includes a control unit 11 and a storage unit 15. The control unit 11 includes a detection unit 111, and the storage unit 15 includes the security processing program 151 and the user management database 152 described above.

[0073] The control unit 11 reads the security processing program 151 stored in the storage unit 15, and executes detection processing in accordance with the security processing program 151. The detection unit 111 included in the control unit 11 accesses the user management database 152 stored in the storage unit 15 in accordance with the security processing program 151, and executes processing to check the operation log of each user.

[0074] The detection unit 111 included in the control unit 11 checks the operation logs of each user in the user management database 152, and then performs processing to determine whether or not there is an operation log that corresponds to an action that interferes with the security of the organization. If there is an operation log that corresponds to an action that interferes with the security of the organization, the detection unit 111 performs processing to detect the corresponding operation log. An example of the detection process will be explained using Figure 5. Because the operation log of user A·A includes an action of deleting antivirus software, which is included in actions that disrupt security, the detection unit 111 included in the control unit 11 performs processing to detect this action as an action that disrupts security. Furthermore, the operation log of user D·D includes an action of investigating security, which is to search for security software on month P, day P, and the detection unit 111 included in the control unit 11 performs processing to detect this action as an action that disrupts security.

[0075] After performing the detection process, the detection unit 111 included in the control unit 11 may or may not perform control to store the detection result in the user management database 152. When performing the control to store, as a non-limiting example, the detection unit 111 included in the control unit 11 may perform control to store the fact that an action that interferes with the security of the organization has been detected in the other information item of the user management database 152. Furthermore, the control unit 11 may perform control to store the detection result not only in the user management database 152 but also in another storage area of ​​the storage unit 15. Note that this control to store is not essential in the first embodiment, and the control to store may or may not be performed.

[0076] Next, the processing according to the first embodiment will be described with reference to the sequence diagram shown in FIG. 7. The processing of the sequence diagram in FIG. 7 is executed by the server 10 and the terminal 20. The processing by the server 10 may be realized by the control unit 11 reading and executing the code of the security processing program 151 stored in the storage unit 15. The processing by the terminal 20 may be realized by the control unit 21 reading and executing the code of the program stored in the storage unit 28. Note that the processing described below is merely an example of a processing for implementing the method of the present disclosure, and is not limited to this. Another step may be added to the processing described below, or some steps may be omitted (deleted or skipped) from the processing described below. 7, for simplicity, the explanation is given using one terminal 20, but the processing shown in FIG. 7 may be executed by two or more terminals 20. In this case, the server 10 receives information based on the user input log 281 described below from the multiple terminals 20. Then, the information based on the user input log 281 transmitted from the multiple terminals 20 is stored in the management database 152.

[0077] First, the control unit 21 of the terminal 20 determines whether or not there is an input from the input / output unit 23 by the user using the terminal 20 (A100). If there is no input (A100: NO), the control unit 21 again determines whether there is an input from the input / output unit 23. If there is an input (A100: YES), the control unit 21 performs control to store the operation information input by the input / output unit 23 in the user input log 281 included in the storage unit 28.

[0078] Thereafter, the control unit 21 controls the communication unit 22 to transmit information based on the user input log 281 via the network 30 (A120). Note that in the sequence diagram shown in FIG. 7, the control unit 21 performs the process of step A120 consecutively after step A110, but this process is not limited to this. The process of step A120 may be performed as appropriate and may be executed independently of the process of step A110. For example, the information recorded in the user input log 281 may be transmitted periodically or aperiodically at a set time after 11:00 PM, when the user's work hours are finished. Furthermore, it is not necessary to transmit all information in the user input log 281, and information that has already been transmitted to the server 10 does not need to be transmitted, and only updated information that is not stored in the server 10 may be transmitted.

[0079] The control unit 11 of the server 10 controls the communication unit 14 of the server 10 to receive information based on the user input log 281 transmitted by the communication unit 22 of the terminal 20 (S200).

[0080] After receiving the information based on the user input log 281 via the communication unit 14 of the server 10, the control unit 11 controls the storage of the information based on the received user input log 281 in the user management database 152 stored in the memory unit 15 of the server 10 (S210).

[0081] Next, the detection unit 111 included in the control unit 11 of the server 10 performs a process of accessing the user management database 152 in order to execute the detection process (S220). Note that in FIG. 7, step S220 is executed following the process of step S210, but it does not have to be executed consecutively. It may be executed independently of step S210, or may be executed at a set timing, similar to step A120. For example, the process of accessing the user management database 152 may be executed periodically or aperiodically at a set time, such as after 10:00 PM when the user's work is finished.

[0082] After accessing the user management database 152, the detection unit 111 included in the control unit 11 determines whether or not the user management database 152 contains any behavior that violates security (S230). If the user management database 152 does not contain any behavior that violates security (S230: NO), the detection process ends.

[0083] On the other hand, if the detection unit 111 included in the control unit 11 determines that the behavior includes behavior that interferes with security (S230: YES), it performs control to detect interference behavior that interferes with the relevant organization from the operation log of the user management database 152 (S235). After performing step S235, the detection process described in FIG. 7 ends.

[0084] As described above, after the processing of step 235, the control unit 11 may or may not control the storage of the detected disruptive behavior in association with the user who committed the disruptive behavior. If the control unit 11 performs the storage, the control unit 11 may or may not control the storage of the fact that the disruptive behavior has been detected in the other information section of the user who committed the disruptive behavior, which is included in the user management database 152. As described above, the control unit 11 may also control the storage of the information in an area of ​​the storage unit 15 different from the user management database 152.

[0085] <Effects of the first embodiment> This embodiment shows a configuration in which an information processing device such as a server 10 detects disruptive behavior, which is behavior related to disrupting security set on an organization's terminal 20 by a user using the organization's terminal 20 (not limited to this, but an example of an organization's equipment), using a detection unit 111 included in the control unit 11. As an example of an effect of an embodiment obtained by such a configuration, it becomes possible to detect information intended to disrupt the security of an organization, thereby making it possible to detect users who directly harm the security of an organization.

[0086] In addition, in this embodiment, actions related to the violation of security include actions to investigate the security set in the terminal 20 (which is not limited to this but is an example of an organization's equipment). This configuration makes it possible to detect security investigation behavior by a user, which is a precursor to a security breach, and therefore makes it possible to detect behavior by a user that could harm the security of an organization before the user breaches security.

[0087] In addition, this embodiment includes, as actions related to the violation of security, an operation by a user of terminal 20 to investigate the security set on terminal 20 (which is not limited to, but is an example of an organization's equipment), or an action to investigate an operation log regarding security. Such a configuration makes it possible to detect user behavior that could compromise the security of an organization before the user actually causes a security disruption.

[0088] Furthermore, in this embodiment, behavior related to the violation of security includes behavior by the user of the terminal 20 that circumvents security set in the terminal 20 (which is not limited to the terminal 20 but is an example of an organization's equipment). This configuration makes it possible to detect malicious user attempts to circumvent security. Furthermore, it will be possible to detect users who have circumvented the organization's security measures and are likely to perform further malicious actions before they perform further malicious actions such as launching specific attacks against the organization (for example, but not limited to, cyber attacks), thereby limiting damage to the organization.

[0089] In addition, in this embodiment, actions related to the disruption of security include actions by the user of terminal 20 to disable security set on terminal 20 (which is not limited to terminal 20 but is an example of an organization's equipment), or actions to delete operation logs of operations performed on security. This configuration makes it possible to detect malicious user attempts to circumvent security. Furthermore, it will be possible to detect users who have circumvented the organization's security measures and are likely to perform further malicious actions before they perform further malicious actions such as launching specific attacks against the organization (for example, but not limited to, cyber attacks), thereby limiting damage to the organization.

[0090] Furthermore, in this embodiment, the security may include security set by an organization to protect the organization's network. With this configuration, as a security measure, it is possible to detect behavior that disrupts the protection of an organization's network, thereby making it possible to detect users who disrupt the organization's network, thereby protecting the organization's network from disruption.

[0091] Furthermore, in this embodiment, security may be set on the terminals 20 (not limited to, but an example of equipment in an organization) distributed to each of a plurality of users belonging to an organization. With this configuration, the security target for detecting interference is set uniformly for the organization, so by detecting acts of interference with security, it is possible to detect interference with the security set for the organization and protect the entire organization from interference with the security set for the organization.

[0092] In addition, in this embodiment, the security may be software-based security. With this configuration, it becomes possible to detect software-based tampering with security, thereby making it possible to protect against software-based tampering with security.

[0093] <Modification 1 of Embodiment 1> In the first embodiment, the actions that disrupt the security of an organization may be input by an administrator who manages the terminal 20 of the organization, who determines what constitutes an action that disrupts security, or the actions included in the actions that disrupt the security of the organization may be obtained from outside via the network 30.

[0094] When input by a user who manages the organization's terminal 20, the input is made through the input / output unit 23 of the organization's terminal 20 or the input / output unit 12 provided in the server 10. As a non-limiting example, when adding an action of deleting the organization's firewall as a specific action included in the above-mentioned actions to circumvent security, the action is input through the input / output unit 23 of the organization's terminal 20 or the input / output unit 12 provided in the server 10 and added as a new action that violates security. The added new action that violates security is stored in the storage unit 15 or the like.

[0095] In addition, when acquiring behaviors included in behaviors that disrupt the organization's security from the outside via the network 30, the communication unit 14 of the server 10 receives new behaviors included in behaviors that disrupt the organization's security and stores them in the memory unit 15 or the like. By way of example and not limitation, the newly added security-compromising behavior is stored in security program 151, which is stored in storage unit 15. This allows control unit 11, when loading security program 151, to obtain information indicating what behaviors, including the newly added disruptive behavior, are threatening the security of the organization.

[0096] By executing the processing described in Variation 1 of Embodiment 1, it becomes possible to appropriately update behaviors that disrupt the security of an organization, and it becomes possible to add newly occurring disruptive behaviors and newly occurring behaviors that disrupt security, thereby making it possible to appropriately detect behaviors that disrupt the security of an organization.

[0097] <Embodiment 2> In the first embodiment, a configuration has been disclosed in which the information processing device such as the server 10 detects, by the detection unit 111 included in the control unit 11, any disruptive behavior against the security of the organization by a user who uses the organization's equipment. In the second embodiment, after the detection is performed by the detection unit 111, a device control unit 114 included in the control unit 11, which will be described later, controls notification and the use of the terminal 20.

[0098] FIG. 8 is a block diagram showing an example of the functional configuration of the server 10 according to the second embodiment. To explain the second embodiment by focusing on the differences between the first and second embodiments, the server 10 according to the second embodiment includes a determination unit 113 and a device control unit 114. As will be described later, the determination unit 113 is not necessarily required, and may or may not be present.

[0099] The determination unit 113 executes a process of determining whether or not to control the device based on the result of detection by the detection unit 111. If it is determined that device control is to be executed, the device control is executed by the device control unit 114. In the second embodiment, the device control will be described using an example of control that notifies information indicating that an action that violates security has been detected, but as described in a modified example below, the device control is not limited to this.

[0100] Next, a sequence diagram showing an example of the flow of processing executed by each device in this embodiment is shown in Figure 9. Here, the contents shown in Figure 9 will be explained, focusing on the differences from the first embodiment. First, unlike the first embodiment, the second embodiment is configured with two terminals 20 and a server 10. Note that the explanation has been given using an example of two terminals, terminal 20A and terminal 20B, but this is not limited to this, and there may be two or more terminals that perform processing equivalent to terminal 20A, or there may be two or more terminals that perform processing equivalent to terminal 20B. 9, the description will be given assuming that the user using terminal 20A is a user belonging to an organization, and the user using terminal 20B is a user (which may be expressed as an administrator) who manages terminal 20A, etc., of the organization, but the present invention is not limited to this. The user using terminal 20B may be a user who belongs to the organization, like the user using terminal 20A, or may be a user who belongs to an organization different from the organization to which terminal 20A belongs.

[0101] Next, in the second embodiment, the processing flow that differs from the first embodiment is that there are no particular differences in terminal 20A, but differs from the first embodiment in that server 10 includes steps S240 and S245, and terminal 20B differs from the first embodiment in that it includes processing in steps B300 and B310.

[0102] In order to focus on the differences between the second embodiment and the first embodiment, the description will begin with the processing after step S235, which is similar to the processing in the first embodiment and is executed by the detection unit 111 included in the control unit 11 of the server 10. As the processing after step S235, based on the detection of the disruptive behavior detected in step S235, the determination unit 113 included in the control unit 11 determines whether to control the device (S240). In the description here, as described above, the control of the device will be described by taking as an example the control of notifying the terminal 20A. 9, an example in which the determination in step S240 is executed is described, but the present invention is not limited to this. Step S240 is not essential, and after step S235, the process may be executed by skipping step S240.

[0103] When the determination unit 113 determines that the notification to the terminal 20B is not to be performed as the device control (S240: NO), the device control is not to be performed and the control by the control unit 11 in FIG. 9 is terminated. On the other hand, if the determination unit 113 determines that the control to notify the terminal 20B is to be performed as the device control (S240: YES), the device control unit 114 executes control to notify the terminal 20B that a security interference behavior has been detected (S245). As the control to notify, the device control unit 114 controls the communication unit 14 to transmit information for the notification to the terminal 20B via the network 30.

[0104] Here, the information for making a notification includes at least information for making terminal 20B execute a notification, and when terminal 20B receives this information, terminal 20B executes a notification of information indicating that a security interference behavior has been detected. Note that the information for making a notification may or may not include notification content made up of text information. If it does include the notification content, as described below, the notification content is displayed on display unit 24 of terminal 20B, by way of example and not limitation.

[0105] Next, the control unit 21 of the terminal 20B determines whether or not the communication unit 22 of the terminal 20B has received information for notification, which is included in the information regarding device control sent from the server 10, via the network 30 (B300).

[0106] If the information for sending a notification has not been received (B300: NO), the control unit 21 of the terminal 20B again determines whether or not the information for sending a notification has been received. If the information for sending a notification has been received (B300: YES), the control unit 21 of the terminal 20B executes a process of sending a notification to the user who uses the terminal 20B based on the information for sending a notification.

[0107] 10 is a diagram showing that, upon receipt of information for notification by terminal 20B, notification of information indicating that an obstructive behavior against security has been detected is executed on display unit 24 of terminal 20B. As shown in FIG. 10, display unit 24 displays "User A·A may be engaging in obstructive behavior" as notification of information indicating that an obstructive behavior against security has been detected.

[0108] As mentioned above, the user using terminal 20B may be an administrator who manages an organization, and so by checking the content of this notification, the user using terminal 20B will be able to immediately know that user A·A is engaging in disruptive behavior.

[0109] Although the notification content has been described using a display as an example, it is not limited to this. The notification here may be a sound notification or a vibration notification. The control unit 21 of the terminal 20B may perform different control depending on the type of notification and control the notification appropriately. A sound notification or a tactile notification may be performed by the input / output unit 23 shown in FIG. 1. The sound notification may be a buzzer sound or chime that is an alarm sound indicating that a security breach has been detected, or a synthesized voice corresponding to text indicating that a security breach has been detected.

[0110] <Effects of the second embodiment> This embodiment shows a configuration in which an information processing device such as a server 10 detects disruptive behavior, which is behavior related to disrupting security set on an organization's terminal 20 by a user using the organization's terminal 20 (not limited to, but an example of an organization's equipment), using a detection unit 111 included in the control unit 11, and controls the equipment (not limited to, but an example of control) based on the detection using an equipment control unit 114 included in the control unit 11. As an example of an effect of an embodiment obtained by such a configuration, control can be exercised based on the detection of information intended to disrupt the security of an organization, making it possible to appropriately respond to disruptive behavior against the security of an organization.

[0111] Furthermore, in this embodiment, a configuration is shown in which the device control unit 114 included in the control unit 11 performs control of notifying an obstructive behavior as control of the device (not a limitation but an example of control). As an example of an effect of an embodiment obtained by such a configuration, based on the detection of information intended to disrupt the security of an organization, it is possible to notify that an action to disrupt security is being taken, and to deal with the disruption early.

[0112] <Modification 1 of Second Embodiment> 9 and 10 of the second embodiment, notification has been described as an example of device control, but the present invention is not limited to this. Device control may be performed by restricting the use of terminal 20B of a user who has engaged in disruptive behavior based on the detection of disruptive behavior. In the assumed example in FIG. 9, the user using terminal 20B is assumed to be a user (administrator) who manages terminals 20A and the like of an organization. However, in this modified example 1, the user using terminal 20B is assumed to be a user who belongs to the organization, just like the user using terminal 20A. Furthermore, the following example is explained using terminals 20A and 20B, but the explanation is given assuming that terminal 20B has already executed the processing performed by terminal 20A in the sequence diagram of FIG. 9 described below. In other words, since terminal 20B has already executed the processing of terminal 20A in FIG. 9, it is assumed that user management database 152 already stores information based on the user's input log stored in terminal 20B. Furthermore, as described below, the terminal 20B may be read as the terminal 20A, and the processing of the first modification of the second embodiment may be executed.

[0113] A specific description will be given with reference to Fig. 9. In the sequence diagram of Fig. 9, the processing is the same up to step S240. When device control is performed in step S240, control of restricting the use of terminal 20B of the user who has engaged in disruptive behavior may be performed by device control unit 114 included in control unit 11 in step S245 as device control.

[0114] The control to restrict the use of terminal 20B by the user who has engaged in disruptive behavior is a control to transmit information for restricting the use of terminal 20B from server 10 to terminal 20B. When terminal 20B receives the information restricting the use of terminal 20B, the use of terminal 20B is restricted, and it no longer accepts operations by the user of terminal 20B, making it impossible to use terminal 20B. It is not necessary to limit the acceptance of all operations, and it is also possible to prevent the acceptance of some operations. As a non-limiting example, only some functions, such as the Internet function, email function, and chat function, or software that constitutes some functions may be made unavailable, or all functions or all software may be made unavailable.

[0115] Furthermore, without being limited to the above example, when terminal 20B receives this information, the user of terminal 20B may be deprived of the authority to use terminal 20B, and may not be able to log in to terminal 20B.

[0116] Therefore, when performing device control, in step S245, device control unit 114 controls communication unit 14 of server 10 to transmit information for restricting the use of terminal 20B. Thereafter, if control unit 21 determines in step B300 that information for restricting the use of terminal 20B has been received by communication unit 22 of terminal 20B, in step B310, control unit 21 executes the above-mentioned control for restricting the use of terminal 20B as device control.

[0117] Although an example of restricting the use of the terminal 20B has been described above, in addition to this, a notification indicating that the use of the terminal 20B has been restricted may be sent. 11 shows the display unit 24 of terminal 20B after control to restrict the use of terminal 20B has been executed. Display unit 24 displays a message indicating that user B-B may be engaging in disruptive behavior and that use of the terminal has been restricted. In this way, a notification may also be sent to the user of terminal 20B informing them that use of the terminal has been restricted in response to the user of terminal 20B engaging in disruptive behavior against the security of the organization.

[0118] In this way, the device control may not only perform the control for making the notification described in the second embodiment, but also perform control for restricting the use of the terminal 20B. In addition, although the explanation of the first modification of the second embodiment has been given using information for restricting the use of terminal 20B, the processing may be executed by replacing terminal 20B with terminal 20A. That is, although the example of the first modification of the second embodiment has been described above using processing executed by two terminals, terminal 20A and terminal 20B, and server 10, the processing may be executed by terminal 20A and server 10, or the processing may be changed so that the processing executed by terminal 20B is executed only by terminal 20A. Furthermore, the processing of Modification 1 of Embodiment 2 may be executed by a plurality of terminals in accordance with the description of Embodiment 2. That is, there may be a plurality of terminals corresponding to terminal 20A described in Modification 1 of Embodiment 2, or there may be a plurality of terminals corresponding to terminal 20B described in Modification 1 of Embodiment 2.

[0119] In the example of the first modification of the second embodiment, the device control is performed on terminal 20B to restrict the use of terminal 20B. However, the present invention is not limited to this, and the device control may be performed by transmitting information to terminal 20B inquiring whether to restrict the use of a terminal different from terminal 20B (for example, terminal 20A). In this case, the user of terminal 20B may be a user corresponding to a user (administrative user) who manages devices in the organization. For example, if an obstructive behavior by a user of a terminal (e.g., terminal 20A) different from terminal 20B is detected in step S235, device control unit 114 of server 10 transmits information inquiring whether to restrict the use of a terminal (e.g., terminal 20A) different from terminal 20B as device control in step S240. Then, terminal 20B receives the information inquiring whether to restrict the use from server 10. Then, terminal 20B displays information corresponding to this on display unit 24 of terminal 20B. When the user of terminal 20B confirms this and inputs permission to restrict use, control may be performed by control unit 11 of server 10 to restrict use of a terminal different from terminal 20B (for example, terminal 20A). That is, referring to the example of Modification 1 of Embodiment 2, server 10 may transmit information inquiring whether to restrict use as device control.

[0120] <Effects of Modification 1 of Second Embodiment> In addition, this modified example shows a configuration in which, as control of the device (not limited to this, but an example of control), control to restrict the use of the device used by the user or control to restrict the software of the device used by the user is performed by the device control unit 114 included in the control unit 11. As an example of an effect of an embodiment obtained by such a configuration, it becomes possible to restrict the use of a terminal that is violating security based on the detection of information intended to violate the security of an organization, thereby making it possible to prevent the user who has violated security from engaging in further malicious behavior before it occurs.

[0121] <Embodiment 3> The first embodiment discloses a configuration in which the detection unit 111 included in the control unit 11 detects, by an information processing device such as the server 10, any disruptive behavior against the security of the organization by a user who uses the organization's equipment. The third embodiment is configured to perform detection by the detection unit 111, and then evaluate the risk value of the disruptive behavior by the evaluation unit 112 included in the control unit 11, which will be described later, and quantitatively evaluate the risk of disruptive behavior performed by users of the organization's equipment.

[0122] The configuration of the third embodiment will be described with reference to Fig. 12. As a difference from the first embodiment, as described above, the control unit 11 includes an evaluation unit 112. This evaluation unit 112 quantitatively evaluates the risk of disruptive behavior against the security of the organization, detected by the detection unit 111 included in the control unit 11. The evaluated value and the like may be stored in the user management database 152 included in the storage unit 15, or may be stored in a separate storage area of ​​the storage unit 15.

[0123] Fig. 13 shows how the evaluations by the evaluation unit 112 are stored in the user management database 152. Unlike the previously described Fig. 5, the user management database 152 shown in Fig. 13 has an item for inputting an evaluation point for each user. An evaluation value based on the behavior of each user is input into this item for inputting an evaluation point. Although the evaluated values ​​are shown here as numerical values, evaluation may be performed using other methods. For example, and without limitation, evaluation may be performed in multiple stages such as high, normal, and low risk, or the magnitude of risk may be indicated in alphabetical order (for example, A indicates the highest risk, and evaluation may be performed in order of decreasing risk from A onwards).

[0124] 13 shows that the evaluation of user A·A is minus 50. This is because user A·A deleted antivirus software, which is an obstructive action against the security of the organization, and so the evaluation unit 112 has assigned the evaluation of minus 50. 13 also shows that the evaluation of user D·D is minus 15. This is because the evaluation unit 112 has evaluated the user D·D as having performed a search for the location where security software is stored, which is an obstruction to the security of the organization.

[0125] The evaluation here may be uniform, or may be different for each behavior. For example, removing antivirus software is included in behaviors that circumvent organizational security. The behavior of circumventing security may be deemed to be higher risk than the behavior of investigating security, and the evaluation may be set higher (so that the negative evaluation is more significant) than the behavior of investigating security. Specifically, in Figure 9, the removal of antivirus software, which is included in the behavior of circumventing security, is scored with a negative score of minus 50 (not a limitation, but an example of a first value). On the other hand, performing a security search, which is included in the behavior of investigating security, is scored with a negative score of minus 15 (not a limitation, but an example of a second value), which is a smaller negative score than removing antivirus software. In this way, the behavior of circumventing security may be scored with a larger negative score than the behavior of investigating security (not a limitation, but an example of a second value having a higher negative score than the first value), or vice versa.

[0126] Furthermore, since multiple types of behaviors to be avoided are set, the evaluation unit 112 may perform a different evaluation for each type. As a non-limiting example, the evaluation may be different for the removal of antivirus software and the deletion of security operation logs, which are included in the behaviors to be avoided. As a non-limiting example, the evaluation unit 112 may perform a minus 50 evaluation for the removal of antivirus software, and a minus 30 evaluation for the deletion of security operation logs. In this way, the evaluation unit 112 may perform a different evaluation for each type. Note that, similarly, with regard to behaviors to investigate security, the evaluation unit 112 may perform a different evaluation for each type included in the behavior to investigate security.

[0127] 13, user B·B has been evaluated as minus 5 by the evaluation unit 112. This does not constitute an action that would compromise the security of the organization, but the evaluation unit 112 has evaluated B·B as minus 5 because the user operates the terminal 20 more frequently than a normal user. Therefore, the evaluation unit 112 evaluates B·B differently from the evaluation of an action that would compromise the security of the organization. 13, the evaluation unit 112 has given user C·C a rating of +15. This is because, as described in the other information, the user has not engaged in any particularly problematic behavior since joining the company, and therefore the evaluation unit 112 has given a positive evaluation. Also, although a positive evaluation is used as an example in the explanation here, the evaluation unit 112 may give a negative evaluation depending on the other information described. Furthermore, a negative or positive evaluation may be made depending on the business content of the user of the terminal 20 and the location information of the terminal 20, as described in the first embodiment. As a non-limiting example, if the "Other" field stores the location of a place different from the place where the user of the terminal 20 normally performs business, the evaluation unit 112 may make a negative or positive evaluation based on the location, time, and time. Although it is disclosed here to perform evaluations unrelated to security breaches and to perform positive evaluations, this processing does not need to be performed. Also, although evaluations are performed using positive and negative evaluations, evaluations may be performed using only one of them, for example, evaluations may be performed using only negative evaluations and no positive evaluations may be performed.

[0128] Furthermore, when multiple actions are stored in the operation log, an evaluation may be performed for each action, and the sum of the evaluations may be used as the evaluation for the user. As a non-limiting example, if user A·A deletes antivirus software and performs more operations than usual, the evaluation unit 112 may add minus 5 to minus 50, thereby evaluating user A·A as minus 55, and may store this in the user database 152.

[0129] Next, the processing of the third embodiment will be described with reference to Fig. 14. Focusing on the differences between the first and third embodiments, the processing up to step S235 is the same, but the processing from step S250 onwards differs between the third embodiment and the first embodiment. Therefore, the processing from step S250 onwards will be described in detail.

[0130] After the detection unit 111 in the control unit 11 detects disruptive behavior in step S235, the evaluation unit 112 evaluates the detected disruptive behavior against the security of the organization (S250). After the evaluation by the evaluation unit 112 is performed, the evaluation is stored in the user management database 152 in the storage unit 15 (step S260). As described above, the evaluation may be stored in a storage area of ​​the storage unit 15 different from the user management database 152.

[0131] <Effects of the third embodiment> In this embodiment, an information processing device such as a server 10 detects disruptive behavior, which is behavior related to disrupting security set on an organization's terminal 20 by a user using the organization's terminal 20 (not limited to, but an example of an organization's equipment), using a detection unit 111 included in the control unit 11, and evaluates the detected disruptive behavior using an evaluation unit 112 included in the control unit 11, and the evaluation by the evaluation unit 112 is stored in a memory unit 15 by the control unit 11. As an example of an effect of an embodiment obtained by such a configuration, by quantitatively evaluating the disruptive behavior performed by users and storing that evaluation, it becomes possible to confirm the extent to which each user's behavior was malicious.

[0132] In addition, this embodiment shows a configuration in which, in the evaluation by the evaluation unit 112, different evaluations are made for behavior that investigates the security set on the terminal 20 (not limited to, but an example of equipment) of the organization and behavior that circumvents the security set on the terminal 20. As an example of an effect of an embodiment obtained by such a configuration, by differently evaluating actions that circumvent security and actions that investigate security, it becomes possible to appropriately evaluate the actions of malicious users.

[0133] In addition, this embodiment shows a configuration in which, in the evaluation by the evaluation unit 112, different evaluations are made for actions that disrupt the security set on the organization's terminal 20 (not limited to this but an example of equipment) and user operations on the terminal 20 that are different from disruptive actions. As an example of an effect of an embodiment obtained by such a configuration, by differently evaluating actions that circumvent security and actions that investigate security, it becomes possible to appropriately evaluate the actions of malicious users.

[0134] <Third embodiment, modified example 1> In the example of the third embodiment, in step S260, the evaluation by the evaluation unit 112 is stored in the user management database 152, and then the processing is terminated. However, the processing described in the second embodiment may be added thereafter. In the second embodiment, a determination is made in step S240 as to whether or not to control the device. This determination as to whether or not to control the device may be made based on the evaluation points stored in the storage unit 15.

[0135] The following describes a first modification of the third embodiment using an example and not a limitation. After step S260 in the sequence diagram shown in Fig. 14, the process of step S240 in Fig. 9 described in the second embodiment may be added and executed. At this time, the evaluations stored for each user are stored in a user management database 152 included in the storage unit 15. Using the evaluations stored in this user management database 152, the device control unit 114 determines whether to control the device. For example, and not by way of limitation, the device control unit may control the device when the evaluation score falls below a set threshold of minus 50. When the evaluation score falls below, exceeds, or becomes equal to a set value (for example, and not by way of limitation, the threshold), the device control unit 114 may determine to control the device. Note that the processing from step S240 onwards may be performed according to FIG. 9 described in the second embodiment.

[0136] Note that the present invention is not limited to the above example, and the device control unit 114 may determine to control the device when a specific disruptive behavior is performed regardless of the evaluation score. As a non-limiting example, when the detection unit 111 detects an action that disrupts security set for an organization, the device control unit 114 may determine to control the device regardless of (or skip) the evaluation by the evaluation unit 112. For example, suppose a user's evaluation score exceeds plus 100 in the evaluation by the evaluation unit 112 described above, and then the user is deducted by 50 for performing an action that circumvents security. In this case, the user's evaluation score is deducted by 50 from plus 100, so that the user's evaluation score is still plus 50. However, regardless of this evaluation, the device control unit 114 may determine to control the device because the user has performed an action that disrupts security.

[0137] Note that when executing control of a device, the device control unit 114 may or may not execute control of the device only when it detects behavior that circumvents security, regardless of (or by skipping) the evaluation by the evaluation unit 112. In other words, when it detects behavior that investigates security, it controls the device based on the evaluation by the evaluation unit 112, and only when it detects behavior that circumvents security, it executes control of the device regardless of (or by skipping) the evaluation by the evaluation unit 112. Furthermore, when executing control of an equipment, the equipment control unit 114 may or may not execute control of the equipment regardless of the evaluation by the evaluation unit 112 (or may skip the evaluation) only if it detects behavior that investigates security.

[0138] Although an example of combining the third embodiment with the second embodiment has been described above, the present invention is not limited to this example and the contents described in the present embodiment may be combined in any manner. Furthermore, when combining the two, it is not necessary to execute all steps, and unnecessary steps may be skipped as appropriate, or other steps may be added as appropriate.

[0139] <Third embodiment, modified example 2> In the third embodiment, the evaluation unit 112 gave a constant evaluation to each of the behaviors that circumvent security and the behaviors that investigate security. However, this evaluation may vary depending on the situation. As a non-limiting example, when the detection unit 111 detects multiple behaviors that circumvent security or multiple behaviors that investigate security per set time (or period) or per unit time (or unit period), the evaluation may be different from when the same multiple behaviors are detected at intervals longer than the set time or unit time.

[0140] As a non-limiting example, suppose the above-mentioned set time is set to 72 hours. Suppose the detection unit 111 detects three instances of security investigation behavior within this set time. In such a case, even if the evaluation unit 112 evaluates the first instance as minus 15, the second instance may be evaluated as minus 20, and the third instance may be evaluated as minus 50, with each evaluation value being different. The reason for this is that even if a security check behavior is detected once within a 72-hour period, the user may perform such an operation by mistake without malicious intent. On the other hand, if the same behavior is performed multiple times within a set period of time, it is highly likely that it is performed with the intention of disrupting. Therefore, if the same behavior is performed multiple times within a set period of time, the negative evaluation will be greater than if the same behavior is performed at a time interval longer than the set period of time, making it possible to more accurately evaluate disruptive behavior. Note that the clock unit 16 or clock unit 29A shown in Fig. 1 may be used to calculate whether or not the set time has passed. Therefore, the terminal 20 or the server 10 may be appropriately equipped with the above-mentioned configuration when calculating whether or not the set time has passed. This makes it possible to calculate whether or not the detected behavior that violates security is within the set time. Note that instead of providing the above-mentioned configuration in the device itself, the device may be configured to acquire time information, etc., via a network.

[0141] Furthermore, without being limited to the above example, a configuration is also possible in which, each time multiple similar behaviors are detected within a set time, an additional minus 10 is added to the evaluation of each behavior. In this way, any evaluation method may be used as long as multiple behaviors performed within a set time are evaluated so that they receive a larger negative evaluation compared to multiple behaviors performed outside the set time. Although the above description has been given using multiple identical actions, different types of actions may also be evaluated so that the negative evaluation is greater. As a non-limiting example, if a security investigation action and a security evasion action are performed, the action would normally be evaluated as minus 15 and minus 50, totaling minus 65. However, if the above actions are performed within the set time of 72 hours, the evaluation unit 112 may evaluate the action as minus 100, which is greater than minus 65, or as minus 130, which is twice the value.

[0142] As described above, a set time is set and evaluation is performed based on disruptive behavior detected at the set time, but the evaluation may be different for each set time. As a non-limiting example, the evaluation unit 112 may perform a normal evaluation between 9:00 and 18:00 when normal business is performed, but may perform a different evaluation during other periods.

[0143] As a non-limiting example, the late night hours between 12:00 and 3:00 are times when normal business operations are not being carried out. If the detection unit 111 detects an action that interferes with security during this time, it is highly likely to be malicious. Therefore, if the above-mentioned action is detected between 12:00 and 3:00 during the late night hours, the evaluation unit 112 will assign a larger negative rating than normal. For example, the evaluation may be set to twice the normal rating.

[0144] The second modification of the third embodiment shows a configuration in which the evaluation unit 112 performs evaluation based on the obstructive behavior detected at a set time. As an example of the effect of this embodiment obtained by such a configuration, it becomes possible to accurately evaluate whether or not a user is intentionally violating security.

[0145] In addition, variant example 2 of this embodiment 3 shows a configuration in which when the detection unit 111 detects multiple security evasion behaviors or multiple behaviors to be investigated per set time or per unit time, the evaluation by the evaluation unit 112 is different compared to when the same multiple behaviors are detected at intervals longer than the set time or unit time. As an example of the effect of this embodiment obtained by such a configuration, it becomes possible to accurately evaluate whether or not a user is intentionally violating security.

[0146] <Embodiment 4> In the first embodiment, a configuration has been disclosed in which the information processing device such as the server 10 detects, by the detection unit 111 included in the control unit 11, any disruptive behavior against the security of the organization by a user who uses the organization's equipment. In the fourth embodiment, instead of the server 10, an information processing device such as a terminal 20 is configured to detect disruptive behavior against the organization's security by a user who uses the organization's equipment using a detection unit 211 included in the control unit 21 of the terminal.

[0147] FIG. 15 is a diagram illustrating an example of functions realized by the control unit 21 of the terminal 20 according to the fourth embodiment. Focusing on the differences between the fourth embodiment and the first embodiment, the terminal 20 illustrated in FIG. 15 includes a control unit 21, which in turn includes a detection unit 211. The detection unit 211 may have the same configuration as the detection unit 111 described above. The storage unit 28 stores, in addition to the user input log described in the first embodiment, a terminal security processing program 282 that the control unit 21 reads and the detection unit 211 executes the detection process. The terminal security processing program 282 may have the same configuration as the security processing program 151 provided in the server 10 described in the first embodiment. However, the terminal security processing program 282 is a program for processing on the terminal 20. Compared to the first embodiment, the communication unit 22 is described here as being removed because communication with the server 10 is not required. However, the communication unit 22 may or may not be provided.

[0148] As described above, the terminal 20 described in the fourth embodiment is capable of reading the terminal security processing program 282 stored in the storage unit 28 by the control unit 20 and executing detection processing in accordance with the terminal security processing program 282. After reading the terminal security processing program 282, the detection unit 211 accesses the user input log 281 and executes processing to check the operation log included in the user input log 281. Then, if the operation log contains any disruptive behavior against the security of the organization, the detection unit 211 executes processing to detect the disruptive behavior.

[0149] Next, the processing of the fourth embodiment will be described with reference to the flowchart shown in Fig. 16. Focusing on the differences from the contents described in the first embodiment, the processing is the same up to step A110, but the processing thereafter is different. After step A110, the detection unit 211 provided in the control unit 21 performs processing to access the user input log 281 (step A130). After the detection unit 211 accesses the user input log 281, it executes processing to determine whether or not any disruptive behavior against security is recorded in the operation log included in the user input log 281 (step A140). For simplicity, the following description is given assuming that step A140 is executed immediately after step A130, but the present invention is not limited to this. As described in the first embodiment, step A140 may be executed independently of step A130. As an example and not a limitation, step A140 may be executed periodically at a set time, separately from step A130.

[0150] If the security disruptive behavior is not stored in the operation log, the detection process ends (step A140: NO). On the other hand, if the detection unit 211 determines that the security disruptive behavior is stored in the operation log, the detection unit 211 executes a process to detect the disruptive behavior (step A145).

[0151] As described above, the fourth embodiment shows that the detection process of the above-described embodiments is executed by the terminal 20 instead of the server 10. Therefore, the present embodiment also includes execution by an information processing device such as the terminal 20 without using the server 10.

[0152] <Effects of the Fourth Embodiment> This embodiment shows a configuration in which an information processing device such as a terminal 20 detects disruptive behavior, which is behavior related to disrupting security set on the organization's terminal 20 by a user using the organization's terminal 20 (not limited to this, but an example of the organization's equipment), using a detection unit 211 included in the control unit 21. As an example of an effect of the embodiment obtained by such a configuration, by executing the detection process by an information processing device such as the terminal 20, it becomes possible to perform the detection process at the terminal itself.

[0153] <Embodiment 5> In the fifth embodiment, in addition to the components of the fourth embodiment, an information processing device such as the terminal 20 may be provided with components corresponding to the determination unit 113 and the device control unit 114 described in the second embodiment. The configuration of the fifth embodiment will be described with a focus on the differences from the fourth embodiment. FIG. 17 is a diagram showing an example of functions realized by the control unit 21 of the terminal 20 according to the fifth embodiment. In addition to the configuration of the fourth embodiment, FIG. 17 adds a determination unit 213 and a device control unit 214. Note that the determination unit 213 may have the same function as the determination unit 113 described in the second embodiment, and the device control unit 214 may have the same function as the device control unit 114 described in the second embodiment. Furthermore, the fifth embodiment includes a communication unit 22 for communication, but this is not necessarily required, and in the case of processing executed only by the terminal 20, the communication unit 22 may or may not be detached.

[0154] 17 also includes a server 10, which includes a communication unit 14, a control unit 11, and an input / output unit 12. The control unit 11 also includes a device control unit 114, and when the control unit 11 receives information for sending a notification as an example of device control transmitted from the device control unit 214 via the communication unit 14, the notification control unit 114 executes control for sending a notification based on the information for sending a notification. In the example described here, notification is sent to the input / output unit 12 provided in the server 10, but notification may be sent to another terminal 20 instead of the server 10. In this case, the information received by the server may be information restricting the use of the terminal, as described in the second embodiment, instead of information for sending notification. The assumed case of outputting to the input / output unit 12 of the server 10 is to send a notification to a user who manages an organization and is located near the input / output unit 12 of the server 10, but this example is not limited to this. It is also possible to send notifications and restrict use to one's own terminal 20, rather than to another terminal 20. In this case, the device control unit 214 may be configured to control the device itself (by way of example and not limitation, to control notifications and to restrict use of the own terminal). In this case, since there is no need to communicate information for device control, the terminal 20 may or may not include the communication unit 22.

[0155] FIG. 18 is a sequence diagram illustrating the processing of the fifth embodiment. Focusing on the differences from the fourth embodiment, the processing up to step A145 is the same as that of the fourth embodiment. After step A145, the determination unit 213 determines whether or not device control is necessary based on the detection of the disruptive behavior (step A160). If it is determined that device control is not necessary, the processing according to the fifth embodiment ends (step A160: NO). On the other hand, if the determination unit 213 determines that device control is necessary (step A160: YES), the device control unit 214 included in the control unit 21 executes device control (step A165). As device control, the device control unit 214 performs control such as transmitting information related to device control to the server 10 via the communication unit 22. Note that the example here is not limited to control such as transmitting information for notification.

[0156] Next, the control unit 11 of the server 10 controls the communication unit 14 to receive the information about the device transmitted via the network 30 (step S250). Then, based on the received information about the device, the device control unit 114 included in the control unit 11 controls the device (step S260). Here, as an example and not a limitation, the device control unit 114 controls the input / output unit to notify the input / output unit that an action that violates security has been detected, based on the information for notification.

[0157] As described above, the fifth embodiment shows a configuration in which the detection process and the process related to device control are executed by an information processing device such as the terminal 20 instead of the server 10. In this way, the process shown in the second embodiment may be executed by an information processing device such as the terminal 20 instead of the server 10. In the above-described embodiment, a configuration in which the detection unit 211 is provided in an information processing device such as the terminal 20 has been described, but the present invention is not limited to this, and the information processing device may also have the configuration described in embodiment 3. As a non-limiting example, the control unit 21 may have a configuration equivalent to the evaluation unit 112 described in embodiment 3. Furthermore, in addition to the configuration equivalent to the evaluation unit 112, the control unit 21 may or may not have a configuration equivalent to the determination unit 213 or the device control unit 214 described above. Furthermore, the control unit 21 may have a configuration equivalent to the evaluation unit 112, and the server 10 may have configurations equivalent to the determination unit 113 and device control unit 114. In this case, the configuration equivalent to the evaluation unit 112 provided in the control unit 21 of the terminal 20 performs an evaluation of the user of the terminal 20, and the terminal 20 transmits the evaluation result to the server 10. The server 10 may be configured to perform device control as described in the second embodiment using the determination unit 113 and the device control unit 114 based on the received result of the evaluation by the terminal 20. These combinations may be freely made as appropriate, and all combinations described in this embodiment are within the scope of the disclosure of this specification.

[0158] <Effects of the Fifth Embodiment> This embodiment shows a configuration in which an information processing device such as a terminal 20 detects disruptive behavior, which is behavior related to disrupting security set on the organization's terminal 20 by a user using the organization's terminal 20 (not limited to this, but an example of the organization's equipment), using a detection unit 211 included in the control unit 21, and controls the equipment using an equipment control unit 114. As an example of the effect of the embodiment obtained by such a configuration, by executing device control using an information processing device such as the terminal 20, it becomes possible to perform device control at the terminal itself without going through a network.

[0159] As explained above, the embodiments may be freely combined, or any of the components of the embodiments may be modified, or any of the components may be omitted from the embodiments. The present disclosure is not limited to the above-described embodiments and modifications, and other forms conceivable within the scope of the technical idea of ​​the present disclosure are also included within the scope of the present disclosure.

[0160] Various aspects of the present disclosure are summarized below as appendices.

[0161] (Appendix 1) The system includes a detection unit that detects disruptive behavior, which is behavior related to disrupting security set in the device, by a user who uses the device in the organization. Information processing device. (Appendix 2) The disruptive behavior includes investigating the security settings of the device. 10. The information processing device according to claim 1. (Appendix 3) The investigating action includes an operation by the user to investigate the security set in the device or an action to investigate an operation log for the security. 3. The information processing device according to claim 2. (Appendix 4) The disruptive behavior includes behavior that circumvents the security set in the device. 4. An information processing device according to any one of claims 1 to 3. (Appendix 5) The avoidance behavior includes a behavior for disabling the security or a behavior for deleting an operation log in which an operation was performed against the security. 5. The information processing device according to claim 4. (Appendix 6) a control unit that performs control based on the detection of the disruptive behavior. 6. An information processing device according to any one of Supplementary Note 1 to Supplementary Note 5. (Appendix 7) The control unit performs the control of notifying the disruptive behavior based on the detection of the disruptive behavior. 7. The information processing device according to claim 6. (Appendix 8) The control unit performs the control to restrict the use of the device used by the user or software of the device based on the detection of the disruptive behavior. 8. The information processing device according to claim 6 or 7. (Appendix 9) an evaluation unit that evaluates the user based on the detection of the disruptive behavior, The control unit controls the storage unit to store the evaluation in association with the user. 9. An information processing device according to any one of Supplementary Note 1 to Supplementary Note 8. (Appendix 10) The evaluation unit evaluates the user based on the disruptive behavior detected at a set time. 10. The information processing device according to claim 9. (Appendix 11) the disruptive behavior includes behavior of investigating the security set in the device and behavior of circumventing the security set in the device; The evaluation unit performs different evaluations when the behavior to be investigated is detected and when the behavior to be avoided is detected. 11. The information processing device according to claim 9 or 10. (Appendix 12) The detection unit detects an operation of the user on a device of the organization that is different from the disruptive behavior, The evaluation unit performs different evaluations when detecting the disruptive behavior and when detecting an operation by the user on a device of the organization that is different from the disruptive behavior. 12. An information processing device according to any one of Supplementary Note 9 to Supplementary Note 11. (Appendix 13) the information processing device is a server, a control unit that controls transmission of information based on the detection of the disruptive behavior to the terminal of the organization. 13. An information processing device according to any one of claims 1 to 12. (Appendix 14) The information processing device is the device used by the user. 13. An information processing device according to any one of claims 1 to 12. (Appendix 15) The security includes security established by the organization to protect the organization's network. 15. An information processing device according to any one of claims 1 to 14. (Appendix 16) The security is set on multiple devices of the organization, including the device. 16. An information processing device according to any one of claims 1 to 15. (Appendix 17) The security includes software-based security. 17. An information processing device according to any one of claims 1 to 16. (Appendix 18) The method includes a step of detecting, by a detection unit, a disruptive behavior by a user who uses a device in the organization, which is a behavior related to disrupting security set in the device. An information processing method for an information processing device. (Appendix 19) On the computer, A process for detecting disruptive behavior, which is a behavior related to disrupting security set in an organization's equipment, by a user who uses the equipment. The program to run. [Industrial Applicability]

[0162] The present disclosure is suitable for information processing, an information processing method, and a program. [Explanation of symbols]

[0163] 10 Server, 11 Control Unit, 12 Input / Output Unit, 13 Display Unit, 14 Communication I / F (Communication Unit), 15 Memory Unit, 16 Clock Unit, 20 Terminal, 21 Control Unit, 22 Communication Unit I / F (Communication Unit), 23 Input / Output Unit, 24 Display Unit, 25 Sound Input Unit, 26 Sound Output Unit, 27 Imaging Unit, 28 Memory Unit, 29A Clock Unit, 29B Position Detection Unit, 30 Network, 111 Detection Unit, 112 Evaluation Unit, 113 Judgment Unit, 114 Device Control Unit, 151 Security Processing Program, 152 User Management Database, 211 Detection Unit, 213 Judgment Unit, 214 Device Control Unit, 281 User Input Log, 282 Terminal Security Processing Program.

Claims

1. a detection unit that detects disruptive behavior, which is behavior related to disruption of security set in a device, by a user who uses the device in the organization; an evaluation unit that evaluates the user based on the detection of the disruptive behavior, the disruptive behavior includes behavior of investigating the security set in the device and behavior of circumventing the security set in the device; The evaluation unit performs different evaluations when the behavior to be investigated is detected and when the behavior to be avoided is detected. Information processing device.

2. The investigating action includes an operation by the user to investigate the security set in the device or an action to investigate an operation log for the security. The information processing device according to claim 1 .

3. The avoidance behavior includes a behavior for disabling the security or a behavior for deleting an operation log in which an operation was performed against the security. The information processing device according to claim 1 .

4. a control unit that performs control based on the detection of the disruptive behavior. The information processing device according to claim 1 .

5. The control unit performs the control of notifying the disruptive behavior based on the detection of the disruptive behavior. The information processing device according to claim 4 .

6. The control unit performs the control to restrict the use of the device used by the user or software of the device based on the detection of the disruptive behavior. The information processing device according to claim 4 .

7. The control unit controls the storage unit to associate the evaluation with the user. The information processing device according to claim 4 .

8. The evaluation unit evaluates the user based on the disruptive behavior detected at a set time. The information processing device according to claim 1 .

9. The detection unit detects an operation of the user on a device of the organization that is different from the disruptive behavior, The evaluation unit performs different evaluations when detecting the disruptive behavior and when detecting an operation by the user on a device of the organization that is different from the disruptive behavior. The information processing device according to claim 1 .

10. the information processing device is a server, a control unit that controls transmission of information based on the detection of the disruptive behavior to the terminal of the organization. The information processing device according to claim 1 .

11. The information processing device is the device used by the user. The information processing device according to claim 1 .

12. The security includes security established by the organization to protect the organization's network. The information processing device according to claim 1 .

13. The security is set on multiple devices of the organization, including the device. The information processing device according to claim 1 .

14. The security includes software-based security. The information processing device according to claim 1 .

15. a step of detecting, by a detection unit, a disruptive behavior by a user who uses a device in the organization, the disruptive behavior being a behavior related to disrupting security set in the device; and evaluating the user by an evaluation unit based on the detection of the disruptive behavior; the disruptive behavior includes behavior of investigating the security set in the device and behavior of circumventing the security set in the device; The step of making the evaluation makes different evaluations when the behavior to be investigated is detected and when the behavior to be avoided is detected. Information processing methods.

16. On the computer, A process of detecting disruptive behavior by a user of an organization's device, which is behavior related to disrupting security set in the device; and performing a process of evaluating the user based on the detection of the disruptive behavior, the disruptive behavior includes behavior of investigating the security set in the device and behavior of circumventing the security set in the device; The evaluation is performed differently when the behavior to be investigated is detected and when the behavior to be avoided is detected. program.

Citation Information

Patent Citations

  • User authority controller, user authority control method and user authority control program

    JP2006178855A

  • Security management server, security management method, and security management program

    JP2019204389A

  • Fraud detection system, fraud detection device, fraud detection method, and non-volatile medium

    WO2012153746A1

  • Information processing device, information processing method, and program

    WO2014045827A1

  • Information processing device, information processing method, and program

    WO2015097889A1