Inspection device, inspection system, and inspection method

The inspection device and system perform immediate vulnerability testing based on device information to quickly identify and mitigate risks, reducing device load and attack exposure.

JP7792754B2Active Publication Date: 2025-12-26OKI ELECTRIC INDUSTRY CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2021034749
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-03-04
Publication Date
2025-12-26
Estimated Expiration
2041-03-04

AI Technical Summary

Technical Problem

Existing vulnerability testing tools take time to initiate after device connection, leaving the device vulnerable to attacks and impose a load on the target device during scanning.

Method used

An inspection device and system that performs immediate vulnerability inspection upon terminal detection, utilizing device information to determine the necessity and scope of testing, thereby reducing the time to discover vulnerabilities and minimizing device load.

Benefits of technology

The solution allows for rapid identification of urgent vulnerabilities by narrowing the scope of testing based on device information, ensuring immediate detection without overburdening the terminal.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007792754000001
    Figure 0007792754000001
  • Figure 0007792754000002
    Figure 0007792754000002
  • Figure 0007792754000003
    Figure 0007792754000003
Patent Text Reader

Abstract

To make it possible to detect vulnerability of a high degree of urgency without overloading a terminal by performing vulnerability inspection right after an inspection object terminal is detected.SOLUTION: An inspection device for inspecting vulnerability of a terminal on a network includes: inspection content information storage means for storing inspection content information that associates apparatus information and vulnerability inspection contents; receiving means for receiving information containing apparatus information of an inspection object terminal; vulnerability inspection means for determining the vulnerability inspection content based on the apparatus information of the inspection object terminal to perform vulnerability inspection; and inspection result generation means for converting vulnerability detection results of the vulnerability inspection means into an output form of inspection output means to output them.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an inspection device, an inspection system, and an inspection method, which can be applied to, for example, remotely monitoring terminals on a network and inspecting vulnerabilities. [Background technology]

[0002] Computer operating systems and software can develop vulnerabilities, which are flaws in information security, due to program malfunctions or design errors. If a computer is used with vulnerabilities remaining, it runs the risk of being used for unauthorized access or being infected with a virus.

[0003] Vulnerabilities like this have become one of the major information security issues for computers connected to the Internet.

[0004] Software for detecting vulnerabilities includes vulnerability testing tools such as those described in Non-Patent Documents 1 to 3. By using vulnerability testing tools to detect and remove vulnerabilities, the risk of virus infection and the like can be reduced. [Prior art documents] [Non-patent literature]

[0005] [Non-Patent Document 1] Nmap.org webpage, Nmap Reference Guide, https: / / nmap.org / , retrieved February 12, 2021 [Non-patent document 2] Tenable Holdings Inc. product webpage, Nessus product page, http: / / www.tenable.com / products / nessus-vulnerability-scanner, retrieved February 12, 2021 [Non-patent document 3] OWASP (Open Web Application Security Project) ZAP index page, https: / / owasp.org / , retrieved February 12, 2021 Summary of the Invention [Problem to be solved by the invention]

[0006] However, because vulnerability testing tools like those mentioned above determine the target device and the test contents before conducting the test, it can take some time for the test to begin after the device is connected to the network, which poses the problem that the device may be vulnerable to attack before the test is completed.

[0007] In addition, because vulnerability testing tools scan the target device, they place a load on the target device, which may affect the processing of the device itself.

[0008] Therefore, there is a need for an inspection device, inspection system, and inspection method that can perform vulnerability inspection immediately after detecting the terminal to be inspected, thereby shortening the time it takes to discover a vulnerable terminal, and that can detect highly urgent vulnerabilities without placing a load on the terminal by narrowing the scope of the vulnerability inspection and determining the order and timing of the inspection based on device information. [Means for solving the problem]

[0009] In order to solve such problems, the first aspect of the present invention is: a new terminal detection device that notifies new connection information including an IP address or a MAC address of a terminal when the terminal is connected to the network; Inspection equipment that checks for vulnerabilities in devices on a network In the inspection system, the inspection device includes a device information storage means for storing information in which the IP address or MAC address of a terminal to be inspected for vulnerability corresponds to the device type, and the IP address or MAC address of which the device type is unknown corresponds to unknown; a vulnerability inspection result storage means for storing the vulnerability inspection result; Inspection target Let's say Device type and brittle Correspondence with vulnerability testing content In addition, the vulnerability inspection contents are associated with the device type unknown and all, which targets vulnerability inspection for all devices. an inspection content information storage means for storing inspection content information; Using the device information storage information, search for the device type corresponding to the IP address or MAC address extracted from the new connection information received from the new terminal inspection device. receiving means for receiving the signal; Using the IP address or MAC address of the terminal to be subjected to vulnerability testing, it is determined whether or not a vulnerability test is necessary for the terminal, depending on whether or not there is a vulnerability test result in the vulnerability test result storage means, and when it is necessary, it refers to the test content information storage means, Determine the vulnerability inspection content based on the device type. inspection Do cormorant Vulnerability testing methods and vulnerability testing results by vulnerability testing methods The vulnerability test result is stored in the vulnerability test result storage unit,and a test result generating means for converting the test result into an output format of the test output means and outputting the converted test result. system .

[0011] No. 2 The present invention provides a testing method for testing vulnerabilities of terminals on a network, comprising: When a new terminal is connected to the network, a new terminal detection device notifies new connection information including the IP address or MAC address of the terminal, and an inspection device that inspects the vulnerability of terminals on the network associates the IP address or MAC address of the terminal to be inspected for vulnerability with the device type, and stores information in which unknown is associated with an IP address or MAC address whose device type is unknown; a vulnerability inspection result storage means that stores the vulnerability inspection result; Inspection target Let's say Device type and brittle Correspondence with vulnerability testing content In addition, the vulnerability inspection contents are associated with the device type unknown and all, which targets vulnerability inspection for all devices. inspection content information storage means for storing inspection content information; and The receiving means is Using the device information storage information, search for the device type corresponding to the IP address or MAC address extracted from the new connection information received from the new terminal inspection device, Vulnerability testing methods include: Using the IP address or MAC address of the terminal to be subjected to vulnerability testing, it is determined whether or not a vulnerability test is necessary for the terminal, depending on whether or not there is a vulnerability test result in the vulnerability test result storage means, and when it is necessary, it refers to the test content information storage means, Determine the vulnerability inspection content based on the device type. inspection and the test result generating means generates the vulnerability test result by the vulnerability test means. The vulnerability test result is stored in the vulnerability test result storage unit, The test output means converts the data into an output format for output. [Effects of the Invention]

[0012] According to the present invention, vulnerability testing can be performed immediately after the detection of a terminal to be tested, shortening the time required to discover a vulnerable terminal, and by narrowing the scope of vulnerability testing and determining the testing order and timing based on device information, it is possible to detect highly urgent vulnerabilities without placing a load on the terminal. [Brief explanation of the drawings]

[0013] [Figure 1] 1 is a configuration diagram showing a configuration of an inspection system according to a first embodiment. [Figure 2] FIG. 2 is an internal configuration diagram showing the internal configuration of the inspection device according to the first embodiment. [Figure 3] FIG. 2 is a diagram illustrating an example of the configuration of device information according to the first embodiment. [Figure 4] 5 is a diagram showing determination information regarding vulnerability testing and testing rankings of vulnerability testing according to the first embodiment; FIG. [Figure 5] FIG. 2 is a configuration diagram showing an example of the configuration of a vulnerability determination result according to the first embodiment. [Figure 6]4 is a flowchart showing the processing operation of the vulnerability testing method according to the first embodiment. [Figure 7] FIG. 10 is a screen diagram showing an example of an output of a vulnerability inspection result according to the first embodiment. [Figure 8] FIG. 10 is an internal configuration diagram showing the internal configuration of an inspection device according to a second embodiment. [Figure 9] FIG. 10 is a diagram illustrating an example of the configuration of device information according to the second embodiment. [Figure 10] 10 is a flowchart showing the processing operation of a vulnerability testing method according to the second embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0014] (A) First embodiment Hereinafter, a first embodiment of an inspection device, an inspection system, and an inspection method according to the present invention will be described in detail with reference to the drawings.

[0015] (A-1) Configuration of the First Embodiment FIG. 1 is a configuration diagram showing the configuration of an inspection system according to the first embodiment.

[0016] In FIG. 1, an inspection system 5 according to the first embodiment includes an inspection device 1, a new terminal detection device 2, and an inspection result output device 3.

[0017] Note that Figure 1 illustrates an example in which the inspection device 1, new terminal detection device 2, and inspection result output device 3 are each configured separately and can be connected via a network NT, but a single physical device may have the functions of the inspection device 1, new terminal detection device 2, and inspection result output device 3.

[0018] The inspection system 5 inspects terminals 4 (4-1 to 4-n; n is a positive integer) that can be connected to a network NT such as the Internet or Ethernet.

[0019] The inspection device 1 has a function of inspecting whether or not a vulnerability exists in the terminal 4 to be inspected. In other words, the inspection device 1 inspects whether or not there is a vulnerability in the OS (Operating System), application software, etc. installed in the terminal 4.

[0020] The inspection device 1 may be implemented by using, for example, a general-purpose computer, and various functions may be realized by installing a processing program (for example, an inspection program) that can be executed by the computer.

[0021] When a terminal 4 is connected to the network NT, the new terminal detection device 2 notifies the inspection device 1 of new connection information if the terminal 4 is determined to be a target for vulnerability testing. The new terminal detection device 2 also has a device identification function that identifies the device type of the terminal 4. Here, device identification is a function that analyzes the traffic behavior of the terminal 4 on the network NT and determines the device type of the terminal 4. Since device identification is a static determination, it does not place a load on the terminal 4. The new terminal detection device 2 may be a function within a device that can manage the connection of terminals 4 within the network NT, such as a gateway.

[0022] The new terminal detection device 2 may be, for example, a general-purpose computer, and various functions may be realized by installing a processing program (for example, an inspection program) that can be executed by the computer.

[0023] The inspection result output device 3 outputs the results of the vulnerability inspection performed by the inspection device 1. For example, the inspection result output device 3 has a browser, and displays the vulnerability inspection results via the browser, and accepts inputs required for displaying the vulnerability inspection results through the operation of an operator.

[0024] The terminals 4 (4-1 to 4-n) are terminals to which an IP (Internet Protocol) address and a MAC (Media Access Control) address are assigned, and are terminals that can be connected to the network NT. The terminal 4 is a terminal to be inspected.

[0025] FIG. 2 is a diagram showing the internal configuration of the inspection device 1 according to the first embodiment.

[0026] In FIG. 2, the inspection device 1 has a data receiving unit 11, a vulnerability inspection unit 12, a scan data generation unit 13, an inspection result generation unit 14, a control unit 15, a device information storage unit 16, a judgment information storage unit 17, and a vulnerability inspection result storage unit 18.

[0027] The data receiving unit 11 receives new connection information of the terminal 4 from the new terminal detection device 2. The data receiving unit 11 also receives the results of the scan performed on the terminal 4 by the inspection device 1.

[0028] The vulnerability inspection unit 12 receives the vulnerability information of the terminal 4 from the data receiving unit 11. New connection information When the vulnerability inspection unit 12 receives the vulnerability information from the new terminal detection device 2, the vulnerability inspection unit 12 determines the vulnerability inspection content to be used for scanning the terminal 4 to be inspected, and provides the vulnerability inspection content to the scan data generation unit 13. New connection information The vulnerability inspection content is determined using the information stored in the device information storage unit 16, the determination information storage unit 17, and the vulnerability inspection result storage unit 18. The types of scans that the vulnerability inspection unit 12 performs on the terminal 4 include, for example, a port scan and a password scan.

[0029] Furthermore, the vulnerability inspection unit 12 acquires the scan results of the terminal 4 that has been scanned from the data receiving unit 11, and provides the vulnerability inspection results based on the scan results of the terminal 4 to the inspection result generating unit .

[0030] The scan data generation unit 13 generates scan data for the vulnerability test content determined by the vulnerability test unit 12 using the data in the determination information storage unit 17, and transmits the scan data to the terminal 4 to be tested.

[0031] The inspection result generation unit 14 has the function of converting the vulnerability inspection results obtained from the vulnerability inspection unit 12, generating results in a format that can be displayed on the inspection result output device 3, and transmitting them to the inspection result output device 3.

[0032] The device information storage unit 16 stores device information of the terminal 4 that is connected to the network NT and is to be subjected to vulnerability testing.

[0033] Fig. 3 is a diagram showing an example of the configuration of device information according to the first embodiment. As shown in Fig. 3, the device information stored in the device information storage unit 16 is information having items such as an IP address, a MAC address, and a device type. The device type is information used to determine the content of a vulnerability test. The device type is set in advance for each device to be subjected to a vulnerability test, but after the vulnerability test results are obtained, the device type of the terminal on which the vulnerability test was performed may be automatically added and set.

[0034] The determination information storage unit 17 stores determination information for determining the test contents of the vulnerability test, as well as the test order, etc. The method for determining the test contents of the vulnerability test may be determined according to the type of scan method (test method), such as a password list for a password scan or a port to be tested for a port scan.

[0035] FIG. 4A is a diagram showing the structure of the determination information of the vulnerability test content according to the first embodiment, and FIG. 4B is a diagram showing the test order of the vulnerability tests.

[0036] As shown in Fig. 4(A), the vulnerability test content determination information includes items such as "test ID," "device type," "test type," "test command," "test file name," and "regular result output file" for identifying the test content of the vulnerability test. In other words, the vulnerability test content determination information is information that associates device information with vulnerability test content. The device information and vulnerability test content may be associated in advance, or may be changed as appropriate by repeatedly performing vulnerability tests.

[0037] For example, when the type of device to be inspected is specified, all of the corresponding "inspection IDs" are returned. Also, when an "inspection ID" is specified from the returned inspection IDs, it is possible to know what to inspect from the "inspection type," and further to obtain the execution format of the inspection from the "inspection command" and "inspection file name." It is also possible to compare the vulnerability inspection results with the official result output file and use this as a reference for vulnerability assessment.

[0038] Also, "Test ID: 2" in Figure 4(A) is the test content common to all devices ("Device Type: ALL"). "Test ID: 3" and "Test ID: 5" are test contents for PCs, and "Test ID: 6" is test content for smart taps. In this way, it is possible to perform tests using different port numbers for each device type, or to perform more detailed tests for PCs than for smart taps. For "Test File Name," if you are performing a port scan, you specify the port number to be scanned; if you are performing a password scan, you specify a file created in advance that contains a password list, and specify this as the test file name.

[0039] Figure 4(B) shows the preset test order. For example, if multiple tests need to be performed, you can know the order in which to perform the tests. "Priority: 1" indicates the highest priority. If the priority is low, the test may be omitted depending on the test results of the test with the higher priority.

[0040] The vulnerability inspection result storage unit 18 stores the vulnerability inspection results inspected by the vulnerability inspection unit 12 .

[0041] Fig. 5 is a configuration diagram showing an example of the configuration of a vulnerability determination result according to the first embodiment. In Fig. 5, the vulnerability determination result stores items such as an "inspection ID," a "terminal ID" indicating, for example, an IP address or MAC address, "inspection time," a "port" indicating a port scan result, a "password" indicating a password scan result, and a "log file name" for each vulnerability determination. For example, if a new vulnerability inspection is performed on terminal 4 with the same terminal ID, the new vulnerability result is overwritten over the previous (past) vulnerability result, or a new inspection ID is assigned and added.

[0042] The control unit 15 controls various functions of the inspection device 1 that perform vulnerability inspection. The control unit 15 has a function of determining the timing to start a vulnerability inspection investigation, and when the timing to start a vulnerability inspection arrives, issuing an inspection execution request to the vulnerability inspection unit 12. In addition, the control unit 15 may acquire the CPU usage rate and load of the terminal 4, and if it determines that the CPU load is high using a threshold, it may delay the timing to start the vulnerability inspection for that terminal 4.

[0043] (A-2) Operation of the First Embodiment Next, the operation of the vulnerability inspection method performed by the inspection system 5 according to the first embodiment will be described in detail with reference to the drawings.

[0044] FIG. 6 is a flowchart showing the processing operations of the vulnerability testing method according to the first embodiment.

[0045] [S101] The new terminal detection device 2 monitors the traffic status of the network NT and detects a newly connected terminal 4 (S101). Then, when the new terminal detection device 2 detects a newly connected terminal 4, the new terminal detection device 2 transmits new connection information to the inspection device 1. Here, the time of new connection refers to the time when the new terminal detection device 2 determines that the terminal 4 in question has started up and connected to the network NT.

[0046] If the new terminal detection device 2 can identify the device other than at the time of a new connection, the new terminal detection device 2 transmits device identification information to the inspection device 1. Furthermore, other than at the time of a new connection, the new terminal detection device 2 may also transmit the terminal information of the terminal 4 when a predetermined time has elapsed since the previous transmission of new connection information.

[0047] [S102] In the inspection device 1, when the data receiving unit 11 receives new connection information from the new terminal detection device 2, the data receiving unit 11 receives the IP address or MAC address included in the new connection information. Su Extract (S102).

[0048] [S103] The data receiving unit 11 uses the IP address or MAC address extracted from the new connection information to search the device information storage unit 16 for device information corresponding to the IP address or MAC address (S103). For example, assume that the IP address extracted by the data receiving unit 11 from the new connection information is "1.1.1.1." In this case, the device information storage unit 16 shown in FIG. 3 is searched for device information of "ID:1" corresponding to the IP address "1.1.1.1."

[0049] [S104] The vulnerability testing unit 12 uses the new connection information from the data receiving unit 11, the data in the device information storage unit 16, and the data in the vulnerability testing result storage unit 18 to determine whether the terminal 4 requires vulnerability testing (S104).

[0050] For example, the vulnerability inspection unit 12 uses the IP address or MAC address included in the new connection information to determine whether or not there is a vulnerability inspection result from the vulnerability inspection result storage unit 18 in Fig. 5. If there is no vulnerability inspection result, a vulnerability inspection has not been performed on the terminal 4, and the vulnerability inspection unit 12 determines that a vulnerability inspection is necessary. For example, assume that the IP address in the new connection information is "5.5.5.5." In this case, the vulnerability inspection unit 12 refers to the vulnerability inspection result storage unit 18 in Fig. 5 and determines that there is no vulnerability inspection result for the IP address "5.5.5.5," and therefore determines that the IP address "5.5.5.5" requires a vulnerability inspection.

[0051] Furthermore, for example, if a predetermined time or more has passed since the previous vulnerability test, the vulnerability test unit 12 may determine that a vulnerability test is necessary. For example, if the current time is "2020 / 9 / 21 00:00:00" and more than 24 hours have passed since the previous test, a vulnerability test is necessary. In this case, the vulnerability test unit 12 refers to the vulnerability test result storage unit 18 in FIG. 5 and determines that the IP address "4.4.4.4" requires a vulnerability test because more than 24 hours have passed since the previous vulnerability test for the IP address "4.4.4.4."

[0052] As another method, if the device identification result differs from the stored device information, the vulnerability inspection unit 12 may determine that a vulnerability inspection is necessary.

[0053] The vulnerability testing unit 12 may determine whether or not a vulnerability test is necessary by using all or any combination of the three determination methods described above. For example, when all of the three determination methods described above are used, the vulnerability testing unit 12 targets two IP addresses for vulnerability testing: IP address "4.4.4.4" for which more than 24 hours have passed since the previous test, and IP address "5.5.5.5" for which no vulnerability test results exist.

[0054] 5, if the vulnerability test result is already NG, the determination of the vulnerability test target may be changed. In other words, the contents of the test for the vulnerability to be tested may be determined based on the result of the vulnerability test performed by the vulnerability tester 12, and that vulnerability test may then be performed. For example, if an unauthorized port is open, an additional test related to that port may be performed.

[0055] [S105] If a vulnerability test is necessary (S104 / YES), the vulnerability test unit 12 refers to the determination information in the determination information storage unit 17, acquires a list of vulnerability test contents, and determines the vulnerability test contents (S105).

[0056] For example, assume that terminal 4 with IP address "1.1.1.1" is the target of vulnerability testing. Vulnerability testing unit 12 searches for the device type of the terminal to be "Device Type: PC" by referring to device information storage unit 16 in Fig. 3. In this case, vulnerability testing unit 12 searches by specifying "Device Type: PC" in determination information storage unit 17 in Fig. 4, and obtains a vulnerability test content list including "Test ID: 2," "Test ID: 3," and "Test ID: 5" that correspond to "Device Type: PC," and determines the target test from this list.

[0057] [S106] Next, the vulnerability testing unit 12 refers to the testing order in the determination information storage unit 17, extracts the order of the target tests, and determines the timing to start testing (S106).

[0058] For example, in the example of S105, a vulnerability test content list of "Test ID: 2," "Test ID: 3," and "Test ID: 5" is obtained. In this case, the vulnerability test unit 12 selects the test with the highest priority, "Test ID: 5," by referring to the test order in FIG. 4(B). If there is a test ID that has not been selected, when the process returns to S104 in the next vulnerability test, it determines that a vulnerability test is necessary (S104 / YES), and selects the test IDs that have not been selected in order of priority. In other words, if "Test ID: 5" is selected in the first round, "Test ID: 2," which has the next highest priority, is selected in the second round, and "Test ID: 3" is selected in the third round.

[0059] [S107] The vulnerability inspection unit 12 performs a vulnerability inspection (S107) using the vulnerability inspection content determined in S105 and at the inspection start timing determined in S106. The vulnerability inspection unit 12 issues a vulnerability inspection request to the terminal 4, receives a vulnerability inspection response from the terminal 4, and inspects for vulnerabilities.

[0060] For example, when the vulnerability inspection unit 12 performs a vulnerability inspection with "inspection ID: 5" on the terminal 4 with "IP address: 1.1.1.1", the vulnerability inspection unit 12 executes "inspection command: bbb" using "inspection file name: Port02" from the inspection information in the determination information storage unit 17 of FIG. 4(A). For example, a vulnerability inspection request is sent to the terminal 4. The response from the terminal 4 is input to the inspection command via the receiving unit, and the presence or absence of a vulnerability is determined. The vulnerability inspection result is written to the vulnerability inspection result storage unit 18.

[0061] [S108] When the vulnerability inspection is completed, the inspection result generating unit 14 generates a vulnerability inspection result for the inspection result output device 3 based on the inspection result from the vulnerability inspection unit 12 (S108).

[0062] For example, the test result generating unit 14 converts the test results into a format such as HTML (HyperText Markup Language) so that the test results can be displayed on the test result output device 3.

[0063] For example, the inspection result generating unit 14 displays the relevant part of the command output as a result of whether or not there is a vulnerability, or generates a result of whether or not there is a vulnerability by comparing it with the contents of the regular result output file.

[0064] [S109] When the inspection result generating unit 14 generates the vulnerability inspection result, the inspection result generating unit 14 transmits the vulnerability inspection result to the inspection result output device 3. Then, the inspection result output device 3 outputs the vulnerability inspection result (S109).

[0065] The inspection result generating unit 14 records the vulnerability inspection results as a log file. The inspection result generating unit 14 may also control the terminal 4 depending on the inspection results.

[0066] Figure 7 is a screen diagram showing an example of the output of vulnerability test results. Figure 7(A) is a screen diagram showing the results when normal, and Figure 7(B) is a screen diagram showing the results when abnormal. As shown in Figures 7(A) and 7(B), the following are displayed: "IP" indicating the IP address of the terminal being tested, "port" indicating the port scan result, "password" indicating the password scan result, "log" indicating the log file name, and "time" indicating the time of the test. The port scan results and password scan results may not be displayed if the test is omitted. Clicking on the log file name will display the log file.

[0067] The vulnerability inspection result is displayed on the inspection result output device 3, and if vulnerability inspection is to be continued, the process returns to S104 and the process is repeated.

[0068] [S110] If no vulnerability testing is required and all vulnerability testing has been completed (S104 / NO), the testing device 1 transmits a message to the testing result output device 3 indicating that all vulnerability testing has been completed, and displays the results of the vulnerability testing (S110).

[0069] (A-3) Effects of the First Embodiment As described above, according to the first embodiment, vulnerability testing is performed immediately after a new terminal is detected, so when a terminal is newly connected to the network, the time required to discover a vulnerable terminal can be reduced compared to conventional technology.

[0070] Furthermore, according to the first embodiment, the results of static processing such as new terminal detection and device identification are used to narrow the scope of vulnerability testing and determine the testing order and timing, thereby achieving the effect of quickly discovering highly urgent vulnerabilities without placing a load on the terminal.

[0071] (B) Second embodiment Next, a second embodiment of an inspection device, an inspection system, and an inspection method according to the present invention will be described in detail with reference to the drawings.

[0072] (B-1) Configuration of the second embodiment FIG. 8 is a diagram showing the internal configuration of an inspection device 1A according to the second embodiment.

[0073] 8, the inspection device 1A includes a data receiving unit 21, an unauthorized terminal inspection unit 22, an inspection result generating unit 24, a control unit 25, a device information storage unit 26, a determination information storage unit 27, and a vulnerability inspection result storage unit .

[0074] 8, an inspection device 1A of the second embodiment is provided with an unauthorized terminal inspection unit 22 instead of the vulnerability inspection unit 12 of FIG.

[0075] The unauthorized terminal inspection unit 22 has a function of inspecting the terminal 4 connected to the network NT for unauthorized connections such as unauthorized terminals, terminals to which unauthorized user accounts have been added, and / or terminals to which unauthorized software has been installed.

[0076] The device information storage unit 26 stores device information in the same way as in the first embodiment, but stores device information with an additional item for device abnormality score added to the device information items.

[0077] Fig. 9 is a diagram showing an example of the configuration of device information according to the second embodiment. As shown in Fig. 9, the device information according to the second embodiment has an additional item of "device abnormality score" in addition to the items in Fig. 3.

[0078] The device abnormality score is expressed as a score value evaluated on a scale of 1 to 10, for example, with the higher the score value, the higher the probability of it being an unauthorized terminal. The device abnormality score is generated by the new terminal detection device 2 or the unauthorized terminal inspection unit 22.

[0079] Furthermore, the device information storage unit 26, the determination information storage unit 27, and the vulnerability test result storage unit 28 can also be referenced by the new terminal detection device 2.

[0080] (B-2) Operation of the Second Embodiment Next, the operation of the process of the vulnerability inspection method by the inspection system 5 according to the second embodiment will be described in detail with reference to the drawings.

[0081] FIG. 10 is a flowchart showing the processing operations of the vulnerability testing method according to the second embodiment.

[0082] Here, as will be described later, the inspection device 1A starts processing when it receives new connection information. However, the inspection device 1A may independently monitor not only the timing of receiving new connection information but also whether a predetermined time has passed since the result of the previous vulnerability inspection, and determine the need for an unauthorized terminal inspection.

[0083] [S201] As in the first embodiment, the new terminal detection device 2 monitors the traffic status of the network NT, detects a newly connected terminal 4 (S201), and transmits new connection information to the inspection device 1 A. Furthermore, if the new terminal detection device 2 can identify the device of the newly connected terminal 4, it also transmits the device identification information to the inspection device 1 A.

[0084] In the second embodiment, the new terminal detection device 2 includes the value of the abnormality score of the device in the message and transmits it to the inspection device 1A.

[0085] Here, an example is given of a method for evaluating an anomaly score by the new terminal detection device 2. The new terminal detection device 2 can refer to the device information storage unit 16 of the inspection device 1A. The new terminal detection device 2 can also identify the device type of the newly connected terminal 4. Therefore, for example, if the new terminal detection device 2 looks at the information in the device information storage unit 26 and finds that the device of the newly connected terminal 4 is not stored in the device information storage unit 26, it will increase the value of the anomaly score. The value of the anomaly score when the device model is new may be determined in advance.

[0086] As another method, the new terminal detection device 2 can refer to the vulnerability test result storage unit 28 of the testing device 1A, so when an abnormality occurs within the same network NT as the network NT that was determined to be vulnerable in a previous vulnerability test, the abnormality score value can be increased.

[0087] The new terminal detection device 2 can refer to the device information storage unit 26, the determination information storage unit 27, and the vulnerability inspection result storage unit 28. Therefore, even if a predetermined time has passed since the previous unauthorized terminal inspection, the new terminal detection device 2 may be configured to transmit new connection information to the inspection device 1. This allows the inspection device 1A to determine the need for an unauthorized terminal inspection.

[0088] Furthermore, as described above, the inspection device 1A can also independently monitor whether a predetermined time has passed since the previous vulnerability inspection result, and determine the need for an unauthorized terminal inspection.

[0089] [S202] In the inspection device 1, the data receiving unit 21 waits for reception of new connection information, and when the new connection information is received, the data receiving unit 21 extracts the IP address or MAC address of the newly connected terminal 4 (S202).

[0090] [S203] The data receiving unit 21 uses the IP address or MAC address extracted from the new connection information to search the device information storage unit 26 for device information corresponding to the IP address or MAC address (S203).

[0091] [S204] The unauthorized terminal inspection unit 22 extracts an abnormality score from the received new connection information and determines whether or not an unauthorized terminal inspection is necessary based on the value of the abnormality score (S204). If it is determined that an unauthorized terminal inspection is necessary, the process proceeds to S205, and if it is determined that an unauthorized terminal inspection is not necessary, the process proceeds to S206.

[0092] For example, if the abnormality score on a 10-point scale is 6 or higher, the unauthorized terminal inspection unit 22 may determine that an unauthorized terminal inspection is necessary. In other words, when the abnormality score is equal to or higher than a threshold value, it may be determined that an unauthorized terminal inspection is necessary.

[0093] [S205] If it is determined that an unauthorized terminal check is necessary (S204 / YES), the unauthorized terminal check unit 22 checks for vulnerability of the newly connected terminal 4 (S205).

[0094] In the second embodiment, it is assumed that a vulnerability check is performed to determine whether the terminal 4 is an unauthorized terminal.

[0095] In the first embodiment, the vulnerability test was carried out after determining the vulnerability test content and timing, but in the second embodiment, the unauthorized terminal test is considered to have the highest test priority, and as soon as it is determined in S204 that an unauthorized terminal test is necessary, the unauthorized terminal test unit 22 immediately carries out a vulnerability test.

[0096] Here, we will explain an example of a method for determining whether a terminal is unauthorized by the unauthorized terminal inspection unit 22. When determining whether a terminal is unauthorized, for example, if an unauthorized terminal or a port used by an unauthorized OS or unauthorized software is detected to be open by a port scan, or if an unauthorized user is discovered by a password scan or the like, the terminal is deemed to be unauthorized.

[0097] Furthermore, for example, a terminal may be deemed to be an unauthorized terminal if the result of the vulnerability test differs from the results of other terminals already present in the network.

[0098] For example, at a base where only devices with Windows® or Linux® operating systems are allowed to connect, a device may be deemed unauthorized if the results of the OS scan are not similar to those of existing devices. For example, if the results of an OS scan using an existing tool do not provide accurate OS version information, a device may be deemed unauthorized if the strings in the scan results indicate that the OS is clearly different from that of other devices already on the network. An anomaly score is determined based on the degree of unauthorizedness.

[0099] The unauthorized terminal inspection unit 22 performs a vulnerability inspection and determines whether or not the terminal 4 is an unauthorized terminal. If the terminal 4 is suspected to be an unauthorized terminal, the unauthorized terminal inspection unit 22 enters a high score value in the "abnormality score" in the device information in Figure 9(A), and enters a low score value if the terminal is highly unlikely to be an unauthorized terminal, and updates the information in the device information storage unit 26.

[0100] Furthermore, after the vulnerability inspection, the unauthorized terminal inspection unit 22 also updates the information in the vulnerability inspection result storage unit 28.

[0101] [S206] When the vulnerability inspection is completed, the inspection result generation unit 24 generates an unauthorized terminal determination result for the inspection result output device 3 based on the inspection result from the unauthorized terminal inspection unit 22. Furthermore, when it is determined in S204 that an unauthorized terminal inspection is unnecessary (S204 / NO), the inspection result generation unit 24 generates an unauthorized terminal determination result including that fact (S206).

[0102] [S207] When the inspection result generation unit 24 generates the vulnerability inspection result, the inspection result generation unit 24 transmits the vulnerability inspection result to the inspection result output device 3. Then, the inspection result output device 3 outputs the vulnerability inspection result (S207). In the second embodiment, the inspection result output device 3 also displays the anomaly score value, the details of the fraud, etc. for the device.

[0103] (B-3) Effects of the Second Embodiment As described above, the second embodiment provides the following advantages in addition to the advantages of the first embodiment.

[0104] According to the second embodiment, the urgency of the unauthorized terminal inspection is checked based on the device anomaly score and the device identification result, and a vulnerability inspection is performed. This has the effect of making it possible to predict how an unauthorized terminal will behave immediately after connecting.

[0105] (C) Other embodiments As described above, various modified embodiments have been mentioned in the first and second embodiments, but the present invention can also be applied to the following modified embodiments.

[0106] (C-1) In the first and second embodiments described above, the inspection device 1 and the inspection device 1A may be provided with the functions of both the inspection device 1 and the inspection device 1A, which are described as operating independently. In other words, the inspection device may be provided with the various functions of the inspection device 1 in Fig. 2 and the various functions of the inspection device 1A in Fig. 8.

[0107] (C-2) The items of device information exemplified in FIG. 3 or FIG. 9, the judgment information and test order information exemplified in FIG. 4, and the vulnerability test result information exemplified in FIG. 5 are not limited to these. Other items may be added to these items, or only some of these items may be included. In the above-described embodiment, the test range and test order were determined based on the device type. However, for example, the control unit 15 may determine the test range, test order, and test load based on load information such as the CPU usage rate of the terminal. For example, the control unit 15 may delay the test order when the CPU usage rate of the terminal is high and the load is high. Alternatively, for example, the control unit 15 may reduce the test load for a smart tap with low CPU performance. [Explanation of symbols]

[0108] 1 and 1A... inspection device, 2... new terminal detection device, 3... inspection result output device, 4... terminal, 5... inspection system, 11 and 21...data receiving unit, 12...vulnerability inspection unit, 22...unauthorized terminal inspection unit, 13...scan data generation unit, 14 and 24...inspection result generation unit, 15 and 25...control unit, 16 and 26...device information storage unit, 17 and 27...determination information storage unit, 18 and 28...vulnerability inspection result storage unit.

Claims

1. A new terminal detection device that notifies new connection information including an IP address or a MAC address of a new terminal when the new terminal is connected to a network; an inspection device that inspects the vulnerability of the terminal on the network; In an inspection system comprising: The inspection device a device information storage means for storing information in which an IP address or a MAC address of a terminal to be subjected to vulnerability testing is associated with a device type, and an IP address or a MAC address whose device type is unknown is associated with "unknown"; a vulnerability test result storage means for storing the vulnerability test result; an inspection content information storage means for associating the device type of the terminal to be inspected for vulnerability with the vulnerability inspection content, and for storing inspection content information in which the vulnerability inspection content is associated with each of the device types "unknown" and "all" which specifies that all devices are subject to vulnerability inspection; a receiving means for searching for a device type corresponding to an IP address or a MAC address extracted from the new connection information received from the new terminal inspection device, using the device information storage information; a vulnerability testing means for determining whether a vulnerability test is necessary for the terminal by using an IP address or a MAC address of the terminal to be the target of the vulnerability test and depending on whether a vulnerability test result is stored in the vulnerability test result storage means, and when a vulnerability test is necessary, for determining the vulnerability test content based on the device type by referring to the test content information storage means and performing the vulnerability test; an inspection result generating means for storing the vulnerability inspection result by the vulnerability inspection means in the vulnerability inspection result storage unit and converting it into an output format of the inspection output means and outputting it; have An inspection system characterized by:

2. The vulnerability inspection contents are prioritized according to the device type and / or inspection type, 2. The inspection system according to claim 1, wherein the vulnerability inspection means performs vulnerability inspections in accordance with the priority order.

3. When there are a plurality of vulnerability inspection contents based on the device type of the terminal, referring to the inspection content information storage means, The inspection system described in claim 2, characterized in that the vulnerability inspection means performs vulnerability inspection of vulnerability inspection contents selected in accordance with the priority set for the vulnerability inspection contents, and in the next vulnerability inspection process, selects vulnerability inspection contents that were not selected in accordance with the priority and performs vulnerability inspection on them.

4. In a testing method for testing vulnerabilities of terminals on a network, When a new terminal is connected to the network, the new terminal detection device notifies the new connection information including the IP address or MAC address of the terminal; An inspection device that inspects vulnerabilities of the terminal on the network, a device information storage means for storing information in which an IP address or a MAC address of a terminal to be subjected to vulnerability testing is associated with a device type, and an IP address or a MAC address whose device type is unknown is associated with "unknown"; a vulnerability test result storage means for storing the vulnerability test result; an inspection content information storage means for associating the device type of the terminal to be inspected for vulnerability with the vulnerability inspection content, and for storing inspection content information in which the vulnerability inspection content is associated with each of the device types "unknown" and "all" which specifies that all devices are to be inspected for vulnerability; and a receiving means, using the device information storage information, searching for a device type corresponding to the IP address or MAC address extracted from the new connection information received from the new terminal inspection device; a vulnerability testing means, using an IP address or a MAC address of the terminal to be subjected to the vulnerability testing, determining whether a vulnerability test is necessary for the terminal depending on whether a vulnerability test result is stored in the vulnerability test result storage means, and when necessary, referring to the test content information storage means, determining the vulnerability test content based on the device type, and performing the vulnerability test; The test result generating means stores the vulnerability test result by the vulnerability test means in the vulnerability test result storage unit, and converts the result into an output format of the test output means and outputs it. An inspection method characterized by:

Citation Information

Patent Citations

  • Network connection management system

    JP2006018766A

  • System, method and program for network connection control

    JP2006268544A

  • Scan processing device, scan processing method, computer program, and scan processing system

    JP2019207593A