Information processing device, information processing method, and program
The information processing device addresses the challenge of determining the appropriateness of password-protected files in emails by storing, decompressing, and analyzing them, thereby enhancing email security and reducing spoofing risks.
Patent Information
- Application Number
- JP2023100746
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2023-06-20
- Publication Date
- 2026-01-20
- Estimated Expiration
- 2038-03-15
AI Technical Summary
Existing systems fail to determine the appropriateness of password-protected compressed files attached to emails, making it difficult to identify spoofed or inappropriate emails.
An information processing device that stores password-protected compressed files in a temporary area, decompresses them with input passwords, and determines their appropriateness before sending to the recipient, with features like whitelists, blacklists, and automated password handling.
Enables quick determination of the appropriateness of password-protected files attached to emails, reducing the risk of spoofing and enhancing email security by automating the decompression and analysis process.
Smart Images

Figure 0007802727000001 
Figure 0007802727000002 
Figure 0007802727000003
Abstract
Description
[Technical Field]
[0001] The present invention relates to an information processing device, an information processing method, and a program for processing compressed files. [Background technology]
[0002] Since there has been a risk of virus infection through received e-mails, it has been proposed to filter such e-mails. For example, Patent Document 1 discloses a method for dealing with so-called "spoofed" e-mails, and discloses the use of a webmail server that stores e-mails addressed to a user and determines whether the e-mails addressed to the user are spoofed e-mails.
[0003] If a password-protected compressed file is attached to an email, it is not possible to determine the appropriateness of the file. For this reason, it is not possible to use compressed files to determine whether the sender is spoofed or other inappropriate email. [Prior art documents] [Patent documents]
[0004] [Patent Document 1] Japanese Patent Application Laid-Open No. 2012-78922 Summary of the Invention [Problem to be solved by the invention]
[0005] The present invention provides an information processing device, a program, a recording medium, and an information processing method that can determine whether a compressed file attached to an e-mail and for which a password is set is appropriate. [Means for solving the problem]
[0006] The information processing device according to the present invention comprises: a separation notification unit that, when a first compressed file with a password set is attached to a received email, stores the email in a temporary save area and notifies a recipient of the email that the email will be stored in the temporary save area or that the email has been stored; a decompression unit that decompresses the first compressed file by inputting the password and extracts the first file; a determination processing unit that determines whether the first file is appropriate for the first file; may also be provided.
[0007] In the information processing device according to the present invention, The judgment processing unit may send the email to the recipient if it determines that the first file is appropriate, and may perform a predetermined action if it determines that the first file is inappropriate, and then send the email with the action performed to the recipient.
[0008] In the information processing device according to the present invention, When the determination processing unit sends the email to the recipient, the determination processing unit may attach the first compressed file after the password has been reset.
[0009] In the information processing device according to the present invention, When the determination processing unit sends the email to the recipient, the determination processing unit may send the first compressed file with the password unlocked to the recipient.
[0010] The information processing device according to the present invention comprises: Further comprising a storage unit for storing the permitted transmission source, If the sender is an authorized sender, the judgment processing unit may send the email to the recipient without determining whether the first file in the first compressed file is appropriate, even if the email has a first compressed file attached that has a password set.
[0011] In the information processing device according to the present invention, The determination processing unit may delete the first compressed file that was not decompressed by the decompression unit and then send the email to the recipient.
[0012] In the information processing device according to the present invention, If the (n+1)th compressed file is stored in the nth compressed file (where "n" is an integer equal to or greater than 1) decompressed by the decompression unit, the determination processing unit notifies the recipient of the email that the (n+1)th compressed file exists; the decompression unit decompresses the (n+1)th compressed file in response to the input of the password, and extracts the (n+1)th file; The determination processing unit may determine whether the (n+1)th file is appropriate for the (n+1)th file.
[0013] In the information processing device according to the present invention, When the nth compressed file (where "n" is an integer equal to or greater than 1) decompressed by the decompression unit contains the (n+1)th compressed file, the decompression unit may automatically input the password.
[0014] In the information processing device according to the present invention, If the (n+1) compressed file is not decompressed using the password automatically entered by the decompression unit, the judgment processing unit may notify the recipient of the email that the (n+1) compressed file exists.
[0015] In the information processing device according to the present invention, When a plurality of n+1-th compressed files are stored in the n-th compressed file decompressed by the decompression unit, the judgment processing unit may judge the appropriateness of the n+1-th file in the n+1-th compressed file that has been decompressed, and delete the n+1-th compressed file that has not been decompressed.
[0016] In the information processing device according to the present invention, An upper limit on the number of layers that can be decompressed by the decompression unit is set in advance, and if the upper limit is exceeded, the decompression unit does not need to decompress the compressed file.
[0017] The information processing method according to the present invention comprises: When a first compressed file with a password set is attached to a received email, storing the email in a temporary save area and notifying a recipient of the email that the email will be stored in the temporary save area or that it has been stored; decompressing the first compressed file by inputting the password and extracting the first file; determining whether the first file is appropriate for the first file; may also be provided.
[0018] The program according to the present invention comprises: A program for causing an information processing device to execute an information processing method, The information processing device includes: When a first compressed file with a password set is attached to a received email, storing the email in a temporary save area and notifying a recipient of the email that the email will be stored in the temporary save area or that it has been stored; decompressing the first compressed file by inputting the password and extracting the first file; determining whether the first file is appropriate for the first file; An information processing method comprising the steps of:
[0019] The recording medium according to the present invention comprises: The above-mentioned program may be recorded. [Effects of the Invention]
[0020] In the present invention, when a compressed file with a password set is attached to a received email, the email is stored in a temporary save area, and the recipient of the email is notified that the email will be stored in the temporary save area or that it has been stored.If a mode is adopted in which the compressed file is decompressed by entering a password to extract the file and a determination is made as to whether the file is appropriate, the appropriateness of a file stored in a compressed file with a password set can be quickly determined. [Brief explanation of the drawings]
[0021] [Figure 1] FIG. 2 is a diagram showing an example of a processing flow according to an embodiment of the present invention. [Figure 2] 1 is a block diagram of an information processing device that can be used in an embodiment of the present invention. [Figure 3] 10A and 10B are diagrams showing ways of disguising link destination information that can be used in an embodiment of the present invention. [Figure 4] FIG. 10 is a diagram showing an example of a notification screen that can be used in the embodiment of the present invention. [Figure 5] FIG. 10 is a diagram showing an example of a password entry screen that can be used in the embodiment of the present invention. [Figure 6] FIG. 2 is a diagram showing an example of a hierarchy of a compressed file that can be used in an embodiment of the present invention. [Figure 7] FIG. 10 is a diagram showing an example of processing content when a compressed file that can be used in an embodiment of the present invention is decompressed. DETAILED DESCRIPTION OF THE INVENTION
[0022] Embodiment "composition" Hereinafter, an embodiment of an information processing device according to the present invention will be described with reference to the drawings. In this embodiment, "or" also means "and." That is, in this embodiment, A or B means either A, B, or A and B.
[0023] The information processing device of this embodiment may be composed of one device, or may be composed of multiple devices. When the information processing device is composed of multiple devices, the devices constituting the information processing device may be installed in different rooms or different locations, and part of the information processing device and the rest of the information processing device may be located in remote locations.
[0024] The information processing device of this embodiment may be installed in an internal network, in a boundary (DMZ: DeMilitarized Zone) connecting an internal network and an external network, or in an external network. The information processing device may be an MTA (Message Transfer Agent).
[0025] As shown in FIG. 2, the information processing device of this embodiment may include a storage unit 10 including a temporary save area; a separation notification unit 20 (see (2) in FIG. 1) that stores a received email with a password-set first compressed file attached to the email in the temporary save area and notifies the recipient of the email that the email will be or has been stored in the temporary save area; a decompression unit 30 that decompresses the first compressed file and extracts the first file upon input of a password; and a determination processing unit 40 that determines whether the first file is appropriate for the first file. The password for the first compressed file may be input by the recipient of the notified email (see (3) in FIG. 1). When a forgery determination is performed to determine whether the file is forged, the temporary save may be released and the file may be moved from the temporary save area to another area. A ZIP file may be used as the compressed file. The recipient of the email may be, for example, the email address listed in the "Envelope To" field.
[0026] If it is unknown whether a password is set for the first compressed file, the determination processing unit 40 may determine, to the extent possible, whether the sender is appropriate. Note that the manner in which the determination processing unit 40 determines, to the extent possible, whether the sender is appropriate will be described later. The determination processing unit 40 may also determine whether an uncompressed file (normal file) is appropriate. A first compressed file or an uncompressed file (normal file) that is determined to be inappropriate by the determination processing unit 40 may be deleted by the determination processing unit 40.
[0027] 2, the storage unit 10 may be provided with a first storage unit 11 for storing received e-mails, and a second storage unit 12 isolated from the first storage unit 11. When the determination processing unit 40 determines that the sender of the e-mail is inappropriate, such as when it determines that the sender information of the e-mail is forged, the e-mail may be stored in the second storage unit 12, such as a dedicated directory.
[0028] The email separated by the separation notification unit 20 and stored in the temporary save area may be treated as an email waiting for inspection and may be in a state of waiting for password entry. In this case, the email and the file such as the first compressed file may be stored without being separated. If such an embodiment is adopted, it is advantageous in that it saves the effort of associating the email and the file attached to the email later. However, the embodiment is not limited to this, and the file such as the first compressed file may be stored separated from the email.
[0029] The notification from the separation notification unit 20 to the recipient of the e-mail may be sent immediately after the e-mail is separated and stored in the temporary save location, or may be sent repeatedly at predetermined intervals until the password is entered. The predetermined interval may be 24 hours, and the notification may be sent, for example, once a day at a set time.
[0030] The predetermined interval at which notifications are sent may become shorter as time passes, or notifications may be sent at a first interval until a first period has elapsed, and then at a second interval (second time < first time) after the first period has elapsed. If such an embodiment is adopted, notifications will be sent more frequently as time passes, preventing the recipient from forgetting to release the password lock. Furthermore, after a certain period of time has elapsed, an emphasis message such as "URGENT" or "URGENT" may be displayed in the title.
[0031] The notification may be sent not only to the recipient but also to a pre-defined administrator, so that the administrator can also know that a password-locked compressed file that has not yet been unlocked is stored.
[0032] The email notified from the separation notification unit 20 may be in the form shown in FIG. 4, and may display a message prompting the user to enter a password, link information for entering the password (shown as a "password entry screen" in FIG. 4), email information including the subject, date and time, sender, and attachment information, and the email body. Adopting such a form is beneficial in that the recipient of the email cannot view the attachments, but can view the email body. The subject of the email notified from the separation notification unit 20 may indicate a request for password entry, as shown in FIG. 4. Adopting such a form allows the recipient to easily recognize that they are being asked to enter a password. The form shown in FIG. 4 also displays that control has been performed by the filtering system "m-FILTER" (registered trademark).
[0033] When the recipient clicks on the link information related to the password entry screen, a password entry screen like that shown in Figure 5 may be displayed. If there are multiple attachments, the password may be entered for each attachment. This is not a limitation, and even if there are multiple attachments, the same password may be entered for each attachment. When the password is entered, it may be masked with ●●●. If an incorrect password is entered, an error message may be displayed. Password entry is not limited to being performed from the password entry screen shown in Figure 5, but may also be performed by entering the password in a reply email to the notification email sent to the recipient. If "English" is selected in the lower right of Figure 5, the text will be displayed in English.
[0034] On the password entry screen, the information in the From header is displayed as the sender, and the To and CC headers may be displayed as the recipients. The email body may also be hidden, as it is dangerous to display the email body before it has been sanitized.
[0035] The determination processing unit 40 may determine whether the first file extracted after entering a password is appropriate (see (4) in FIG. 1). If the determination processing unit 40 determines that the first file is appropriate, it may send an email to the recipient, who is the destination of the file. If the determination processing unit 40 determines that the first file is inappropriate, it may perform a predetermined action and then send the email after the action is performed to the recipient, who is the destination of the file (see (6) in FIG. 1). Note that, if link destination information is included in the first file, the appropriateness may be determined based on the link destination information. For example, the first file may be determined to be inappropriate in one or more of the following cases: when a display URL displayed as a link destination in the body of the first file differs from an actual URL that is the actual link destination (see (a) in FIG. 3); when the actual URL that is the actual link destination is a link to a file with a prohibited extension (see (b) in FIG. 3); when a prohibited keyword is displayed in association with the actual URL that is the actual link destination (see (c) in FIG. 3); when the actual URL that is the actual link destination includes a global IP address (see (d) in FIG. 3); and when link destination information is included in the body of the first file but no other information is described. This point will be explained in detail later.
[0036] When the determination processing unit 40 sends an e-mail to a recipient, the determination processing unit 40 may attach the first compressed file after resetting the initially set password. The present invention is not limited to this mode, and when the determination processing unit 40 sends an e-mail to a recipient, the determination processing unit 40 may send the first compressed file with the password unlocked to the recipient.
[0037] The storage unit 10 may store permitted senders as a whitelist. If the sender is a permitted sender, the determination processing unit 40 may send an email to the recipient without determining whether the first file in the first compressed file is appropriate, even if the email is accompanied by a password-protected first compressed file (see (5) in FIG. 1). Alternatively, if the sender is a permitted sender, the separation notification unit 20 may not separate the email. The domain, IP address, etc. of the sender may be stored in the storage unit 10 as a permitted sender. For example, by selecting "Trusted Source" in FIG. 5, the domain, IP address, etc. of the target sender are stored in the storage unit 10 as permitted senders. In this case, future emails from the sender will not require password entry, and will be sent to the recipient without determining whether the first file in the first compressed file is appropriate (see (5) in FIG. 1). The sender and the recipient may be associated and stored in the storage unit 10, and a whitelist may be created based on the combination of these. By combining senders and recipients in this way and creating a whitelist, for example, when a first recipient receives an email from the first sender, the source may be determined to be an allowed source, but when a second recipient different from the first recipient receives an email from the first sender, they may be required to enter a password to inspect the compressed file.
[0038] 5 is selected, emails from that sender may not be received. The sender and the recipient may be associated and stored in the storage unit 10, and a blacklist may be created based on the combination of the sender and the recipient. By combining the sender and the recipient and creating a blacklist in this manner, for example, when a first recipient receives an email from the first sender, the email may be determined to be a prohibited sender, but when a second recipient different from the first recipient receives an email from the first sender, the email may be received as a normal sender, and if a compressed file is attached, a password may be required to inspect the compressed file.
[0039] On the other hand, if the sender is not registered as an authorized sender, it may be determined whether or not the sender is locked with a password (see (1) in FIG. 1).
[0040] If a certain period of time has passed without the correct password being entered, the determination processing unit 40 may delete the first compressed file that has not been decompressed by the decompression unit 30 and send the email to the recipient.
[0041] If a file has multiple levels, the notification by the separation notification unit 20, password entry, and decompression may be repeated for each level. That is, if the n+1-th compressed file (where "n" is an integer greater than or equal to 1) decompressed by the decompression unit 30 contains the n+1-th compressed file, the determination processing unit 40 may notify the recipient of the email that the n+1-th compressed file exists. The decompression unit 30 may decompress the n+1-th compressed file and extract the n+1-th file upon input of the password. The determination processing unit 40 may determine, for the n+1-th file, whether the n+1-th file is appropriate. For example, if a second compressed file is stored in the first file decompressed by the decompression unit 30 (see FIG. 6), the determination processing unit 40 may notify the recipient of the email that the second compressed file exists. The decompression unit 30 may decompress the second compressed file and extract the second file upon input of the password. The determination processing unit 40 may determine, for the second file, whether the second file is appropriate.
[0042] When multiple (n+1)th compressed files are stored in the nth compressed file decompressed by the decompression unit 30, the determination processing unit 40 may determine whether the (n+1)th file in the decompressed (n+1)th compressed file is appropriate, while deleting the (n+1)th compressed file that was not decompressed. Furthermore, the determination processing unit 40 may determine whether the (n+1)th compressed file that was not decompressed is appropriate to the extent possible. As an example of a manner in which a compressed file is determined to be appropriate, the determination processing unit 40 may use the file name as a basis for determination, and may determine that the compressed file is inappropriate if there are one or more blanks before the file name extension, if the file name contains a prohibition control code, or the like.
[0043] An upper limit on the number of layers to be decompressed by the decompression unit 30 may be set in advance. If the upper limit is exceeded, the decompression unit 30 may not decompress the compressed file. In this case, the determination processing unit 40 may determine, to the extent possible, whether a compressed file that has not been decompressed by the decompression unit 30 is a forged file. The upper limit on the number of layers may be, for example, 3 to 10. If the password locks of all compressed files and files can be released, or if the upper limit on the number of layers is exceeded, the determination processing unit 40 may determine the appropriateness of the password-released files.
[0044] If the files are multi-level, the determination processing unit 40 may input the password input for the nth compressed file as the password for the files in the lower level, such as the (n+1)th compressed file. If the compressed file cannot be decompressed with this password, the separation notification unit 20 may issue a notification requesting the input of a password. When such an embodiment is adopted, the receiver is not required to input a common password, thereby reducing the hassle for the receiver.
[0045] Such password input may be repeated. For example, if the (n+2)th compressed file is stored within the (n+1)th compressed file, the determination processing unit 40 may input the password input for the nth compressed file as the password for the (n+1)th compressed file, decompress the file, and then input the same password for the (n+2)th compressed file within the decompressed (n+1)th file.
[0046] The storage unit 10 may store a password list. Passwords in the password list may be stored in association with senders, and the password for a sender may be automatically entered for a file attached to an email from that sender. For example, one or more first passwords may be associated with a first sender, and the password for the first sender may be automatically entered for a file attached to an email from the first sender. Similarly, one or more second passwords may be associated with a second sender, and the password for the second sender may be automatically entered for a file attached to an email from the second sender. Registration in the password list may be limited to those with certain authority, such as an administrator. Recipients may be able to register a password in the password list when entering it. Registered sender addresses may be paired with passwords to create a whitelist, or pre-registered passwords may be paired with sender addresses to create a whitelist.
[0047] The determination processing unit 40 may sequentially apply multiple passwords stored in the storage unit 10 to a password-locked file attached to an e-mail. In this way, if the password cannot be unlocked by sequentially applying multiple passwords stored in the storage unit 10, the separation notification unit 20 may separate the e-mail and notify the user that the e-mail will be separated or that it has been separated.
[0048] When a preset retention period has elapsed, emails stored in the temporary save area may be automatically sent to the recipient. The retention period may be configurable, for example, a few hours, one day, three days, etc. It may also be set to "the same day," and if "the same day" is set, the retention period will be set to until the date changes.
[0049] When an email is automatically sent after a preset retention period has elapsed, the determination processing unit 40 may determine the appropriateness of the email to the extent possible. Even when an email is automatically sent, if the determination processing unit 40 determines that the email is inappropriate, the attached file may be deleted. However, it may be possible to set whether or not to delete the attached file when automatically sending the email, or it may be possible to set the file not to be deleted. When an email is automatically sent, this fact may be stated in the body or title of the email. If such an embodiment is adopted, the recipient can recognize that only a simple determination of whether the email is a fake email has been performed, and if the recipient feels it is necessary, the recipient may unlock the password of the file attached to the email and have the determination processing unit 40 determine whether the email is a fake email.
[0050] The compressed file format is typically ZIP, but various other formats, such as TAR, CAB, 7z, and RAR, can also be used. The decompressible compressed file formats may be preset. In this case, if a file is attached to an email in a format that cannot be decompressed, the compressed file may be deleted. Even if a compressed file format can be decompressed, the compressed file may be deleted in certain cases. For example, even if a file compressed with ZIP can be decompressed, if the compressed file is encrypted with AES128 / 192 / 256, the compressed file may be deleted. Instead of deleting the file, the determination processing unit 40 may perform a forgery determination to the extent possible.
[0051] Examples of cases where a file cannot be inspected include when the password is not entered, when the password is entered but continues to be incorrect after a certain period of time has passed, when the password is entered incorrectly more than a certain number of times, when the attachment level exceeds the maximum level and it is not possible to determine whether it is password locked, or when the format of the password-locked attachment is not supported by the system.
[0052] The action (control mode) for a file that cannot be inspected may be set to one of sending, quarantining, and deleting. If it is determined that the file should be quarantined or deleted, a notification may be sent to the administrator, recipient, or sender. The notification to the administrator, recipient, and sender may include information about the subject and body of the email in question. Also, the information on the screen shown in Figure 4 may be sent by email.
[0053] If the hierarchy of the attached file exceeds the hierarchy limit and it cannot be determined whether it is password locked, the e-mail may be sent with only the files of the hierarchy that have been extracted attached, or the e-mail may be sent after deleting the files including the hierarchy that have been extracted.
[0054] Sanitization processing may be performed on the attached file. As the sanitization processing, for example, the password lock of the attached file may be released and then macros may be removed, or the attached file may be deleted. The attached file from which the macros have been removed may be compressed in a format such as ZIP using the original password, attached to the original e-mail, and sent to the recipient. Alternatively, the attached file from which the macros have been removed may be compressed in a format such as ZIP without being password protected, attached to the original e-mail, and sent to the recipient. Alternatively, the attached file from which the macros have been removed may be attached to the original e-mail without being compressed, and sent to the recipient. When the sanitization processing is performed, the recipient may be notified of the details of the sanitization processing.
[0055] It should be noted that the file may be compressed in a format different from the original compression format. For example, the file may have been compressed in a first format when attached to the original e-mail, but when re-compressed after the password lock is released, it may be compressed in a second format (e.g., ZIP) different from the first format. It should be noted that even if the file was compressed in the second format when attached to the original e-mail, it may still be compressed in the second format. When such an embodiment is adopted, it can be compressed in a uniform format (second format) when re-compressed, which is beneficial in that it makes control easier.
[0056] The judgment processing unit 40 may determine that the mail information may be inappropriate if the file attached to the email uses a prohibited extension, if the file name has multiple extensions, if the file name of the file attached to the email has one or more blank spaces before the extension, if the file name of the file attached to the email contains a prohibited control code, if the file attached to the email is an executable file, if the email has a file attached but the email body is empty, etc. In these cases, even if the file is password-locked, it can be determined whether it is appropriate without unlocking the password, and these situations are included in the judgment of the "extent possible" mentioned above.
[0057] Examples of prohibited extensions include the use of "exe" as in "quote.exe" or the use of multiple extensions as in "quote.pdf.exe." An example of a prohibited control code is the use of "RLO" as in "quote(RLO)xcod.exe." Here, "RLO" stands for "Right-to-Left Override," a symbol used to reverse the left-right order of horizontally written characters. Since the use of such "RLO" may be used to prevent users from recognizing that the file is executable, it may be possible to determine that the email information is potentially inappropriate. Examples of executable files include the use of extensions such as "exe," "dll," "obj," "sys," and "com." Prohibited control codes or extensions may also be input via input means such as the input unit 90 shown in FIG. 2.
[0058] The judgment processing unit 40 may also determine that the email information may be inappropriate if the file attached to the email is in a prohibited format, if the file attached to the email contains a macro, etc.
[0059] An example of a case where a blank space is provided before the file extension of a file attached to an e-mail is a file name such as "quote.exe." Furthermore, the judgment processing unit 40 may determine that the e-mail information may be inappropriate if the number of blank spaces provided before the file extension is equal to or greater than a certain value (e.g., five words). The number of blank spaces may also be input via input means such as the input unit 90.
[0060] Even if a file attached to an e-mail contains a URL that is inappropriate for viewing, the determination processing unit 40 may determine that the mail information may be inappropriate. The inappropriate URL may be a URL (blacklist information) that is registered in advance in the storage unit 10.
[0061] When a file is determined to be a forged file, the recipient may be notified of the contents of the forged file determination and the result of the determination. This notification may be made by adding it to the body of the e-mail to be delivered, or may be sent as a separate e-mail from the e-mail to be delivered.
[0062] Inappropriate files may be collected using a honeypod or the like, and their hash values may be obtained. These hash values may then be blacklisted and compared with the hash values of files that are the subject of inspection.
[0063] Virus detection may be performed using antivirus software or the like on emails stored in the second storage unit 12, such as quarantined emails (see (7) in FIG. 1). Furthermore, emails stored in the second storage unit 12 that are detected as dangerous by antivirus software may be automatically deleted. When such an embodiment is adopted, the number of emails stored in the second storage unit 12 can be reduced, thereby reducing the burden on in-house administrators of assessing the appropriateness of emails, for example.
[0064] Furthermore, emails stored in the second storage unit 12 may be automatically deleted after a predetermined time has elapsed. The predetermined time after which emails are deleted may be input from the input unit 90 or may be set in advance. Furthermore, such an automatic deletion function may be switched on and off by the input unit 90.
[0065] The number of emails stored in the second storage unit 12, the number according to date and time, etc. may be notified to the administrator, or may be stored in the storage unit 10 so that the administrator can check them as needed. When such an embodiment is adopted, it is beneficial in that it is possible to check the number of emails determined to be inappropriate and the increase or decrease in the number over time.
[0066] A relay unit 50 (see FIG. 2) may be provided to relay web access from internal terminals within the internal system. When the judgment processing unit 40 determines that email information is inappropriate based on link destination information, the relay unit 50 may store the link destination in the storage unit 10 and deny access to the link destination from the internal terminal. The internal terminal refers to an information processing device such as a personal computer connected to the internal network. The storage unit 10 may store email information linked to the link destination. The email information may include the email body, acquisition date and time, sender address, etc., and if a file is attached to the email, information about the file may also be included in the email information.
[0067] The link destination information may include any information related to the link destination obtained from the email body, the attached file attached to the email, the macro of the attached file, etc. The email body may include both text and HTML format, and for HTML format, the URL of the linked portion may be obtained. Access to a URL stored in the storage unit 10 and prohibited by the relay unit 50 may be permitted via the input unit 90.
[0068] Even if an email is split into separate files, the determination processing unit 40 may combine the split files to restore a single file, and then the determination processing unit 40 may determine the appropriateness of the restored file.
[0069] Next, other aspects of determining whether a sender is appropriate to the extent possible will be described below.
[0070] [Sender information] First, a description will be given of how the determination processing unit 40 determines that the information in a received e-mail is likely to be inappropriate based on the sender information.
[0071] The determination processing unit 40 may acquire forgery detection information from an external terminal 100 located outside the internal network and use the forgery detection information to determine whether the sender information of the e-mail has been forged. In this case, the determination processing unit 40 may compare the forgery detection information with the sender information to determine whether the sender information has been forged. The external terminal 100 may be, for example, a DNS (Domain Name System) server. The forgery detection information may be, for example, an SPF (Sender Policy Framework) record. Whether the sender information of the e-mail has been forged may be determined using the source IP address, source e-mail address, FQDN (Fully Qualified Domain Name) of the source MTA, etc.
[0072] The determination processing unit 40 may determine whether the sender information is falsified using sender information other than the falsification detection information. As an example, if the destination of the header (Header From) does not match the destination of the envelope (Envelope From), it may be determined that the email may be inappropriate.
[0073] Furthermore, if the number of relay servers (number of Received headers) passed through from the sender to the receiver is equal to or greater than a predetermined threshold, for example, if the email contains a number of entries such as "Received: from [20x.0.xxx.1] by example1.ne.jp; Tue, 14 Sep 2010 15:16:37 JST" equal to or greater than the threshold, the judgment processing unit 40 may determine that the email is possibly inappropriate. The threshold may be set in advance or may be changeable via the input unit 90.
[0074] If the email is received via an unexpected route (e.g., China, Russia, etc.), the judgment processing unit 40 may determine that the email may be inappropriate. In this case, the country may be identified by the IP address in Received: from [20x.0.xxx.1]. The unexpected route may be predetermined, or may be changeable via the input unit 90.
[0075] When an email is sent using email software different from the email software the sender has previously used, the determination processing unit 40 may determine that the email may be inappropriate. The email software previously used may be stored in the memory unit 10, and the determination processing unit 40 may make a determination by comparing the email software stored in the memory unit 10 with the email software used in the email sent. It may be input from the input unit 90 that it is okay for the email software to be different for the sender, and in this case, the email software of the email sent later may be stored in the memory unit 10 as being correct for the sender of the email, or both the email software of the email previously used and the email software of the email sent later may be stored as being correct for the sender of the email.
[0076] When a sender sends an e-mail using a free mail service, the judgment processing unit 40 may determine that the e-mail may be inappropriate. In this case, the sender may be informed through the input unit 90 that there is no problem with using the free mail service, and in this case, the information may be stored in the storage unit 10 as being that there is no problem with e-mail sent via the free mail service for the sender.
[0077] [Link Information] Next, a description will be given of how the determination processing unit 40 determines that the information in the received e-mail is likely to be inappropriate based on the link destination information.
[0078] If an email contains link destination information, the determination processing unit 40 may determine whether the email is appropriate based on the link destination information. In this embodiment, the determination processing unit 40 may determine that an email may be inappropriate in the following cases: when the displayed URL displayed as the link destination in the email differs from the actual URL that is the actual link destination (see FIG. 3(a)); when the actual URL that is the actual link destination is a link to a file with a prohibited extension (see FIG. 3(b)); when a prohibited keyword is displayed in association with the actual URL that is the actual link destination (see FIG. 3(c)); when the actual URL that is the actual link destination includes a global IP address (see FIG. 3(d)); or when the email contains link destination information but the email body is empty. Note that the "link destination information" in this embodiment includes all information related to the link destination obtained from the email body, attached files attached to the email, macros in the attached files, etc. Therefore, if URL information is contained in a password-decrypted compressed file, the URL information may be used to determine the appropriateness of the email, as described above.
[0079] In the embodiment shown in FIG. 3(a), the body of the email contains the following display URL: The email address "http: / / technet.ABC.com" is displayed, but the actual URL is In the example shown in Figure 3(b), the URL is "http: / / technet.ABC.com.xx", which is different from the " uploaded file.exe " and has "exe" attached, which is a link to a file with a prohibited extension. In the mode shown in FIG. 3(c), the prohibited keyword "Authenticate now" is displayed in association with the actual URL. Here, the prohibited keyword being "associated with the actual URL" means, for example, that the prohibited keyword is displayed before or after the actual URL, or that an arrow appears from the prohibited keyword and points to the actual URL. Note that the prohibited keyword may be changed, such as input, addition, deletion, or correction, from the input unit 90. In the mode shown in FIG. 3(d), " 123.45.67.89" is included as a global IP address.
[0080] The determination processing unit 40 may determine that an email may be inappropriate if a redirect URL including a shortened URL is used. Redirection means that the email does not connect directly to the server where the content is stored, but goes through another server. A shortened URL is a URL with a long character string shortened, and it is considered to be used to connect to the original long URL using a redirect.
[0081] If the text does not include "all" but only "part" of the name registered in the storage unit 10, etc., there is a possibility that the URL is disguised, and in this case the judgment processing unit 40 may determine that the email is likely to be inappropriate. One example is the case where "example.com" is registered and the URL "http: / / example.com.xxxx / xxxxxx" is written.
[0082] [Text information] Next, a manner in which the determination processing unit 40 determines that the information in the received e-mail is likely to be inappropriate based on the body information will be described.
[0083] The determination processing unit 40 may determine that an e-mail may be inappropriate based on the information in the body of the e-mail.
[0084] If the text of the email contains a language other than the predetermined language, for example, if it contains kanji characters other than Japanese, such as traditional or simplified Chinese characters, the judgment processing unit 40 may determine that the email may be inappropriate. The permitted languages and prohibited languages may also be input from the input unit 90.
[0085] If the body of an email contains the name of a non-existent organization or company or a telephone number, the determination processing unit 40 may determine that the email may be inappropriate. When this mode is adopted, the determination processing unit 40 may be capable of acquiring information regarding existing organizations, company names, telephone numbers, etc. Such information regarding existing organizations, company names, telephone numbers, etc. may be stored in the storage unit 10 or in an external storage unit provided in an external device. The external device in this embodiment means any device other than the information device of this embodiment.
[0086] The determination processing unit 40 may determine that an email may be inappropriate if the sender's email address and the email address stated in the signature of the email body are different. The determination processing unit 40 may also determine that an email may be inappropriate if the email body contains content requesting the entry of an ID or password.
[0087] Furthermore, if there is nothing written in the body of the email, the determination processing unit 40 may determine that the email may be inappropriate.
[0088] Furthermore, if the text contains a "numeric character reference," the determination processing unit 40 may determine that the email is potentially inappropriate. A "numeric character reference" corresponds to a "character string" and a "numeric character," and they are convertible into one another. The determination processing unit 40 may determine that a "numeric character reference" is included if the text contains a predetermined "numeric character," such as "I'm waiting for you at a certain law firm in Otemachi." Alternatively, the determination processing unit 40 may determine whether the aforementioned "numeric character" can be converted back into a "character string" according to predetermined rules, and if it can be converted back into a "character string" without any problems, determine that a "numeric character reference" is included in the text. For example, the "numeric character" in the aforementioned "I'm waiting for you at a certain law firm in Otemachi" can be converted into the character string "I'm waiting for you at a certain law firm in Otemachi" by applying predetermined rules. In this way, if the "numeric characters" can be converted back into a "character string" without any problems, the judgment processing unit 40 may determine that the email contains a "numeric character reference" in the body of the email and that the email may be inappropriate. Note that, although the description here uses a case where a "numeric character reference" is included in the "body", this is not limiting, and for example, if a "numeric character reference" is included in the title of an email, the judgment processing unit 40 may determine that the email may be inappropriate.
[0089] The reason why an email is determined to be possibly inappropriate may be stored in the storage unit 10 and may be searchable. For example, if an email is determined to be possibly inappropriate because a prohibited file extension is used, this information may be stored in the storage unit 10 and may be searchable by the administrator.
[0090] The control method for received emails may be set differently for each group. An administrator may be set for each group. Group members may be changed as needed. If there are overlapping members in a group, it may be possible to select which group's control method to apply as needed.
[0091] If the determination processing unit 40 determines that the received email may be inappropriate, the email may be stored in the second storage unit 12 described above.
[0092] The determination processing unit 40 may delete emails that are determined to be inappropriate. When deleting emails, only a log may be left. By deleting emails in this manner, accidents such as accidentally opening the emails can be prevented.
[0093] Furthermore, when an attachment is deleted, URL information is deleted, or some other sanitization process is performed, the fact that the sanitization process has been performed and / or the details of the sanitization process may be added or changed in a section that is not visible to the user (for example, the header). By recording such processing, an administrator or the like may be able to search for the target email at a later date.
[0094] In addition, when a sanitization process is performed on an email, the fact that the sanitization process has been performed and / or the details of the sanitization process may be included in the body of the email and sent to the recipient and the administrator.
[0095] If the email body is in HTML format, the actual URL may not be displayed, so the determination processing unit 40 may acquire information about the actual URL.
[0096] As information about URLs that are not problematic, permitted URL information may be stored in a storage means such as the storage unit 10. Even if an email contains URL information, if the URL information corresponds to permitted URL information, the judgment processing unit 40 may judge the email to be problem-free.
[0097] The storage unit 10 may store, as permitted sender information, a destination with which transmission and reception have taken place a predetermined number of times (for example, 10 times). This predetermined number of times may also be input and changed via the input unit 90.
[0098] The storage unit 10 may store a URL that the determination processing unit 40 has determined to be problematic, and the determination processing unit 40 may determine the appropriateness of emails that it will receive from the next time onward by comparing the URL with the stored URL. When the storage unit 10 stores a URL that it has determined to be problematic in this way, the storage unit 10 may also store information about the email in which the URL was written or attached. This information about the email may include the email body, the date and time of acquisition, the sender's address, etc., and if a file is attached to the email, information about the file may also be included in the email information.
[0099] It should be noted that the determination processing unit 40 does not need to determine the appropriateness of e-mails (such as whether the sender is disguised) when the e-mails are sent via the internal network without going through an external network.
[0100] In this embodiment, there are also provided information processing methods in all aspects related to the above-mentioned information processing device, programs for generating the information processing device, and recording media including USB memory, CDs, DVDs, etc. on which the programs are recorded.
[0101] The information processing device of this embodiment is generated by installing a program such as a server program. This program may be distributed by email, may be available by logging in after accessing a predetermined URL, or may be recorded on a recording medium. The information processing method of this embodiment is performed by the information processing device in which the program is installed.
[0102] "effect" Next, effects of the present embodiment having the above-described configuration will be described, focusing on those that have not yet been explained. Note that all of the configurations described in the "Effects" section can be used as configurations of the present embodiment.
[0103] When a password-protected compressed file is attached to a received email, the email is stored in a temporary storage area, and the recipient of the email is notified that the email will be stored in the temporary storage area or that it has been stored. The compressed file is decompressed upon entry of the password, the file is extracted, and the appropriateness of the file is determined. This allows for a prompt determination of the appropriateness of a file stored in a password-protected compressed file. By notifying the recipient, the password can be expected to be promptly entered. Furthermore, while it is not possible to determine the appropriateness of a file stored in a password-protected compressed file, this aspect allows for a determination of the appropriateness of the file even when the file is stored in a password-protected compressed file.
[0104] In this embodiment, if the file is determined to be appropriate, an email is sent to the recipient, and if the file is determined to be inappropriate, a predetermined action is performed and then an email with the action performed is sent to the recipient.In this case, the recipient will receive the email after the appropriate action has been taken.
[0105] When the judgment processing unit 40 sends an e-mail to a recipient, if the judgment processing unit 40 adopts a mode of attaching the first compressed file after resetting the password and sending it, the e-mail can be sent to the recipient in a mode that is substantially the same as the original e-mail.
[0106] When the judgment processing unit 40 sends an e-mail to a recipient, if the judgment processing unit 40 adopts a mode of sending the first compressed file with the password unlocked to the recipient, the recipient does not need to input the password again, thereby saving the trouble.
[0107] When the sender is an authorized sender, even if an email has a compressed file with a password attached, if the email is sent to the recipient without determining whether the files in the compressed file are appropriate, this is advantageous in that it eliminates the need to determine the appropriateness of emails from senders that the user has determined to be safe.
[0108] When a mode is adopted in which the first compressed file that was not decompressed by the decompression unit 30 is deleted and the email is sent to the recipient, it is possible to prevent the first compressed file whose appropriateness cannot be confirmed from being sent to the recipient, while sending the body of the email, etc. to the recipient.
[0109] When the n+1th compressed file is stored within the nth compressed file (where "n" is an integer greater than or equal to 1), the judgment processing unit 40 notifies the recipient of the email that the n+1th compressed file exists, and when a password is entered, the decompression unit 30 decompresses the n+1th compressed file to extract the n+1th file, and the judgment processing unit 40 determines whether the n+1th file is appropriate for the n+1th file.In this case, the appropriateness of the files in the folder can be determined even if the folder has a multi-layer structure.
[0110] When a plurality of n+1th compressed files are stored within the nth compressed file decompressed by the decompression unit 30, if a mode is adopted in which the judgment processing unit 40 judges the appropriateness of the n+1th file within the decompressed n+1th compressed file and deletes the n+1th compressed file that was not decompressed, safety can be ensured by checking the appropriateness of the decompressed files and deleting compressed files whose appropriateness could not be confirmed.
[0111] An upper limit on the number of layers that can be decompressed by the decompression unit 30 is set in advance, and if a mode is adopted in which the decompression unit 30 does not decompress the compressed file if the upper limit is exceeded, an upper limit can be set on decompression of the compressed file, thereby limiting the load on the judgment processing unit 40.
[0112] The determination processing unit 40 may have an artificial intelligence function and may learn the password for the sender by using the relationship between sender information and password information used for decompression as training data. If such an embodiment is adopted, it is possible to increase the possibility that the compressed file can be decompressed without the receiver inputting a password.
[0113] If the relay unit 50 is configured to deny access from an internal terminal based on the link destination information when the judgment processing unit 40 determines that the email information is inappropriate based on the link destination information, this is beneficial in that it not only prevents access to dangerous websites using email, but also prevents employees who have not received emails of questionable suitability from accessing dangerous websites.
[0114] If an embodiment is adopted in which access to a URL that is prohibited by the relay unit 50 is permitted via the input unit 90, it will be possible to permit access to a URL that has been determined to be safe by an administrator, for example, which is beneficial in that it can prevent unnecessary and excessive restrictions on access to URLs.
[0115] The above description of the embodiment and the disclosure of the drawings are merely examples for explaining the invention described in the claims, and the invention described in the claims is not limited by the description of the embodiment or the disclosure of the drawings. The description of the claims as originally filed may be changed or expanded as appropriate within the scope of the patent specification.
[0116] Each component including the separation notification unit 20, decompression unit 30, judgment processing unit 40, relay unit 50, storage unit 10, etc. in each of the above embodiments may be realized by a logic circuit (hardware) or dedicated circuit formed in an integrated circuit such as an IC chip or LSI, or may be realized by software using a CPU, memory, etc. Furthermore, each component may be realized by one or more integrated circuits, or multiple components may be realized by a single integrated circuit. Furthermore, a control unit may be thought of as a component including the separation notification unit 20, decompression unit 30, judgment processing unit 40, relay unit 50, etc. [Explanation of symbols]
[0117] 10 Storage section 11 First memory section 12 Second memory section 20 Separation Notification Department 30 Decompression section 40 Judgment processing unit 50 Relay Section
Claims
1. a separation notification unit that, when a first compressed file with a password set is attached to a received email, stores the email in a temporary save area and notifies a recipient of the email that the email will be stored in the temporary save area or that the email has been stored; a decompression unit that decompresses the first compressed file by inputting the password and extracts the first file; a determination processing unit that determines whether the first file is appropriate for the first file, When the first compressed file contains multiple compressed files, the determination processing unit inputs a password for each compressed file to extract the file, determines whether the extracted file is appropriate, and sanitizes the file attached to the email.
1. An information processing device comprising:
2. The information processing device according to claim 1, characterized in that the judgment processing unit sends the email to the recipient if it determines that the first file is appropriate, and if it determines that the first file is inappropriate, performs a predetermined action and then sends the email with the action performed to the recipient.
3. When a first compressed file with a password set is attached to a received email, storing the email in a temporary save area and notifying a recipient of the email that the email will be stored in the temporary save area or that it has been stored; decompressing the first compressed file by inputting the password and extracting the first file; determining whether the first file is appropriate for the first file; When compressed files are stored in multiple stages within the first compressed file, inputting a password for each compressed file to extract the file, determining whether the extracted file is appropriate, and sanitizing the file attached to the email; An information processing method comprising:
4. A program for causing an information processing device to execute an information processing method, The information processing device includes: When a first compressed file with a password set is attached to a received email, storing the email in a temporary save area and notifying a recipient of the email that the email will be stored in the temporary save area or that it has been stored; decompressing the first compressed file by inputting the password and extracting the first file; determining whether the first file is appropriate for the first file; When compressed files are stored in multiple stages within the first compressed file, inputting a password for each compressed file to extract the file, determining whether the extracted file is appropriate, and sanitizing the file attached to the email; A program for executing an information processing method comprising:
Citation Information
Patent Citations
Mail server, method for processing electronic mail and program therefor
JP2011004132A
Web mail server, mail client program and mail server
JP2012078922A
Method, system and program product for maximizing virus check coverage while minimizing redundancy in virus checking
US20080222177A1