Malware infection status notification system
The system allows users to receive malware infection status notifications by querying a server with their terminal's number, addressing the lack of user notification in existing systems and ensuring secure, effective communication.
Patent Information
- Application Number
- JP2024206959
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2024-11-28
- Publication Date
- 2026-02-03
- Estimated Expiration
- 2044-11-28
AI Technical Summary
Existing systems fail to provide a mechanism for end users to receive notifications about malware infections on their terminals.
A method and system for notifying a user terminal of its malware infection status by querying a judgment server or determination server using the terminal's telephone number, which refers to a database of infected terminals, and sending a message to the user terminal with the infection status.
Enables users to determine if their terminals are infected with malware, maintaining confidentiality and ensuring effective notification even when SMS functions are compromised.
Smart Images

Figure 0007810368000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to a technique for notifying the infection status of a mobile terminal. [Background technology]
[0002] There is a technology to detect terminals infected with malware (Patent Document 1, etc.). [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Patent No. 5655185 Summary of the Invention [Problem to be solved by the invention]
[0004] Although Patent Document 1 makes it possible to determine whether a terminal within the system is infected with malware, it does not provide a mechanism for an end user to receive the results of an infection determination for a terminal when the end user suspects that the terminal he or she is using is infected with malware.
[0005] The present invention provides a technique for notifying a terminal whether the terminal is infected with malware in response to a request from the terminal. [Means for solving the problem]
[0006] One aspect of the present invention provides a method for notifying a malware infection status, comprising the steps of: setting the telephone number of a terminal to be judged on a user terminal; sending an inquiry including the set telephone number to a judgment server; the judgment server referring to a database storing telephone numbers of terminals infected with malware to judge whether the user terminal is infected with malware; and the judgment server sending the result of the judgment using a system that sends messages addressed to the telephone number of the terminal to be judged.
[0007] Another aspect of the present invention provides a method for notifying a malware infection status, comprising the steps of: accepting input of consent information at a user terminal indicating consent to providing the user terminal's telephone number to a determination server that determines whether the user terminal is infected with malware; transmitting the input consent information to a telecommunications carrier server that manages the user terminal's telephone number; in response to a request from the determination server, the telecommunications carrier server providing the telephone number to the determination server; the determination server referring to a database that stores telephone numbers of malware-infected terminals to determine whether the user terminal is infected with malware; and the determination server notifying the user terminal of the result of the determination.
[0008] Yet another aspect of the present invention provides a program for causing a computer to execute the following steps: setting a telephone number of a terminal to be judged; sending an inquiry including the set telephone number to a judgment server; and receiving from the judgment server, using a system that sends a message addressed to the telephone number, the result of the judgment server's determination of whether the terminal to be judged is infected with malware by referring to a database that stores the telephone numbers of terminals infected with malware.
[0009] Yet another aspect of the present invention provides a program for causing a computer of a user terminal to execute the steps of accepting input of consent information indicating consent to providing the telephone number of the user terminal to a determination server that determines whether the user terminal is infected with malware, transmitting the input consent information to a telecommunications carrier server that manages the telephone number of the user terminal, and receiving from the determination server the results of the determination of whether the user terminal is infected with malware, made by the determination server using the telephone number provided by the telecommunications carrier server in response to a request from the determination server, by referring to a database that stores telephone numbers of terminals infected with malware.
[0010] Yet another aspect of the present invention provides an information processing system comprising a user terminal and a determination server, wherein the user terminal has a means for setting a telephone number of a terminal to be determined and a means for sending an inquiry including the set telephone number to the determination server, and the determination server has a means for determining whether the terminal to be determined is infected with malware by referring to a database storing telephone numbers of terminals infected with malware, and a means for sending the result of the determination using a system that sends messages addressed to the telephone number.
[0011] Yet another aspect of the present invention provides an information processing system comprising a user terminal and a determination server, wherein the user terminal has means for accepting input of consent information indicating consent to providing the user terminal's telephone number to a determination server that determines malware infection, and means for transmitting the input consent information to a telecommunications carrier server that manages the user terminal's telephone number, and the determination server has means for acquiring the telephone number from the telecommunications carrier server, means for using the acquired telephone number to refer to a database that stores telephone numbers of malware-infected terminals to determine whether the user terminal is infected with malware, and means for notifying the user terminal of the result of the determination. [Effects of the Invention]
[0012] According to the present invention, it is possible to notify a user terminal whether or not it is infected with malware. [Brief explanation of the drawings]
[0013] [Figure 1] FIG. 1 is a diagram showing the configuration of an information processing system according to an embodiment. [Figure 2] FIG. 1 is a diagram illustrating an example of the functional configuration of an information processing system. [Figure 3] FIG. 2 is a diagram illustrating an example of the hardware configuration of a user terminal. [Figure 4] FIG. 2 is a diagram illustrating an example of the hardware configuration of a determination server. [Figure 5]10 is a sequence chart illustrating an example of the operation of a database generation process. [Figure 6] FIG. 10 is a diagram illustrating an example of an infected phone number database. [Figure 7] 10 is a sequence chart illustrating an example of the operation of a determination result notification process. [Figure 8] FIG. 10 is a diagram illustrating an example of a display screen for a determination result. [Figure 9] 10 is a sequence chart illustrating an example of the operation of a determination result notification process. [Figure 10] FIG. 10 is a diagram illustrating a telephone number database. DETAILED DESCRIPTION OF THE INVENTION
[0014] 1. Configuration 1 is a diagram showing the configuration of an information processing system S according to one embodiment. The information processing system S is composed of a plurality of user terminals 10-1, 10-2, ..., 10-n (hereinafter collectively referred to as user terminals 10), a network 20, a determination server 30, and at least one or more telecommunications carrier servers 40-1, 40-2, ..., 40-n (hereinafter collectively referred to as telecommunications carrier servers 40). The user terminals 10, the determination server 30, and the telecommunications carrier servers 40 are connected to one another via the network 20. The network 20 is a network line such as the Internet. Each of the plurality of user terminals 10 can be connected to the network 20, and can communicate with the determination server 30 and the telecommunications carrier servers 40 connected to the network 20 via the network 20.
[0015] The information processing system S is a system that notifies a user terminal 10 of the determination result as to whether or not the user terminal 10 is infected with malware. The information processing system S refers to a database that stores the telephone numbers of mobile phone terminals (hereinafter referred to as terminals) that are infected with malware, and determines whether or not the terminal to be determined is infected with malware. The information processing system S notifies the user terminal 10 of the determination result. Note that, hereinafter, malware, also known as a virus, is a general term for malicious software or malicious programs created with the intention of performing fraudulent or harmful operations, and broadly refers to code that performs operations that are not intended by the user.
[0016] The user terminal 10 is a terminal used by a user and is assigned a telephone number by a telecommunications carrier. This telephone number functions as information that uniquely identifies the terminal. The user terminal 10 is, for example, a smartphone or tablet terminal, and may have a function for performing various incidental information processing in addition to a function for performing communication using a telephone number. Furthermore, it does not necessarily have to have a function for performing voice communication. The user terminal 10 communicates with the determination server 30 or the telecommunications carrier server 40 and can display information transmitted from the determination server 30 or the telecommunications carrier server 40 on the user terminal 10. A user using the user terminal 10 can input information to be transmitted to the determination server 30 via the display of the user terminal 10. An infection checker application for determining whether the user terminal 10 is infected with malware is installed on the user terminal 10.
[0017] The determination server 30 is a server that determines whether the user terminal 10 is infected with malware. The determination server 30 manages an infection checker application. The determination server 30 has an infected phone number database in which phone numbers of terminals that are (confirmed or presumed to be) infected with malware are registered. The infected phone number database may be a so-called blacklist type (which lists terminals infected with malware) or a so-called whitelist type (which lists terminals confirmed to be uninfected), and its data structure and information representation format are not important. In short, it is sufficient if it stores information that can be used to determine the infection status, including the presence or possibility of infection. Furthermore, the construction of the infected phone number database (registration and updating of information) may be performed within the information processing system S, as described below, or may be performed by a system provided separately and independently from the information processing system S. The determination server 30 references the phone numbers stored in the infected phone number database to determine whether the user terminal 10 or a terminal corresponding to a phone number acquired from the telecommunications carrier server 40 is infected with malware.
[0018] The telecommunications carrier server 40 is a server of a telecommunications carrier that provides communication services to the user terminal 10. The telecommunications carrier server 40 has a telephone number database that describes the telephone numbers of the user terminal 10. When the telecommunications carrier server 40 receives consent information from the user terminal 10 indicating consent to providing the telephone number of the user terminal 10 to the determination server 30 that determines whether the user terminal 10 is infected with malware, the telecommunications carrier server 40 transmits the telephone number of the user terminal 10 to the determination server 30.
[0019] 2 is a diagram illustrating an example of the functional configuration of the information processing system S. The information processing system S includes a receiving unit 201, a transmitting unit 202, a transmitting unit 203, an acquiring unit 204, a storage unit 205, a determining unit 206, a notifying unit 207, a storage unit 208, a control unit 209, and a control unit 210. The receiving unit 201, the transmitting unit 202, the transmitting unit 203, the storage unit 208, and the control unit 209 are implemented in the user terminal 10. The acquiring unit 204, the storage unit 205, the determining unit 206, the notifying unit 207, and the control unit 210 are implemented in the determination server 30.
[0020] The functions of the user terminal 10 will be described. The storage means 208 stores various types of information. The control means 209 performs various controls on the user terminal 10. The reception means 201 receives input of the telephone number of the terminal to be judged through operation by the user. The reception means 201 also receives input of consent information indicating consent to providing the telephone number of the user terminal to a judgment server that judges malware infection through operation by the user. The transmission means 202 transmits the consent information input by the reception means 201 to the telecommunications carrier server 40. The transmission means 203 transmits an inquiry including the telephone number input by the reception means 201 (corresponding to the telephone number of the terminal to be judged) to the judgment server 30.
[0021] The functions of the determination server 30 will be described. The storage means 205 stores an infected phone number database including the phone numbers of terminals infected with malware. The control means 210 performs various controls in the determination server 30. The acquisition means 204 acquires the phone number of the terminal to be determined from the user terminal 10. The acquisition means 204 also acquires the phone number of the user terminal 10 from the telecommunications carrier server 40. The determination means 206 determines whether the terminal to be determined or the user terminal 10 is infected with malware. The notification means 207 notifies the user terminal 10 of the malware infection determination result.
[0022] FIG. 3 is a diagram illustrating an example of the hardware configuration of the user terminal 10. The user terminal 10 is a computer device having a CPU (Central Processing Unit) 101, memory 102, storage 103, a communication IF (Interface) 104, an input unit 105, and a display 106. The CPU 101 is a control device that executes programs to perform various calculations and controls other hardware elements of the user terminal 10. The memory 102 is a main storage device that functions as a work area when the CPU 101 executes programs. The storage 103 is a non-volatile auxiliary storage device that stores various programs and data. The communication IF 104 is a communication device that communicates with other devices in accordance with a predetermined communication standard (e.g., Ethernet (registered trademark)). The input unit 105 is an operation unit composed of a keyboard, mouse, touch panel, or the like, and inputs various information in response to user instructions. The display 106 is a flat panel display such as a liquid crystal display or an organic electroluminescence (EL) display, and outputs images or characters.
[0023] In this example, the storage 103 stores a program (hereinafter referred to as the "user terminal program") for causing the computer device to function as a user terminal 10 in the information processing system S. When the CPU 101 executes the user terminal program, the functions shown in FIG. 2 are implemented in the computer device. The user terminal program is an application for determining whether the user terminal 10 is infected with malware. When the CPU 101 is executing the user terminal program, at least one of the memory 102 and the storage 103 is an example of a storage means 208, the CPU 101 is an example of a control means 209, the communication IF 104 is an example of a transmission means 202 and a transmission means 203, and the input unit 105 is an example of a reception means 201.
[0024] 4 is a diagram illustrating an example of the hardware configuration of the determination server 30. The determination server 30 is a computer device having a CPU (Central Processing Unit) 301, a memory 302, a storage 303, and a communication IF (Interface) 304. The CPU 301 is a control device that executes programs to perform various calculations and controls other hardware elements of the determination server 30. The memory 302 is a main storage device that functions as a work area when the CPU 301 executes programs. The storage 303 is a non-volatile auxiliary storage device that stores various programs and data. The communication IF 304 is a communication device that communicates with other devices according to a predetermined communication standard (e.g., Ethernet (registered trademark)).
[0025] In this example, the storage 303 stores a program (hereinafter referred to as the "determination server program") for causing the computer device to function as the determination server 30 in the information processing system S. The CPU 301 executes the determination server program, thereby implementing the functions of Fig. 2 in the computer device. When the CPU 301 is executing the determination server program, at least one of the memory 302 and the storage 303 is an example of the storage means 205, the CPU 301 is an example of the determination means 206 and the control means 210, and the communication IF 304 is an example of the acquisition means 204 and the notification means 207.
[0026] 2.Operation 2.1 Creating a database 5 is a sequence chart illustrating the operation of the database generation process. In step S501, the multiple user terminals 10 transmit to the determination server 30 a history of transmissions made using a communication method (e.g., SMS (Short Message Service)) in which the sender and the recipient are specified by telephone number. Specifically, through a user operation, an infection checker application installed in the user terminal 10 transmits to the determination server 30 at least all transmission and reception histories (transmission and reception histories) recorded in the user terminal 10. The transmission and reception history includes the telephone numbers of the sender and the recipient, and the sent (received) messages (including the text body, attachments, link information such as URLs, etc.). The determination server 30 acquires from each of the multiple user terminals 10 a history of transmissions made using a communication method in which the sender and the recipient are specified by telephone number. Note that this infection checker application may automatically transmit an SMS to the determination server 30 every time it receives an SMS at each user terminal 10, without user operation. Also, the function of checking whether the user terminal 10 is infected with malware and the function of determining whether the SMS received by the user terminal 10 is a spam SMS (so-called filtering) may be provided by independent applications rather than being provided by a single infection checker application.
[0027] In step S502, the determination server 30 determines whether each user terminal 10 is infected with malware based on the transmission history acquired in step S501. Specifically, the determination means 226 determines whether the user terminal 10 has sent messages with similar text to multiple recipients using a communication method in which the sender and recipient are specified by telephone number. Specifically, first, the determination means 226 calculates, using a predetermined natural language analysis algorithm, the similarity between the text of any one message (hereinafter referred to as the target message) from the acquired transmission history and the text of each message sent within a predetermined time range (e.g., 24 hours before and after the sending time) determined based on the time the message was sent. If the number of messages whose similarity with the target message exceeds a predetermined standard exceeds a predetermined threshold, the user terminal 10 from which the message was sent is determined to be infected with malware. In addition, if the number of messages whose similarity to the target message exceeds a predetermined standard exceeds a predetermined percentage of the number of messages sent within a specified time range determined based on the sending time, it is determined that the sending user terminal 10 is infected with malware.
[0028] In step S503, the storage means 205 of the determination server 30 stores the result of the determination made in step S502 in the infected phone number database.
[0029] FIG. 6 is a diagram illustrating an example of an infected phone number database 600. The infected phone number database 600 includes a phone number 601, infection status 602, and infection status confirmation time 603. The phone number 601 is the phone number of the user terminal 10. The phone number 601 is stored in an encrypted state. Storing the phone number 601 in an encrypted state provides a sense of security to the user of the user terminal 10. Furthermore, even if information in the infected phone number database 600 is leaked to the outside, the infected phone number database 600 can be prevented from being misused. The infection status 602 indicates whether the user terminal 10 corresponding to the phone number 601 is infected with malware. The infection status confirmation time 603 is the time when the infection status 602 was confirmed. For example, in Figure 6, the user terminal 10 whose telephone number 601 is "gki48ngao9" is determined to be infected with malware at 11:24:00 AM on September 10, 2024, and the user terminal 10 whose telephone number 601 is "39gnjek3o7" is determined to not be infected with malware at 8:05:00 PM on September 10, 2024.
[0030] 2.2 Notification of malware infection results 7 to 10 are diagrams relating to the process of notifying the result of the malware infection determination. FIG. 7 is a sequence chart illustrating the operation of the first embodiment. FIG. 9 is a sequence chart illustrating the operation of the second embodiment. In both the first and second embodiments, the determination of malware infection is performed by referring to a database of malware-infected phone numbers stored in the determination server 30. Since the database stores phone numbers, which are highly identifiable information and should be kept confidential, the contents of the database are not generally made public. According to this embodiment, the user of the user terminal 10 can be notified of the presence or absence of malware infection while maintaining the confidentiality of the database.
[0031] 2.2.1 Example 1 Fig. 7 is a sequence chart illustrating the operation of the determination result notification process. The process shown in Fig. 7 is performed between the user terminal 10 and the determination server 30. The process in Fig. 7 is started, for example, when the user of the user terminal 10 launches an infection checker application. In step S701, the receiving means 201 of the user terminal 10 receives input of the telephone number of the terminal to be determined (i.e., the user terminal 10) through operation by the user of the user terminal 10.
[0032] In step S702, the sending means 203 of the user terminal 10 sends an inquiry including the telephone number entered in step S701 to the determination server 30. The acquiring means 204 of the determination server 30 acquires the inquiry including the telephone number entered in step S701 from the user terminal 10.
[0033] In step S703, the determination means 206 of the determination server 30 determines whether the user terminal 10 is infected with malware by referring to the infected phone number database 600, which stores the phone numbers of terminals infected with malware. Specifically, the determination server 30 first determines whether the phone number of the terminal to be determined is included in the phone number 701 of the infected phone number database 600. If the phone number of the terminal to be determined is not included in the phone number 701 of the infected phone number database 600, it is unclear whether the terminal to be determined is infected with malware, and the determination result is, for example, "It is unknown whether the terminal is infected with malware" (or "No clear evidence of malware infection is found"). If the phone number of the terminal to be determined is included in the phone number 701 of the infected phone number database 600, and the infection status 702 corresponding to the phone number is "yes," the determination result is, for example, "suspected of being infected with malware." If the phone number of the terminal to be determined is included in the phone number 701 of the infected phone number database 600, and the infection status 702 corresponding to the phone number is "no," the determination result is "not infected with malware." The above-described method of expressing the information indicating the determination result (message text presented to the user) is just an example.
[0034] In step S704, the notification means 207 of the determination server 30 notifies the terminal corresponding to the telephone number acquired from the user terminal 10 in step S702 (i.e., the user terminal 10) of the determination result using a system (e.g., SMS) that sends a message addressed to the telephone number. Specifically, the determination server 30 notifies the user terminal 10 of a URL indicating the determination result. The user terminal 10 receives the determination result from the determination server 30. Specifically, the user terminal 10 receives a message indicating the URL indicating the determination result.
[0035] In step S705, the user terminal 10 displays the result of the determination through an operation by the user of the user terminal 10 (for example, tapping on a URL link).
[0036] FIG. 8 is a diagram illustrating a display screen of the determination result. The display screen of the determination result displays the telephone number of the terminal to be determined and the determination result. In the diagram shown in FIG. 8, it displays that a terminal with the telephone number "080XXXXXXXX" is suspected of being infected with malware. Here, the determination result is notified to the terminal corresponding to the telephone number entered by the user in step S701. Therefore, even if the user mistakenly enters a telephone number different from the telephone number of his / her own terminal or intentionally attempts to infect a user terminal 10 owned by another person with malware, the determination result is notified to the user terminal 10 corresponding to the entered telephone number. Therefore, even if the terminal to be determined and the user terminal 10 are different, information regarding malware infection of the terminal to be determined will not be leaked to others. As such, according to the first embodiment, it is possible to provide the result of the determination regarding malware infection in response to a user request while ensuring confidentiality.
[0037] 2.2.2 Example 2 FIG. 9 is a sequence chart illustrating the operation of the determination result notification process. The process shown in FIG. 9 is performed among the user terminal 10, the determination server 30, and the telecommunications carrier server 40. The process in FIG. 9 is started, for example, when the user of the user terminal 10 launches an infection checker application. In step S901, the user terminal 10 requests the determination server 30 to confirm malware infection. This request includes identification information that identifies the telecommunications carrier. The determination server 30 receives the request to confirm malware infection from the user terminal 10.
[0038] In step S902, the determination server 30 instructs the user terminal 10 to access the telecommunications carrier server 40. The server of which of the multiple telecommunications carriers the user terminal 10 should access is specified by identification information included in the request. The user terminal 10 receives the instruction to access the telecommunications carrier server 40 from the determination server 30.
[0039] In step S903, the accepting means 201 of the user terminal 10 accepts, via an operation by the user of the user terminal 10, input of consent information indicating consent to providing the telephone number of the user terminal 10 to the determination server 30 that determines whether the user terminal 10 is infected with malware. The consent information is, for example, an ID and password for accessing the telecommunications carrier server 40 used by the user terminal 10.
[0040] In step S904, the transmission means 202 of the user terminal 10 accesses the telecommunications carrier server 40 and transmits consent information to the telecommunications carrier server 40. That is, the user terminal 10 permits the determination server 30 to acquire the telephone number of the user terminal 10 stored in the telecommunications carrier server 40. The telecommunications carrier server 40 acquires the consent information from the user terminal 10.
[0041] In step S905, the carrier server 40 issues a token in response to the consent information. The issued token is linked to the telephone number of the user terminal 10 as a token ID and stored in the telephone number database 1000.
[0042] 10 is a diagram illustrating a telephone number database 1000. The telephone number database 1000 stores telephone numbers 1001 of user terminals 10 that have contracts with telecommunications carriers corresponding to the telecommunications carrier server 40, and token IDs 1002 for identifying the telephone numbers 1002.
[0043] In step S906, the telecommunications carrier server 40 transmits the token issued in step S905 to the user terminal 10. The user terminal 10 obtains the token from the telecommunications carrier server 40.
[0044] In step S907, the user terminal 10 transmits the token acquired in step S906 to the determination server 30. The determination server 30 acquires the token from the user terminal 10.
[0045] In step S908, the determination server 30 accesses the telecommunications carrier server 40 using the token acquired in step S907. Specifically, first, the determination server 30 transmits the token to the telecommunications carrier server 40. If the telecommunications carrier server 40 determines that the token ID corresponding to the transmitted token matches the token ID 1002 stored in step S905, the determination server 30 can access the telecommunications carrier server 40. The determination server 30 requests the telecommunications carrier server 40 for the telephone number of the user terminal 10. The telecommunications carrier server 40 accepts the request for the telephone number from the determination server 30.
[0046] In step S909, the telecommunications carrier server 40 refers to the telephone number database 1000 stored in the telecommunications carrier server 40, and encrypts and transmits the telephone number 1001 corresponding to the token ID 1002 used for the access to the determination server 30. The telecommunications carrier server 40 transmits the telephone number 1001 corresponding to the token ID 1002 used for the access, i.e., the telephone number of the user terminal 10, to the determination server 30. The acquisition means 204 of the determination server 30 acquires the telephone number of the user terminal 10 from the telecommunications carrier server 40.
[0047] In step S910, the determination means 206 of the determination server 30 refers to the infected phone number database 600 to determine whether the user terminal 10 is infected with malware. The determination server 30 and the telecommunications carrier server 40 share an encryption algorithm and an encryption key for encrypting phone numbers. The infection determination is performed while the phone number of the user terminal 10 is encrypted. Specifically, the determination server 30 first determines whether the phone number of the user terminal 10 is included in the phone number 601 of the infected phone number database 600. If the phone number of the user terminal 10 is not included in the phone number 601 of the infected phone number database 600, it is unclear whether the user terminal 10 is infected with malware, and the determination result is, for example, "whether infected with malware is unknown." If the phone number of the user terminal 10 is included in the phone number 601 of the infected phone number database 600 and the infection status 602 corresponding to the phone number is "yes," the determination result is, for example, "suspected of being infected with malware." If the telephone number of the user terminal 10 is included in the telephone number 601 of the infected telephone number database 600, and the infection status 602 corresponding to the telephone number is "no," the result of the determination is, for example, "not suspected of being infected with malware." Note that, as in the above-described first embodiment, the method of expressing the information indicating the determination result (the message text presented to the user) is just one example, and the possibility of infection may be expressed, for example, as a numerical value (probability).
[0048] In step S911, the notification means 207 of the determination server 30 notifies the user terminal 10 of the determination result read from the infected phone number database 600. The reception means 222 of the user terminal 10 receives the determination result from the determination server 30.
[0049] In step S912, the user terminal 10 displays the result of the determination on the infection checker application, as shown in FIG. 8. In a user terminal 10 infected with malware, the SMS sending or receiving function may be tampered with, causing predetermined messages to be automatically generated and sent regardless of the user's intention, or causing received emails to be deleted without permission or a large amount of received emails to be received, resulting in the SMS function not functioning effectively (i.e., the SMS function being "hijacked"). As shown in FIG. 9, the result of the malware infection determination is displayed not via SMS but on the infection checker application that operates independently of SMS. This allows the user to check the result of the malware infection determination even when the SMS function of the user terminal 10 is not functioning properly. In other words, according to the second embodiment, notification of the determination result in response to a user's request can be performed with high effectiveness.
[0050] In the second embodiment, the user consents to the telecommunications carrier server 40 providing the telephone number to the determination server, thereby enabling the determination of whether the user terminal 10 is infected with malware without directly disclosing the telephone number to the determination server 30. Generally, a user may hesitate to provide such consent to a carrier with which the user is unfamiliar, especially if the user suspects malware infection. In this regard, in the second embodiment, consent is generally provided to the telecommunications carrier that the user most trusts, allowing the user to safely request a malware infection determination. Furthermore, in the second embodiment, the malware infection determination result is displayed on the infection checker application, allowing the user to check the malware infection determination result even when SMS is not functioning effectively.
[0051] 3. Variations The present invention is not limited to the above-described embodiment, and various modifications are possible. Some modifications will be described below. Two or more of the features described in the following modifications may be used in combination.
[0052] In the above embodiment, the user inputs the telephone number of the terminal to be judged (typically the telephone number of the user's own terminal), but the telephone number to be judged may be automatically determined by the user terminal 10. For example, the telephone number of the user terminal 10 stored in a storage unit of the user terminal 10 (for example, a SIM card inserted in the user terminal 10) is determined to be the telephone number of the terminal to be judged. Alternatively, one or more telephone numbers may be determined as the terminal to be judged according to a predetermined algorithm from among the telephone numbers registered in a telephone book stored in the user terminal 10. The infected telephone number database may be held not by the determination server 30 but by another server.
[0053] The method of transmitting the transmission history to the determination server 30 in step S501 is not limited to via a user operation. For example, the transmission history may be transmitted to the determination server 30 at a predetermined timing, such as 10:00 AM every day.
[0054] The transmission history transmitted to the determination server 30 in step S501 is not limited to the entire transmission history recorded in the user terminal 10, but may be a portion of the transmission history recorded in the user terminal 10. For example, the transmission history transmitted to the determination server 30 may be a transmission history from within the past week. Furthermore, the transmission history transmitted to the determination server 30 may be a portion of the transmission history selected by the user of the user terminal 10.
[0055] The method of determining whether a malware infection has occurred in step S502 is not limited to determining whether the user terminal 10 has sent messages with similar text to multiple recipients. For example, the method of determining whether a malware infection has occurred may be determining whether a fraudulent URL is included in a message sent by the user terminal 10.
[0056] In step S503, the storage means 205 may not only store the telephone number of the sender user terminal 10 infected with malware as the infected telephone number, but may also store the telephone number of the destination user terminal 10 as the telephone number that received a message from the infected telephone number. If the storage means 205 stores the telephone number of the user terminal 10 as the telephone number that received a message from the infected telephone number, in step S705 or step S912, the user terminal 10 may display, as the malware infection determination result, that there is a history of receiving a message from a telephone number suspected of being infected with malware.
[0057] In step S704, the determination server 30 may notify the user terminal 10 of the link information of the access destination as well as a password for displaying the result of the malware infection determination.
[0058] In the first embodiment, the method of notifying the result of the malware infection determination is not limited to the determination server 30 notifying the user terminal 10 of link information for displaying the result of the malware infection determination by sending a message, but may be another method. For example, a message including the text itself indicating the result of the malware infection determination may be sent to the user terminal 10.
[0059] In the second embodiment, the method of notifying the result of the malware infection determination is not limited to displaying the result on the infection checker application, and other methods may be used. For example, as in the first embodiment, the determination server 30 may notify the result of the malware infection by sending a message to the telephone number of the user terminal 10.
[0060] The correspondence between the functional elements and the hardware elements in the information processing system S is not limited to that exemplified in the embodiments. For example, some of the functions described in the embodiments as the functions of the determination server 30 may be implemented in another server. Alternatively, some of the functions described in the embodiments as the functions of the determination server 30 may be implemented in another device on the network. The determination server 30 may be a physical server or a virtual server (including a so-called cloud). Furthermore, for example, some of the functions described in the embodiments as the functions of the telecommunications carrier server 40 may be implemented in another server. Alternatively, some of the functions described in the embodiments as the functions of the telecommunications carrier server 40 may be implemented in another device on the network. The telecommunications carrier server 40 may be a physical server or a virtual server (including a so-called cloud).
[0061] The operation of the information processing system S is not limited to the above example. The order of the processing procedures of the information processing system S may be changed as long as there is no contradiction. Furthermore, some of the processing procedures of the information processing system S may be omitted. Furthermore, identification information other than a telephone number may be used as information that uniquely identifies a user terminal as a sender or receiver of information. In this case, this identification information will be registered in a database for determining whether or not the user terminal is infected with malware. In short, the information processing system of the present invention simply executes the steps of accepting input of identification information of the terminal to be judged, sending an inquiry including the input identification information to a judgment server, the judgment server referring to a database that stores identification information of malware-infected terminals to judge whether the user terminal is infected with malware, and the judgment server notifying the result of the judgment using a system that sends messages addressed to the identification information of the terminal to be judged.
[0062] The various programs exemplified in the embodiments may be provided by downloading via a network such as the Internet, or may be provided in a state recorded on a computer-readable non-transitory recording medium such as a DVD-ROM (Digital Versatile Disc Read Only Memory). [Explanation of symbols]
[0063] 10...user terminal, 20...network, 30...determination server, 40...telecommunications carrier server, 101...CPU, 102...memory, 103...storage, 104...communication IF, 105...input unit, 106...display, 201...receiving means, 202...transmitting means, 203...transmitting means, 204...acquiring means, 205...storage means, 206...determination means, 207...notifying means, 208...storage means, 209...control means, 210...control means, 301...CPU, 302...memory, 303...storage, 304...communication IF, 600...infected telephone number database, 1000...telephone number database
Claims
1. receiving, at the user terminal, input of consent information indicating consent to providing the telephone number of the user terminal to a determination server that determines whether the user terminal is infected with malware; transmitting the input consent information to a telecommunications carrier server that manages the telephone number of the user terminal; In response to a request from the determination server, the telecommunications carrier server provides the telephone number to the determination server; a step in which the determination server refers to a database storing telephone numbers of terminals infected with malware to determine whether the user terminal is infected with malware; the determination server notifying the user terminal of the result of the determination; A method for notifying a malware infection state, comprising:
2. When the determination server receives a request for confirmation of malware infection from the user terminal, the determination server causes the user terminal to access the telecommunications carrier server; When the telecommunications carrier server acquires the consent information, the telecommunications carrier server issues a token linked to the telephone number of the user terminal and transmits the token to the user terminal; When the determination server acquires the token from the user terminal, the determination server accesses the telecommunications carrier server using the acquired token; further comprising The method for notifying a malware infection state according to claim 1 .
3. The telecommunications carrier server encrypts the telephone number requested by the determination server and transmits the encrypted telephone number to the determination server; The telephone numbers registered in the database are encrypted, The determination is made in an encrypted form, The result of the determination is notified from the determination server to the user terminal. The method for notifying a malware infection state according to claim 1 .
4. The determination server acquires a history of transmissions made using a communication method in which a sender and a destination are specified by telephone numbers for a plurality of terminals; determining whether each terminal is infected with malware based on the acquired transmission history; storing the result of the determination in the database; further comprising 4. The method according to any one of claims 1 to 3.
5. On the user's computer, receiving input of consent information indicating consent to providing the telephone number of the user terminal to a determination server that determines whether the user terminal is infected with malware; transmitting the input consent information to a telecommunications carrier server that manages the telephone number of the user terminal; receiving from the determination server a result of the determination made by the determination server as to whether or not the user terminal is infected with malware by referring to a database storing telephone numbers of malware-infected terminals using the telephone number provided by the communication carrier server in response to a request from the determination server; A program to execute.
6. A user terminal and a determination server are provided, The user terminal means for receiving input of consent information indicating consent to providing the telephone number of the user terminal to a determination server that determines whether the user terminal is infected with malware; means for transmitting the input consent information to a communication carrier server that manages the telephone number of the user terminal; and The determination server means for acquiring the telephone number from the carrier server; a means for using the acquired phone number to refer to a database storing phone numbers of terminals infected with malware, and determining whether the user terminal is infected with malware; means for notifying the user terminal of the result of the determination; having Information processing system.
Citation Information
Patent Citations
Vessel for packed food
JP1981055185A
Malware-infected terminal detection apparatus, malware-infected terminal detection method and malware-infected terminal detection program
JP2013011948A