Quarantine network system and quarantine server
The quarantine network system verifies wireless access point authenticity and communication path confidentiality by inspecting client devices against security policies, addressing security vulnerabilities in existing systems.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2023-07-11
- Publication Date
- 2026-04-16
AI Technical Summary
Existing quarantine network systems fail to ensure network security when client devices connect via wireless access points with insufficient security measures, leading to risks such as information leakage and data tampering.
A quarantine network system that includes a quarantine server and wireless access point, which inspects client devices for compliance with security policies by comparing acquired wireless communication property information against a quarantine management table, ensuring the authenticity and confidentiality of wireless connections.
Enhances network security by verifying the authenticity of wireless access points and ensuring the confidentiality of wireless communication paths, preventing unauthorized connections and potential security breaches.
Smart Images

Figure 0007847105000001 
Figure 0007847105000002 
Figure 0007847105000003
Abstract
Description
Technical Field
[0001] The present invention relates to a quarantine network system and a quarantine server.
Background Art
[0002] Patent Document 1 discloses a quarantine network system that subjects to quarantine devices that apply security policies other than the security policies to which general-purpose computers should conform. In this system, the quarantine server identifies the security policy to which an embedded device should conform based on the ID information received from the embedded device, and transmits a test request to the embedded device to cause the embedded device to check whether it conforms to the identified security policy. The embedded device acquires test information for checking whether it conforms to the security policy in response to the test request, performs its own test based on the test information, and transmits the test result to the quarantine server.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] For example, as shown in Patent Document 1, there is known a quarantine network system that inspects, isolates, and treats a client device to be quarantined using a quarantine server. The quarantine server preset security inspection items for the client device, and inspects the client device based on the security inspection items when the client device connects to the network. Then, when the inspection result is qualified, the quarantine server permits the client device to connect to the network.
[0005] Using such a system, client devices with insufficient security measures can be excluded from the network. However, client devices may connect to the network via wireless access points. In this case, if the security measures of the wireless access point are insufficient, risks such as information leakage and data tampering may arise even if the client device has sufficient security measures. For example, if the wireless access point uses an encryption method with low encryption strength, security measures may be insufficient.
[0006] This invention has been made in view of the above, and one of its objectives is to provide a quarantine network system and a quarantine server that can enhance the security of a network including wireless access points.
[0007] The aforementioned and other objects and novel features of the present invention will become apparent from the description herein and the accompanying drawings. [Means for solving the problem]
[0008] A brief overview of a representative embodiment of the invention disclosed in this application is as follows:
[0009] A quarantine network system according to one embodiment comprises a client device, a wireless access point that mediates wireless access from the client device to the network, and a quarantine server that inspects the client device and determines whether the client device is compliant with quarantine based on the inspection results. When the client device connects to the network via the wireless access point, it acquires property information related to wireless communication with the wireless access point and transmits the information described in one or more target items included in the property information to the quarantine server as acquired information. The quarantine server maintains a quarantine management table in which standard information for each security inspection item is registered, using the one or more target items as security inspection items, and when it receives acquired information from the client device, it compares the acquired information with the standard information to determine whether the quarantine is compliant. [Effects of the Invention]
[0010] To briefly explain the effects obtained by a representative embodiment of the invention disclosed in this application, the security of a network including a wireless access point can be enhanced. [Brief explanation of the drawing]
[0011] [Figure 1] This is a schematic diagram showing an example configuration of a quarantine network system according to the first embodiment. [Figure 2] Figure 1 is a schematic diagram showing an example of the hardware configuration of the client device. [Figure 3] Figure 1 shows an example of property information related to wireless communication acquired by a client device. [Figure 4A] Figure 1 is a schematic diagram showing an example of the configuration of the quarantine management table maintained by the quarantine server. [Figure 4B] Figure 4A shows an example of the registered contents of the ID management table associated with the quarantine management table. [Figure 5] Figure 1 is a sequence diagram showing an example of the processing steps of the quarantine network system. [Figure 6] Figure 1 is a block diagram showing a detailed example of the functional configuration of the main parts of the client device. [Figure 7] Figure 1 is a block diagram showing a detailed example of the functional configuration of the main components of the quarantine server. [Figure 8A] This is a schematic diagram showing an example of the configuration of a quarantine management table maintained by a quarantine server in a quarantine network system according to a second embodiment. [Figure 8B] Figure 8A shows an example of the registered contents of the level management table associated with the quarantine management table. [Figure 9] This is a block diagram showing a detailed functional configuration example of the main part of the quarantine server in the quarantine network system according to the second embodiment. [Modes for carrying out the invention]
[0012] Hereinafter, embodiments of the present invention will be described in detail with reference to the drawings. In all drawings used to illustrate the embodiments, the same reference numerals are generally used for identical components, and repeated descriptions of such components will be omitted.
[0013] (Embodiment 1) <Outline of the Quarantine Network System> Figure 1 is a schematic diagram showing an example configuration of a quarantine network system according to the first embodiment. The quarantine network system shown in Figure 1 comprises an internal network 11, a gateway 12, a business server 13, a quarantine server 14, an authentication server 15, an authentication switch ASW, a wireless access point 16, and client devices TM10 and TM11. In this specification, access points are abbreviated as APs. The gateway 12, business server 13, quarantine server 14, authentication server 15, and authentication switch ASW are connected to the internal network 11.
[0014] The wireless AP 16 mediates the wireless access from the client device TM10 to the internal network 11. The authentication switch ASW is connected between the wireless AP 16 or the client device TM11 and the internal network 11. In this example, the client device TM10 is connected to the port P1 of the authentication switch ASW via the wireless AP 16. On the other hand, the client device TM11 is connected to the port Pn of the authentication switch ASW via an Ethernet (registered trademark) cable.
[0015] The client device TM10 is a mobile terminal such as a tablet terminal or a smartphone, for example, and is used by the user 17a. The client device TM11 is a personal computer or the like, for example, and is used by the user 17b. In the specification, the client devices TM10 and TM11 are collectively referred to as the client device TM, and the users 17a and 17b are collectively referred to as the user 17.
[0016] The authentication switch ASW performs network authentication of the client device TM or the user 17, and based on the authentication result, controls the relay of frames or packets between the client device TM and the internal network 11. The internal network 11 is, for example, a corporate internal network or the like, and although not shown in the figure, has a layer 2 (L2) switch, a layer 3 (L3) switch, or the like responsible for the relay of frames or packets.
[0017] The gateway 12 is a router or the like, and mediates the communication between the internal network 11 and the external network 10. The external network 10 is the Internet or the like. The business server 13 is, for example, a file server, a web server, or the like, and provides various services required for business.
[0018] The quarantine server 14 inspects the client device TM and determines whether the client device TM passes or fails quarantine based on the inspection results. Specifically, the quarantine server 14 inspects, for example, the patch application status of the OS (Operating System) and the application status of antivirus programs on the client device TM. Furthermore, as will be described in detail later, the quarantine server 14 also inspects the security status of the wireless access point 16 for client devices TM 10 that perform wireless communication. In this case, the quarantine server 14 performs the inspection using the quarantine management table 21 stored in memory 20.
[0019] The authentication server 15 works in conjunction with the authentication switch ASW to perform network authentication for client devices TM or users 17. Specifically, although not shown in the diagram, the authentication server 15 maintains an authentication table that defines the account information of client devices TM or users 17 that are permitted to perform network authentication. In response to an authentication determination request from the authentication switch ASW, the authentication server 15 performs an authentication determination based on the authentication table and sends the authentication determination result to the authentication switch ASW. The authentication server 15 is, for example, a RADIUS (Remote Authentication Dial In User Service) server.
[0020] Figure 2 is a schematic diagram showing an example of the hardware configuration of the client device TM in Figure 1. The client device TM shown in Figure 2 is implemented by a computer system including a computer 25, a display 26, and a user input interface 27. The computer 25 includes a processor 30 such as a CPU (Central Processing Unit), memory 31, a communication interface (IF) 32, and a bus 33 connecting them. The memory 31 is composed of a combination of volatile memory such as DRAM (Dynamic Random Access Memory) and SRAM (Static Random Access Memory), and non-volatile memory such as flash memory, SSD (Solid State Drive), and HDD (Hard Disk Drive).
[0021] Memory 31 holds a security inspection program 34, which will be described in detail later. The processor 30 executes the security inspection program 34 to realize the quarantine function in the client device TM. The communication interface 32 is, for example, a wireless LAN interface in the case of client device TM10 in Figure 1, and a wired LAN interface in the case of client device TM11. The client device TM is connected to the authentication switch ASW via the communication interface 32.
[0022] The display 26 is, for example, a liquid crystal display, an organic EL (Electro-Luminescence) display, and displays information based on image signals from the computer 25. The user input interface 27 is a touch panel integrated with the display 26, or a keyboard and mouse, and outputs input signals based on the user 17's operations to the computer 25. The business server 13, quarantine server 14, and authentication server 15 shown in Figure 1 can also be implemented using such a computer.
[0023] <Method for determining whether quarantine inspection is successful or not> Figure 3 shows an example of wireless communication property information acquired by the client device TM10 in Figure 1. The client device TM10 uses the security inspection program 34 to acquire wireless communication property information 35 with the wireless AP16 with which it is connected.
[0024] Specifically, if the client device TM10 is equipped with, for example, the Windows® OS, it can obtain property information 35 as shown in Figure 3 by executing a command such as "netsh wlan show interfaces". The property information 35 includes multiple items representing wireless communication settings, status information, attribute information, etc.
[0025] In the example shown in Figure 3, the property information 35 includes, as part of several items, a target item 36a representing the physical address, i.e., the MAC (Media Access Control) address, and a target item 36b representing the SSID (Service Set IDentifier). Furthermore, the property information 35 includes, as part of several other items, a target item 36c representing the type of wireless, a target item 36d representing authentication, and a target item 36e representing encryption.
[0026] When the client device TM10 connects to the internal network 11 via the wireless AP16, it acquires such property information 35. The client device TM10 then transmits the information contained in one or more target items in the property information 35, in this example five target items 36a-36e, to the quarantine server 14 as acquired information 37.
[0027] Figure 4A is a schematic diagram showing an example of the configuration of the quarantine management table 21 maintained by the quarantine server 14 in Figure 1. Figure 4B is a diagram showing an example of the registered contents of the ID management table associated with the quarantine management table 21 shown in Figure 4A. In the quarantine management table 21, as shown in Figure 4A, the five target items 36a-36e shown in Figure 3 are designated as security inspection items 40a-40e, and standard information 41 for each security inspection item 40a-40e is registered in advance by the administrator. The standard information 41 is information that serves as the criteria for determining whether quarantine is successful or not, and is determined based on the administrator's security policy.
[0028] Security inspection item 40a is an item representing the MAC address. The administrator registers the MAC address information of the wireless AP 16 that is legally installed on the internal network 11 as the reference information 41 for security inspection item 40a. Security inspection item 40b is an item representing the SSID. The administrator registers the SSID information that is legally configured for the legal wireless AP 16 as the reference information 41 for security inspection item 40b.
[0029] Security inspection item 40c is an item representing the wireless connection method, which corresponds to item 36c representing the type of wireless. Security inspection item 40d is an item representing the wireless authentication standard, which corresponds to item 36d representing authentication. Security inspection item 40e is an item representing the encryption method, which corresponds to item 36e representing encryption. In this example, the administrator registers the ID values based on the ID management tables 45a-45c shown in Figure 4B as the reference information 41 for each of the security inspection items 40c-40e.
[0030] The ID management table 45a shown in Figure 4B is a table for wireless connection methods, and an ID value is assigned to each type of wireless connection method. Examples of wireless connection methods include IEEE 802.11a, b, g, n, ac, which are also transmission standards for wireless LANs. Wireless LAN transmission standards specify, for example, the frequency band used, the modulation method, the transmission speed, etc.
[0031] The ID management table 45b shown in Figure 4B is a table for wireless authentication standards, assigning ID values to each type of wireless authentication standard. Examples of wireless authentication standards include WEP (Wired Equivalent Privacy), WPA (Wi-Fi Protected Access), WPA2, and WPA3. In WEP, shared key authentication is performed using a WEP key, such as a 104-bit key. However, it is known that WEP keys can be deciphered relatively easily by intercepting wireless communications.
[0032] On the other hand, WPA was developed as a successor to WEP, and with each generation incorporating countermeasures against vulnerabilities, it has been improved in the order of WPA, WPA2, and WPA3. For example, WPA3 uses elliptic curve cryptography calculated based on passwords, etc., to perform a Simultaneous Authentication of Equals (SAE) handshake between the client device TM10 and the wireless AP16, enabling highly secure authentication.
[0033] The ID management table 45c shown in Figure 4B is a table for encryption methods, assigning an ID value to each type of encryption method. Examples of encryption methods include WEP, TKIP (Temporal Key Integrity Protocol), and CCMP (Counter mode with Cipher-block chaining Message authentication code Protocol). In WEP, the plaintext is encrypted using a 128-bit encryption key generated by adding a 24-bit IV (Initial Vector) to the aforementioned WEP key, and the stream cipher encryption algorithm RC4 (Rivest Cipher 4).
[0034] TKIP uses the RC4 encryption algorithm but increases its encryption strength compared to WEP by introducing a dynamically changing temporary key (TK) and extending the number of bits in the IV. CCMP uses the Advanced Encryption Standard (AES), a block cipher encryption algorithm, instead of RC4, and encrypts the counter value with the encryption key, and then encrypts the plaintext using the encrypted counter value.
[0035] When WEP is used as the wireless authentication standard, WEP is also used as the encryption method. On the other hand, when WPA or WPA2 is used as the wireless authentication standard, you can choose to use TKIP or CCMP as the encryption method. Furthermore, when WPA3 is used as the wireless authentication standard, you can choose to use CCMP or GCMP (Galois Counter Mode Protocol), which is not illustrated, as the encryption method. GCMP is a standard that extends CCMP to enable parallel processing by using a Galois field.
[0036] Furthermore, the quarantine management table 21 shown in Figure 4A can register additional information for each entry, in addition to the standard information 41 for security inspection items 40a-40e. In the example shown in Figure 4A, the additional information includes the access point (AP) name set for the wireless AP 16, the manufacturer of the wireless AP 16, and the location where the wireless AP 16 is installed. By registering this additional information in the quarantine management table 21, administrators can centrally manage all necessary information regarding the wireless AP 16.
[0037] The quarantine server 14 determines whether the quarantine is successful or unsuccessful based on the quarantine management table 21. More specifically, when the quarantine server 14 receives acquired information 37 from the client device TM10, it compares the acquired information 37 with the reference information 41 to determine whether the quarantine is successful or unsuccessful. More specifically, the quarantine server 14 first compares the acquired information 37 for target items 36a and 36b with the reference information 41 for security inspection items 40a and 40b. Then, the quarantine server 14 determines whether an entry with matching pair information for the acquired information 37 for target items 36a and 36b, i.e., MAC address and SSID pair information, is registered in the quarantine management table 21.
[0038] The quarantine server 14 determines that the quarantine has failed if no entry matching the pair information is registered in the quarantine management table 21. In this case, the client device TM10 is not permitted to connect to the internal network 11, for example, to the business server 13. As a result, in order for the client device TM10 to connect to the internal network 11 via the wireless AP 16, the wireless AP 16 must be registered in the quarantine management table 21. Consequently, the authenticity of the wireless AP 16 can be verified, and for example, connections to the internal network 11 via a wireless AP 16 that has been brought in illegally can be prevented.
[0039] Meanwhile, if an entry matching the pair information is registered in the quarantine management table 21, the quarantine server 14 verifies the remaining security inspection items 40c-40e in the hit entry. Specifically, the quarantine server 14 determines whether the acquired information 37 for items 36c, 36d, and 36e matches the reference information 41 for security inspection items 40c, 40d, and 40e. For example, in Figure 4A, if the quarantine server 14 receives MAC address "MA02" and SSID "SS02" as acquired information 37, it determines whether the wireless connection method is IEEE802.11ac, the wireless authentication standard is WPA3, and the encryption method is CCMP.
[0040] The quarantine server 14 determines that the quarantine has failed if there are security inspection items 40c-40e that have been determined to be inconsistent, and determines that the quarantine has passed if there are no security inspection items 40c-40e that have been determined to be inconsistent. If the quarantine has failed, the client device TM10 is not permitted to connect to the internal network 11. On the other hand, if the quarantine has passed, and network authentication by the authentication server 15 is also permitted, the client device TM10 is permitted to connect to the internal network 11.
[0041] These security inspection items 40c, 40d, and 40e allow verification that the wireless connection method, wireless authentication standard, and encryption method used during wireless communication satisfy the security policy defined in Quarantine Management Table 21. As a result, the confidentiality of the wireless communication path can be ensured. In this way, the authenticity of the wireless AP16 and the confidentiality of the wireless communication path can be verified, thereby enhancing network security.
[0042] Furthermore, the security check items used to verify the authenticity of wireless AP16 do not necessarily have to be both security check items 40a and 40b, i.e., both the MAC address and the SSID; either one alone may suffice. However, MAC addresses can be spoofed in some cases, and SSIDs can be arbitrarily changed by administrators. Therefore, to perform more reliable verification, it is desirable to use both MAC address and SSID as security check items 40a and 40b.
[0043] Similarly, the security inspection items for verifying the confidentiality of wireless communication paths do not necessarily have to include all of security inspection items 40c, 40d, and 40e, i.e., all of the wireless connection method, wireless authentication standard, and encryption method; it is sufficient to include at least one of security inspection items 40c, 40d, or 40e. In this case, which security inspection items to apply may vary depending on the administrator's security policy. Accordingly, the quarantine management table 21 should be configured so that the administrator can arbitrarily select whether or not to apply each security inspection item 40a-40e.
[0044] Furthermore, the types of security inspection items are not necessarily limited to the security inspection items 40a-40e shown in Figure 4A. In other words, the security inspection items only need to be items from which information can be obtained by the client device TM10, at least in the same manner as in Figure 3. For example, if the client device TM10 can obtain the model of the wireless AP16, this may be designated as a security inspection item. In this case, the wireless connection method, wireless authentication standard, and encryption method may be identified by the model of the wireless AP16.
[0045] <Operation of the Quarantine Network System> Figure 5 is a sequence diagram showing an example of the processing content of the quarantine network system in Figure 1. First, as a prerequisite, the authentication switch ASW restricts network access in advance to allow only access from client device TM10 to the quarantine server 14 (step S10a). Specifically, the authentication switch ASW uses, for example, an authentication VLAN (Virtual Local Area Network) function to assign a VLAN to client device TM10, which is not permitted to perform network authentication, that allows only access to the quarantine server 14.
[0046] Furthermore, the administrator pre-registers standard information 41 based on security policies, etc., in the quarantine management table 21 shown in Figure 4A on the quarantine server 14 (step S10b). Based on this premise, the quarantine network system executes the processes from step S11 onwards shown in Figure 5.
[0047] First, the client device TM10 requests a connection to the internal network 11 via the wireless AP16 and the authentication switch ASW (step S11). At this time, the authentication switch ASW sends the network connection request to the quarantine server 14 using the authentication VLAN function described above or a pre-configured redirection function. In response to the network connection request from the client device TM10, the quarantine server 14 requests the client device TM10 to execute the security inspection program 34 (step S12). Note that the network connection request refers to a connection request made while connection to the internal network 11 is restricted.
[0048] In step S12, the quarantine server 14 prompts the client device TM10 to download the security inspection program 34 if it has not already been downloaded. Specifically, the quarantine server 14 holds the executable file of the security inspection program in memory 20, for example. The quarantine server 14 displays a link or button on the client device TM10's display 26, for example, a web screen, to allow the client device TM10 to download the executable file from memory 20. When user 17a selects such a link, the client device TM10 downloads the executable file from the quarantine server 14 to its own memory 31.
[0049] Next, the client device TM10 starts the security inspection program 34 stored in memory 31 (step S13). At this time, the client device TM10 may download the executable file of the security inspection program 34 in step S12 and then automatically start the downloaded security inspection program 34.
[0050] Note that the download and startup of the security inspection program 34 in steps S12 and S13 may be performed each time a network connection request is made from the client device TM10 in step S11. Alternatively, the quarantine server 14 may cause the client device TM10 to download the program when it receives the first network connection request from the client device TM10. In this case, when the quarantine server 14 receives the second and subsequent network connection requests from the client device TM10, it only needs to cause the client device TM10 to run the downloaded security inspection program 34, unless there are any updates to the security inspection program 34.
[0051] Furthermore, the download source for the executable file of the security inspection program 34 does not necessarily have to be the quarantine server 14; it could be a business server 13 connected to the internal network 11, such as a file server. In other words, the quarantine server 14 only needs to know the link to the download source. Subsequently, the client device TM10, more specifically the processor 30 of the client device TM10, executes the security inspection program 34, thereby performing the processes of the following steps S14, S15, S18a-1, S18a-2, and S18b.
[0052] In step S14, the client device TM10 acquires property information 35 related to wireless communication with the wireless AP16, as shown in Figure 3. The client device TM10 then transmits the information described in predetermined target items 36a-36e included in the property information 35 as acquired information 37 to the quarantine server 14 (step S15). The quarantine server 14 receives the acquired information 37 from the client device TM10 and, as described in Figures 3 and 4A, compares the acquired information 37 with the standard information 41 registered in the quarantine management table 21 to determine whether the quarantine is successful or not (step S16). The quarantine server 14 then transmits the result of the quarantine success or failure determination to the client device TM10 (step S17).
[0053] If the pass / fail judgment result received in step S17 is a pass, the client device TM10 notifies the user 17a of the successful quarantine, for example, by displaying a message on the display 26 stating "Quarantine has passed" (step S18a-1). Furthermore, the client device TM10 sends a network authentication request to the authentication switch ASW (step S18a-2).
[0054] In step S18a-2, for example, if web authentication is used, the client device TM10 displays an account input screen on the display 26 in response to a response from the authentication switch ASW, prompting the user 17a to enter account information. The client device TM10 then sends a network authentication request to the authentication switch ASW based on the entered account information. Note that the network authentication request may be sent using the OS or the like instead of the security inspection program 34 of the client device TM10.
[0055] Upon receiving a network authentication request, the authentication switch ASW performs network authentication processing (step S18a-3). Specifically, the authentication switch ASW sends a request to the authentication server 15 to determine whether to allow or deny network authentication based on the received account information. The authentication switch ASW then receives the network authentication determination result from the authentication server 15 and sends the determination result to the client device TM10 (step S18a-4).
[0056] Furthermore, in step S18a-3, if the authentication switch ASW determines that network authentication is permitted, it removes the network restriction on the client device TM10. Specifically, the authentication switch ASW assigns the client device TM10 a VLAN with the network restriction removed, for example, using an authentication VLAN function. As a result, the client device TM10 becomes able to access, for example, the business server 13. On the other hand, if the authentication switch ASW determines that network authentication is not permitted, it does not remove the network restriction. Note that network authentication is not limited to web authentication; it may also be MAC address authentication or authentication using digital certificates, etc.
[0057] On the other hand, if the pass / fail judgment result received in step S17 is a failure, the client device TM10 notifies the user 17a of the quarantine failure, for example, by displaying a message on the display 26 stating that "Quarantine for the wireless AP has failed" (step S18b). Also, in this example, unlike when the quarantine is passed, the client device TM10 does not send a network authentication request to the authentication switch ASW when the quarantine fails. As a result, network authentication is not performed, and the network restriction is not lifted.
[0058] However, the method is not limited to this one. For example, a method may be used in which the authentication switch ASW does not lift the network restriction regardless of whether or not a network authentication request has been made. In other words, the authentication switch ASW can recognize that the quarantine for the client device TM10 has failed through the processing in step S17. In this case, even if the authentication switch ASW subsequently receives a network authentication request from the client device TM10, it will not perform the network authentication processing in step S18a-3.
[0059] Furthermore, in step S18b, the client device TM10 may notify the administrator of the quarantine failure not only to the user 17a but also via email or other means. In this case, the client device TM10 should notify the user 17a and the administrator, including the reasons why the quarantine failed. As a specific example, consider the case in Figure 4A where entry "2" is hit, and consequently, the standard information 41 for the encryption method is CCMP.
[0060] If the quarantine server 14 receives TKIP as the acquired information 37 for the target item 36e, it determines that the quarantine has failed and, in step S17, sends information to the client device TM10 stating that "the quarantine has failed because the encryption method is not CCMP." User 17a, upon seeing this information, may take action by, for example, changing the encryption method of the communication IF32 on the client device TM10, specifically the wireless LAN client device, to CCMP.
[0061] On the other hand, it is also possible that the root cause of the quarantine failure lies in a configuration error on the wireless AP16, for example. A specific example would be a case where, although the encryption method on the wireless AP16 should ideally be set to CCMP only, both CCMP and TKIP are enabled, and TKIP is selected between the wireless AP16 and the client device TM10. Therefore, in order to have the administrator verify the possibility of such a configuration error, it is desirable for the quarantine server 14 to notify the administrator, including the reasons why the quarantine failed. This notification to the administrator may also be made by the client device TM10.
[0062] Here, network restrictions were implemented using an authentication switch (ASW), but instead, network restrictions could be implemented using methods such as a personal firewall, an authenticated DHCP (Dynamic Host Configuration Protocol) method, or an ARP (Address Resolution Protocol) spoofing method. In this case, the authentication switch (ASW) is not required in Figure 1.
[0063] The personal firewall method is a method that restricts access to the internal network 11 using a personal firewall installed on the client device TM10. When using this method, the quarantine server 14 determines whether the quarantine is successful or not using the quarantine management table 21, as in step S16, and in step S17, it should send the success or failure determination result to the client device TM10.
[0064] If client device TM10 receives notification from quarantine server 14 that quarantine has failed, it controls its personal firewall via security inspection program 34 to maintain the network restriction in effect. On the other hand, if client device TM10 receives notification from quarantine server 14 that quarantine has passed, it controls its personal firewall via security inspection program 34 to remove the network restriction.
[0065] The authentication DHCP method is a method that restricts connection to the internal network 11 using a DHCP server (not shown). When using this method, the DHCP server, for example, pre-assigns a test IP address to the client device TM10, and if the quarantine is successful, assigns an IP address with network restrictions lifted. When using this method, the quarantine server 14 only needs to send the pass / fail judgment result to the DHCP server in step S17.
[0066] The ARP spoofing method is a method of restricting access to the internal network 11 by connecting the sensor device to a regular Layer 2 (L2) switch installed in place of the authentication switch ASW, for example. When communication begins, the client device TM10 usually obtains the MAC address corresponding to the IP address of the communication partner using an ARP command. At this time, the sensor device detects the ARP command from the client device TM10, and if the quarantine fails, it responds to the client device TM10 with its own MAC address or the like, which is not the legitimate MAC address. When using this method, the quarantine server 14 only needs to send the pass / fail judgment result to the sensor device in step S17.
[0067] <Variations on how to download / start the security inspection program> In the example shown in Figure 5, the client device TM10 downloaded and started the security inspection program 34 triggered by a network connection request in step S11, such as launching a web browser. Alternatively, the client device TM10 may download and start the security inspection program 34 by accessing the quarantine server 14 based on a logon script during logon.
[0068] <Variations on quarantine timing> In the example shown in Figure 5, quarantine was performed using the security inspection program 34, triggered by a network connection request being sent from the client device TM10 to the quarantine server 14. However, the security inspection program 34 may be a resident program that constantly monitors wireless communication. In this case, the client device TM10 can use the security inspection program 34 to execute steps S14 and S15 not only when connecting to the network, but also when detecting, for example, a dynamic switch of the wireless AP16. If the quarantine fails, the authentication switch ASW or the security inspection program 34 can block communication from the client device TM10.
[0069] <Details of the Security Inspection Program> Figure 6 is a block diagram showing a detailed functional configuration example of the main parts of the client device TM in Figure 1. The client device TM shown in Figure 6 includes, for example, a communication interface 32 such as a wireless LAN interface, as well as a property information acquisition unit 50, a pass / fail judgment request unit 51, a judgment result receiving unit 52, and a network authentication request unit 53. Each of these units is realized by the processor 30 of the client device TM executing a security inspection program 34 in the memory 31. In other words, the security inspection program 34 causes the computer 25 to function as the property information acquisition unit 50, the pass / fail judgment request unit 51, the judgment result receiving unit 52, and the network authentication request unit 53.
[0070] The property information acquisition unit 50 acquires property information 35 related to wireless communication with the wireless AP 16, as shown in step S14 in Figure 5. The pass / fail judgment request unit 51, as shown in step S15 in Figure 5, takes the information described in one or more target items included in the acquired property information 35 as acquired information 37 and sends a pass / fail judgment request based on the acquired information 37 to the quarantine server 14.
[0071] The judgment result receiving unit 52 receives the quarantine pass / fail judgment result from the quarantine server 14, as shown in step S17 in Figure 5. The network authentication request unit 53 sends a network authentication request to the authentication switch ASW if the quarantine pass / fail judgment result is a pass, as shown in step S18a-2 in Figure 5.
[0072] <Quarantine Server Details> Figure 7 is a block diagram showing a detailed functional configuration example of the main parts of the quarantine server 14 in Figure 1. The quarantine server 14 shown in Figure 7 comprises a connection request receiving unit 55, a pass / fail determination unit 56, and a memory 20. Each of these parts is implemented, for example, by the processor of the quarantine server 14 executing a quarantine management program (not shown) in the memory 20. However, each of these parts is not limited to this software implementation form, but may also be implemented with hardware such as an FPGA (Field Programmable Gate Array) or ASIC (Application Specific Integrated Circuit), or with a combination of software and hardware.
[0073] As shown in Figure 4A, memory 20 holds a quarantine management table 21 in which standard information 41 for each security inspection item 40a-40e is registered. Memory 20 also holds an executable file 58 of the security inspection program to be downloaded by the client device TM. Furthermore, although not shown in the figure, memory 20 also holds ID management tables 45a, 45b, and 45c in detail, as shown in Figure 4B.
[0074] As shown in steps S11 and S12 in Figure 5, the connection request receiving unit 55 receives a connection request from the client device TM to the internal network 11 via the authentication switch ASW. In response to the connection request, the connection request receiving unit 55 requests the client device TM to execute the security inspection program 34. At this time, as described in step S12, if the security inspection program 34 has not been downloaded to the client device TM, the connection request receiving unit 55 prompts the client device TM to download the security inspection program 34.
[0075] Specifically, the connection request receiving unit 55 displays a screen on the client device TM, for example, a screen containing a link or button to the executable file 58 of the security inspection program stored in memory 20, allowing the client device TM to download the executable file 58. When the user 17 selects such a link, the client device TM downloads the security inspection program 34 from the quarantine server 14 and executes it.
[0076] As shown in steps S15 and S16 in Figure 5, the pass / fail determination unit 56, upon receiving acquired information 37 from the client device TM, compares the acquired information 37 with the standard information 41 in the quarantine management table 21 to determine whether the quarantine is successful or not. The pass / fail determination unit 56 then transmits the pass / fail determination result to the client device TM via the authentication switch ASW. More specifically, the pass / fail determination unit 56 acquires an ID corresponding to the acquired information 37 based on the ID management tables 45a, 45b, and 45c, and compares the acquired ID with the ID registered as standard information 41 in the quarantine management table 21.
[0077] <Main effects of the first embodiment> As described above, in the first embodiment, information regarding wireless communication with the wireless AP16 is acquired by the client device TM, and the acquired information is verified by the quarantine server 14. This enables not only quarantine of the client device TM, but also, in effect, quarantine of the wireless AP16, allowing verification of the authenticity of the wireless AP16 and the confidentiality of the wireless communication path. As a result, it becomes possible to enhance the security of the network including the wireless AP16.
[0078] (Second Embodiment) <Method for determining whether quarantine inspection is successful or not> FIG. 8A is a schematic diagram showing a configuration example of a quarantine management table 21b held by a quarantine server 14 in a quarantine network system according to a second embodiment. FIG. 8B is a diagram showing an example of registration contents of a level management table associated with the quarantine management table 21b shown in FIG. 8A. The configuration of the quarantine network system according to the second embodiment is the same as the configuration shown in FIG. 1. However, the quarantine server 14 holds a quarantine management table 21b as shown in FIG. 8A in the memory 20. Further, the quarantine server 14 also holds level management tables 65a, 65b, 65c as shown in FIG. 8B in the memory 20.
[0079] The level management tables 65a, 65b, 65c shown in FIG. 8B define the relationship between the information that can be registered within each security inspection item representing the wireless connection method, wireless authentication standard, and encryption method, and the permission level. The level management table 65a is for the wireless connection method, and is preset so that the permission level increases in the order of IEEE802.11a < b < g < n < ac, for example. The level management table 65b is for the wireless authentication standard, and is preset so that the permission level increases in the order of WEP < WPA < WPA2 < WPA3, for example. The level management table 65c is for the encryption method, and is preset so that the permission level increases in the order of WEP < TKIP < CCMP, for example.
[0080] Also, different from the quarantine management table 21 shown in FIG. 4A, in the quarantine management table 21b shown in FIG. 8A, the reference permission level instead of the ID is registered as the reference information 61 within the security inspection items 60c - 60e representing the wireless connection method, wireless authentication standard, and encryption method. The quarantine server 14 executes the processes of steps S15 and S16 shown in FIG. 5 using such a quarantine management table 21b and level management tables 65a, 65b, 65c.
[0081] In detail, when the quarantine server 14 receives acquired information 37 from the client device TM10, it acquires the permission level of the acquired information 37 based on the level management tables 65a, 65b, and 65c. The quarantine server 14 then compares the acquired permission level with the standard permission level in the quarantine management table 21b to determine whether the quarantine is successful or not. Specifically, for example, if the acquired permission level is equal to or higher than the standard permission level, the quarantine server 14 determines that the quarantine is successful, and if the acquired permission level is lower than the standard permission level, it determines that the quarantine is unsuccessful.
[0082] As a concrete example, let's assume that the quarantine server 14 receives the MAC address "MA02", the SSID "SS02", and the encryption method "CCMP" as acquired information 37. For the sake of simplicity, the wireless connection method and wireless authentication standard are ignored here. In this case, the quarantine server 14 acquires "Level 4" as the permission level corresponding to "CCMP" based on the level management table 65c. Meanwhile, in the quarantine management table 21b, entry "2" is hit, and "Level 2" is registered as the standard permission level for the encryption method.
[0083] The quarantine server 14 determines that the quarantine is successful because the permission level "Level 4" obtained based on the level management table 65c is higher than the standard permission level "Level 2" registered in the quarantine management table 21b. On the other hand, if the quarantine server 14 receives "WEP" as the encryption method information 37, it determines that the quarantine is unsuccessful because the permission level for "WEP" is "Level 1".
[0084] <Quarantine Server Details> Figure 9 is a block diagram showing a detailed functional configuration example of the main part of the quarantine server 14 in the quarantine network system according to the second embodiment. The quarantine server 14 shown in Figure 9 differs from the configuration example shown in Figure 7 in the following ways. The first difference is that the memory 20 holds the quarantine management table 21b shown in Figure 8A, and also holds the level management tables 65 shown in Figure 8B. The second difference is that a pass / fail determination unit 56b different from the one in Figure 7 is provided.
[0085] As described above, when the pass / fail determination unit 56b receives the acquired information 37 from the client device TM, it acquires the permission level of the acquired information 37 based on the level management table 65. The pass / fail determination unit 56b then compares the acquired permission level with the standard permission level in the quarantine management table 21b to determine whether the quarantine is successful or not.
[0086] <Main effects of the second embodiment> As described above, the same effects as those described in the first embodiment can be obtained by using the method of the second embodiment. Furthermore, compared to the method of the first embodiment, the management of the quarantine management table 21b by the administrator and the pass / fail judgment processing of quarantine by the quarantine server 14 can be simplified. That is, for example, it is possible to register multiple IDs as standard information 41 for each security inspection item 40c-40e in Figure 4A. In this case, the management of the table by the administrator becomes more complex, and furthermore, in the pass / fail judgment processing, it is necessary to compare one ID obtained from the acquired information 37 with multiple IDs. The method of the second embodiment can resolve these problems.
[0087] The present invention has been described in detail above based on embodiments, but the present invention is not limited to the embodiments described above and can be modified in various ways without departing from its essence. For example, the embodiments described above are described in detail in order to explain the present invention in an easy-to-understand manner and are not necessarily limited to those having all the described configurations. Furthermore, it is possible to replace a part of the configuration of one embodiment with the configuration of another embodiment, and it is also possible to add a configuration from another embodiment to the configuration of one embodiment. In addition, it is possible to add, delete, or replace a part of the configuration of each embodiment with a configuration from another embodiment.
[0088] For example, the various programs mentioned above can be stored in a non-temporary, tangible, computer-readable recording medium and then supplied to a computer. Examples of such recording media include magnetic recording media such as hard disk drives, optical recording media such as DVDs (Digital Versatile Discs) and Blu-ray discs, and semiconductor memory such as flash memory. [Explanation of Symbols]
[0089] 11: Internal network, 14: Quarantine server, 16: Wireless access point, 20, 31: Memory, 21, 21b: Quarantine management table, 25: Computer, 34: Security inspection program, 35: Property information, 36a-36e: Target items, 37: Acquired information, 40a-40e, 60c-60e: Security inspection items, 41, 61: Standard information, 50: Property information acquisition unit, 51: Pass / fail judgment request unit, 52: Judgment result reception unit, 53: Network authentication request unit, 55: Connection request acceptance unit, 56, 56b: Pass / fail judgment unit, 65: Level management table, ASW: Authentication switch, TM: Client device
Claims
1. Client device and A wireless access point that mediates wireless access from the client device to the network, A quarantine server that inspects the client device and determines whether the client device is compliant with quarantine based on the inspection results, A quarantine network system comprising, The aforementioned client device When connecting to the network via the aforementioned wireless access point, property information relating to wireless communication with the wireless access point is acquired. The information described in one or more target items included in the aforementioned property information is transmitted to the quarantine server as acquired information. The aforementioned quarantine server, The system maintains a quarantine management table in which the standard information for each of the aforementioned one or more target items is registered, with the aforementioned one or more target items as security inspection items. When the acquired information is received from the client device, the system compares the acquired information with the reference information to determine whether the client device is compliant with the quarantine requirements. The aforementioned security inspection items include an item representing at least one of the following: wireless connection method, wireless authentication method, or encryption method. The aforementioned quarantine server, A level management table is maintained that defines the relationship between the information that can be registered in the aforementioned security inspection items and the permission level. The standard information in the quarantine management table contains the standard permit level, When the acquired information is received from the client device, the permission level of the acquired information is obtained based on the level management table. The relationship between the acquired permit level and the standard permit level in the quarantine management table is compared. Quarantine network system.
2. In the quarantine network system described in claim 1, The security inspection items include an item representing the MAC address or SSID of the wireless access point. Quarantine network system.
3. A client device and A wireless access point that mediates wireless access from the client device to the network, A quarantine server that inspects the client device and determines whether the client device is compliant with quarantine based on the inspection results, A quarantine network system comprising, The aforementioned client device When connecting to the network via the aforementioned wireless access point, property information relating to wireless communication with the wireless access point is acquired. The information described in one or more target items included in the aforementioned property information is transmitted to the quarantine server as acquired information. The aforementioned quarantine server, The system maintains a quarantine management table in which the standard information for each of the aforementioned one or more target items is registered, with the aforementioned one or more target items as security inspection items. When the acquired information is received from the client device, the system compares the acquired information with the reference information to determine whether the client device is compliant with the quarantine requirements. The aforementioned client device is implemented using a computer. When the client device requests to connect to the network, the quarantine server requests the client device to run a security inspection program. The client device executes the security inspection program, A property information acquisition unit that acquires the aforementioned property information, A pass / fail determination request unit transmits a quarantine pass / fail determination request to the quarantine server based on the acquired information included in the property information. A judgment result receiving unit that receives the quarantine pass / fail judgment result from the quarantine server. Functions as, Quarantine network system.
4. In the quarantine network system described in claim 3, The wireless access point and the network are connected and include an authentication switch that performs network authentication for the client device, The client device, by executing the security inspection program, further functions as a network authentication request unit that transmits a network authentication request to the authentication switch if the pass / fail judgment result of the quarantine received by the judgment result receiving unit is a pass. Quarantine network system.
5. A quarantine server that inspects client devices connected to a network via a wireless access point and determines whether the client devices are compliant with quarantine based on the inspection results, Assuming that the client device acquires property information relating to wireless communication with the wireless access point, and transmits the information described in one or more target items included in the property information to the quarantine server as acquired information, The aforementioned quarantine server, A memory that holds a quarantine management table in which standard information for each of the aforementioned one or more target items is registered as security inspection items, A pass / fail determination unit, upon receiving the acquired information from the client device, compares the acquired information with the reference information to determine whether the client device is eligible for quarantine, Equipped with, The aforementioned security inspection items include an item representing at least one of the following: wireless connection method, wireless authentication method, or encryption method. The memory maintains a level management table that defines the relationship between information that can be registered in the security inspection items and the permission level. The standard information in the quarantine management table contains the standard permit level, When the pass / fail determination unit receives the acquired information from the client device, it obtains the permission level of the acquired information based on the level management table, and compares the relationship between the obtained permission level and the standard permission level in the quarantine management table. Quarantine server.
6. In the quarantine server described in claim 5, The security inspection items include an item representing the MAC address or SSID of the wireless access point. Quarantine server.
7. A quarantine server that inspects a client device connected to a network via a wireless access point and determines whether the client device is quarantined based on the inspection results, Assuming that the client device acquires property information relating to wireless communication with the wireless access point, and transmits the information described in one or more target items included in the property information to the quarantine server as acquired information, The aforementioned quarantine server, A memory that holds a quarantine management table in which standard information for each of the aforementioned one or more target items is registered as security inspection items, A pass / fail determination unit, upon receiving the acquired information from the client device, compares the acquired information with the reference information to determine whether the client device is eligible for quarantine, Equipped with, The system includes a connection request receiving unit that receives a connection request from the client device to the network and, in response to the connection request, requests the client device to execute a security inspection program. The security inspection program uses the client device to A property information acquisition unit that acquires the aforementioned property information, A pass / fail determination request unit transmits a quarantine pass / fail determination request to the quarantine server based on the acquired information included in the property information. A judgment result receiving unit that receives the quarantine pass / fail judgment result from the quarantine server. This is a program designed to function as such. Quarantine server.
8. In the quarantine server described in claim 7, The security inspection program uses the client device to If the quarantine pass / fail judgment result received by the judgment result receiving unit is a pass, the network authentication request unit sends a network authentication request to the authentication switch. This is a program to make it function even better. Quarantine server.
Citation Information
Patent Citations
Information system setting device, information system setting method and program
JP2006184936A
Method for cooperatively finding out disconnected client, and unauthorized access point within wireless network
JP2007089006A
Quarantine network system and quarantine client
JP2012198659A
Method and system for remote identification of wireless LAN master unit
JP2014057232A