Network testing device, network testing program, network testing method, and network testing system

The network inspection device detects unauthorized connections using spoofed packets and gateway monitoring, addressing limitations of existing systems by identifying security issues across diverse connection methods without additional software, thereby improving network security.

JP7861549B2Active Publication Date: 2026-05-19OKI ELECTRIC INDUSTRY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
OKI ELECTRIC INDUSTRY CO LTD
Filing Date
2022-07-08
Publication Date
2026-05-19

AI Technical Summary

Technical Problem

Existing network inspection systems fail to detect unauthorized relay connections using methods other than wireless LAN communication (Wi-Fi) and require dedicated programs on protected devices.

Method used

A network inspection device that transmits inspection packets with spoofed source addresses, monitors response packets at a gateway, and checks for security-inappropriate settings based on the received packets, supporting detection of unauthorized connections via USB tethering, Bluetooth tethering, and wired LAN relay connections without requiring additional software on inspected devices.

Benefits of technology

Enables comprehensive detection of security-inappropriate settings across various communication devices, independent of their connection configurations, enhancing network security by identifying unauthorized access attempts.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007861549000001
    Figure 0007861549000001
  • Figure 0007861549000002
    Figure 0007861549000002
  • Figure 0007861549000003
    Figure 0007861549000003
Patent Text Reader

Abstract

To detect unauthorized settings on security in each of communication devices, regardless of connection configuration of the communication devices connected to a network to be inspected.SOLUTION: There is provided a network inspection apparatus including: inspection packet transmission means which transmits, to an inspection target device connected to a network to be inspected, an inspection packet including an address not used in the network to be inspected set for a transmission source address; and inspection processing means which holds monitor data including information on a packet received on a gateway provided on a path to access an external network from the network to be inspected, performs response packet detection processing to try to detect a response packet transmitted by the inspection target device in response to the inspection packet from the monitor data, and performs inspection processing to inspect whether the inspection target device includes unauthorized settings on security on the basis of a result of the response packet detection processing.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a network inspection apparatus, a network inspection program, a network inspection method, and a network inspection system, and can be applied to, for example, a system for detecting devices that can pose a threat to an internal network in an IP communication network.

Background Art

[0002] Currently, in a network (for example, a corporate internal network, etc.; hereinafter also referred to as an "internal network") to which a plurality of devices (for example, PCs, IoT devices, edge computers, etc.) are connected, the presence of devices that are illegally connected to an external network by tethering or the like has become a problem. Conventionally, as a technique for detecting a device illegally connected to an external network in an internal network, there is the technique described in Patent Document 1.

[0003] In the system described in Patent Document 1, a wireless LAN access point that can perform relay (for example, tethering) in the vicinity (for example, an access point that receives a relay connection by Wi-Fi (registered trademark) communication) is monitored, and when an unpermitted wireless LAN access point (a wireless LAN access point with an ID not included in the whitelist) is detected, a process of restricting a relay connection using the unpermitted wireless LAN access point is performed on each device in the internal network.

Prior Art Documents

Patent Documents

[0004]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0005] However, the system described in Patent Document 1 has the problem that while it can detect access points that support relaying via wireless LAN communication (Wi-Fi communication), it cannot detect relay connections using other means (for example, USB tethering, Bluetooth tethering, and wired LAN relay connections). Furthermore, the system described in Patent Document 1 has the problem that a dedicated program for restricting communication must be installed on the device to be protected.

[0006] In light of the above issues, there is a need for a network inspection device, network inspection program, network inspection method, and network inspection system that can detect security-inappropriate settings in each communication device, without being limited to the connection configuration of the communication devices connected to the network under inspection. [Means for solving the problem]

[0007] The first network inspection device of the present invention is characterized by comprising: inspection packet transmission means for transmitting inspection packets to a device connected to a network to be inspected, with the source address set to an address not used in the network to be inspected; and inspection processing means for holding monitoring data including information of packets received at a gateway located on the path from the network to be inspected to an external network, performing a response packet detection process that attempts to detect a response packet sent by the device to be inspected in response to the inspection packet from the monitoring data, and performing an inspection process that checks whether there are any security-inappropriate settings in the device to be inspected based on the result of the response packet detection process.

[0008] The second network inspection program of the present invention is characterized in that a computer functions as an inspection packet transmission means that transmits inspection packets to a device connected to the network under inspection, with the source address set to an address not used in the network under inspection; and an inspection processing means that holds monitoring data including information of packets received at a gateway located on the path from the network under inspection to an external network, performs a response packet detection process that attempts to detect a response packet sent by the device under inspection in response to the inspection packet from the monitoring data, and performs an inspection process that checks whether there are any security-inappropriate settings in the device under inspection based on the result of the response packet detection process.

[0009] The third aspect of the present invention relates to a network inspection method performed by a network inspection device, wherein the network inspection device comprises inspection packet transmission means and inspection processing means, the inspection packet transmission means transmits an inspection packet to a device connected to the network under inspection, with the source address set to an address not used in the network under inspection; the inspection processing means maintains monitoring data including information of packets received at a gateway located on the path from the network under inspection to an external network; performs a response packet detection process that attempts to detect a response packet sent by the device under inspection in response to the inspection packet from the monitoring data; and performs an inspection process that checks whether there are any security-inappropriate settings in the device under inspection based on the result of the response packet detection process.

[0011] The 4 The network inspection device of the present invention holds monitoring data including information on packets received at a gateway located on the path from the network to be inspected to an external network, and from the monitoring data, it determines that the device to be inspected connected to the network to be inspected is other Sent by the network inspection device The source address was set to an address not used in the aforementioned network under inspection.The system is characterized by comprising inspection processing means that performs a response packet detection process to attempt to detect a response packet sent in response to an inspection packet, and performs an inspection process to check whether there are any security-inappropriate settings in the device under inspection based on the results of the response packet detection process.

[0012] The 5 The present invention's network inspection system is 1 Network inspection device and 2nd Equipped with a network inspection device, The first network inspection device has inspection packet transmission means for transmitting inspection packets to a device connected to the network under inspection, with the source address set to an address not used in the network under inspection. The second network inspection device has inspection processing means for maintaining monitoring data including information on packets received at a gateway located on the path from the network under inspection to an external network, performing a response packet detection process to attempt to detect response packets sent by the device connected to the network under inspection in response to the inspection packets transmitted by the first network inspection device from the monitoring data, and performing an inspection process to check whether there are any security-inappropriate settings in the device under inspection based on the result of the response packet detection process. It is characterized by the following: [Effects of the Invention]

[0013] According to the present invention, it is possible to detect security-related inappropriate settings in each communication device, without being limited to the connection configuration of the communication devices connected to the network under inspection. [Brief explanation of the drawing]

[0014] [Figure 1] This is a block diagram showing the functional configuration of the network inspection device according to the first embodiment. [Figure 2] This is a block diagram showing the connection configuration of each device related to the first embodiment. [Figure 3] This is a diagram (Part 1: First Inspection Procedure) showing a specific example of the unauthorized configuration inspection process procedure by the network inspection device according to the first embodiment (specific example of inspection packets and evaluation). [Figure 4] This is a diagram (Part 2: Second Inspection Procedure) showing a specific example of the unauthorized configuration inspection process procedure by the network inspection device according to the first embodiment (specific example of inspection packets and evaluation). [Figure 5] This is a diagram (Part 3: Third Inspection Procedure) showing a specific example of the unauthorized configuration inspection procedure by the network inspection device according to the first embodiment (specific example of inspection packets and evaluation). [Figure 6]It is a flowchart (Part 1) showing an example of the operation of the network inspection apparatus (inspection management unit 101) according to the first embodiment. [Figure 7] It is a flowchart (Part 2) showing an example of the operation of the network inspection apparatus (inspection management unit 101) according to the first embodiment. [Figure 8] It is a flowchart (Part 3) showing an example of the operation of the network inspection apparatus (inspection management unit 101) according to the first embodiment. [Figure 9] It is a block diagram showing the functional configuration of the network inspection apparatus according to the second embodiment. [Figure 10] It is a block diagram showing the functional configuration of the network inspection system according to the third embodiment.

Embodiments for Carrying Out the Invention

[0015] (A) First Embodiment Hereinafter, the first embodiment of the network inspection apparatus, network inspection program, and network inspection method according to the present invention will be described in detail while referring to the drawings.

[0016] (A-1) Configuration of the First Embodiment FIG. 2 is a diagram showing the connection relationship of each apparatus related to this embodiment.

[0017] Here, the network inspection apparatus 10 is an apparatus that inspects communication apparatuses 30 (30-1, 30-2, ···) connected to an inspection target network N1 that is the inspection target.

[0018] The type of the communication apparatus 30 is not limited, but for example, it may include IoT (Internet of Things) devices, edge computers (for example, edge computers dedicated to AI, etc.), client PCs, server apparatuses, various network apparatuses (for example, routers, etc.), and the like.

[0019] In the configuration example shown in Figure 2, each communication device 30 is connected to the network N1 under test. Furthermore, it is assumed that a gateway 20 is located on the path to access the Internet N2 (external network) within the network N1 under test. In other words, in the example shown in Figure 2, each communication device 30 in the network N1 under test is configured to communicate with the Internet N2 only via the gateway 20. In Figure 2, the internal interface (LAN interface) of the gateway 20 (the network N1 side) is designated as interface 21. It should be noted that the number of communication devices 30 connected to the network N1 under test is not limited and may increase or decrease during operation.

[0020] Here, the packet data itself transmitted and received on the gateway 20's interface 21, or the data resulting from the analysis of those packets (e.g., flow data), will be referred to as "monitoring data." Here, the monitoring data will be supplied from the gateway 20 to the network inspection device 10 (for example, by a message in any format or by the port mirroring function).

[0021] In other words, in this embodiment, the gateway 20 itself may be used as a means for collecting monitoring data and supplying it to the network inspection device 10 (hereinafter referred to as the "monitoring data collection means"), but the monitoring data collection means is not limited to the above configuration and various configurations can be applied. For example, on the L2 / L3 switch (not shown) to which the interface 21 of the gateway 20 is connected, the monitoring data collection means may be realized by supplying a copy of the traffic of the port of the L2 / L3 switch to which the interface 21 is connected to the port to which the network inspection device 10 is connected, using a port mirroring function. As described above, in the first embodiment, the specific configuration of the monitoring data collection means is not limited and various configurations can be applied.

[0022] In this embodiment, the only external network connected to the gateway 20 (a network other than the network under test N1) is the internet N2. However, other arbitrary networks (for example, any carrier network) may also be connected as external networks. In other words, in this embodiment, there may be multiple external networks, but the connection from the network under test N1 to the external network must always go through the interface 21 of the gateway 20. In this embodiment, for the sake of simplicity, the gateway 20 is shown as a single configuration, but it may be configured as multiple configurations.

[0023] Next, we will explain the operational policy (security policy) for the network N1 under inspection.

[0024] Here, we will explain that the operational policy (security policy; operational rule) for the network under inspection N1 is that each communication device 30 is configured to always route connections from the network under inspection N1 (hereinafter also simply referred to as the "internal network") to external networks such as the Internet N2 (networks other than the internal network) via gateway 20 (address A0 of interface 21) in its IP layer (layer 3) routing settings (for example, default gateway or static route settings). In other words, in the network under inspection N1, the operational policy is applied to each communication device 30 that, in principle, connections to external networks must always be made via gateway 20 (interface 21).

[0025] Hereinafter, the configuration items related to IP layer (Layer 3) routing in the communication device 30 will be collectively referred to as "IP routing settings." For example, the default gateway setting, static route settings, dynamic route settings, etc., will be included in the concept of IP routing settings.

[0026] For example, if only IP address A0 of gateway 20 (interface 21) is set as the default gateway (the gateway used when connecting to the outside of the network N1 under inspection) for each communication device 30, then the above operational policy is being followed. In other words, if a communication device 30 is configured in accordance with the operational policy (security policy), it will not communicate with the outside of the network N1 under inspection through any gateway other than gateway 20 (interface 21). Therefore, if a communication device 30 is configured with a default gateway that violates the operational policy (for example, a default gateway other than IP address A0 of gateway 20 (interface 21)), then that communication device 30 has been configured in an illegal manner that violates the operational policy (i.e., an illegal configuration from a security standpoint). Hereafter, a communication device 30 with an illegal configuration from a security standpoint will be referred to as an "illegibly configured device". In other words, an illegally configured device is highly likely to be illegally accessing the external network.

[0027] An overview of the network inspection process performed by the network inspection device 10 will be described.

[0028] In this embodiment, the network N1 under inspection performs a process to inspect for the unauthorized configuration devices described above. As described above, within the network N1 under inspection, access to external networks (Internet N2 or other carrier networks, etc.) via any route other than the gateway 20 (interface 21) is prohibited by operational policy (i.e., unauthorized tethering connections, etc., are prohibited). Therefore, the network inspection device 10 performs a process (hereinafter referred to as "unauthorized configuration inspection process") to each communication device 30 to check whether or not it is configured to access external networks via a route other than the gateway 20 (interface 21). Specifically, the network inspection device 10 performs the unauthorized configuration inspection process by sending a packet to each communication device 30 to inspect the IP routing settings (hereinafter referred to as "inspection packet") and monitoring the status of the packets that each communication device 30 sends in response to the inspection packet (hereinafter referred to as "response packet"). For example, ICMP packets or SYN packets using any TCP communication port can be applied as inspection packets. For example, when communication device 30 receives an ICMP packet, it will send an ICMP packet as a response packet with the source address of the ICMP packet (hereinafter also simply referred to as "SrcIP") set as the destination IP address (hereinafter also simply referred to as "DstIP"). Similarly, when communication device 30 receives a SYN packet with an arbitrary TCP communication port set as the destination IP address (DstIP), it will send an ACK packet as a response packet with the source address of the SYN packet (SrcIP) set as the destination IP address (DstIP). Note that the protocols and communication ports applied to the inspection packet / response packet are not limited to the examples above.

[0029] Therefore, the network inspection device 10 can monitor the response status of the communication device 30 (the status of sending response packets to inspection packets) by acquiring monitoring data regarding packets sent and received at the gateway 20 (interface 2). For example, the network inspection device 10 may search the monitoring data for a corresponding response packet (hereinafter also referred to as a "corresponding response packet") for each inspection packet, and determine that the communication device 30 for which a corresponding response packet cannot be detected is a device with an incorrect configuration.

[0030] Figures 3 to 5 illustrate an example of the unauthorized configuration inspection process performed by the network inspection device 10 on the communication device 30-1.

[0031] In Figures 3 to 5, the network address (network portion of the subnet) of the network under test N1 is shown as NA, the IP address of interface 21 (LAN interface connected to the network under test N1) of gateway 20 is shown as A0 (IP address belonging to network address NA), and the IP address of LAN interface 31 (LAN interface connected to the network under test N1) of communication device 30-1 is shown as A1 (IP address belonging to network address NA). Here, it is assumed that network address NA is 192.168.1.0 / 24, IP address A0 is 192.168.1.1, and IP address A1 is 192.168.1.2. In addition, in Figures 3 to 5, the source address set in the test packet is assumed to be IP address C1 of a system (network address NC) that does not exist in the network under test N1. Furthermore, Figures 3 to 5 will be explained assuming that the network address NC is 192.168.11.0 / 24 and address C1 is 192.168.11.1.

[0032] In Figures 4 and 5, the communication device 30-1 is connected to the mobile device 40 via USB cable C, and the mobile device 40 is capable of connecting to the carrier network N4. The carrier network N4 is connected to the internet N2. The mobile device 40 is a device capable of connecting to the carrier network N4 (for example, a smartphone or mobile router) and supports the function of relaying other devices to the carrier network N4 side via tethering. In other words, in Figures 4 and 5, the communication device 30-1 is configured to also be able to connect to the internet N2 via tethering (USB tethering) through the mobile device 40. In Figures 4 and 5, the USB interface 32 on the communication device 30-1 side and the USB interface 41 on the mobile device 40 side are connected by USB cable C.

[0033] In Figures 4 and 5, the IP network segment assigned to the tethering connection between communication device 30-1 and mobile device 40 (hereinafter referred to as the "tethering segment" or "tethering network") is defined as N3. The tethering segment N3 is assumed to be assigned the network address NB. From the perspective of communication device 30-1, mobile device 40 functions as a gateway within tethering segment N3, and the IP address of this gateway is assumed to be B0. In other words, in Figures 4 and 5, from the perspective of communication device 30-1, it is assumed that connection to the higher-level network (carrier network N4 and the Internet N2) is possible via the gateway with IP address B0. For the purposes of this explanation, it is assumed that the network address NB is 192.168.0.0 / 24 and the IP address B0 is 192.168.0.1.

[0034] First, let's explain the fraudulent configuration check process shown in Figure 3.

[0035] In Figure 3, the IP routing settings for communication device 30-1 only include setting the default gateway to A0 (gateway 20), and no other settings (such as static route settings) are configured.

[0036] In the example shown in Figure 3, the network inspection device 10 sends a SYN packet as an inspection packet with source address (SrcIP) C1, destination address (DstIP) A1, and TCP port number (TCPPort) 135 (step S101).

[0037] In the example shown in Figure 3, the test packet is received by the communication device 30-1. At this time, the communication device 30-1 has only one IP routing setting configured: the default gateway is set to A0. Therefore, all packets destined for the external network will be sent out from the LAN interface 31 as packets that pass through IP address A0 (step S102). In this case, the communication device 30-1 sets C1 as the destination address (DstIP) of the response packet (ACK packet) that responds to the test packet in step S101. As a result, the destination of the response packet will be IP address A0, and it will be sent out from the LAN interface 31 and supplied to the gateway 20 (interface 21).

[0038] As described above, the network inspection device 10 can monitor packets sent and received on the gateway 20's interface 21 using monitoring data. Therefore, if the network inspection device 10 cannot detect a corresponding response packet (SYN / ACK packet, RST packet, etc.) from the monitoring data after sending an inspection packet (SYN packet), it will consider the inspection to be NG and determine that the communication device 30 is a device with an incorrect configuration. On the other hand, if the network inspection device 10 can detect a corresponding response packet (SYN / ACK packet, RST packet, etc.) from the monitoring data after sending an inspection packet (SYN packet), the inspection will be considered OK within the range of the conditions of the inspection packet (SYN packet) (e.g., source IP address, protocol / communication port, etc.). The network inspection device 10 may send inspection packets to each communication device 30 under multiple conditions (for example, source IP address, protocol / communication port combination), and if even one corresponding response packet is not detected under a condition (inspection NG condition), it may recognize that communication device 30 as an improperly configured device. If corresponding response packets are detected for all inspection packets, it may recognize that communication device 30 as a device that is not improperly configured (hereinafter referred to as a "normally configured device").

[0039] For example, after sending a test packet (SYN packet), the network inspection device 10 may detect a SYN / ACK packet or RST packet from the monitoring data that matches the source IP address (SrcIP), destination address (DstIP), and TCP communication port, etc., as the corresponding response packet. Alternatively, the network inspection device 10 may detect an ACK packet as the corresponding response packet if it finds an ACK packet that matches not only the source IP address (SrcIP), destination address (DstIP), and TCP communication port, but also the sequence number. Furthermore, after sending a test packet (SYN packet), the network inspection device 10 may recognize the device as an unauthorized configuration device if no corresponding response packet is found in the monitoring data within a predetermined period.

[0040] In the example shown in Figure 3, the response packet (ACK packet) from step S103 is forwarded to the gateway 20 (interface 21), so the network inspection device 10 detects the corresponding response packet from the monitoring data, resulting in an inspection OK result under these conditions.

[0041] Next, we will explain the fraudulent configuration check process shown in Figure 4.

[0042] In the example in Figure 4, the IP routing settings for communication device 30-1 only specify that the default gateway is B0 (tethering segment: mobile device 40), and no other settings (such as static route settings) are configured.

[0043] In the example in Figure 4, similar to the case in Figure 3, the network inspection device 10 sends a SYN packet as an inspection packet with source address (SrcIP) C1, destination address (DstIP) A1, and TCP port number (TCPPort) 135 (step S201).

[0044] The test packet is then received by the communication device 30-1. At this time, the communication device 30-1 has only one IP routing setting configured: the default gateway is B0 (tethering segment: mobile device 40). Therefore, all packets destined for the external network are sent from the tethering segment N3 side as packets with IP address B0 as the forwarding (relaying) destination (step S202).

[0045] Therefore, in the example in Figure 4, the response packet (ACK packet) from communication device 30-1 will be sent to the tethering segment N3 and will not reach the gateway 20. Consequently, in the example in Figure 4, the network inspection device 10 will not detect a corresponding response packet to the inspection packet (SYN packet) sent to communication device 30-1, resulting in a failure to inspect, and communication device 30-1 will be determined to be an improperly configured device.

[0046] Next, we will explain the fraudulent configuration check process shown in Figure 5.

[0047] In the example in Figure 5, the IP routing settings of communication device 30-1 are configured to set the default gateway to IP address A0 (gateway 20: interface 21). However, a static route setting (individual IP routing setting) that forwards packets destined for IP addresses belonging to network address NC to IP address B0 (tethering segment N3 side) takes precedence. Therefore, in the example in Figure 5, communication device 30-1 is configured to forward packets destined for IP addresses belonging to network address NC to IP address B0 (tethering segment N3 side), and to forward packets destined for other IP addresses (IP addresses of the external network) to IP address A0 (gateway 20: interface 21).

[0048] In the example shown in Figure 5, similar to the case in Figure 3, the network inspection device 10 sends a SYN packet as an inspection packet with source address (SrcIP) C1, destination address (DstIP) A1, and TCP port number (TCPPort) 135 (step S301).

[0049] The test packet is then received by the communication device 30-1. At this time, the communication device 30-1 generates a response packet (ACK packet) destined for IP address C1 belonging to network address NC, and this response packet (ACK packet) is sent from the tethering segment N3 side based on the static route setting (step S302).

[0050] Therefore, in the example in Figure 5, the response packet (ACK packet) from communication device 30-1 does not contain a corresponding response packet to the test packet (SYN packet) sent to communication device 30-1, similar to the example in Figure 4. As a result, the test fails, and communication device 30-1 is determined to be an unauthorized device.

[0051] As described above, the network inspection device 10 will perform an unauthorized configuration inspection process.

[0052] Next, an example of the internal configuration of the network inspection device 10 will be explained using Figure 1.

[0053] The network testing device 10 includes a testing management unit 101, a testing NW input unit 102, a testing result output unit 103, a testing source address information holding unit 104, a transmission condition information holding unit 105, a response monitoring unit 106, a monitoring IF unit 107, a testing execution unit 108, and a communication IF unit 109.

[0054] The network inspection device 10 can be implemented, for example, by installing a program (including a network inspection program according to the embodiment) on a computer having a processor, memory, etc.

[0055] The inspection network input unit 102 receives input of information related to the target of the fraudulent configuration inspection process (for example, individual IP addresses or network addresses; hereinafter referred to as "inspection target information") and supplies it to the inspection management unit 101. The inspection target information may be, for example, a list of individual IP addresses (IP addresses of the communication device 30 to be monitored), or the bandwidth (range) of IP addresses used by the communication device 30 on the inspection target network N1. Examples of IP address bandwidths include information such as "192.168.1.2~192.168.1.240" or the notation in the format of a network address (segment; subnet) (for example, "192.168.1.0 / 24"). If the supplied inspection target information is a bandwidth of IP addresses, the inspection network input unit 102 may perform a communication check (for example, sending ICMP packets, etc.) to all IP addresses in that bandwidth, obtain the IP addresses that respond as a list of IP addresses to be inspected, and supply it to the inspection management unit 101.

[0056] The format in which the inspection network input unit 102 accepts input of the information to be inspected is not limited, and various input methods can be applied. The inspection network input unit 102 supplies the stored information to the inspection management unit 101. The inspection network input unit 102 may, for example, accept connections from external devices via a web browser and present an operation screen (GUI screen) that accepts input of the information to be inspected. Alternatively, the inspection network input unit 102 may, for example, receive and store a file containing the information to be inspected (e.g., a text file or CSV file) from an external device via file transfer (e.g., file transfer via communication such as http or ftp).

[0057] The inspection source address information holding unit 104 is responsible for holding information (hereinafter referred to as "inspection source address information") that shows a list of spoofed source IP addresses (hereinafter referred to as "inspection source addresses") to be set in the inspection packets transmitted during the fraudulent configuration inspection process. The inspection source address information holding unit 104 supplies the held inspection source address information to the inspection management unit 101. The format of the inspection source address information is not limited; for example, it may be a list of IP addresses that will become inspection source addresses, similar to the information to be inspected, or it may be the bandwidth (range) of spoofed source addresses. The method by which the inspection source address information holding unit 104 holds the inspection source address information is not limited. For example, the inspection source address information holding unit 104 may hold the inspection source address information in the same manner as the inspection network input unit 102 described above.

[0058] It is desirable to exclude test source addresses from addresses actually used on the Internet N2, as this could lead to response packets reaching those addresses and being mistaken for attacks. If possible, it is desirable to use addresses from which response packets are discarded by gateway 20. Alternatively, network devices within the target network N1, such as gateway 20, may be configured to discard packets destined for test source addresses that are pre-registered in the test source address information storage unit 104. This means that test source addresses only need to be registered in the test source address information storage unit 104 within the range where discarding is configured for gateway 20.

[0059] The transmission condition information holding unit 105 is responsible for holding information (hereinafter referred to as "transmission condition information") that shows a list of conditions (hereinafter referred to as "transmission conditions") such as protocols and communication ports to be set in the test packets to be sent during the fraudulent setting inspection process. The transmission condition information includes, for example, information such as the types of various protocols (e.g., ICMP, TCP, UDP, etc.) and the communication port numbers (in the case of ICMP, there is no communication port setting). The transmission condition information holding unit 105 supplies the held transmission condition information to the inspection management unit 101. The format of the transmission condition information is not limited and may be, for example, a list of protocols / communication ports (for example, in the format "ICMP, 135 / tcp, 139 / tcp, 445 / tcp, ...") or a range of protocols / communication ports (for example, in the format "TCP / 135~140"). The method by which the transmission condition information holding unit 105 holds the transmission conditions is not limited. The transmission condition information holding unit 105 may, for example, hold the transmission condition information in the same manner as the inspection NW input unit 102 described above. Note that the inspection port must be a protocol / communication port (for example, a port such as "135 / tcp", "139 / tcp", "445 / tcp", etc.; hereinafter also simply referred to as an "open port") in which each communication device 30 connected to the network N1 under inspection is expected (highly likely) to have communication open and respond (for example, responding with an ACK packet to a SYN packet). In other words, the transmission condition information holds a list of communication conditions in which a communication device 30 that is not a malconfigured device (i.e., a properly configured device) should respond.

[0060] The response monitoring unit 106 is responsible for acquiring and storing monitoring data from an external source via the monitoring IF unit 107. The response monitoring unit 106 supplies the stored monitoring data to the inspection management unit 101.

[0061] The inspection execution unit 108 generates inspection packets and sends them via the communication IF unit 109, in accordance with the control of the inspection management unit 101.

[0062] The monitoring IF unit 107 and the communication IF unit 109 are interfaces (LAN interfaces) connected to the network N1 under inspection. The monitoring IF unit 107 and the communication IF unit 109 may be configured with a single physical LAN interface, or they may be configured with separate physical LAN interfaces.

[0063] The inspection management unit 101 is responsible for the overall control processing of the network inspection device 10 (various control processing related to unauthorized configuration inspection processing, etc.). The inspection management unit 101 acquires inspection target information, inspection source address information, and transmission condition information from the inspection NW input unit 102, inspection source address information holding unit 104, and transmission condition information holding unit 105, respectively, and causes the inspection execution unit 108 to generate and transmit inspection packets for each inspection target (IP address of each communication device 30) according to the acquired information. Then, after the transmission of the inspection packets, the inspection management unit 101 receives monitoring data from the response monitoring unit 106 and attempts to detect the corresponding response packets (corresponding response packets) for each transmitted inspection packet from the received monitoring data. In other words, the inspection management unit 101 associates and manages the detected corresponding response packets for each inspection packet, and attempts to detect unauthorized configuration devices (communication devices 30 suspected of illegally connecting to the external network) based on the management status (for example, inspection packets that do not have a corresponding response packet associated with them). The inspection management unit 101 supplies the results of the fraudulent setting inspection process to the inspection result output unit 103.

[0064] The inspection result output unit 103 performs processing to output the results of the fraudulent configuration inspection process supplied from the inspection management unit 101. The means and data format by which the inspection result output unit 103 outputs the results of the fraudulent configuration inspection process are not limited. For example, the inspection result output unit 103 may output a list of communication devices 30 that have been determined to be fraudulent devices (for example, a list of IP addresses, hostnames, etc.) as the result of the fraudulent configuration inspection process. In this case, the inspection result output unit 103 may add information on ports for which a corresponding response packet could not be detected for each communication device 30 as a result of the fraudulent configuration inspection process. The inspection result output unit 103 may also output information on communication devices 30 that were normal as a result of the fraudulent configuration inspection process (communication devices 30 that were not fraudulent devices). For example, the inspection result output unit 103 may present the results of the fraudulent configuration inspection process on a web browser screen (GUI screen), output data in a predetermined message format to a predetermined output destination, or output data in a predetermined file format (for example, text file or CSV file format) to a predetermined output destination.

[0065] (A-2) Operation of the first embodiment Next, the operation of the network inspection device 10 of the first embodiment having the above configuration (network inspection method according to the embodiment) will be described.

[0066] First, we will explain the overview of the unauthorized configuration inspection process performed by the network inspection device 10.

[0067] Prior to performing the fraudulent configuration inspection process, the inspection management unit 101 obtains the inspection target information, the inspection source address information, and the transmission condition information from the inspection network input unit 102, the inspection source address information holding unit 104, and the transmission condition information holding unit 105, respectively.

[0068] The inspection management unit 101 identifies the communication devices 30 to be inspected (such as a list of IP addresses for each communication device 30) based on the information to be inspected. Then, based on the inspection source address information and transmission condition information, the inspection management unit 101 determines the content of the inspection packet to be sent to each communication device 30 (source IP address, protocol / communication port number, etc.). At this time, the inspection management unit 101 may decide to send multiple types of inspection packets to each communication device 30. In other words, the inspection management unit 101 may evaluate whether each communication device 30 is a rogue device based on the results of sending inspection packets with multiple different transmission conditions.

[0069] Then, the inspection management unit 101 determines the content of the inspection packet to be transmitted to each communication device 30 (parameters to be set in the inspection packet) and supplies the determined content to the inspection execution unit 108 and the response monitoring unit 106.

[0070] The inspection execution unit 108 generates inspection packets according to instructions from the inspection management unit 101 and transmits them from the communication IF unit 109.

[0071] The response monitoring unit 106 acquires monitoring data (e.g., traffic data) via the monitoring IF unit 107 and attempts to detect the corresponding response packet associated with each test packet from the acquired monitoring data. The response monitoring unit 106 reports the result to the test management unit 101 each time a corresponding response packet is detected.

[0072] The inspection management unit 101 determines whether a corresponding response packet exists for each inspection packet in accordance with the report from the response monitoring unit 106, and determines the result of the unauthorized configuration inspection process for each communication device 30 based on the results. The inspection management unit 101 may also consider that no corresponding response packet was detected for an inspection packet if a corresponding response packet is not detected for a predetermined period of time or longer after the inspection packet has been sent.

[0073] The inspection result output unit 103 performs the process of outputting the results of the fraudulent setting inspection process supplied from the inspection management unit 101.

[0074] Through the above process, the network inspection device 10 determines the response result (presence or absence of a corresponding response packet) to the transmission of inspection packets for each communication device 30, and evaluates the results of the misconfiguration inspection based on the results. There are many possible combinations of the content of the inspection packets and the evaluation method in the network inspection device 10, but several specific examples are explained below.

[0075] Figures 6 to 8 are flowcharts showing specific examples of the unauthorized configuration inspection procedure performed by the network inspection device 10 (specific examples of inspection packets and evaluation). Hereafter, the examples of unauthorized configuration inspection procedures shown in Figures 6 to 8 will be referred to as the first to third inspection procedures, respectively. Figures 6 to 8 mainly explain the processing performed by the inspection management unit 101. Furthermore, below, as an example, an example of the inspection management unit 101 performing an inspection on the communication device 30-1 will be described.

[0076] First, the first inspection procedure using the network inspection device 10 will be explained using Figure 6.

[0077] The first inspection procedure shows an example where only ICMP is described in the transmission condition information. The first inspection procedure also shows an example where only C1 (an arbitrary IP address not belonging to the network N1 under inspection) is described in the source address information for inspection.

[0078] The inspection management unit 101 controls the inspection execution unit 108 to send an ICMP packet with the source IP address spoofed as C1 to the communication device 30-1 as an inspection packet (S401), and waits for a predetermined time (for example, about 5 seconds) for a report from the response monitoring unit 106 indicating the detection of a corresponding response packet (S402).

[0079] Then, if the response monitoring unit 106 receives a report of the detection of a corresponding response packet within a predetermined time, it determines that the communication device 30-1 is not an unauthorized device (a device connected to an external network) (S403), and if the detection of a corresponding response packet is not reported within a predetermined time, it determines that there is a high probability that the communication device 30-1 is an unauthorized device (a device connected to an external network) (S404).

[0080] Next, the second inspection procedure using the network inspection device 10 will be explained using Figure 7.

[0081] The second inspection procedure shows an example where the transmission condition information includes multiple transmission conditions (protocols / communication ports) in addition to ICMP. Below, transmission conditions other than ICMP described in the transmission condition information (protocols / communication ports) are referred to as "additional transmission conditions." The protocol / transmission ports to be set as additional transmission conditions should preferably be a list of ports that are likely to be open on the communication device 30-1 unless it is a malfunctioning device (i.e., if it is a properly configured device).

[0082] First, the inspection management unit 101 controls the inspection execution unit 108 to send an ICMP packet with the source IP address spoofed as C1 to the communication device 30-1 as an inspection packet (S501), and waits for a predetermined time (for example, about 5 seconds) for the response monitoring unit 106 to report the detection of a corresponding response packet for the inspection packet (S502).

[0083] The inspection management unit 101 then determines that the communication device 30-1 is not an unauthorized device (a device connected to an external network) if a report of the detection of a corresponding response packet is received within a predetermined time (S503). If no report of the detection of a corresponding response packet is received within a predetermined time, the unit proceeds to step S504, which will be described later.

[0084] If, in step S502 described above, no detection of a corresponding response packet is reported within a predetermined time, the inspection management unit 101 controls the inspection execution unit 108 to send an inspection packet (a packet with the source IP address spoofed as C1) to the communication device 30-1, with additional transmission conditions (transmission conditions other than ICMP) described in the transmission condition information set (S504), and waits for a report from the response monitoring unit 106 of detection of a corresponding response packet for the inspection packet, up to a predetermined time limit (S505).

[0085] Then, if the inspection management unit 101 receives reports of the detection of corresponding response packets for all inspection packets within a predetermined time, it proceeds to step S503 and determines that the communication device 30-1 is not a rogue device (a device connected to an external network). If no reports of the detection of corresponding response packets for some or all transmission conditions are received within a predetermined time, it determines that there is a high probability that the communication device 30-1 is a rogue device (a device connected to an external network) (S506).

[0086] As described above, in the second inspection procedure, the network inspection device 10 (inspection management unit 101) sends an inspection packet to the communication device 30-1 with the communication port changed based on additional transmission conditions (multiple communication ports that are likely to be open ports) as an additional process if there is no ICMP response.

[0087] Next, the third inspection procedure using the network inspection device 10 will be explained using Figure 8.

[0088] In the third inspection procedure, the transmission condition information is assumed to be set to the same content as in the second inspection procedure. The third inspection procedure shows an example in which the inspection source address information includes multiple IP addresses (arbitrary IP addresses not belonging to the inspection network N1) in addition to IP address C1. In the inspection source address information of the third inspection procedure, inspection source addresses other than C1 are referred to as the "additional address list". It is desirable that the inspection source addresses set in the additional address list be IP addresses that are commonly used by external devices connected when tethering (e.g., routers, mobile routers, smartphones, etc.). Note that the order of the inspection source addresses set in the additional address list is not limited.

[0089] First, the inspection management unit 101 controls the inspection execution unit 108 to send an ICMP packet with the source IP address spoofed as A1 to the communication device 30-1 as an inspection packet (S601), and waits for a predetermined time (for example, about 5 seconds) for the response monitoring unit 106 to report the detection of a corresponding response packet for the inspection packet (S602).

[0090] Then, if no report of the detection of a corresponding response packet is received within the predetermined time, the inspection management unit 101 determines that the communication device 30-1 is an unauthorized device (a device connected to an external network) (S608). If the detection of a corresponding response packet is reported within the predetermined time, the unit proceeds to step S603, which will be described later.

[0091] In step S602 described above, if the detection of a corresponding response packet is reported within a predetermined time, the inspection management unit 101 controls the inspection execution unit 108 to send a packet with additional transmission conditions (transmission conditions other than ICMP) described in the transmission condition information (a packet with the source IP address spoofed as C1) to the communication device 30-1 as an inspection packet (S603), and waits for a report from the response monitoring unit 106 of the detection of a corresponding response packet for the inspection packet, up to a predetermined time limit (S604). If the inspection management unit 101 receives reports of corresponding response packet detection for all inspection packets within the predetermined time, it proceeds to step S605 described later. If there are no reports of corresponding response packet detection for some or all transmission conditions within the predetermined time, it proceeds to step S608 and determines that the communication device 30-1 is highly likely to be a rogue device (a device connected to an external network).

[0092] In step S604 described above, if the inspection management unit 101 receives reports of corresponding response packet detection for all inspection packets within a predetermined time, it controls the inspection execution unit 108 to send inspection packets to the communication device 30-1 for each combination of additional address list and additional transmission conditions (S605), and waits for a report from the response monitoring unit 106 of corresponding response packet detection for the inspection packets, up to a predetermined time limit (S606). If the inspection management unit 101 receives reports of corresponding response packet detection for all inspection packets within a predetermined time, it proceeds to step S607 described later and determines that the communication device 30-1 is not an unauthorized configuration device (a device connected to an external network) (S607). If no reports of corresponding response packet detection for some or all transmission conditions are received within a predetermined time, it proceeds to step S608 and determines that there is a high probability that the communication device 30-1 is an unauthorized configuration device (a device connected to an external network).

[0093] As described above, in the third inspection procedure, the network inspection device 10 (inspection management unit 101) sends an inspection packet to the communication device 30-1 with modified communication conditions based on additional transmission conditions (multiple communication ports that are likely to be open ports) when an ICMP response is received, and further sends an inspection packet with modified source address based on the inspection source address. As a result, even if the communication device 30-1 has individual static route settings in addition to the default gateway, as shown in Figure 5, it can be detected as an unauthorized device.

[0094] (A-3) Effects of the first embodiment According to the first embodiment, the following effects can be achieved.

[0095] In the first embodiment, the network inspection device 10 sends inspection packets to each communication device 30, disguised with an inspection source address instead of a source IP address, and monitors the reception status of corresponding response packets at the gateway 20. As a result, the network inspection device 10 in the first embodiment can detect inappropriate security settings without being limited to the connection configuration or settings of each communication device 30.

[0096] (B) Second Embodiment A second embodiment of the network inspection device, network inspection program, and network inspection method according to the present invention will be described in detail below with reference to the drawings.

[0097] (B-1) Configuration of the second embodiment Figure 9 is a block diagram showing the overall configuration of the network inspection device 10A of this embodiment, and the same or corresponding parts as in Figure 1 are denoted by the same or corresponding reference numerals.

[0098] The following describes the differences between the network inspection device 10A of the second embodiment and the first embodiment.

[0099] Network inspection device 10A differs from the first embodiment in that the inspection management unit 101 and the response monitoring unit 106 are replaced by the inspection management unit 101A and the response monitoring unit 106A, and a response packet processing unit 110 is added.

[0100] The response packet processing unit 110 obtains transmission information for inspection packets (including at least the inspection source address information) from the inspection management unit 101A and performs control processing (hereinafter referred to as "guidance control processing") to guide response packets (corresponding response packets) for each inspection packet so that they do not leave the gateway 20 and go out to the external network (Internet N2 side). Specifically, the response packet processing unit 110 controls the communication IF unit 109 to send and receive ARP packets by performing proxy ARP (Address Resolution Protocol) responses for the inspection source address using the so-called Proxy ARP function. The Proxy ARP function is a function that allows advertising that it is acting as a proxy for the physical address (MAC address) corresponding to the IP address of another node. The response packet processing unit 110 uses this Proxy ARP function to advertise within the inspection target network N1 (L2 / L3 switches, etc. within the inspection target network N1) that the network inspection device 10A (communication IF unit 109) is acting as a proxy for the inspection source address (the destination IP address of the corresponding response packet). In other words, the response packet processing unit 110 can advertise that the network inspection device 10A (communication IF unit 109) is the inspection source address (the destination IP address of the corresponding response packet) by causing the communication IF unit 109 to send and receive packets according to the Proxy Arp function. The Proxy Arp function applied to the response packet processing unit 110 can be the same as that of various network devices (for example, routers and L3 switches).

[0101] As described above, in this embodiment, the corresponding response packets transmitted from each communication device 30 are received by the communication IF unit 109 through induction control processing. When the communication IF unit 109 receives a corresponding response packet, it is desirable to discard it without further forwarding it.

[0102] Note that the corresponding response packets that reach the communication IF unit 109 do not reach the gateway 20 and are therefore not included in the monitoring data. For this reason, in this embodiment, the response packet processing unit 110 monitors the reception status of the corresponding response packets (packets forwarded with the test source address as the destination) at the communication IF unit 109 and notifies the response monitoring unit 106A. As a result, the response monitoring unit 106A can detect the transmission status of corresponding response packets from each communication device 30 based on the monitoring data and the notification from the response packet processing unit 110.

[0103] (B-2) Effects of the second embodiment According to the second embodiment, in addition to the effects of the first embodiment, the following effects can be achieved.

[0104] In the network inspection device 10A of the second embodiment, the response packet processing unit 110 performs guidance control processing, thereby preventing the corresponding response packet from being sent from the gateway 20 (interface 21) to the internet N2 side. In other words, in the network inspection device 10A of the second embodiment, instead of leaving the corresponding response packet until it disappears, the network inspection device 10A collects and discards it. As a result, in the second embodiment, it is possible to suppress the load on the entire network and to suppress problems caused by sending unnecessary packets to external networks (for example, being falsely detected as a malicious attack on the destination external network).

[0105] (C) Third Embodiment A third embodiment of the network inspection device, network inspection program, network inspection method, and network inspection system according to the present invention will be described in detail below with reference to the drawings.

[0106] In the first and second embodiments, the network inspection devices 10 and 10A were shown to be configured in which a means for transmitting inspection packets (hereinafter referred to as the "inspection packet transmission means") and a means for detecting corresponding response packets based on monitoring data and obtaining the results of the fraudulent configuration inspection process (hereinafter referred to as the "inspection processing means") are implemented in a single device. However, in the second embodiment, the inspection packet transmission means and the inspection processing means are implemented as separate devices.

[0107] The details of how the two devices are divided are not limited, but for example, the division shown in Figure 10 may be used.

[0108] Figure 10 illustrates a network inspection system 50 comprising a first network inspection device 51 and a second network inspection device 52. In Figure 10, the same or corresponding parts as those in Figure 1 are denoted by the same or corresponding reference numerals.

[0109] The first network inspection device 51 is a device of the network inspection device 10 that includes a means for transmitting inspection packets, and the second network inspection device 52 is a device of the network inspection device 10 that includes a means for processing inspections.

[0110] In Figure 10, the first network inspection device 51 includes, as components necessary for the inspection packet transmission means, an inspection management unit 101B1, an inspection NW input unit 102, an inspection result output unit 103, an inspection source address information holding unit 104, a transmission condition information holding unit 105, an inspection execution unit 108, and a communication IF unit 109. The inspection management unit 101B1 is at least one of the inspection management unit 101 in the first embodiment that is capable of executing the inspection packet transmission means (control processing until the inspection packet is transmitted).

[0111] In Figure 10, the second network inspection device 52 includes an inspection management unit 101B2, an inspection result output unit 103, a response monitoring unit 106, and a monitoring IF unit 107 as components necessary for the inspection packet transmission means. The inspection management unit 101B2 can execute inspection processing means (processing that detects corresponding response packets based on monitoring data, etc., and obtains the result of the fraudulent setting inspection process) from at least the inspection management unit 101 of the first embodiment.

[0112] (D) Other embodiments The present invention is not limited to the embodiments described above, and modified embodiments such as those exemplified below can also be cited.

[0113] (D-1) In each of the above embodiments, the network inspection device has been described as a dedicated device, but it may be configured to operate on a device with other functions. For example, the network inspection device according to each of the above embodiments may be mounted on a network device (e.g., a router, gateway, switch, wireless LAN access point, etc.). For example, in the above embodiment, each element of the network inspection device according to the above embodiment may be mounted on the gateway 20. In this case, since the network inspection device monitors interface 21 within the same device, the transmission of monitoring data becomes unnecessary, thus reducing the network load. In this case, the network inspection device can prevent leakage to the external network by discarding the response packet each time a response packet reaches interface 21 within the same device, so there is no need to use the Proxy Arp function as in the second embodiment, thus further reducing the network load.

[0114] (D-2) In each of the above embodiments, the source address information to be registered in the inspection source address information holding unit 104 may be an address actually used on the Internet N2. In this case, as shown in the communication device 30-1 in Figure 5, the default gateway is set to the gateway 20 of the internal network (network to be inspected N1), and it is effective for inspecting unauthorized settings when an unauthorized connection to the external network is made by individual static route settings (when the system is configured to respond to the local IP address on the internal network side so that it is not detected that an unauthorized connection to the external network is made).

[0115] (D-3) In each of the above embodiments, the transmission condition information (list of transmission conditions) to be set in the transmission condition information holding unit 105 was described as being set according to the environment of the network N1 under inspection. However, the transmission condition information holding unit 105 may be configured to generate this information dynamically by scanning for ports that are open on one or more communication devices 30. For example, in each of the above embodiments, the transmission condition information holding unit 105 may use a network survey tool (for example, a port scanning tool such as Nmap (Network Mapper)) to survey for ports that are open on one or more communication devices 30. This eliminates the need to manually set the transmission condition information in the transmission condition information holding unit 105.

[0116] (D-4) If a so-called virtual machine (e.g., Docker) is built on the communication device 30, a virtual network may also be built. When a virtual network is built within the communication device 30, if a test packet is received with an IP address belonging to a network address included in the virtual network as the source, the test packet will be incorporated into the internal virtual network. In other words, for a communication device 30 with a virtual machine built inside, even if it is not connected to an external network, the response packet to the test packet will not be sent to the network N1 under inspection, which may cause the network inspection device to mistakenly detect it as a device with an incorrect configuration. For this reason, it is desirable that the test source address set in the test source address information holding unit 104 does not include the address space generally used by virtual machines (e.g., a predetermined class B address space such as "172.16.0.0 / 12"). [Explanation of symbols]

[0117] 10...Network testing device, 20...Gateway, 21...Interface, 30...Communication device, 31...LAN interface, 32...USB interface, 40...Mobile device, 41...USB interface, 50...Network testing device, 51...Network testing device, 52...Network testing device, 101...Test management unit, 102...Test NW input unit, 103...Test result output unit, 104...Test source address information holding unit, 105...Transmission condition information holding unit, 106...Response monitoring unit, 107...Monitoring IF unit, 108...Test execution unit, 109...Communication IF unit, 110...Response packet processing unit, N1...Network to be tested, N2...Internet.

Claims

1. A test packet transmission means that transmits a test packet to a device connected to the network under test, with the source address set to an address not used in the network under test; An inspection processing means that maintains monitoring data including information of packets received at a gateway located on the path from the network under inspection to an external network, performs a response packet detection process that attempts to detect response packets sent by the device under inspection in response to the inspection packets from the monitoring data, and performs an inspection process that checks whether there are any security-inappropriate settings in the device under inspection based on the result of the response packet detection process. A network inspection device characterized by having the following features.

2. The network inspection device according to claim 1, characterized in that the inspection packet transmission means maintains a source address list in which multiple source addresses to be set in the inspection packet are described, and changes the source address to be set in the inspection packet according to the source address described in the source address list.

3. The network inspection device according to claim 2, characterized in that the inspection packet transmission means holds a transmission condition list in which multiple transmission conditions to be set for the inspection packet are described, and changes the transmission conditions to be set for the inspection packet according to the transmission condition list.

4. The network inspection device according to claim 3, characterized in that the transmission conditions described in the transmission conditions list are transmission conditions that will be responded to by the inspection target device if it does not have any security-related unauthorized settings.

5. The network inspection device according to claim 1, further comprising guidance control means for performing guidance control processing to guide each node in the inspection network so that the response packets are not transmitted from the gateway to the outside of the inspection network.

6. The network inspection device according to claim 5, characterized in that the guidance control means guides each node in the inspection network to forward packets destined for the source address set in the inspection packet to its own device using a Proxy ARP function.

7. The network inspection device according to claim 6, further comprising a response packet discarding means for discarding the response packets that have been transferred to the device by the guidance control means.

8. Computers, A test packet transmission means that transmits a test packet to a device connected to the network under test, with the source address set to an address not used in the network under test; An inspection processing means that maintains monitoring data including information of packets received at a gateway located on the path from the network under inspection to an external network, performs a response packet detection process that attempts to detect response packets sent by the device under inspection in response to the inspection packets from the monitoring data, and performs an inspection process that checks whether there are any security-inappropriate settings in the device under inspection based on the result of the response packet detection process. A network inspection program characterized by its ability to function in this way.

9. In a network inspection method performed by a network inspection device, The network inspection device comprises inspection packet transmission means and inspection processing means, The inspection packet transmission means transmits an inspection packet to a device connected to the network under inspection, with the source address set to an address not used in the network under inspection. The inspection processing means maintains monitoring data including information on packets received at a gateway located on the path from the network under inspection to an external network, performs a response packet detection process that attempts to detect response packets sent by the device under inspection in response to the inspection packets from the monitoring data, and performs an inspection process that checks whether there are any security-inappropriate settings in the device under inspection based on the results of the response packet detection process. A network inspection method characterized by the following features.

10. A network inspection device characterized by comprising: monitoring data containing information on packets received at a gateway located on a path from the network under inspection to an external network; a response packet detection process that attempts to detect response packets sent from the monitoring data by a device under inspection connected to the network under inspection in response to an inspection packet sent by another network inspection device with an address not used in the network under inspection set as the source address; and an inspection process that checks whether there are any security-inappropriate settings in the device under inspection based on the result of the response packet detection process.

11. comprising a first network inspection device and a second network inspection device, The first network inspection device has inspection packet transmission means for transmitting inspection packets to devices connected to the network under inspection, with the source address set to an address not used in the network under inspection. The second network inspection device includes inspection processing means that maintains monitoring data containing information on packets received at a gateway located on the path from the network under inspection to an external network, performs a response packet detection process to attempt to detect response packets sent by the device under inspection connected to the network under inspection in response to the inspection packets transmitted by the first network inspection device, and performs an inspection process to check whether there are any security-inappropriate settings in the device under inspection based on the results of the response packet detection process. A network inspection system characterized by the following features.