Information provision device, information provision method, and information provision program
The information providing apparatus addresses the challenge of slow security information sharing by using an acquisition and providing unit to rapidly disseminate detection results to multiple users, enhancing efficiency and automation in security information distribution.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- NTT DOCOMO BUSINESS INC
- Filing Date
- 2025-11-20
- Publication Date
- 2026-05-19
AI Technical Summary
Conventional systems face difficulties in quickly sharing security information among multiple users, particularly in parent-child or partner relationships, requiring significant time and effort for manual information sharing.
An information providing apparatus that includes an acquisition unit to detect unauthorized communication and a providing unit to rapidly share detection results with users, including those designated as recipients, via a portal screen, with optional cost approval and sharing functionality.
Enables quick and efficient sharing of security-related information among multiple users, facilitating intuitive information access and enabling automated response to unauthorized communication events.
Smart Images

Figure 0007862665000001_ABST
Abstract
Description
Technical Field
[0006] ,
[0007] , ,
[0001] The present invention relates to an information providing apparatus, an information providing method, and an information providing program.
Background Art
[0002] Conventionally, an apparatus for notifying security information regarding a network to which a plurality of terminals are connected has been known (for example, see Patent Document 1).
Prior Art Document
Patent Document
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] However, in the conventional technology, there is a problem that it is difficult to quickly share information regarding security among a plurality of users. For example, in the case of companies in a parent-child relationship or a partner relationship, sharing of information regarding security may be desired. In that case, when performing the work for sharing information manually, a lot of time and effort are required.
[0005] The present invention has been made in view of the above, and an object thereof is to quickly share information regarding security among a plurality of users.
Means for Solving the Problems
[0006] In order to solve the above-described problems, an information providing apparatus of the present invention includes an acquisition unit that acquires a detection result of unauthorized communication for each line, and a providing unit that provides the detection result of unauthorized communication of the line to a user of the line where unauthorized communication is detected and a user defined as a destination of the line.
Effects of the Invention
[0007] According to the present invention, security-related information can be quickly shared among multiple users. [Brief explanation of the drawing]
[0008] [Figure 1] Figure 1 shows an example of the configuration of a monitoring system. [Figure 2] Figure 2 shows an example of the configuration of an information provision device. [Figure 3] Figure 3 shows an example of user information. [Figure 4] Figure 4 shows an example of line information. [Figure 5] Figure 5 is a diagram illustrating the flow of the authentication process. [Figure 6] Figure 6 shows an example of information that is shared. [Figure 7] Figure 7 is a flowchart showing the processing flow of the information provision device. [Figure 8] Figure 8 shows an example of a computer configuration for running the information provision program. [Modes for carrying out the invention]
[0009] The embodiments for carrying out the present invention will be described below with reference to the drawings. The present invention is not limited to these embodiments.
[0010] [First Embodiment] The configuration of the monitoring system in the first embodiment will be explained using Figure 1. Figure 1 is a diagram showing an example of the configuration of the monitoring system.
[0011] As shown in Figure 1, the monitoring system 1 includes an information providing device 10 and a detection device 30. The service provision network 3 is a network for providing services to users. For example, the service provision network 3 is a network for providing NaaS (Network as a Service) type ICT services, including connection to the Internet 2, VPN (Virtual Private Network), virtual network functions, mobile access, remote access, security functions, etc.
[0012] Company A, Company B, and Company B are users receiving the service. Each user receives the service using one or more lines. Furthermore, the users' terminals connect to the lines via CPE (Customer Premises Equipment).
[0013] As shown in Figure 1, Company A uses lines 41a, 42a, and 43a. Lines 41a, 42a, and 43a are connected via CPE 51a, CPE 52a, and CPE 53a, respectively. For example, PC 63a connects to line 43a via CPE 53a. Terminal 71a is a management terminal used by a person in charge at Company A.
[0014] Company B utilizes lines 41b, 42b, and 43b. Connections to lines 41b, 42b, and 43b are made via CPE51b, CPE52b, and CPE53b, respectively. For example, PC63b connects to line 43b via CPE53b. Terminal 71b is a management terminal used by a representative of Company B.
[0015] Company C utilizes lines 41c, 42c, and 43c. Connections to lines 41c, 42c, and 43c are made via CPE51c, CPE52c, and CPE53c, respectively. For example, PC63c connects to line 43c via CPE53c. Terminal 71c is a management terminal used by Company C's personnel.
[0016] The information providing device 10 provides information regarding security to the user. For example, the information providing device 10 causes a portal screen to be displayed on the management terminal of each user. The information providing device 10 can provide information via the portal screen. For example, the information providing device 10 monitors the detection of unauthorized communication by the detection device 30 and notifies the user of the detection result.
[0017] The detection device 30 detects unauthorized communication of the user. For example, the detection device 30 detects that the user's terminal has accessed a malicious site (for example, a website listed on the blacklist) via the Internet 2. The detection result by the detection device 30 is notified to the user by the information providing device 10.
[0018] The information providing device 10 provides the detection result of unauthorized communication to a predetermined destination for each line. For example, assume that the terminal of Company C has accessed a malicious site via CPE52c and line 42c. The detection device 30 detects that there has been unauthorized communication via line 42c. The information providing device 10 notifies the terminal 71c that there has been unauthorized communication via line 42c. In this way, the information providing device 10 provides the detection result of unauthorized communication to the user of the line where unauthorized communication has occurred.
[0019] Furthermore, the information providing device 10 can provide the detection result of unauthorized communication to users other than the user of the line where unauthorized communication has occurred. For example, assume that it has been predetermined to provide the detection result of unauthorized communication via line 42c to Company A. In this case, the information providing device 10 notifies the terminal 71c of Company C and the terminal 71a of Company A that there has been unauthorized communication via line 42c. Note that the provision of the detection result of unauthorized communication may be performed by actively transmitting a message, or may be performed by giving permission to view information from the portal screen.
[0020] For example, suppose Company A is an automobile manufacturer, and Companies B and C are parts manufacturers that supply parts to Company A. For example, Company A can receive the results of detection of unauthorized communications at Companies B and C.
[0021] The configuration of the information provision device according to the first embodiment will be explained using Figure 2. Figure 2 is a diagram showing an example of the configuration of the information provision device.
[0022] As shown in Figure 2, the information providing device 10 has an input unit 12, an output unit 13, a storage unit 14, and a control unit 15. The communication unit 11 is an interface for communicating with other devices (for example, the detection device 30, terminals 71a, 71b, and 71c). The input unit 12 accepts data input. For example, the input unit 12 is an interface connected to input devices such as a mouse and a keyboard. The output unit 13 outputs data. For example, the output unit 13 is an interface connected to output devices such as a display and a speaker.
[0023] The storage unit 14 is a storage device such as an HDD (Hard Disk Drive), SSD (Solid State Drive), or optical disc. Alternatively, the storage unit 14 may be a rewritable semiconductor memory such as RAM (Random Access Memory), flash memory, or NVSRAM (Non-Volatile Static Random Access Memory). The storage unit 14 stores the OS (Operating System) and various programs executed by the information provision device 10. The storage unit 14 also stores user information 141 and line information 142.
[0024] Figure 3 shows an example of user information. As shown in Figure 3, user information 141 has the following items: "User," "Sharing Function," and "Help Desk." The "User" item is information to identify the user. The "Sharing Function" item indicates whether the sharing function is ON (enabled) or OFF (disabled). The "Help Desk" item indicates whether the help desk function is ON (enabled) or OFF (disabled).
[0025] Figure 3 shows that Company A's sharing function and help desk function are ON. Figure 3 also shows that Company B's sharing function is ON and its help desk function is OFF. Furthermore, Figure 3 shows that Company D's sharing function and help desk function are OFF.
[0026] Figure 4 shows an example of line information. As shown in Figure 4, line information 142 has the following items: "Line", "User", "Recipient", and "Status". The item "Line" is information for identifying the line. The item "User" is information for identifying the user. The item "Recipient" is information indicating the recipient of the malicious communication detection results. The item "Status" is information indicating the status regarding the detection of malicious communication.
[0027] Figure 4 shows that for line 41b, the user is company B, and the detection results of the unauthorized communication are provided to company A. Figure 4 also shows that for line 42c, the user is company C, and the detection results of the unauthorized communication are provided to companies A and B, and the status is abnormal (for example, a state in which unauthorized communication has been detected).
[0028] Returning to Figure 2, the control unit 15 controls the entire information providing device 10. The control unit 15 is, for example, an electronic circuit such as a CPU (Central Processing Unit), MPU (Micro Processing Unit), or GPU (Graphics Processing Unit), or an integrated circuit such as an ASIC (Application Specific Integrated Circuit) or FPGA (Field Programmable Gate Array). The control unit 15 also has an internal memory for storing programs and control data that define various processing procedures, and executes each process using the internal memory.
[0029] Furthermore, the control unit 15 functions as various processing units through the operation of various programs. For example, the control unit 15 includes an acquisition unit 151, a management unit 152, and a supply unit 153.
[0030] The acquisition unit 151 acquires information from other devices. For example, the acquisition unit 151 acquires the detection results of unauthorized communication from the detection device 30. The management unit 152 manages the database. For example, the management unit 152 adds, updates, deletes, etc., data in the user information 141 and line information 142, which are the databases. The provision unit 153 provides information to other devices. For example, the provision unit 153 provides the detection results of unauthorized communication to the user's management terminal.
[0031] The sharing function is a function that provides the results of detecting malicious communication to other users. When malicious communication is detected on a certain line, the provisioning unit 153 refers to the user information 141 and line information 142 and provides the results of the malicious communication to the user of that line and to the user set as the recipient for that line. For example, if malicious communication is detected on line 41b, the provisioning unit 153 provides the results to company B, the user of line 41b, and company A, the recipient of line 41b.
[0032] Here, the recipient is determined through an authentication process. Figure 5 illustrates the flow of the authentication process. The recipient is the user who receives the results of detecting unauthorized communication on another user's line. The provider is the user of the line on which unauthorized communication is detected.
[0033] As shown in Figure 5, both the recipient and the provider enable the sharing function (steps S11, S12). For example, the management unit 152 updates the sharing function of user information 141 to "ON" in response to an operation via the management terminal.
[0034] The recipient shares their ID with the provider. This allows the provider to obtain the recipient's ID (Step S13). The management unit 152 requests approval from the recipient (Step S14). At this time, the management unit 152 may request approval not only for acceptance of the sharing but also for the arrangement of the costs associated with the sharing function (e.g., service usage fees). Regarding the costs, the recipient may bear the full cost, the provider may bear the full cost, or the costs may be shared proportionally between the recipient and the provider.
[0035] For example, suppose the billing rules for the sharing function service are 0.2 yen per minute, with a monthly limit of 10,000 yen. Suppose the total service usage time for the sharing function in a given month is 18,000 minutes. In this case, the service usage fee would be 0.2 yen × 18,000 minutes = 9,000 yen. Also, assume that Company A is the recipient and Company C is the provider.
[0036] In this case, if the apportionment ratio between Company A and Company C is 100:0, Company A will bear 9,000 yen. Also, if the apportionment ratio between Company A and Company C is 0:100, Company C will bear 9,000 yen. Also, if the apportionment ratio between Company A and Company C is 50:50, Company A will bear 4,500 yen and Company C will bear 4,500 yen. Also, if the apportionment ratio between Company A and Company C is 70:30, Company A will bear 6,300 yen and Company C will bear 2,700 yen.
[0037] Thus, the management unit 152 requests the second user to approve the provision of the detection results of unauthorized communication on the first user's line to the second user. If the second user approves, the provision unit 153 provides the second user with the detection results of unauthorized communication on the line. The management unit 152 also requests the second user to approve the apportionment rate for the service charges for providing the second user with the detection results of unauthorized communication on the line.
[0038] The recipient approves the approval request (step S15). When the management unit 152 receives the approval operation from the recipient's management terminal, it notifies the provider that the approval is complete and updates the recipient of the line information 142.
[0039] Subsequently, the provider confirms the approval and enables information sharing (Step S16). The provider can check their own detection logs (detection results) via the portal screen (Step S17). The recipient receives a notification that information sharing has started (Step S18), and can then check their own and the provider's detection logs (detection results) via the portal screen (Step S19).
[0040] Figure 6 shows an example of shared information. The relationship between the provider and recipient is as shown in Figure 4. Specifically, the detection results for lines 41b and 42b of company B are provided to company A. The detection results for line 41c of company C are provided to company A. The detection results for line 42c of company C are provided to company A and company B. The detection results for line 43c of company C are provided to company B.
[0041] As shown in Figure 6, the service provider 153 displays the detection results for lines 41a, 42a, and 43a, which are A's own lines, as well as lines 41b, 42b, 41c, and 42c, which are the lines of the other service providers (B and C), on the portal screen displayed on A's terminal 71a. The service provider 153 also displays the detection results for lines 41b, 42b, and 43b, which are B's own lines, as well as lines 42c and 43c, which are the lines of the other service provider (C), on the portal screen displayed on B's terminal 71b. The service provider 153 also displays the detection results for lines 41c, 42c, and 43c, which are C's own lines, on the portal screen displayed on C's terminal 71c.
[0042] Furthermore, if the help desk function is enabled, the service unit 153 can request the detection device 30 to block the line on which unauthorized communication has been detected, in response to an operation from the management terminal.
[0043] The processing flow of the information provision device 10 will be explained using Figure 7. Figure 7 is a flowchart of the processing flow of the information provision device. Here, the information provision device 10 provides detection results via a portal screen in response to inquiries from the user.
[0044] The acquisition unit 151 waits until an inquiry occurs (Step S101; No). When an inquiry occurs from a user (Step S101; Yes), the acquisition unit 151 acquires the status of the user's line from which the inquiry originated (Step S102). The provision unit 153 acquires the status of the line to which the user from which the inquiry originated is providing the service (Step S103).
[0045] The acquisition unit 151 can obtain the status of a line from the line information 142. For example, if the inquiry source is company A, the acquisition unit 151 refers to the line information 142 and obtains the status of lines 41a, 42a, and 43a, which are lines of company A. The acquisition unit 151 also refers to the line information 142 and obtains the status of lines 41b, 42b, 41c, and 42c, which are lines to which company A is the recipient.
[0046] The provision unit 153 provides the user who made the inquiry with the line status acquired by the acquisition unit 151 (step S104).
[0047] As explained above, the acquisition unit 151 acquires the detection results of unauthorized communication for each line. The provision unit 153 then provides the detection results of unauthorized communication for the line to the user of the line where unauthorized communication was detected, and to the user designated as the recipient of the line. This allows the information provision device 10 to quickly share security-related information with multiple users.
[0048] The service provider 153 displays the results of detecting unauthorized communication on the line to the line's users and users designated as recipients of the line on a portal screen. This makes it possible to intuitively grasp information for multiple users.
[0049] The management unit 152 requests the first user's approval to provide the second user with the results of detecting unauthorized communication on the first user's line. If the first user approves, the provision unit 153 provides the second user with the results of detecting unauthorized communication on the line. The management unit 152 further requests the first user's approval for the apportionment rate of the service charges for providing the second user with the results of detecting unauthorized communication on the line. As a result, the information provision device 10 can start sharing the information after confirming the user's intentions.
[0050] [System configuration, etc.] Furthermore, the components of each part shown in the diagram are functional concepts and do not necessarily need to be physically configured as shown. In other words, the specific forms of distribution and integration of each device are not limited to those shown in the diagram, and all or part of them can be functionally or physically distributed and integrated in any unit according to various loads and usage conditions. Moreover, all or any part of the processing functions performed by each device can be realized by a CPU and the program executed on that CPU, or by hardware using wired logic.
[0051] Furthermore, among the processes described in the embodiments described above, all or part of the processes described as being performed automatically can be performed manually, or all or part of the processes described as being performed manually can be performed automatically by known methods. In addition, the processing procedures, control procedures, specific names, and information including various data and parameters shown in the above document and drawings can be arbitrarily changed unless otherwise specified.
[0052] [program] The aforementioned information-providing device 10 can be implemented by installing a program (correction program) as packaged software or online software on a desired computer. For example, by having the computer run the above program, the computer can function as the information-providing device 10. The term "computer" here includes mobile communication terminals such as smartphones, mobile phones and PHS (Personal Handyphone System), as well as terminals such as PDA (Personal Digital Assistant).
[0053] Figure 8 shows an example configuration of a computer running an information provision program. Computer 1000 has, for example, memory 1010 and a CPU 1020. Computer 1000 also has a hard disk drive interface 1030, a disk drive interface 1040, a serial port interface 1050, a video adapter 1060, and a network interface 1070. These components are connected by a bus 1080.
[0054] Memory 1010 includes ROM (Read Only Memory) 1011 and RAM (Random Access Memory) 1012. ROM 1011 stores, for example, a boot program such as BIOS (Basic Input Output System). The hard disk drive interface 1030 is connected to the hard disk drive 1090. The disk drive interface 1040 is connected to the disk drive 1100. For example, a removable storage medium such as a magnetic disk or optical disk is inserted into the disk drive 1100. The serial port interface 1050 is connected to, for example, a mouse 1110 and a keyboard 1120. The video adapter 1060 is connected to, for example, a display 1130.
[0055] The hard disk drive 1090 stores, for example, the OS 1091, application programs 1092, program modules 1093, and program data 1094. That is, the programs that define each process executed by the information providing device 10 are implemented as program modules 1093 in which executable code for a computer is written. The program modules 1093 are stored, for example, in the hard disk drive 1090. For example, a program module 1093 for executing processes similar to the functional configuration of the information providing device 10 is stored in the hard disk drive 1090. Note that the hard disk drive 1090 may be replaced by an SSD (Solid State Drive).
[0056] Furthermore, the data used in the processing of the above-described embodiment is stored as program data 1094 in, for example, memory 1010 or hard disk drive 1090. The CPU 1020 then reads the program module 1093 and program data 1094 stored in memory 1010 or hard disk drive 1090 into RAM 1012 as needed and executes them.
[0057] Furthermore, the program module 1093 and program data 1094 are not limited to being stored in the hard disk drive 1090; for example, they may be stored in a removable storage medium and read by the CPU 1020 via a disk drive 1100 or the like. Alternatively, the program module 1093 and program data 1094 may be stored in another computer connected via a network (LAN (Local Area Network), WAN (Wide Area Network), etc.). The program module 1093 and program data 1094 may then be read by the CPU 1020 from the other computer via a network interface 1070.
[0058] The functions of the elements disclosed herein may be implemented using circuits or processing circuitry that include general-purpose processors, special-purpose processors, integrated circuits, ASICs (Application Specific Integrated Circuits), FPGAs (Field Programmable Gate Arrays), conventional circuits, and / or combinations thereof that are programmed using one or more programs stored in one or more memories, or otherwise configured to perform the disclosed functions. A processor is considered processing circuitry or circuitry because it includes transistors and other circuits. A processor may be a programmed processor that executes programs stored in memory. In this disclosure, circuits, units, or means are hardware that performs the enumerated functions, or hardware programmed to perform the enumerated functions. Hardware may be any hardware disclosed herein that is programmed or configured to perform the enumerated functions.
[0059] There is memory for storing a computer program that includes computer instructions. These computer instructions provide logic and routines that enable hardware (e.g., processing circuitry or circuitry) to perform the methods disclosed herein. This computer program can be implemented in commonly known forms, such as computer-readable storage media, computer program products, memory devices, recording media such as CD-ROMs and DVDs, and / or memory of FPGAs and ASICs. [Explanation of symbols]
[0060] 10 Information provision device 11 Communications Department 12 Input section 13 Output section 14 Storage section 15 Control Unit 141 User Information 142 Line Information 151 Acquisition Department 152 Management Department 153 Provision Department
Claims
1. An acquisition unit that acquires the detection results of unauthorized communication for each line, A provisioning unit that provides a portal screen to the user of the line where unauthorized communication has been detected, and to the user designated as the recipient of the said line, to display the results of the unauthorized communication detection on the said line. An information-providing device having the following features.
2. An acquisition unit that acquires the detection result of unauthorized communication for each line, A provisioning unit that provides the results of the detection of unauthorized communication on the line to the user of the line on which unauthorized communication was detected, and to the user designated as the recipient of the line. The management department requests the second user to approve the provision of the detection results of unauthorized communication on the first user's line to the second user, It has, The providing unit will provide the second user with the results of detecting unauthorized communication on the line if the second user approves. Information provision device.
3. The management unit further requests the second user to approve the apportionment rate for the service fee that will be used to provide the second user with the results of detecting unauthorized communication on the line. The information providing device according to claim 2.
4. Obtain the detection results for unauthorized communication for each line, A portal screen is provided to display the results of the detection of unauthorized communication on the line to the user of the line where unauthorized communication has been detected, and to the user designated as the recipient of the said line. A method of providing information that allows a computer to perform processing.
5. Obtain the detection results of unauthorized communication for each line, The user of the line where the unauthorized communication was detected, and the user designated as the recipient of the said line, will be provided with the results of the unauthorized communication detection on the said line. The second user is asked to approve the provision of the detection results of unauthorized communication on the first user's line to the second user. The computer performs the process, The process described above, if approved by the second user, provides the second user with the results of detecting unauthorized communication on the line. Information provision method.
6. Obtain the detection results for unauthorized communication for each line, A portal screen is provided to display the results of the detection of unauthorized communication on the line to the user of the line where unauthorized communication has been detected, and to the user designated as the recipient of the said line. A program that provides information to a computer to perform a process.
7. Obtain the detection results of unauthorized communication for each line, The user of the line where the unauthorized communication was detected, and the user designated as the recipient of the said line, will be provided with the results of the unauthorized communication detection on the said line. The second user is asked to approve the provision of the detection results of unauthorized communication on the first user's line to the second user. Let the computer perform the process, The process described above, if approved by the second user, provides the second user with the results of detecting unauthorized communication on the line. Information provision program.