Programs, methods, information processing devices, systems

JP7926818B2Active Publication Date: 2026-09-30OPTIM
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2024056626
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2024-03-29
Publication Date
2026-09-30
Estimated Expiration
2044-03-29

Smart Images

  • Figure 0007926818000001
    Figure 0007926818000001
  • Figure 0007926818000002
    Figure 0007926818000002
  • Figure 0007926818000003
    Figure 0007926818000003
Patent Text Reader

Abstract

To determine, in advance, an access to a service of which the use is to be restricted.SOLUTION: A program to be executed by a computer equipped with a processor and a memory, causes the processor to execute the steps of: acquiring first character string information stored in a clip board region prepared in a memory; and comparing the first character string information with second character string information pertaining to a service of which the use is to be restricted, stored in advance in the memory, to determine whether the first character string information is character string information pertaining to the service of which the use is to be restricted.SELECTED DRAWING: Figure 16
Need to check novelty before this filing date? Find Prior Art

Description

[[TECHNICAL FIELD]]

[0001] The present disclosure relates to a program, a method, an information processing apparatus, and a system. [[BACKGROUND ART]]

[0002] In recent years, the use of SaaS (Software as a Service) has been expanding. In SaaS, software running on a server is provided as a service to users via a network such as the Internet. Patent Document 1 describes an information processing apparatus or the like that can identify a service being used. [[PRIOR ART DOCUMENTS]] [[PATENT DOCUMENTS]]

[0003] [[Patent Document 1]] Japanese Patent No. 7044451 [[SUMMARY OF THE INVENTION]] [[Problems to be Solved by the Invention]]

[0004] In Patent Document 1, a server receives a monitoring result of an access log by a terminal device, and identifies a service that is not a management target in the server. However, when a user accesses a service that is not a management target, there is a possibility that problems such as information leakage have already occurred. Therefore, if it can be determined in advance that a user is trying to access a service that is not a management target, that is, a service whose use should be restricted, appropriate measures can be taken before the service is actually used.

[0005] An object of the present disclosure is to determine access to a service whose use should be restricted in advance. [[Means for Solving the Problems]]

[0006] A program for execution on a computer having a processor and memory, the program causing the processor to perform the steps of: obtaining first string information stored in a clipboard area provided in memory; and determining whether the first string information is string information relating to a service that should be restricted by comparing the first string information with second string information relating to a service that should be restricted, which is stored in memory beforehand. [Effects of the Invention]

[0007] According to this disclosure, it is possible to proactively determine whether access to services should be restricted. [Brief explanation of the drawing]

[0008] [Figure 1] This is a block diagram showing an example of the overall configuration of System 1. [Figure 2] Figure 1 is a block diagram showing an example configuration of the terminal device 10. [Figure 3] This figure shows an example of the functional configuration of the first server 20. [Figure 4] This figure shows an example of the functional configuration of the second server 30. [Figure 5] This diagram shows the data structure of correspondence table 182. [Figure 6] This diagram shows the data structure of account table 183. [Figure 7] This diagram shows the data structure of SaaS table 184. [Figure 8] This diagram shows the data structure of the judgment result table 185. [Figure 9] This diagram shows the data structure of restriction table 186. [Figure 10] This figure shows the data structure of the target table 188. [Figure 11] This diagram shows the data structure of the detection log table 189. [Figure 12]It is a diagram showing the data structure of the aggregation table 2022 stored in the first server 20. [Figure 13] It is a schematic diagram showing processing in which the agent application 187 installed in the terminal device 10 monitors processing performed by a user. [Figure 14] It is a flowchart showing an example of the operation of the terminal device 10 when monitoring a user's operation. [Figure 15] It is a schematic diagram showing an example of a display screen of the display 141 of the terminal device 10. [Figure 16] It is a schematic diagram showing processing in which the agent application 187 installed in the terminal device 10 monitors a clipboard area. [Figure 17] It is a flowchart showing an example of the operation of the terminal device 10 when monitoring a clipboard area. [Figure 18] It is a schematic diagram showing an example of a display screen of the display 141 of the terminal device 10. [Figure 19] It is a flowchart showing an example of the operation of the terminal device 10 when updating a detection target. [Figure 20] It is a block diagram showing a basic hardware configuration of a computer 90. DETAILED DESCRIPTION OF EMBODIMENTS

[0009] Hereinafter, embodiments of the present disclosure will be described with reference to the drawings. In the following description, identical components are denoted by identical reference numerals. Their names and functions are also the same. Therefore, detailed description thereof will not be repeated.

[0010] <Outline> An agent application is installed in a terminal device, and an agent implemented by the agent application monitors an operation performed by a user. The agent identifies a service used by the user based on the detected operation, and determines whether the identified service is a managed service.

[0011] The agent transmits the determination result to the server in accordance with the determination result. The agent also limits the operation of the terminal device in accordance with the determination result.

[0012] Furthermore, the agent implemented by the agent application monitors the specific storage area reserved for the clipboard function provided by the OS of the terminal device. The agent determines whether the character string information stored in the storage area is character string information related to a service whose use should be restricted. The agent executes predetermined processing in accordance with the determination result.

[0013] <1 Overall system configuration diagram> FIG. 1 is a block diagram showing an example of the overall configuration of a system 1. The system 1 shown in FIG. 1 includes, for example, a terminal device 10, a first server 20, and a second server 30. The terminal device 10, the first server 20, and the second server 30 are communicatively connected via, for example, a network 80.

[0014] Although FIG. 1 shows an example in which the system 1 includes two terminal devices 10, the number of terminal devices 10 included in the system 1 is not limited to two. The number of terminal devices 10 included in the system 1 may be less than three or three or more.

[0015] In FIG. 1, an aggregate of a plurality of devices may be used as one first server 20. The method of allocating the plurality of functions required for implementing the first server 20 according to the present embodiment to one or more pieces of hardware can be appropriately determined in consideration of the processing capacity of each piece of hardware and / or the specifications required for the first server 20, and the like.

[0016] In FIG. 1, an aggregate of a plurality of devices may be used as one second server 30. The method of allocating the plurality of functions required for implementing the second server 30 according to the present embodiment to one or more pieces of hardware can be appropriately determined in consideration of the processing capacity of each piece of hardware and / or the specifications required for the second server 30, and the like.

[0017] The terminal device 10 shown in Figure 1 is, for example, an information processing device operated by a user. Specifically, for example, the terminal device 10 is an information processing device operated by an employee belonging to a company.

[0018] The terminal device 10 may be implemented by, for example, a stationary PC, a laptop PC, etc. The terminal device 10 may also be a mobile device such as a smartphone or tablet. The terminal device 10 may also be a wearable device such as an HMD (Head Mount Display) or a smartwatch.

[0019] The terminal device 10 comprises a communication interface 12, an input device 13, an output device 14, memory 15, storage 16, and a processor 19. The input device 13 is a device for receiving input operations from the user (e.g., a touch panel, touchpad, mouse or other pointing device, keyboard, etc.). The output device 14 is a device for presenting information to the user (display, speaker, etc.).

[0020] The first server 20 is, for example, an information processing device that manages web services used by employees belonging to a company. The first server 20 is implemented, for example, by a computer connected to a network 80. As shown in Figure 1, the first server 20 includes a communication IF 22, an I / O IF 23, memory 25, storage 26, and a processor 29. The I / O IF 23 functions as an interface to an input device for receiving input operations from a user and an output device for outputting information to the user.

[0021] The second server 30 is, for example, an information processing device that provides web services used by employees belonging to a company. In other words, the second server 30 is, for example, an information processing device that provides SaaS (Software as a Service). The second server 30 issues accounts to employees based on a contract with the company. Employees use the web services through the assigned accounts. The second server 30 is implemented by, for example, a computer connected to the network 80. The second server 30 has a configuration similar to the first server 20 in Figure 1.

[0022] Each information processing device consists of a computer equipped with an arithmetic unit and a memory device. The basic hardware configuration of the computer and the basic functional configuration of the computer realized by said hardware configuration will be described later. For each of the terminal device 10, the first server 20, and the second server 30, explanations that overlap with the basic hardware configuration and basic functional configuration of the computer described later will be omitted.

[0023] <1.1 Terminal Device Configuration> Figure 2 is a block diagram showing an example configuration of the terminal device 10 shown in Figure 1. As shown in Figure 2, the terminal device 10 includes a communication unit 120, an input device 13, an output device 14, an audio processing unit 17, a microphone 171, a speaker 172, a camera 160, a location information sensor 150, a storage unit 180, and a control unit 190. Each block included in the terminal device 10 is electrically connected, for example, by a bus.

[0024] The communication unit 120 performs processing such as modulation and demodulation processing for the terminal device 10 to communicate with other devices. The communication unit 120 performs transmission processing on the signal generated by the control unit 190 and transmits it to an external source (for example, the first server 20 or the second server 30). The communication unit 120 performs reception processing on the signal received from the external source and outputs it to the control unit 190.

[0025] The input device 13 is a device for a user operating the terminal device 10 to input instructions or information. The input device 13 can be implemented, for example, by a touch-sensitive device 131 on which instructions are input by touching the operating surface. If the terminal device 10 is a PC, the input device 13 may be implemented by a reader, keyboard, mouse, etc. The input device 13 converts the instructions input by the user into electrical signals and outputs the electrical signals to the control unit 190. The input device 13 may also include, for example, a receiving port that accepts electrical signals input from an external input device.

[0026] The output device 14 is a device for presenting information to the user operating the terminal device 10. The output device 14 is implemented, for example, by a display 141. The display 141 displays data according to the control of the control unit 190. The display 141 is implemented, for example, by an LCD (Liquid Crystal Display) or an organic EL (Electro-Luminescence) display.

[0027] The audio processing unit 17 performs, for example, digital-to-analog conversion processing of the audio signal. The audio processing unit 17 converts the signal received from the microphone 171 into a digital signal and provides the converted signal to the control unit 190. The audio processing unit 17 also provides the audio signal to the speaker 172. The audio processing unit 17 is implemented, for example, by an audio processing processor. The microphone 171 receives an audio input and provides the audio signal corresponding to that audio input to the audio processing unit 17. The speaker 172 converts the audio signal received from the audio processing unit 17 into audio and outputs the audio to the outside of the terminal device 10.

[0028] Camera 160 is a device that receives light using a photodetector and outputs it as a shooting signal.

[0029] The location information sensor 150 is a sensor that detects the position of the terminal device 10, and is, for example, a GPS (Global Positioning System) module. A GPS module is a receiving device used in a satellite positioning system. In a satellite positioning system, signals are received from at least three or four satellites, and the current position of the terminal device 10, which is equipped with a GPS module, is detected based on the received signals. The location information sensor 150 may also detect the current position of the terminal device 10 from the position of the wireless base station to which the terminal device 10 is connected.

[0030] The storage unit 180 is implemented, for example, by memory 15 and storage 16, and stores data and programs used by the terminal device 10. The storage unit 180 stores, for example, user information 181, correspondence table 182, account table 183, SaaS table 184, decision result table 185, restriction table 186, and agent application 187. The tables and applications stored in the storage unit 180 are not limited to these.

[0031] User information 181 includes, for example, information about a user who uses terminal device 10. User information includes, for example, user ID, user's name, age, address, date of birth, password, contact information (address), etc.

[0032] The correspondence table 182 is a table that associates SaaS with processes performed by users. Details will be described later. The correspondence table 182 is based, for example, on master information stored on the first server 20. When the master information is updated, for example, the entire master information or the updated parts are downloaded from the first server 20 to maintain the latest state of the correspondence table 182.

[0033] The account table 183 is a table that stores information about accounts set for users. Details will be described later. The account table 183 is based, for example, on master information stored on the first server 20. When the master information is updated, for example, the entire master information or the updated parts are downloaded from the first server 20 to maintain the latest state of the account table 183.

[0034] The SaaS table 184 is a table that stores SaaS applications under management. SaaS applications stored in the SaaS table 184 are, for example, SaaS applications that are not permitted for use. In other words, the SaaS table 184 is a blacklist. Alternatively, SaaS applications stored in the SaaS table 184 may be, for example, SaaS applications that are permitted for use. In other words, the SaaS table 184 may be a whitelist. Details will be described later. The SaaS table 184 is based on master information stored in the first server 20, for example. When the master information is updated, the SaaS table 184 is kept up-to-date by downloading the entire master information or the updated parts from the first server 20.

[0035] The judgment result table 185 is a table that stores the results determined based on the detected processing. Details will be described later.

[0036] The restriction table 186 is a table that associates the judgment result with the restrictions on the operation of the terminal device 10. Details will be described later. The restriction table 186 is based, for example, on master information stored in the first server 20. When the master information is updated, for example, the entire master information or the updated parts are downloaded from the first server 20 to maintain the latest state of the restriction table 186.

[0037] Agent app 187 is an application for managing user usage of SaaS. Agent app 187 is installed on terminal device 10. Agent app 187 runs in the background of other applications installed on terminal device 10, for example, and monitors processes performed by the user.

[0038] Table 188, the detection target table, stores string information that should be detected for services that should be restricted from user access. Details will be described later.

[0039] The detection log table 189 is a table that stores the detection history on the terminal device 10 of the string information of the detected targets registered in the detection target table 188. Details will be described later.

[0040] The control unit 190 is realized by the processor 19 reading a program, including an agent application 187, stored in the memory unit 180, and executing instructions contained in the program. The control unit 190 controls the operation of the terminal device 10. By operating according to the program, the control unit 190 performs the functions of an operation reception unit 191, a transmission / reception unit 192, a presentation control unit 193, a first acquisition unit 194, a second acquisition unit 195, a determination unit 196, a restriction unit 197, a string acquisition unit 199, a restriction target determination unit 1910, a post-detection processing unit 1911, and a detection target update unit 1912.

[0041] The operation reception unit 191 processes instructions or information input from the input device 13. Specifically, for example, the operation reception unit 191 receives instructions or information input from a touch-sensitive device 131 or the like.

[0042] Furthermore, the operation reception unit 191 receives voice instructions input from the microphone 171. Specifically, for example, the operation reception unit 191 receives voice signals input from the microphone 171 and converted into digital signals by the voice processing unit 17. The operation reception unit 191 obtains instructions from the user by, for example, analyzing the received voice signals and extracting predetermined nouns.

[0043] The transmitting / receiving unit 192 performs processing to enable the terminal device 10 to send and receive data with an external device such as the first server 20 or the second server 30 in accordance with a communication protocol. Specifically, for example, the transmitting / receiving unit 192 transmits information or instructions from the user to the first server 20 or the second server 30. The transmitting / receiving unit 192 also receives information provided by the first server 20 or the second server 30.

[0044] The presentation control unit 193 controls the output device 14 in order to present information provided by the first server 20 or the second server 30 to the user. Specifically, for example, the presentation control unit 193 causes the information provided by the first server 20 or the second server 30 to be displayed on the display 141. The presentation control unit 193 also causes the information provided by the first server 20 or the second server 30 to be output from the speaker 172.

[0045] The first acquisition unit 194 acquires information about processes executed by the user operating the terminal device 10. Specifically, for example, the first acquisition unit 194 acquires the name of the application executed by the user's operation and the process name of that application. The first acquisition unit 194 stores the acquired application name, process name, and the date and time these information was acquired in the storage unit 180 (not shown).

[0046] Furthermore, the first acquisition unit 194 acquires information generated when a user operates the browser. This information includes, for example, the browser's usage history, and more specifically, the URLs and page titles of the web pages the user has visited using the browser. The first acquisition unit 194 acquires this information from the browser used in the terminal device 10 at predetermined intervals, for example, every 5 minutes. The first acquisition unit 194 stores the acquired information, the date and time the information was acquired, the name of the browser from which the information was acquired, and the identification information of the terminal device 10 (for example, the device GUID) in the storage unit 180 (not shown).

[0047] The second acquisition unit 195 acquires information about the SaaS used by the user based on information about the processes performed by the user. Specifically, for example, the second acquisition unit 195 matches the URL of the web page visited by the user with the correspondence table 182 and obtains the SaaSID of the SaaS used by the user. In this way, the second acquisition unit 195 identifies the SaaS used by the user.

[0048] Based on the acquired SaaSID, the determination unit 196 determines whether the SaaS used by the user is a SaaS to be managed. The determination unit 196 stores the determination result in the determination result table 185. This can be rephrased as, for example, the determination unit 196 storing in the determination result table 185 the processes that the user has performed that should be managed.

[0049] Specifically, for example, the determination unit 196 refers to the SaaS table 184, or to the account table 183 and the SaaS table 184, to determine whether the user's use of SaaS is appropriate.

[0050] More specifically, for example, if the SaaS table 184 is a blacklist and contains SaaS that are prohibited from use (SaaS as managed), the determination unit 196 determines whether the acquired SaaSID is included in the SaaS table 184. If the acquired SaaSID is included in the SaaS table 184, the determination unit 196 stores in the determination result table 185 that the user used an unauthorized SaaS. If the acquired SaaSID is not included in the SaaS table 184, the determination unit 196 refers to the account table 183 and determines whether the user has an account for the acquired SaaSID. If the user has an account for the acquired SaaSID, the determination unit 196 does not store any information in the determination result table 185. If the user does not have an account for the acquired SaaSID, the determination unit 196 stores in the determination result table 185 that the user used the SaaS using a shadow ID.

[0051] Furthermore, for example, if the SaaS table 184 is a whitelist and the SaaS for which use is permitted (SaaS as managed) is included in the SaaS table 184, the determination unit 196 determines whether or not the acquired SaaSID is included in the SaaS table 184. If the acquired SaaSID is not included in the SaaS table 184, the determination unit 196 stores in the determination result table 185 that the user used an unauthorized SaaS. If the acquired SaaSID is included in the SaaS table 184, the determination unit 196 refers to the account table 183 and determines whether or not the user has an account for the acquired SaaSID. If the user has an account for the acquired SaaSID, the determination unit 196 does not store any information in the determination result table 185. If the user does not have an account for the acquired SaaSID, the determination unit 196 stores in the determination result table 185 that the user used the SaaS using a shadow ID.

[0052] The transmitting / receiving unit 192 transmits the decision results stored in the decision result table 185 to the first server 20. Specifically, for example, the transmitting / receiving unit 192 transmits the decision results stored in the decision result table 185 to the first server 20 at predetermined intervals.

[0053] The transmitting / receiving unit 192 does not have to send all of the decision results stored in the decision result table 185 to the first server 20. For example, the transmitting / receiving unit 192 may send to the first server 20 only the decision results that meet predetermined conditions from among the decision results stored in the decision result table 185. Specifically, for example, the transmitting / receiving unit 192 determines whether or not the decision results stored in the decision result table 185 meet predetermined conditions. The predetermined conditions include, for example, the following: • The use of a SaaS that was on the blacklist. • The number of times the same judgment has been made has reached a predetermined value. • The number of times the same judgment was made within a specified period reached a specified value.

[0054] The transmitting / receiving unit 192 transmits the judgment result to the first server 20 if, for example, the judgment result stored in the judgment result table 185 satisfies at least one of the above conditions, or at least one combination thereof.

[0055] The restriction unit 197 restricts the operation of the terminal device 10 based on the determination result of the determination unit 196. In other words, the restriction unit 197 restricts the operation of the processor of the terminal device 10 based on the determination result of the determination unit 196. Specifically, for example, the restriction unit 197 determines whether the determination result stored in the determination result table 185 satisfies predetermined conditions. The predetermined conditions include, for example, the following: • The use of a SaaS that was on the blacklist. • The number of times the same judgment has been made has reached a predetermined value. • The number of times the same judgment was made within a specified period reached a specified value. • The user has the required permissions.

[0056] The limiting unit 197 imposes a predetermined restriction on the operation of the terminal device 10 if, for example, the judgment result stored in the judgment result table 185 satisfies at least one of the above conditions, or at least one combination thereof. The predetermined restriction includes, for example, the following: - Disable any operations on terminal device 10. • Prohibition of access to the specified URL • Prohibit execution of specified applications. • Prohibit access to designated folders. • Execution of specified files is prohibited. • Prohibition of specified operations such as reading and writing. • Stopping running applications

[0057] The judgment result and the restrictions on the operation of the terminal device 10 are stored, for example, in the restriction table 186. The restriction unit 197, for example, compares the judgment result of the judgment unit 196 with the restriction table 186 and determines the restrictions on the operation of the terminal device 10.

[0058] The string acquisition unit 199 acquires string information relating to a string from a storage area in the storage unit 180 provided for the clipboard function of the terminal device 10. Here, in this disclosure, the clipboard function is a function provided by, for example, the OS of the terminal device 10, and refers to a function that transfers information stored in a specific storage area in the storage unit 180 between processes of a predetermined application. In this disclosure, the storage area in the storage unit 180 provided for the clipboard function is referred to as the clipboard area.

[0059] Specifically, the string retrieval unit 199 accesses the clipboard area at a predetermined timing. If string information is stored in the clipboard area, the string retrieval unit 199 retrieves that string information. However, if the string information stored in the clipboard area is the same as the string information retrieved at the previous timing, the string retrieval unit 199 does not need to retrieve that string information.

[0060] The string acquisition unit 199 accesses the clipboard area using the clipboard function and acquires string information at the timings exemplified below, for example. • Predetermined cycle • The timing when information is entered into the clipboard area. For example, the timing when a given application calls an API related to the clipboard function in order to copy string information. • The timing at which information is output from the clipboard area. For example, the timing at which a specific application calls an API related to the clipboard function in order to paste string information. • The timing when notification is received that information stored in the clipboard area has been changed. For example, a notification is received from a designated application that information stored in the clipboard area has been changed.

[0061] The restriction determination unit 1910 determines whether the first string information obtained by the string acquisition unit 199 is restricted string information relating to a service whose use by the user should be restricted.

[0062] Specifically, the restriction determination unit 1910 compares the first string information with the second string information stored in the "Detection Target" column of the detection target table 188 to determine whether the first string information is restricted string information.

[0063] For example, the restriction determination unit 1910 determines that the first string information is restricted string information if it can be associated with the second string information. The case in which the first string information can be associated with the second string information is when it is possible to associate the string information stored in the "Detection Target" field of at least one record in the detection target table 188 with the first string information, for example, as follows. If the string information stored in the "Target" field of at least one record in the target table 188 matches the first string information. If the string information stored in the "Detection Target" field of at least one record in the detection target table 188 contains the first string information. - If the first string information includes string information stored in the "Detected" field of at least one record in the target table 188.

[0064] Furthermore, the fact that the first string information could be associated with the second string information can also be expressed as "the target was detected from the first string information" or "the first string information was included in the second string information."

[0065] Furthermore, the restriction determination unit 1910 may determine whether the first string information is string information representing a URL based on whether the first string information contains specific elements such as a protocol name or a domain name. If the first string information represents a URI that includes a URL (hereinafter referred to as a URL in the sense of an example), the restriction determination unit 1910 may extract specific elements or combinations of elements of the URL and treat them as the first string information. For example, the restriction determination unit 1910 may extract the domain portion from the URL and determine whether the string information of the domain portion is string information subject to restriction.

[0066] Furthermore, the restriction determination unit 1910 may use any natural language processing technique to extract strings indicating a specific part of speech (e.g., a noun) from the first string information and treat them as the first string information. The extracted strings may be one or more. For example, the restriction determination unit 1910 may determine whether the extracted noun string information is restricted string information.

[0067] Furthermore, if the restriction determination unit 1910 determines that the first string information is string information relating to a service that should be restricted, the presentation control unit 193 may present to the user that the first string information has been determined to be string information relating to a service that should be restricted (determination result).

[0068] If the post-detection processing unit 1911 determines that the first string information is restricted string information, it performs a predetermined process on the operation of the terminal device 10.

[0069] The predetermined processing includes, for example, the following. The content of the predetermined processing to be performed by the post-detection processing unit 1911 is set in advance by, for example, an administrator or the like making a setting for the agent application 187, which selects one or more of the following processes in advance. (Restrictions on operations on terminal device 10) - Disable any operations on terminal device 10. (Operations on the clipboard area) • Deletion of the first string information from the clipboard area. • Modification of the first string information stored in the clipboard (for example, changing it to a predetermined notification or warning message) (Restrictions on the operation of the application that is the source (copy source) of the first string information) • Stopping the application • Prohibition of inputting information into the clipboard area (copy operation) (Restrictions on the operation of the application to which the first string information is output (pasted)) • Stopping the application • Prohibition of outputting information from the clipboard area to a specified application (paste operation). (Prohibition of access to the service provider) • Disconnection from network communication • Prohibition of connections to destinations that include the first string information as identification information. For example, prohibition of connections to destinations (including resources) identified by the first string information (URL, etc.). Also, for example, prohibition of connections to search results pages that include the first string information (word, etc.) in the search query portion, or prohibition of connections to destinations that can be accessed from such search results pages. In this case, the string representing the word may be expressed in a format that is arbitrarily encoded for incorporation into the URL. (Presenting information to the user) • Presentation or notification to the user via display 141, speaker 172, etc., regarding the determination that the first string information is restricted string information. • Presentation or notification to the user via display 141, speaker 172, etc., of information regarding the execution of a predetermined process.

[0070] The detection target update unit 1912 updates the second string information that is the target of detection. Specifically, the detection target update unit 1912 acquires new string information to be detected and updates the second string information by storing this new string information in the detection target table 188.

[0071] For example, the detection target update unit 1912 acquires new string information to be detected, as follows:

[0072] (Accepting input of string information) For example, the detection target update unit 1912 acquires string information entered by the user via the input device 13. Alternatively, for example, the detection target update unit 1912 receives string information from other information processing devices such as the first server 20 via the network 80. The user operating these information processing devices is, for example, the user who manages the terminal device 10.

[0073] (Retrieving string information related to SaaS that is not permitted for use) Furthermore, for example, the detection target update unit 1912 may, at a predetermined timing, obtain string information about SaaS that are not permitted to be used from the SaaS table 184, which manages SaaS as a blacklist. For example, the detection target update unit 1912 may obtain the following information about the updated parts of the SaaS table 184 when the SaaS table 184 is updated by information downloaded from the master information of the first server 20 to the terminal device 10. Note that the following information may also be obtained directly from the master information of the first server 20 via the network 80 without going through the SaaS table 184. • Name of SaaS • Information regarding the connection destination for accessing SaaS.

[0074] (In response to the detection of inappropriate SaaS usage, string information is retrieved.) Furthermore, for example, the detection target update unit 1912 acquires string information related to a SaaS in response to the detection of inappropriate use of a SaaS by a user. For example, if the first acquisition unit 194 acquires information about a process performed by a user, the second acquisition unit 195 acquires information about the SaaS used in that process, and the determination unit 196 determines that the use of the SaaS related to that process is inappropriate, the detection target update unit 1912 may acquire the following information. • SaaS name: For example, the detection target update unit 1912 searches the SaaS table 184 based on the SaaSID of the SaaS and obtains string information indicating the name of the SaaS. • Information regarding the connection destination for accessing the SaaS: For example, the detection target update unit 1912 obtains information about the SaaS obtained by the second acquisition unit 195 (for example, information about the provider such as the URL).

[0075] The detection target update unit 1912 updates the detection target by storing the string information obtained as described above in the detection target table 188 as a new detection target.

[0076] In this case, the detection target update unit 1912 may store a portion of the acquired string information in the detection target table 188. For example, if the acquired string information is a URL, the detection target update unit 1912 may extract a predetermined element from the URL and store it in the detection target table 188. For example, the detection target update unit 1912 may store the domain name extracted from the acquired URL in the detection target table 188. This makes detection more comprehensive than if the entire URL were the detection target. Furthermore, even if the URL structure of the SaaS changes, the detection target can continue to be detected as long as the registered components (domain name, etc.) remain unchanged.

[0077] <1.2 Functional Configuration of the First Server> Figure 3 shows an example of the functional configuration of the first server 20. As shown in Figure 3, the first server 20 functions as a communication unit 201, a storage unit 202, and a control unit 203.

[0078] The communications unit 201 performs processing to enable the first server 20 to communicate with external devices.

[0079] The storage unit 202 may include, for example, a user information table 2021, an aggregation table 2022, a correspondence master table 2023, an account master table 2024, a SaaS master table 2025, a restriction master table 2026, etc. The tables stored in the storage unit 202 are not limited to these.

[0080] User Information Table 2021 is a table that stores information about users as employees. For example, User Information Table 2021 can store information about multiple users. User Information Table 2021 is updated when information about a new user is registered.

[0081] The summary table 2022 is a table that stores information compiled from the decision results transmitted from the terminal device 10. For example, the human resources department of a company that manages the first server 20 may refer to the summary table 2022 to evaluate users.

[0082] The Correspondence Master Table 2023 is a table that stores master information on the correspondence between SaaS applications and processes performed by users. The Correspondence Master Table 2023 is updated whenever new correspondences between SaaS applications and information about their operation are registered.

[0083] The Account Master Table 2024 is a table that stores information about accounts set up for multiple users. The Account Master Table 2024 is updated whenever a new account is issued.

[0084] The SaaS Master Table 2025 is a table that stores master information on SaaS applications under management. The SaaS Master Table 2025 is updated whenever a new SaaS application is registered.

[0085] The Restriction Master Table 2026 is a table that stores master information regarding the correspondence between the judgment result and the operational restrictions of the terminal device 10. The Restriction Master Table 2026 is updated when a new correspondence between the judgment result and the operational restrictions of the terminal device 10 is registered.

[0086] The control unit 203 is realized when the processor 29 reads a program stored in the memory unit 202 and executes instructions contained in the program. By operating according to the program, the control unit 203 performs the functions indicated as the receive control module 2031, the transmit control module 2032, the aggregation module 2033, the management module 2034, and the creation module 2035.

[0087] The receiver control module 2031 controls the process by which the first server 20 receives signals from an external device according to a communication protocol.

[0088] The transmission control module 2032 controls the process by which the first server 20 transmits signals to an external device according to a communication protocol.

[0089] The aggregation module 2033 controls the aggregation of decision results transmitted from the terminal device 10. Specifically, for example, the aggregation module 2033 updates the aggregation table 2022 based on the decision results transmitted from the terminal device 10.

[0090] The management module 2034 manages the information stored in the storage unit 202. Specifically, for example, the management module 2034 updates the user information table 2021 if there is information about a new user. Also, for example, the management module 2034 updates the correspondence master table 2023 if there is a new correspondence between a SaaS and a process performed by a user. Also, for example, the management module 2034 updates the account master table 2024 if a new account is issued. Also, for example, the management module 2034 updates the SaaS master table 2025 if there is a new SaaS. Also, for example, the management module 2034 updates the restriction master table 2026 if there is a new correspondence between a judgment result and a restriction on the operation of the terminal device 10.

[0091] The creation module 2035 creates information listing predetermined information based on the information transmitted from the terminal device 10. Specifically, the creation module 2035 understands the hardware being used by the user based on the identification information of the terminal device 10 transmitted from the terminal device 10. The creation module 2035 then creates information listing the hardware and software (applications and SaaS) being used by the user.

[0092] <1.3 Functional Configuration of the Second Server> Figure 4 shows an example of the functional configuration of the second server 30. As shown in Figure 4, the second server 30 functions as a communication unit 301, a storage unit 302, and a control unit 303.

[0093] The communication unit 301 performs processing to enable the second server 30 to communicate with external devices.

[0094] The storage unit 302 includes, for example, a user information table 3021. The tables stored in the storage unit 302 are not limited to these. For example, tables other than the user information table 3021 may be stored.

[0095] User information table 3021 is, for example, a table that stores information about users of companies that receive services provided by the second server 30.

[0096] The control unit 303 is realized when the processor reads a program stored in the memory unit 302 and executes instructions contained in the program. By operating according to the program, the control unit 303 performs the functions indicated as the receive control module 3031, the transmit control module 3032, and the service provision module 3033.

[0097] The receiving control module 3031 controls the process by which the second server 30 receives signals from an external device in accordance with a communication protocol.

[0098] The transmission control module 3032 controls the process by which the second server 30 transmits signals to an external device according to a communication protocol.

[0099] The service provision module 3033 provides services to, for example, users of a company that receives services provided by the second server 30.

[0100] <2 Data Structure> Figures 5 to 11 show the data structure of the tables stored by the terminal device 10. Note that Figures 5 to 11 are examples and do not exclude data not shown. Furthermore, even data listed in the same table may be stored in separate memory areas within the storage unit 180.

[0101] Figure 5 shows the data structure of correspondence table 182. Correspondence table 182, as shown in Figure 5, is a table that uses SaaSID as the key and has columns such as URL. Note that correspondence table 182 may also have columns that store other information.

[0102] The SaaSID is an item that stores an identifier to uniquely identify a SaaS. The URL is an example of information that indicates that the SaaS has been executed. The "URL" item stores, for example, the URL of the homepage that provides the corresponding SaaS.

[0103] Figure 6 shows the data structure of account table 183. Account table 183, as shown in Figure 6, is a table that uses User ID as the key and has columns such as SaaSID, usage scope, and registration start date. Note that account table 183 may have columns that store other information, or it may not have any of this information.

[0104] The User ID is an item that stores an identifier to uniquely identify a user. The Scope of Use is an item that stores the range of functions permitted to the user when using the SaaS. The Scope of Use is set, for example, when the account is signed up. The Scope of Use may be changed at any time during the contract period, or at a predetermined time, such as when a renewal request is submitted. The Registration Start Date is an item that stores the date when the account was registered and the use of the SaaS began.

[0105] Figure 7 shows the data structure of SaaS table 184. SaaS table 184, as shown in Figure 7, is a table with columns such as name, provider, version, and support information, with SaaSID as the key. Note that SaaS table 184 may have columns to store other information, or it may not have any of this information.

[0106] The "Name" field stores the name of the SaaS. The "Provider" field stores the entity that provides the SaaS. The "Provider" field may store, for example, the name of the company or the address of the website providing the service. The "Provider" field may also store information about the connection destination for accessing the SaaS. Information about the connection destination may include, for example, the URL of the website providing the SaaS or at least one of the elements that make up the URL (protocol name, hostname, domain name, path, etc.), the IP address of the connection destination, the port number, etc. Alternatively, information about the connection destination may include information for identifying the server or other resources on which the SaaS is provided in network space (this network space can be accessed via the internet and / or intranet).

[0107] The "Version" field stores the version of the SaaS being offered. The "Support Information" field stores information about the support provided for the SaaS.

[0108] Figure 8 shows the data structure of the judgment result table 185. The judgment result table 185 shown in Figure 8 is a table that uses date and time as the key and has columns for software used, usability, and account existence. The judgment result table 185 may also have columns that store other information, or it may not have any of this information. For example, the judgment result table 185 may have a column that stores whether the SaaS is on a blacklist.

[0109] The "Date and Time" field stores the date and time when usage was detected. The "Software Used" field stores information about the SaaS whose usage was detected. In the example shown in Figure 8, the "Software Used" field stores the SaaSID of the SaaS whose usage was detected. The "Available" field stores whether the SaaS whose usage was detected is a SaaS whose use is permitted. The determination unit 196 determines whether the SaaS whose usage was detected is permitted by referring to the SaaS table 184. In the example shown in Figure 8, "1" is stored if it is available, and "0" is stored if it is unavailable. The "Account Existence" field stores whether the user has an account for the SaaS whose usage was detected. The determination unit 196 determines whether the user has an account for the SaaS whose usage was detected by referring to the account table 183. In the example shown in Figure 8, "1" is stored if the user has an account, and "0" is stored if the user does not have an account.

[0110] Figure 9 shows the data structure of the restriction table 186. The restriction table 186 shown in Figure 9 is a table that has columns such as correspondence and priority, with the condition as the key. Note that the restriction table 186 may also have columns that store other information.

[0111] The "Condition" field stores the conditions under which restrictions are placed on the operation of the terminal device 10. For example, the following information may be stored in the "Condition" field: • The user had the necessary permissions, and the SaaS used was blacklisted. • The number of times the same judgment has been made has reached a predetermined value. • The number of times the same judgment was made within a specified period reached a specified value.

[0112] The "Restrictions" item stores the restrictions imposed on the terminal device 10. For example, the following may be stored in the "Restrictions" item: - Disable any operations on terminal device 10. • Prohibition of access to the specified URL • Prohibit execution of specified applications. • Prohibit access to designated folders. • Execution of specified files is prohibited. • Prohibition of specified operations such as reading and writing. • Stopping running applications

[0113] Priority is an item that stores the order of priority when adopting a restriction. For example, priority 1 has a higher priority than priorities 2 and 3, and if multiple conditions are met simultaneously, the restriction with the highest priority will be adopted. Note that if multiple conditions are met simultaneously, multiple restrictions may be adopted.

[0114] Figure 10 shows the data structure of the detection target table 188. The detection target table 188 shown in Figure 10 is a table that has columns for detection targets, etc., with the detection target ID as the key. Note that the detection target table 188 may also have columns that store other information.

[0115] The "Detection Target ID" field stores an identifier that uniquely identifies the target to be detected from the clipboard area. The "Detection Target" field stores the string information to be detected from the clipboard area. In other words, the "Detection Target" field stores string information related to services whose use should be restricted. For example, the "Detection Target" field may store the following:

[0116] • String information that identifies resources related to services that should be restricted. Here, a resource refers to any type of element available on a network, including, for example, physical or virtual devices such as servers, and various types of data and information such as web pages, files, and databases. The string information that identifies a resource refers to identification information used to identify a resource, such as a URI (URL), local address, directory path, file path, IP address, or string information indicating the elements or combinations of elements that constitute this identification information. Examples of elements that constitute the identification information in a URL include the protocol, hostname, domain name, and path.

[0117] • Words related to services whose use should be restricted Words related to services whose use should be restricted include, for example, words related to the name of the service, the provider, etc., and in particular, words used to search for the service in search engines.

[0118] In this disclosure, the string information stored in the item "Detection Target" may be simply referred to as "Detection Target."

[0119] Figure 11 shows the data structure of the detection log table 189. The detection log table 189 shown in Figure 11 is a table that has columns such as time, detection string, and detection target ID, with the detection log ID as the key. Note that the detection log table 189 may also have columns that store other information.

[0120] The detection log ID is an item that stores an identifier for uniquely identifying a detection log, which is a log of string detection by the string acquisition unit 199.

[0121] The "Time" field stores the time when the detection occurred. For example, the "Time" field stores the timestamp when the detection process corresponding to the detection log ID was executed.

[0122] The "detection string" field is an item that stores string information corresponding to the detection log ID. For example, the "detection string" field stores a string detected by the storage unit 180 in the detection process when it matches the detection target conditions in the detection target table 188.

[0123] The "Detection Target ID" is an item that stores the detection target ID associated with the detection process corresponding to the detection log ID. For example, in a process that monitors the clipboard area, if string information corresponding to a specific record in the detection target table 188 is detected from the string information obtained from the clipboard area, the "Detection Target ID" in the detection log table 189 will store the value of the "Detection Target ID" item of that record.

[0124] Figure 12 shows the data structure of the aggregation table 2022 stored by the first server 20. Note that Figure 12 is an example and does not exclude data that is not shown. Also, even if data is listed in the same table, it may be stored in separate memory areas in the storage unit 202.

[0125] The summary table 2022 shown in Figure 12 is a table that uses User ID as the key and has columns for reported events, detection counts, etc. Note that the summary table 2022 may also have columns that store other information, or it may not contain any of this information.

[0126] A "reported event" is an item that records events that may be subject to reporting. The "reported event" item may include, for example, the following: • It was confirmed that unauthorized use of SaaS was being performed. • Use of an unauthorized application was detected. • It was confirmed that they possess a Shadow ID.

[0127] The detection count is an item that stores the number of times an event defined as a reportable event has been detected.

[0128] <3 operations> This section describes how agent application 187 operates when monitoring SaaS used on terminal device 10.

[0129] Figure 13 is a schematic diagram illustrating the process by which an agent application 187 installed on terminal device 10 monitors user actions. In Figure 13, the user operates terminal device 10 with agent application 187 running and uses a predetermined SaaS. Terminal device 10 detects the user's use of the SaaS, makes a predetermined decision, and sends the decision result to the first server 20.

[0130] Figure 14 is a flowchart illustrating an example of the operation of terminal device 10 when monitoring user activity. In the explanation of Figure 14, agent application 187 is installed on terminal device 10.

[0131] First, the user of terminal device 10 starts up terminal device 10. The agent application 187 is configured to start automatically, for example, and is started by the OS of terminal device 10, for example, when terminal device 10 starts up. When agent application 187 is started, the control unit 190 may or may not indicate to the user that agent application 187 is running. The user operates terminal device 10 and performs tasks assigned to the user, for example.

[0132] In step S11, the control unit 190 acquires information about the process performed by the user. Specifically, for example, the first acquisition unit 194 accesses the browser log file at predetermined intervals and acquires the URLs of web pages visited by the user during that interval. The first acquisition unit 194 stores the acquired URL, the date and time the URL was acquired, the name of the browser used by the user, and identification information of the terminal device 10 in the storage unit 180 (not shown). Note that the date and time the URL was acquired may be the date and time the user visited the web page related to the URL.

[0133] In step S12, the control unit 190 obtains information about the SaaS used by the user. Specifically, for example, the second acquisition unit 195 matches the URLs of the web pages visited by the user during a predetermined period with the correspondence table 182 and obtains the SaaSID of the SaaS used by the user.

[0134] In step S13, the control unit 190 determines whether it is appropriate for the user to use the SaaS. Specifically, for example, if the SaaS table 184 is a blacklist, the determination unit 196 determines whether the acquired SaaSID is included in the SaaS table 184. If the acquired SaaSID is "SID0001" which is included in the SaaS table 184, the determination unit 196 stores, for example, the item "Software Used": SID0001, the item "Available": 0, and the item "Account Existence": 0 in the determination result table 185. If the acquired SaaSID (for example, "SID0002") is not included in the SaaS table 184, the determination unit 196 refers to the account table 183 and determines whether the user has an account for the acquired SaaSID. If the user has an account for the acquired SaaSID, the determination unit 196 does not store any information in the determination result table 185. If the user does not have an account for the acquired SaaSID, the determination unit 196 stores, for example, the item "Software Used": SID0002, the item "Available": 1, and the item "Account Existence": 0 in the determination result table 185.

[0135] Furthermore, for example, if the SaaS table 184 is a whitelist, the determination unit 196 determines whether the acquired SaaSID is included in the SaaS table 184. If the acquired SaaSID (for example, "SID0003") is not included in the SaaS table 184, the determination unit 196 stores, for example, the item "Software Used": SID0003, the item "Available": 0, and the item "Account Existence": 0 in the determination result table 185. If the acquired SaaSID is "SID0004" which is included in the SaaS table 184, the determination unit 196 refers to the account table 183 and determines whether the user has an account for the acquired SaaSID. If the user has an account for the acquired SaaSID, the determination unit 196 does not store any information in the determination result table 185. If the user does not have an account for the acquired SaaSID, the determination unit 196 stores, for example, the item "Software Used": SID0004, the item "Available": 1, and the item "Account Existence": 0 in the determination result table 185.

[0136] In step S14, the control unit 190 determines whether or not to send the judgment result stored in the judgment result table 185 to the first server 20. Specifically, for example, the transmitting / receiving unit 192 determines whether or not the judgment result stored in the judgment result table 185 satisfies predetermined conditions. If the judgment result satisfies the predetermined conditions, the transmitting / receiving unit 192 moves the process to step S15. If the judgment result does not satisfy the predetermined conditions, the transmitting / receiving unit 192 moves the process to step S16.

[0137] In step S15, the transmitting / receiving unit 192 transmits the determination result that satisfies the conditions to the first server 20.

[0138] In step S16, the control unit 190 determines whether or not to restrict the operation of the terminal device 10. Specifically, for example, the restriction unit 197 determines whether or not the judgment result stored in the judgment result table 185 satisfies predetermined conditions. If the judgment result satisfies the predetermined conditions, the restriction unit 197 moves the process to step S17. If the judgment result does not satisfy the predetermined conditions, the restriction unit 197 moves the process to step S11.

[0139] In step S17, the restriction unit 197 imposes predetermined restrictions on the operation of the terminal device 10. Specifically, for example, the restriction unit 197 compares the judgment results stored in the judgment result table 185 with the restriction table 186 to determine the restrictions on the operation of the terminal device 10, and then applies the determined restrictions to the terminal device 10.

[0140] More specifically, for example, if a user has the authority to access highly confidential information but uses a SaaS that is on a blacklist, the restriction unit 197 controls the terminal device 10 so that it does not accept any operations. Also, for example, if the number of times an unauthorized SaaS is used reaches N, the restriction unit 197 prohibits access to the site that provides the SaaS. Also, for example, if the number of times an unauthorized SaaS is used reaches N within a predetermined period, the restriction unit 197 prohibits access to the site that provides the SaaS. Also, for example, if a predetermined SaaS is used N times using a shadow ID, the restriction unit 197 prohibits access to the site that provides the SaaS. Also, for example, if a predetermined SaaS is used N times within a predetermined period using a shadow ID, the restriction unit 197 prohibits access to the site that provides the SaaS.

[0141] In step S18, the presentation control unit 193 informs the user that restrictions have been placed on the operation of the terminal device 10.

[0142] Figure 15 is a schematic diagram showing an example of the display screen of the display 141 of the terminal device 10. Figure 15 shows an example where the processing of the terminal device 10 is stopped due to the use of SaaS that is not permitted. In the screen shown in Figure 13, a first area 1411 is displayed to notify the user that restrictions have been placed on the operation of the terminal device 10. The display control unit 193 may also display in the first area 1411 the process for removing the restrictions placed on the terminal device 10.

[0143] Figure 16 is a schematic diagram illustrating the process by which an agent application 187 installed on terminal device 10 monitors the clipboard area. In Figure 16, the user operates terminal device 10 with agent application 187 running and executes a predetermined application. Based on the user's operation, terminal device 10 retrieves predetermined string information from the storage area allocated for the predetermined application and stores it in the clipboard area. Terminal device 10 monitors the clipboard area and determines whether the string information stored in the clipboard area is restricted string information.

[0144] Figure 17 is a flowchart illustrating an example of the operation of terminal device 10 when monitoring the clipboard area. In the explanation of Figure 17, agent application 187 is installed on terminal device 10.

[0145] First, the user of the terminal device 10 starts up the terminal device 10. The agent application 187 is configured to start automatically, for example, and is started by the OS of the terminal device 10, for example, when the terminal device 10 starts up. When the agent application 187 is started, the control unit 190 may or may not indicate to the user that the agent application 187 is running. The user operates the terminal device 10 and performs, for example, a task assigned to the user. In the process, the user performs a copy operation of string information in a predetermined application. As a result, the string information is stored in the clipboard area of ​​the terminal device 10.

[0146] In step S21, the control unit 190 acquires string information stored in the clipboard area. Specifically, for example, the string acquisition unit 199 accesses the clipboard area at predetermined intervals and acquires the string information if it is stored in the clipboard area.

[0147] In step S22, the control unit 190 determines whether the first string information obtained by the string acquisition unit 199 is restricted string information relating to a service whose use should be restricted. Specifically, for example, the restriction target determination unit 1910 refers to the item "detection target" in the detection target table 188 and determines whether the obtained first string information can be associated with the string information stored in at least one record of the item "detection target" (whether the detection target can be detected from the first string information).

[0148] If it is determined that the acquired first string information is not the string information subject to restrictions (NO in step S22), the control unit 190 proceeds to step S21.

[0149] If the acquired first string information is determined to be restricted string information (YES in step S22), the control unit 190 obtains the detection target ID of the string information record that could be associated with the string information acquired in step S21, and then proceeds to step S23.

[0150] In step S23, the control unit 190 performs a predetermined process on the terminal device 10. Specifically, the post-detection processing unit 1911 performs a predetermined process on the terminal device 10 when it is determined that the string information is subject to restrictions. For example, if a user attempts to paste the string information from the clipboard area by operating the terminal device 10, the post-detection processing unit 1911 prohibits the output of the string information from the clipboard area.

[0151] Furthermore, the control unit 190 may proceed to step S24 after step S22 without moving the process to step S23. In other words, the control unit 190 does not have to perform the processing in this step for the terminal device 10.

[0152] In step S24, the control unit 190 presents the determination result to the user. Specifically, for example, the presentation control unit 193 displays on the display 141 of the terminal device 10 that it has been determined that the string information acquired in step S21 is restricted string information. That is, the presentation control unit 193 displays on the display 141 that restricted string information has been detected from the clipboard area of ​​the terminal device 10.

[0153] Figure 18 is a schematic diagram showing an example of the display screen of the terminal device 10's display 141. Figure 18 shows an example where the output of restricted string information from the clipboard area is prohibited because a restricted string has been detected in the clipboard area of ​​the terminal device 10. In the screen shown in Figure 18, an area 1412 is displayed to notify the user that a restricted string has been detected in the clipboard area of ​​the terminal device 10.

[0154] For example, area 1412 may display the following example information. • Detected restricted string information • Information regarding the processing performed by the post-detection processing unit 1911 in step S23 • Information regarding the SaaS related to the restricted string information

[0155] In step S25, the control unit 190 records a detection log. Specifically, for example, the control unit 190 stores the time at which the string information was obtained in step S21 in the "Time" field of the new record in the detection log table 189, the string information obtained in step S21 in the "Detection String" field, and the detection target ID obtained in step S22 in the "Detection Target ID" field. The control unit 190 then proceeds to step S21.

[0156] In this way, by repeating steps S21 to S25, the control unit 190 monitors the clipboard area. The control unit 190 may also send the detection results stored in the detection log table 189 to the first server 20 at predetermined intervals.

[0157] (Update process for detected targets) Figure 19 is a flowchart illustrating an example of the operation when the terminal device 10 updates the string information to be detected.

[0158] In step S31, the control unit 190 acquires new string information to be detected. Specifically, for example, the detection target update unit 1912 acquires string information from a predetermined information processing device.

[0159] In step S32, the control unit 190 updates the detection target. Specifically, the detection target update unit 1912 stores the string information acquired in step S31 in the storage unit 180 as a new detection target. For example, the detection target update unit 1912 creates a new record in the detection target table 188 and stores the string information acquired in step S31 in the item "Detection Target".

[0160] <Summary> As described above, in the above embodiment, the string acquisition unit 199 acquires string information stored in the storage unit 180 by the clipboard function of the terminal device 10. The restriction target determination unit 1910 determines whether the first string information acquired by the string acquisition unit 199 is second string information relating to a service that should be restricted from use by the user. This makes it possible to determine whether the string information stored in the clipboard area is string information relating to a service that should be restricted from use by the user.

[0161] When a user stores string information in the clipboard area, they may access services related to that string information by pasting it into the search bar of a browser application or by performing a search using that string information on a search engine. Therefore, according to the above embodiment, the terminal device 10 can determine in advance whether the user is attempting to use a service that should be restricted by the user, before the service is actually used.

[0162] Furthermore, in the above embodiment, if the post-detection processing unit 1911 determines that the first string information is string information relating to a service whose use should be restricted, it restricts the operation of a predetermined application when the first string information is output to that application. This makes it possible to restrict the application's access to the service.

[0163] Furthermore, in the above embodiment, if the post-detection processing unit 1911 determines that the first string information relates to a service whose use should be restricted, it prohibits the output of the first string information from the storage unit 180. This prevents, for example, a predetermined application from pasting the first string information, thereby restricting the application's access to the service.

[0164] Furthermore, in the above embodiment, if the post-detection processing unit 1911 determines that the first string information relates to a service whose use should be restricted, it deletes the first string information from the storage unit 180. This makes it impossible for a given application to paste the first string information, thereby restricting the application's access to the service.

[0165] Furthermore, in the above embodiment, the second string information includes string information that identifies resources related to services whose use should be restricted. This allows the terminal device 10 to determine that string information identifying resources related to services whose use should be restricted is stored in the clipboard area.

[0166] Furthermore, in the above embodiment, the second string information includes string information indicating a word related to a service whose use should be restricted. This allows the terminal device 10 to determine that string information indicating a word related to a service whose use should be restricted is stored in the clipboard area.

[0167] Furthermore, in the above embodiment, the detection target update unit 1912 acquires information about the service to be managed. Based on the acquired information, the detection target update unit 1912 updates the second string information. This improves the accuracy of the determination by the restriction target determination unit 1910.

[0168] Furthermore, in the above embodiment, the first acquisition unit 194 acquires information about a process performed by the user. Based on the information acquired by the first acquisition unit 194, the second acquisition unit 195 acquires information about a service associated with that process. The determination unit 196 determines whether the service related to the information acquired by the second acquisition unit 195 is a service that is appropriate for use by the user. If the service is determined to be a service that is not appropriate for use by the user, the detection target update unit 1912 updates the second string information based on the information about the process performed by the user. This improves the accuracy of the determination by the restriction target determination unit 1910.

[0169] Furthermore, in the above embodiment, the first acquisition unit 194 acquires information about a process performed by the user. The second acquisition unit 195 acquires information about a service associated with the process based on the acquired information about the process. The determination unit 196 determines whether or not the acquired information about the service is a service that is under management. This enables the terminal device 10 to quickly determine whether or not there is a problem with the user's use of the service.

[0170] Therefore, according to the above embodiment, the terminal device 10 can take a quick response if there is a problem using the service. Also, because it is edge computing, the cost of operating the first server 20 is reduced. Furthermore, even if communication between the terminal device 10 and the network is interrupted, the terminal device 10 can monitor the processes performed by the user.

[0171] Furthermore, in the above embodiment, the first acquisition unit 194 acquires information related to the process at a predetermined interval. The second acquisition unit 195 acquires information related to the service associated with the process based on the information acquired during that interval. As a result, the terminal device 10 acquires information related to the process at a reduced frequency, but it becomes possible to effectively monitor the operation of the terminal device 10 while suppressing power consumption.

[0172] Furthermore, in the above embodiment, the determination unit 196 determines whether or not the user has an account based on information about the service. This makes it possible for the terminal device 10 to know whether or not the user has an account for the service the user is using. In other words, the terminal device 10 can determine the existence of a shadow ID held by the user.

[0173] Furthermore, in the above embodiment, the determination unit 196 refers to a pre-stored account list (account table 183) and determines whether or not the user has an account. This makes it possible for the determination unit 196 to accurately determine whether or not the user has an account for the service the user is using.

[0174] Furthermore, in the above embodiment, if the judgment result satisfies predetermined conditions, the transmitting / receiving unit 192 transmits the judgment result that satisfies the conditions to an external device. There may be differences in the level of management for SaaS whose use is managed. Some SaaS whose use is prohibited may cause problems if habitual use is permitted. In such circumstances, if information is transmitted to the first server 20 every time an unrecommended SaaS is used, the power consumption of the terminal device 10 will increase. In addition, events that do not need to be aggregated will accumulate in the first server 20, which may lead to a waste of memory resources. In this embodiment, by transmitting the judgment result that satisfies predetermined conditions to the first server 20, it is possible to reduce the power consumption of the terminal device 10 and avoid wasting the memory resources of the first server 20.

[0175] Specifically, the transmitting / receiving unit 192 transmits the determination result to an external device when a predetermined determination has been made a predetermined number of times. In addition, the transmitting / receiving unit 192 transmits the determination result to an external device when it has been determined a predetermined number of times that the user does not have an account.

[0176] Furthermore, in the above embodiment, the limiting unit 197 restricts the operation of the processor based on the determination result. This allows the terminal device 10 to respond immediately if there is a problem with the user's use of the service.

[0177] Furthermore, in the above embodiment, the terminal device 10 transmits information identifying the hardware used by the user to the first server 20. The first server 20 has pre-stored information about the software used by the user and creates a list of the hardware and software used by the user based on the hardware identification information. This reduces the burden on the first server 20 in managing the hardware and software used by employees.

[0178] <Variation> In the above embodiment, when the operation of the terminal device 10 is restricted because the user's use of the service is inappropriate, an example of informing the user of the restriction, such as as shown in Figure 13, has been described. The information presented to the user is not limited to the fact that the operation of the terminal device 10 has been restricted. The presentation control unit 193 may also present the user with a grace period until the conditions for sending judgment information to the first server 20 are met, or a grace period until the conditions for restricting the operation of the terminal device 10 are met.

[0179] Furthermore, in the above embodiment, the case where browser usage history is used as information regarding the process performed by the user was explained as an example. However, the application name and process name of the application executed by the user may also be used as information regarding the process performed by the user. In this case, for example, the correspondence table 182 associates the SaaS with the application name and process name of the application executed by the user. The second acquisition unit 195 compares the acquired application name and process name with the correspondence table 182 to obtain the SaaSID of the SaaS used by the user. As a result, the second acquisition unit 195 identifies the SaaS used by the user.

[0180] Furthermore, in the above embodiment, the case in which the determination unit 196 recognizes the existence of a shadow ID was described as an example. However, the control unit 190 may also perform the function of the identification unit 198 which identifies the shadow ID. When the existence of a shadow ID is recognized by the determination unit 196, the identification unit 198 accesses the second server 30 and obtains information about the account on which the user is using SaaS. This makes it possible for the identification unit 198 to identify the user's shadow ID. Once the identification unit 198 identifies the shadow ID, the transmitting / receiving unit 192 transmits the identified shadow ID to the first server 20.

[0181] Furthermore, although the above embodiment describes the case of monitoring SaaS usage as an example, application usage may also be monitored by an agent running on the terminal device 10. In this case, the terminal device 10 stores, for example, a table that stores applications or processes whose usage needs to be managed. The restriction unit 197 compares the acquired information with the table and determines whether the application or process used by the user is appropriate or not. The restriction unit 197 stores the determination result in the determination result table 185.

[0182] Furthermore, in the above embodiment, the string acquisition unit 199 acquired string information stored in the clipboard area. However, the string acquisition unit 199 may also acquire string information before it is transferred (copied) to the clipboard area in response to an API call associated with a copy operation of a predetermined application. Alternatively, the string acquisition unit 199 may also acquire string information that has been transferred (pasted) from the clipboard area in response to an API call associated with a paste operation of a predetermined application.

[0183] Furthermore, in the above embodiment, the content of the processing performed by the post-detection processing unit 1911 was set in advance by an administrator or the like. However, the content of the processing may be determined separately for each detection target ID stored in the detection target table 188. The post-detection processing unit 1911 may then determine and execute the content of the processing based on the detection target ID related to the "detection target" item in the detection target table 188 where the string information that could be associated with the first string information is stored.

[0184] Furthermore, in the above embodiment, the post-detection processing unit 1911 performed predetermined processing each time a detection target was detected from the first string information. However, the post-detection processing unit 1911 may perform predetermined processing only when certain conditions are met. For example, the post-detection processing unit 1911 may perform predetermined processing on the condition that the same detection target has been detected a predetermined number of times in the terminal device 10, or that the same detection target has been detected a predetermined number of times within a predetermined period. Such conditions may be associated with the detection target ID and stored in the detection target table 188.

[0185] Furthermore, in the above embodiment, the terminal device 10 acquired string information from the clipboard area and determined whether the acquired first string information was restricted string information. However, the first server 20 may perform at least one of the processes that the terminal device 10 performed in the above embodiment. For example, as shown in the example below, the first server 20 may determine whether the first string information is restricted string information.

[0186] In this modified example, the storage unit 202 of the first server 20 further includes a correspondence table 202a, an account table 202b, a SaaS table 202c, a judgment result table 202d, a restriction table 202e, a detection target table 202f, and a detection log table 202g.

[0187] The correspondence table 202a is a table that associates SaaS with processes performed by users. The correspondence table 202a is updated when a new correspondence between a SaaS and information about its operation is registered.

[0188] Correspondence table 202a is a table that uses SaaSID as the key and has columns such as URL. Note that correspondence table 202a may also have columns that store other information.

[0189] The SaaSID is an item that stores an identifier to uniquely identify a SaaS. The URL is an example of information that indicates that the SaaS has been executed. The "URL" item stores, for example, the URL of the homepage that provides the corresponding SaaS.

[0190] Account table 202b is a table that stores information about accounts set for a user. Account table 202b is updated when a new account is issued.

[0191] Account table 202b is a table that uses User ID as the key and has columns such as SaaSID, usage scope, and registration start date. Note that account table 202b may also have columns to store other information, or it may not contain any of this information.

[0192] The User ID is an item that stores an identifier to uniquely identify a user. The Scope of Use is an item that stores the range of functions permitted to the user when using the SaaS. The Scope of Use is set, for example, when the account is signed up. The Scope of Use may be changed at any time during the contract period, or at a predetermined time, such as when a renewal request is submitted. The Registration Start Date is an item that stores the date when the account was registered and the use of the SaaS began.

[0193] The SaaS table 202c is a table that stores SaaS applications that are under management. SaaS applications stored in SaaS table 202c are, for example, SaaS applications that are not permitted for use. In other words, SaaS table 202c is a blacklist. Alternatively, SaaS applications stored in SaaS table 202c may also be, for example, SaaS applications that are permitted for use. In other words, SaaS table 202c can also be a whitelist. SaaS table 202c is updated when a new SaaS application is registered.

[0194] The SaaS table 202c is a table with SaaSID as the key and columns for name, provider, version, support information, etc. Note that the SaaS table 202c may also have columns to store other information, or may not contain any of this information.

[0195] The "Name" field stores the name of the SaaS. The "Provider" field stores the entity that provides the SaaS. The "Provider" field may store, for example, the name of the company or the address of the website providing the service. The "Provider" field may also store information about the connection destination for accessing the SaaS. This connection destination information may include, for example, the URL of the website providing the SaaS or at least one of the elements that make up the URL (protocol name, hostname, domain name, path, etc.), the IP address of the connection destination, the port number, etc. Alternatively, the connection destination information may include information for identifying the server or other resources on which the SaaS is provided in network space (this network space can be accessed via the internet and / or intranet).

[0196] The "Version" field stores the version of the SaaS being offered. The "Support Information" field stores information about the support provided for the SaaS.

[0197] The judgment result table 202d is a table that stores the results determined based on the detected processing.

[0198] The judgment result table 202d is a table with columns for date and time, software used, usability, and account existence. The judgment result table 202d may also have columns to store other information, or may not contain any of this information. For example, the judgment result table 202d may have a column to store whether a SaaS is on a blacklist.

[0199] The "Date and Time" field stores the date and time when usage was detected. The "Software Used" field stores information about the SaaS whose usage was detected. The "Available" field stores whether the SaaS whose usage was detected is a SaaS whose use is permitted. The determination module 203d determines whether the SaaS whose usage was detected is permitted by referring to the SaaS table 202c. If it is available, "1" is stored; if it is unavailable, "0" is stored. The "Account Existence" field stores whether the user has an account for the SaaS whose usage was detected. The determination module 203d determines whether the user has an account for the SaaS whose usage was detected by referring to the account table 202b. If the user has an account, "1" is stored; if the user does not have an account, "0" is stored.

[0200] The restriction table 202e is a table that associates the judgment result with the restrictions on the operation of the terminal device 10. The restriction table 202e is updated when a new correspondence between the judgment result and the restrictions on the operation of the terminal device 10 is registered.

[0201] Restriction table 202e is a table that uses conditions as keys and has columns for correspondence, priority, etc. Restriction table 202e may also have columns to store information other than those mentioned above.

[0202] The "Condition" field stores the conditions under which restrictions are placed on the operation of the terminal device 10. For example, the following information may be stored in the "Condition" field: • The user had the necessary permissions, and the SaaS used was blacklisted. • The number of times the same judgment has been made has reached a predetermined value. • The number of times the same judgment was made within a specified period reached a specified value.

[0203] The "Restrictions" item stores the restrictions imposed on the terminal device 10. For example, the following may be stored in the "Restrictions" item: - Disable any operations on terminal device 10. • Prohibition of access to the specified URL • Prohibit execution of specified applications. • Prohibit access to designated folders. • Execution of specified files is prohibited. • Prohibition of specified operations such as reading and writing. • Stopping running applications

[0204] Priority is an item that stores the order of priority when adopting a restriction. For example, priority 1 has a higher priority than priorities 2 and 3, and if multiple conditions are met simultaneously, the restriction with the highest priority will be adopted. Note that if multiple conditions are met simultaneously, multiple restrictions may be adopted.

[0205] The detection target table 202f is a table that stores string information to be detected regarding services that should be restricted from user use. The detection target table 202f is a table that has columns such as the detection target, with the detection target ID as the key. Note that the detection target table 202f may also have columns that store other information.

[0206] The "Detection Target ID" field stores an identifier that uniquely identifies the target to be detected from the clipboard area. The "Detection Target" field stores the string information to be detected from the clipboard area. In other words, the "Detection Target" field stores string information related to services whose use should be restricted. For example, the "Detection Target" field may store the following:

[0207] • String information that identifies resources related to services that should be restricted. Here, a resource refers to any type of element available on a network, including, for example, physical or virtual devices such as servers, and various types of data and information such as web pages, files, and databases. The string information that identifies a resource refers to identification information used to identify a resource, such as a URI (URL), local address, directory path, file path, IP address, or string information indicating the elements or combinations of elements that constitute this identification information. Examples of elements that constitute the identification information in a URL include the protocol, hostname, domain name, and path.

[0208] • Words related to services whose use should be restricted Words related to services whose use should be restricted include, for example, words related to the name of the service, the provider, etc., and in particular, words used to search for the service in search engines.

[0209] The detection log table 202g is a table that stores the detection history of the string information of the target to be detected, which is registered in the detection target table 202f. The detection log table 202g is a table that has columns such as time, detected string, and detected target ID, with the detection log ID as the key. The detection log table 202g may also have columns that store other information.

[0210] The detection log ID is an item that stores an identifier to uniquely identify the detection log, which is a log of string detection by the string acquisition module 203f.

[0211] The "Time" field stores the time when the detection occurred. For example, the "Time" field stores the timestamp when the detection process corresponding to the detection log ID was executed.

[0212] The "Detection String" field stores string information corresponding to the detection log ID. For example, the "Detection String" field stores the string detected from the first string information acquired by the first acquisition module 203b when the detection process matches the detection target conditions in the detection target table 202f.

[0213] The detection target ID is an item that stores the detection target ID associated with the detection process corresponding to the detection log ID. For example, if string information corresponding to a specific record in the detection target table 202f is detected from the first string information obtained from terminal device 10, the value of the "detection target ID" item of that record will be stored in the "detection target ID" field of the detection log table 202g.

[0214] Furthermore, in this modified example, the control unit 203 operates according to the program to further perform the functions shown as presentation control module 203a, first acquisition module 203b, second acquisition module 203c, judgment module 203d, restriction module 203e, string acquisition module 203f, restriction target judgment module 203g, post-detection processing module 203h, and detection target update module 203i.

[0215] The presentation control module 203a controls the process of presenting information stored in the memory unit 202 to the user. For example, the presentation control module 203a presents information regarding restrictions imposed by the restriction module 203e, information regarding processing imposed by the post-detection processing module 203h, etc., to the user via the terminal device 10.

[0216] The first acquisition module 203b acquires information about processes performed by the user operating the terminal device 10. At predetermined timings (for example, at predetermined intervals), the first acquisition module 203b sends a request to the terminal device 10 for information acquired by the first acquisition unit 194 of the terminal device 10. The terminal device 10 sends the information acquired by the first acquisition unit 194 to the first server 20 in response to the request. The first acquisition module 203b acquires the information sent from the terminal device 10.

[0217] Alternatively, the terminal device 10 transmits the information acquired by the first acquisition unit 194 to the first server 20 at a predetermined timing (for example, at a predetermined interval, or at the timing when the first acquisition unit 194 acquires the information). The first acquisition module 203b acquires the information transmitted from the terminal device 10.

[0218] The second acquisition module 203c retrieves information about the SaaS used by the user based on information about the processes performed by the user. Specifically, for example, the second acquisition module 203c matches the URL of the web page visited by the user with the correspondence table 202a and retrieves the SaaSID of the SaaS used by the user. This allows the second acquisition module 203c to identify the SaaS used by the user.

[0219] Based on the acquired SaaSID, the decision module 203d determines whether the SaaS used by the user is a SaaS that should be managed. Depending on the determination, the decision module 203d stores the determination result in the decision result table 202d. This can be rephrased as, for example, the decision module 203d storing in the decision result table 202d the processes that the user has performed that should be managed.

[0220] Specifically, for example, the decision module 203d refers to the SaaS table 202c, or to the account table 202b and the SaaS table 202c, to determine whether the user's use of SaaS is appropriate.

[0221] More specifically, for example, if the SaaS table 202c is a blacklist and contains SaaS that are prohibited from use (SaaS as managed), the decision module 203d determines whether the retrieved SaaSID is included in the SaaS table 202c. If the retrieved SaaSID is included in the SaaS table 202c, the decision module 203d stores in the decision result table 202d that the user used an unauthorized SaaS. If the retrieved SaaSID is not included in the SaaS table 202c, the decision module 203d refers to the account table 202b and determines whether the user has an account for the retrieved SaaSID. If the user has an account for the retrieved SaaSID, the decision module 203d does not store any information in the decision result table 202d. If the user does not have an account for the retrieved SaaSID, the decision module 203d stores in the decision result table 202d that the user used the SaaS using a shadow ID.

[0222] Furthermore, for example, if the SaaS table 202c is a whitelist and the SaaS for which use is permitted (SaaS as managed) is included in the SaaS table 202c, the decision module 203d determines whether the acquired SaaSID is included in the SaaS table 202c. If the acquired SaaSID is not included in the SaaS table 202c, the decision module 203d stores in the decision result table 202d that the user used an unauthorized SaaS. If the acquired SaaSID is included in the SaaS table 202c, the decision module 203d refers to the account table 202b and determines whether the user has an account for the acquired SaaSID. If the user has an account for the acquired SaaSID, the decision module 203d does not store any information in the decision result table 202d. If the user does not have an account for the acquired SaaSID, the decision module 203d stores in the decision result table 202d that the user used the SaaS using a shadow ID.

[0223] The restriction module 203e restricts the operation of the terminal device 10 based on the decision result of the decision module 203d. In other words, the restriction module 203e sends an instruction to the terminal device 10 regarding restricting the operation of the terminal device 10's processor based on the decision result of the decision module 203d. When the terminal device 10 receives an instruction from the first server 20, it executes a predetermined process corresponding to that instruction.

[0224] Specifically, for example, the restriction module 203e determines whether the judgment result stored in the judgment result table 202d satisfies predetermined conditions. These predetermined conditions include, for example, the following: • The use of a SaaS that was on the blacklist. • The number of times the same judgment has been made has reached a predetermined value. • The number of times the same judgment was made within a specified period reached a specified value. • The user has the required permissions.

[0225] The restriction module 203e imposes a predetermined restriction on the operation of the terminal device 10 if, for example, the judgment result stored in the judgment result table 202d satisfies at least one or at least one combination of the above conditions. The predetermined restriction includes, for example, the following: - Disable any operations on terminal device 10. • Prohibition of access to the specified URL • Prohibit execution of specified applications. • Prohibit access to designated folders. • Execution of specified files is prohibited. • Prohibition of specified operations such as reading and writing. • Stopping running applications

[0226] The decision result and the restrictions on the operation of the terminal device 10 are stored, for example, in the restriction table 202e. The restriction module 203e, for example, compares the decision result of the decision module 203d with the restriction table 202e to determine the restrictions on the operation of the terminal device 10.

[0227] The string acquisition module 203f acquires string information stored in the clipboard of the terminal device 10. The string acquisition module 203f sends a request to the terminal device 10 for string information to be stored in the clipboard area of ​​the terminal device 10 at a predetermined timing (for example, at a predetermined period). The terminal device 10 sends the string information acquired by the string acquisition unit 199 to the first server 20 in response to the request. The string acquisition module 203f acquires the string information sent from the terminal device 10. Note that if the string information sent from the terminal device 10 is the same as the string information acquired at the previous timing, the string acquisition module 203f does not need to acquire that string information.

[0228] Alternatively, the terminal device 10 transmits the string information acquired by the string acquisition unit 199 to the first server 20 at a predetermined timing (for example, at a predetermined interval, or at the timing when the string acquisition unit 199 acquires the string information). The string acquisition module 203f acquires the string information transmitted from the terminal device 10.

[0229] The restriction determination module 203g determines whether the first string information obtained by the string acquisition module 203f is restricted string information relating to a service whose use by the user should be restricted.

[0230] Specifically, the restriction determination module 203g determines whether the first string information is restricted by comparing it with the second string information stored in the "Detection Target" column of the detection target table 202f.

[0231] For example, the restriction determination module 203g determines that the first string information is restricted if it can be associated with the second string information. The case in which the first string information can be associated with the second string information is when the string information stored in the "Detection Target" field of at least one record in the detection target table 202f can be associated with the first string information, for example, as follows. If the string information stored in the "Target" field of at least one record in the target table 202f matches the first string information. If the string information stored in the "Detection Target" field of at least one record in the target table 202f contains the first string information. • If the first string information includes string information stored in the "Target" field of at least one record in the target table 202f.

[0232] Furthermore, the fact that the first string information could be associated with the second string information can also be expressed as "the target was detected from the first string information" or "the first string information was included in the second string information."

[0233] Furthermore, the restriction determination module 203g may determine whether the first string information is string information representing a URL based on whether the first string information contains specific elements such as a protocol name or a domain name. If the first string information represents a URI containing a URL (hereinafter referred to as a URL in the sense of an example), the restriction determination module 203g may extract specific elements or combinations of elements of the URL and treat them as the first string information. For example, the restriction determination module 203g may extract the domain portion from the URL and determine whether the string information of the domain portion is string information subject to restriction.

[0234] Furthermore, the restriction determination module 203g may use any natural language processing technique to extract strings indicating a specific part of speech (e.g., noun) from the first string information and treat them as the first string information. The extracted strings may be one or more. For example, the restriction determination module 203g may determine whether the extracted noun string information is restricted string information or not.

[0235] Furthermore, if the restriction determination module 203g determines that the first string information is string information relating to a service that should be restricted, the presentation control module 203a may present to the user that the first string information has been determined to be string information relating to a service that should be restricted (the determination result).

[0236] If the post-detection processing module 203h determines that the first string information is restricted string information, it sends an instruction to the terminal device 10 regarding the performance of a predetermined process. Upon receiving the instruction from the first server 20, the terminal device 10 performs the predetermined process corresponding to the instruction.

[0237] The prescribed process includes, for example, the following. The content of the prescribed process is determined by, for example, an administrator or the like making a setting on the first server 20, which allows one or more processes to be selected and set in advance from the following processes. (Restrictions on operations on terminal device 10) - Disable any operations on terminal device 10. (Operations on the clipboard area) • Deletion of the first string information from the clipboard area. • Modification of the first string information stored in the clipboard (for example, changing it to a predetermined notification or warning message) (Restrictions on the operation of the application that is the source (copy source) of the first string information) • Stopping the application • Prohibition of inputting information into the clipboard area (copy operation) (Restrictions on the operation of the application to which the first string information is output (pasted)) • Stopping the application • Prohibition of outputting information from the clipboard area to a specified application (paste operation). (Prohibition of access to the service provider) • Disconnection from network communication • Prohibition of connections to destinations that include the first string information as identification information. For example, prohibition of connections to destinations (including resources) identified by the first string information (URL, etc.). Also, for example, prohibition of connections to search results pages that include the first string information (word, etc.) in the search query portion, or prohibition of connections to destinations that can be accessed from such search results pages. In this case, the string representing the word may be expressed in a format that is arbitrarily encoded for incorporation into the URL. (Presenting information to the user) • Presentation or notification to the user via display 141, speaker 172, etc., regarding the determination that the first string information is restricted string information. · Presenting or notifying a user, via a display 141, a speaker 172, or the like, of information related to execution of a predetermined process

[0238] Further, the post-detection processing module 203h newly records a detection log by storing, in a detection log table 202g, the time at which first character string information was acquired by the first acquisition module 203b, the acquired first character string information, and a detection target ID of a detection target that could be associated with the first character string information by the restricted target determination module 203g, respectively.

[0239] A detection target update module 203i updates second character string information that is a detection target. Specifically, the detection target update module 203i acquires character string information to be newly set as a detection target, and updates the second character string information by storing the new character string information in a detection target table 202f.

[0240] For example, the detection target update module 203i acquires character string information to be newly set as a detection target as follows.

[0241] (Acceptance of input of character string information) For example, the detection target update module 203i accepts character string information from another information processing apparatus via a network 80. A user who operates the other information processing apparatus is, for example, a user who manages the terminal apparatus 10.

[0242] (Acquisition of character string information related to SaaS for which use is not permitted) Further, for example, the detection target update module 203i acquires character string information related to SaaS for which use is not permitted from an SaaS table 202c that manages SaaS as a blacklist at a predetermined timing. For example, at the timing when the SaaS table 202c is updated, the following information may be acquired for an updated portion of the SaaS table 202c. · Name of SaaS · Information related to a connection destination for accessing SaaS

[0243] (In response to the detection of inappropriate SaaS usage, string information is retrieved.) Furthermore, for example, the detection target update module 203i acquires string information related to a SaaS in response to the detection of inappropriate use of the SaaS by the user. For example, if the first acquisition module 203b acquires information about a process performed by the user, the second acquisition module 203c acquires information about the SaaS used in that process, and the judgment module 203d determines that the use of the SaaS related to that process is inappropriate, the detection target update module 203i may acquire the following information. • SaaS name: For example, the detected update module 203i searches the SaaS table 202c based on the SaaSID of the SaaS and obtains string information indicating the name of the SaaS. • Information regarding the connection destination for accessing the SaaS: For example, the detection target update module 203i retrieves information about the SaaS (e.g., information about the provider such as the URL) obtained by the second acquisition module 203c.

[0244] The detection target update module 203i updates the detection targets by storing the string information obtained as described above in the detection target table 202f as a new detection target.

[0245] In this case, the detection target update module 203i may store a portion of the acquired string information in the detection target table 202f. For example, if the acquired string information is a URL, the detection target update module 203i may extract a predetermined element from the URL and store it in the detection target table 202f. For example, the detection target update module 203i may store the domain name extracted from the acquired URL in the detection target table 202f. This makes detection more comprehensive than detecting the entire URL. Furthermore, even if the URL structure of the SaaS changes, the detection target can continue to be detected as long as the registered components (domain name, etc.) remain unchanged.

[0246] <4. Basic Hardware Configuration of a Computer> Figure 14 is a block diagram showing the basic hardware configuration of computer 90. Computer 90 includes at least a processor 91, main memory 92, auxiliary storage 93, and a communication interface 99. These are electrically connected to each other by a bus.

[0247] The processor 91 is hardware for executing the instruction set written in the program. The processor 91 consists of an arithmetic unit, registers, peripheral circuits, etc.

[0248] Main memory 92 is used to temporarily store programs and data processed by programs, etc. For example, it is a volatile memory such as DRAM (Dynamic Random Access Memory).

[0249] Auxiliary storage device 93 is a storage device for storing data and programs. Examples include flash memory, HDD (Hard Disc Drive), magneto-optical disk, CD-ROM, DVD-ROM, semiconductor memory, etc.

[0250] A communication IF99 is an interface for inputting and outputting signals for communication with other computers via a network using wired or wireless communication standards. A network consists of various mobile communication systems, such as the internet, LANs, and wireless base stations. For example, a network includes 3G, 4G, and 5G mobile communication systems, LTE (Long Term Evolution), and wireless networks that can connect to the internet via designated access points (e.g., Wi-Fi®). When connecting wirelessly, communication protocols include, for example, Z-Wave®, ZigBee®, and Bluetooth®. When connecting via a wired connection, the network also includes connections made directly via USB (Universal Serial Bus) cables, etc.

[0251] Furthermore, by distributing all or part of each hardware configuration across multiple computers 90 and connecting them to each other via a network, a computer 90 can be virtually realized. Thus, the concept of computer 90 includes not only a computer 90 housed in a single enclosure or case, but also a virtualized computer system.

[0252] <Basic Functional Configuration of Computer 90> The functional configuration of the computer realized by the basic hardware configuration of computer 90 shown in Figure 20 will be explained. The computer comprises at least one functional unit: a control unit, a memory unit, and a communication unit.

[0253] Furthermore, the functional units of computer 90 can also be realized by distributing all or part of each functional unit across multiple computers 90 interconnected via a network. The concept of computer 90 includes not only a single computer 90 but also a virtualized computer system.

[0254] The control unit is realized when the processor 91 reads various programs stored in the auxiliary storage device 93, loads them into the main memory device 92, and executes processing according to those programs. The control unit can realize various functional units that perform information processing depending on the type of program. In this way, the computer is realized as an information processing device that performs information processing.

[0255] The memory unit is implemented by a main memory 92 and an auxiliary memory 93. The memory unit stores data, various programs, and various databases. The processor 91 can also reserve memory areas corresponding to the memory unit in the main memory 92 or the auxiliary memory 93 according to the program. The control unit can also cause the processor 91 to perform operations such as adding, updating, and deleting data stored in the memory unit according to the various programs.

[0256] A database, specifically a relational database, is used to manage and link data sets called tables, which are structurally defined by rows and columns. In a database, tables are called tables, the columns of a table are called columns, and the rows of a table are called records. In a relational database, relationships can be established and linked between tables. Typically, each table has a key column to uniquely identify records, but setting a key on a column is not mandatory. The control unit can instruct the processor 91 to add, delete, or update records in specific tables stored in the memory unit according to various programs.

[0257] The communication unit is implemented by the communication IF99. The communication unit implements the function of communicating with other computers 90 via the network. The communication unit can receive information transmitted from other computers 90 and input it to the control unit. The control unit can cause the processor 91 to perform information processing on the received information according to various programs. The communication unit can also transmit information output from the control unit to other computers 90.

[0258] The functions implemented by the components described in this specification may be implemented in circuitry or processing circuitry including general-purpose processors, special-purpose processors, integrated circuits, ASICs (Application Specific Integrated Circuits), CPUs (Central Processing Units), conventional circuits, and / or combinations thereof programmed to implement the described functions. A processor includes transistors and other circuits, and is considered circuitry or processing circuitry. The processor may be a programmed processor that executes a program stored in a memory. As used in this specification, circuitry, units, and means are hardware programmed to, or configured to, perform the described functions. The hardware may be any hardware disclosed herein, or any hardware known to be programmed or configured to implement the described functions. Where the hardware is a processor considered to be a type of circuitry, the circuitry, means or unit is a combination of hardware and software used to configure the hardware and / or the processor.

[0259] While several embodiments of the present disclosure have been described above, these embodiments can be implemented in various other forms, and various omissions, substitutions, and alterations can be made without departing from the gist of the invention. These embodiments and their modifications are included in the scope and gist of the invention, as well as within the scope of the invention described in the claims and equivalents thereof.

[0260] <Supplementary Note> The matters described in each of the above embodiments are supplemented below. (Supplementary Note 1) A program for execution on a computer having a processor and memory, the program causing the processor to perform the steps of: obtaining first string information stored in a clipboard area provided in memory; and determining whether the first string information is string information relating to a service that should be restricted by comparing the first string information with second string information relating to a service that should be restricted, which is stored in memory beforehand. (Note 2) The program, as described in Appendix 1, causes the processor to execute a step to restrict the operation of a predetermined application when the first string information is output to a predetermined application, if the first string information is determined in the decision-making step to be string information relating to a service whose use should be restricted. (Note 3) The program, as described in Appendix 1, causes the processor to execute a step in which, if it is determined in the decision-making step that the first string information is string information relating to a service whose use should be restricted, the program prohibits outputting the first string information from memory to a predetermined application. (Note 4) The program, as described in Appendix 1, causes the processor to execute a step of deleting the first string information from memory if, in the decision-making step, it is determined that the first string information relates to a service whose use should be restricted. (Note 5) The second string information is the program described in Appendix 1, which includes string information that identifies resources related to services whose use should be restricted. (Note 6) The second string information is the program described in Appendix 1, which includes string information indicating words related to services whose use should be restricted. (Note 7) The program is the program described in Appendix 1, which causes the processor to perform the steps of obtaining information about a managed service and updating a second string information based on the information obtained in the step of obtaining information about a managed service. (Note 8) The program, as described in Appendix 1, causes the processor to perform the following steps: obtain information about a process performed by a user; obtain information about a service associated with the process based on the obtained information about the process performed by the user; determine whether the service related to the obtained information is a service that is appropriate for use by the user; and if the service is determined to be an inappropriate service for use by the user, update a second string information based on the information about the process performed by the user. (Note 9) A method performed by a computer equipped with a processor, the method comprising: the step of obtaining first string information stored in a clipboard area provided in memory; and the step of determining whether the first string information is string information relating to a service that should be restricted by comparing the first string information with second string information relating to a service that should be restricted, which is stored in memory beforehand. (Note 10) An information processing device comprising a control unit and a storage unit, wherein the control unit performs the steps of: acquiring first string information stored in a clipboard area provided in the storage unit; and determining whether the first string information is string information relating to a service that should be restricted by comparing the first string information with second string information relating to a service that should be restricted, which is stored in the storage unit in advance. (Note 11) A system comprising multiple terminal devices and at least one server, wherein each terminal device includes means for performing the steps of: obtaining first string information stored in a clipboard area provided in memory; and determining whether the first string information is string information relating to a service that should be restricted by comparing the first string information with second string information relating to a service that should be restricted, which is stored in memory beforehand. [Explanation of Symbols]

[0261] 1... System 10…Terminal device 120... Communications Department 13…Input device 131…Touch-sensitive devices 14…Output device 15…Memory 16…Storage 19… Processor 20… Server 1 22...Communication IF 23…Input / Output Interface 25…Memory 2 hours… storage 29… Processor 30…Second Server

Claims

1. A program to be executed by a computer having a processor and memory, wherein the program is to be executed by the processor, The steps include obtaining first string information stored in the clipboard area provided in the memory, A program that performs the steps of: analyzing the first string information and determining whether a service whose use should be restricted, as defined in the second string information, is associated with the first string information, The first string information is a program containing words for searching for services in a search engine.

2. The program is provided to the processor: The program according to claim 1, which, in the determination step, determines that a service defined in the second string information that should be restricted is associated with the first string information, and then, when the first string information is output to a predetermined application, causes the program to execute a step to restrict the operation of the application.

3. The program is provided to the processor: The program according to claim 1, which, in the determination step, determines that a service defined in the second string information that should be restricted is associated with the first string information, and then causes the program to execute a step of prohibiting the output of the first string information from the memory to a predetermined application.

4. The program is provided to the processor: The program according to claim 1, which, in the determination step, determines that a service defined in the second string information that should be restricted is associated with the first string information, causes the program to execute the step of deleting the first string information from memory.

5. The program according to claim 1, wherein the second string information includes string information that identifies a resource relating to the service whose use should be restricted.

6. The program according to claim 1, wherein the second string information includes string information indicating a word relating to the service whose use should be restricted.

7. The program is provided to the processor: Steps to obtain information about the managed services, The program according to claim 1, which causes the program to perform the step of updating the second string information based on the information obtained in the step of obtaining information about the service to be managed.

8. The program is provided to the processor: Steps include obtaining information about the process performed by the user, The steps include obtaining information about the service associated with the process based on the information obtained about the process performed by the user, The steps include determining whether the service related to the acquired information is an appropriate service for use by the user, The program according to claim 1, which, if the service is determined to be a service that is not appropriate for use by the user, causes the program to perform the step of updating the second string information based on information about the process performed by the user.

9. A method performed by a computer comprising a processor and memory, wherein the processor The steps include obtaining first string information stored in the clipboard area provided in the memory, A method for performing the steps of: parsing the first string information and determining whether a service whose use should be restricted, as defined in the second string information, is associated with the first string information, The first string information includes words for searching for a service in a search engine, and is a method.

10. An information processing apparatus comprising a control unit and a storage unit, wherein the control unit is The steps include: obtaining first string information stored in the clipboard area provided in the storage unit; An information processing device that performs the steps of: analyzing the first string information and determining whether a service whose use should be restricted, as defined in the second string information, is associated with the first string information, The first string information includes words for searching for services in a search engine, and is an information processing device.

11. A system comprising a control unit and a storage unit, Means for acquiring first string information stored in the clipboard area provided in the storage unit, A system comprising: means for analyzing the first string information and determining whether a service whose use should be restricted, as defined in the second string information, is associated with the first string information, The first string information is a system that includes words for searching for services in a search engine.

Citation Information

Patent Citations

  • Security gateway and identity verification method

    CN117439805A

  • Information processing method and control method thereof

    JP2004013483A

  • Information processor, application activation control program, and application activation control method

    JP2007041631A

  • Information processing device and program

    JP7044451B1

  • Method to classify compliance protocols for saas apps based on web page content

    US20240037158A1