Information processing device, information processing method, and program

The information processing apparatus addresses the challenge of distinguishing between regular business operations and unauthorized actions by employing a detection unit to identify interference actions, thereby enhancing security and reducing false detection.

WO2025109668A1PCT designated stage expired Publication Date: 2025-05-30MITSUBISHI ELECTRIC CORP
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
PCT/JP2023/041719
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-11-21
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

Existing systems struggle to accurately differentiate between regular business operations and unauthorized actions, leading to potential false detection and security interference.

Method used

An information processing apparatus with a detection unit that identifies interference actions related to security settings on devices used by organization members, allowing for appropriate evaluation of user behavior.

Benefits of technology

Effectively detects and differentiates unauthorized actions from regular business operations, reducing the risk of false detection and enhancing security within the organization.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2023041719_30052025_PF_FP_ABST
    Figure JP2023041719_30052025_PF_FP_ABST
Patent Text Reader

Abstract

An information processing device according to the present disclosure solves the following problem: business activities generally involve a wide variety of operations, and with conventional methods, operations performed to distinguish whether a user is engaging in legitimate business activities or fraudulent activities are not frequent enough, possibly resulting in erroneous detection. This information processing device comprises a detection unit that detects disruptive behavior, which is related to interference with security settings on equipment of an organization, performed by a user using the equipment, and includes a device capable of appropriately detecting whether the user is engaging in fraudulent activities.
Need to check novelty before this filing date? Find Prior Art

Description

Information processing device, information processing method, and program

[0001] The present disclosure relates to an information processing device, an information processing method, and a program.

[0002] In user systems with multiple terminals, users often commit fraud. To address fraud, systems are used to detect fraud and analyze the risk of fraud. Conventional technology effectively utilizes user logs managed in various locations, using various logs to calculate a risk score for each user via a security management server, and then uses the calculated risk score to detect users engaging in fraudulent activities (see Patent Document 1). For example, the conventional technology tallies the average number of operations for each of multiple types of operations during a target period, and calculates each user's risk score based on the average number of operations.

[0003] Japanese Patent Application Laid-Open No. 2019-204389

[0004] However, business-related operations typically vary widely, and conventional techniques, such as those based on the frequency of operations, make it difficult to distinguish whether a user is performing legitimate business or committing fraud, posing the risk of false positives.

[0005] The present disclosure has been made to solve the above-mentioned problems, and aims to appropriately evaluate whether a user of a terminal is committing fraud.

[0006] According to a first aspect of the present invention, an information processing device includes a detection unit that detects disruptive behavior, which is behavior related to disruption of security set in the device, by a user who uses an organization's device. According to a second aspect of the present invention, an information processing method for an information processing device includes a step in which the detection unit detects disruptive behavior, which is behavior related to disruption of security set in the device, by a user who uses the organization's device. According to a third aspect of the present invention, a program causes a computer to perform processing to detect disruptive behavior, which is behavior related to disruption of security set in the device, by a user who uses the organization's device.

[0007] According to the present disclosure, since interference with the security of an organization is detected by a user of a terminal that uses equipment in the organization, it is possible to appropriately detect whether a user is committing fraud.

[0008] 1 is a diagram showing an example of a system configuration in an embodiment. A diagram showing an entire system in the first embodiment. A diagram showing an example of a system configuration in the first embodiment. A diagram showing an example of a user input log in the first embodiment. A diagram showing an example of a user management database in the first embodiment. A diagram showing the functional configuration of a server in the first embodiment. A sequence diagram showing an example of a flow of processing executed by each device in the first embodiment. A diagram showing an example of a system configuration in the second embodiment. A sequence diagram showing an example of a flow of processing executed by each device in the second embodiment. An example of a screen displayed on a display unit in the second embodiment. An example of a screen displayed on a display unit in the second embodiment. A diagram showing the functional configuration of a server in the third embodiment. A diagram showing an example of a user management database in the third embodiment. A sequence diagram showing an example of a flow of processing executed by each device in the third embodiment. A diagram showing the functional configuration of a terminal in the fourth embodiment. A flowchart showing an example of a flow of processing executed by a terminal in the fourth embodiment. A diagram showing an example of a system configuration in the fifth embodiment. A sequence diagram showing an example of a flow of processing executed by each device in the fifth embodiment.

[0009] In order to explain the present disclosure in more detail, embodiments for carrying out the present disclosure will be described below with reference to the accompanying drawings. <System Configuration> Fig. 1 is a diagram showing an example of the system configuration of a communication system 1 in this embodiment. In the communication system 1, by way of example and not limitation, a server 10 and a plurality of terminals 20 (terminal 20A, terminal 20B, terminal 20C, ...) are connected via a network 30.

[0010] The server 10 is connected to a terminal 20 used by a user via a network 30. Note that, in the example of Fig. 1, the number of servers 10 connected to the network 30 is one and the number of terminals 20 is three, but this number is not limited thereto, and a plurality of servers 10 may be provided, and the number of terminals 20 may be one or more.

[0011] The network 30 serves to connect one or more terminals 20 and one or more servers 10. That is, the network 30 refers to a communication network that provides a connection path so that the above-mentioned various devices can connect and then transmit and receive data.

[0012] One or more portions of network 30 may or may not be a wired or wireless network. Network 30 may include, by way of example and not limitation, an ad hoc network, an intranet, an extranet, a virtual private network (VPN), a local area network (LAN), a wireless LAN (WLAN), a wide area network (WAN), a wireless WAN (WWAN), a metropolitan area network (MAN), a portion of the Internet, a portion of the Public Switched Telephone Network (PSTN), a cellular network, integrated service digital networks (ISDN), wireless LAN, long term evolution (LTE), code division multiple access (CDMA), Bluetooth, satellite communications, etc., or a combination of two or more thereof. Network 30 may include one or more networks 30.

[0013] The server 10 may be any device capable of implementing the functions described in each embodiment. The server 10 may be, for example, but not limited to, a server device, a computer (for example, but not limited to, a desktop, laptop, tablet, etc.), a handheld computing device (for example, but not limited to, a PDA (personal digital assistant)), or any other type of computer or communication platform. The server 10 may also be referred to as an information processing device or an information management device.

[0014] The terminal 20 may be any device capable of implementing the functions described in each embodiment. Examples of the terminal 20 include, but are not limited to, computers (such as desktops, laptops, and tablets), handheld computing devices (such as personal digital assistants (PDAs)), and other types of computers. The terminal 20 may also be referred to as an information processing device or an information management device.

[0015] [Hardware (HW) Configuration of Each Device] The HW configuration of each device included in the communication system 1 will be described.

[0016] (1) Server Hardware Configuration FIG. 1 shows an example of the hardware configuration of a server 10. The server 10 includes a control unit 11 (CPU: central processing unit), a memory unit 15, a communication I / F 14 (interface), an input / output unit 12, a display 13, and a clock unit 16. The components of the hardware of the server 10 are interconnected via a bus, by way of example and not limitation. It is not essential that the hardware of the server 10 include all of the components. By way of example and not limitation, the hardware of the server 10 may or may not be configured such that the display 13 and the clock unit 16 are detachable. The display 13 and other components may be installed externally to the server, and information output via the communication I / F 14 (interface) may be received and displayed on the display 13 installed externally to the server.

[0017] The control unit 11 has circuits physically structured to execute the functions realized by the codes or instructions contained in the program, and is realized by, for example and not by way of limitation, a data processing device incorporated in hardware.

[0018] The control unit 11 is typically a central processing unit (CPU), but may also be a microprocessor, processor core, multiprocessor, ASIC (application-specific integrated circuit), or FPGA (field programmable gate array). Furthermore, each process may or may not be realized by a logic circuit (hardware) or dedicated circuit formed in an integrated circuit (IC (Integrated Circuit) chip, LSI (Large Scale Integration)), etc. These circuits may be realized by one or more integrated circuits, and multiple processes shown in each embodiment may or may not be realized by a single integrated circuit. Furthermore, LSIs may also be referred to as VLSIs, super LSIs, ultra LSIs, etc. depending on the degree of integration. Therefore, the control unit 11 may or may not be referred to as a control circuit. In the present disclosure, the control unit 11 is not limited to these.

[0019] The storage unit 15 has a function of storing various programs and various data required for the operation of the server 10. The storage unit 15 is realized by various storage media such as a hard disk drive (HDD), a solid state drive (SSD), and a flash memory. However, in the present disclosure, the storage unit 15 is not limited to these. Furthermore, the storage unit 15 may or may not be expressed as a memory.

[0020] The server 10 stores a program P in the storage unit 15, and by executing this program P, the control unit 11 executes the processes of each unit included in the control unit 11. In other words, the program P stored in the storage unit 15 causes the server 10 to realize each function executed by the control unit 11. This program P may or may not be expressed as a program module.

[0021] The communication I / F 14 transmits and receives various data via the network 30. The communication may be performed either wired or wirelessly, and any communication protocol may be used as long as mutual communication is possible. The communication I / F 14 has a function of communicating with various devices, such as the terminal 20, via the network 30. The communication I / F 14 transmits various data to various devices, such as the terminal 20, in accordance with instructions from the control unit 11. The communication I / F 14 also receives various data transmitted from various devices, such as the terminal 20, and transmits it to the control unit 11. The communication I / F 14 may also be simply referred to as a communication unit. When the communication I / F 14 is configured as a physically structured circuit, it may also be referred to as a communication circuit.

[0022] The input / output unit 12 includes a device for inputting various operations to the server 10 and a device for outputting processing results processed by the server 10. The input / output unit 12 may be an integrated unit having an input unit and an output unit, or may be separated into an input unit and an output unit.

[0023] The input unit of the input / output 12 is realized by a device that inputs various operations to the server 10. The input unit is realized by any one or combination of all types of devices that can accept input from a user and transmit information related to the input to the control unit 11. The input unit is typically realized by hardware keys such as a keyboard or a pointing device such as a mouse. Note that the input unit may or may not include, but is not limited to, a touch panel, a camera (for inputting operations via video images), or a microphone (for inputting operations via voice). However, in the present disclosure, the input / output unit 12 is not limited to these. Note that the input unit may be detachable as appropriate or may be attached as needed. For example, in each embodiment, the configuration related to the input unit may be detached in its entirety or only a portion thereof may be attached as needed.

[0024] The output unit of the input / output 12 is realized by any one of or a combination of any type of device capable of outputting the processing results processed by the control unit 11. An example of the output unit is the display 13, which is typically realized by a monitor (for example, but not limited to, a liquid crystal display or an organic electroluminescence display (OELD)). The display 13 may or may not be a head-mounted display (HMD), a projection mapping device, a hologram, or a device capable of displaying images, text information, etc. in air (which may or may not be a vacuum). The display 13 may or may not be capable of displaying data in 3D. In the present disclosure, the display 13 is not limited to these. The output unit is not limited to the display 13, but may be a touch panel, a touch display, a speaker, a printer, or any other device that notifies the user of information or notifies the user of processing results, such as presenting information. The output unit may be detachable as appropriate or attached as needed. For example, in each embodiment, the configuration relating to the output section may be entirely removed or partly attached as needed.

[0025] The clock unit 16 is a built-in clock of the server 10 and outputs time information (timekeeping information). The clock unit 16 is configured to include, for example and without limitation, a real time clock (RTC) as a hardware clock, a system clock, etc. The clock unit 16 can also be expressed as a timekeeping unit or a time information detection unit, for example and without limitation.

[0026] (2) HW Configuration of Terminal FIG. 1 shows an example of the HW configuration of the terminal 20. The terminal 20 includes a control unit 21 (CPU: central processing unit), a memory unit 28, a communication I / F 22 (interface), an input / output unit 23, a display unit 24, a microphone 25, a speaker 26, a camera 27, a clock unit 29A, and a position calculation information detection unit 29B. The HW components of the terminal 20 are connected to each other via a bus, for example and not by way of limitation. Note that it is not essential for the HW configuration of the terminal 20 to include all of the components. For example and not by way of limitation, the terminal 20 may or may not be configured such that individual components, such as the microphone 25 and the camera 27, or multiple components, are detachable.

[0027] The control unit 21 has circuits physically structured to execute the functions realized by the code or instructions contained in the program, and is realized by, for example and not by way of limitation, a data processing device embedded in hardware.

[0028] The control unit 21 may include, but is not limited to, a central processing unit (CPU), a microprocessor, a processor core, a multiprocessor, an application-specific integrated circuit (ASIC), or a field programmable gate array (FPGA). Furthermore, each process may or may not be realized by a logic circuit (hardware) formed in an integrated circuit (IC chip, LSI (Large Scale Integration)), or a dedicated circuit. These circuits may be realized by one or more integrated circuits, and multiple processes shown in each embodiment may or may not be realized by a single integrated circuit. Furthermore, LSIs may also be referred to as VLSIs, super LSIs, ultra LSIs, etc., depending on the level of integration. Therefore, the control unit 21 may or may not be referred to as a control circuit.

[0029] The storage unit 28 has a function of storing various programs and various data required for the operation of the terminal 20. The storage unit 28 includes, but is not limited to, various storage media such as a hard disk drive (HDD), a solid state drive (SSD), a flash memory, a random access memory (RAM), and a read only memory (ROM). The storage unit 28 may or may not be referred to as a memory.

[0030] Terminal 20 stores program P in storage unit 28, and by executing this program P, control unit 21 executes the processes of each unit included in control unit 21. In other words, program P stored in storage unit 28 causes terminal 20 to realize each function executed by control unit 21. Furthermore, this program P may or may not be expressed as a program module.

[0031] The communication I / F 22 transmits and receives various data via the network 30. The communication may be performed either wired or wirelessly, and any communication protocol may be used as long as mutual communication is possible. The communication I / F 22 has a function of communicating with various devices, such as the server 10, via the network 30. The communication I / F 22 transmits various data to various devices, such as the server 10, in accordance with instructions from the control unit 21. The communication I / F 22 also receives various data transmitted from various devices, such as the server 10, and transmits it to the control unit 21. The communication I / F 22 may also be simply referred to as a communication unit. When the communication I / F 22 is configured as a physically structured circuit, it may also be referred to as a communication circuit.

[0032] The input / output unit 23 includes a device for inputting various operations to the terminal 20 and a device for outputting processing results processed by the terminal 20. The input / output unit 23 may be an integrated unit having an input section and an output section, or may be separate units having an input section and an output section, or may not be so.

[0033] The input unit is realized by any one or combination of devices capable of receiving input from a user and transmitting information related to the input to the control unit 21. Examples of the input unit include, but are not limited to, hardware keys such as a touch panel, a touch display, and a keyboard, pointing devices such as a mouse, a camera (operation input via video images), and a microphone (operation input via voice). The camera is an example of the imaging unit 27, and the microphone is an example of the sound input unit 26, but is not limited to these. The input unit is not limited to the disclosure of this application, and individual components or multiple components may or may not be detachable from each embodiment as needed. Configurations not described in this disclosure may also be added as appropriate.

[0034] The output unit is realized by any one of or a combination of all types of devices that can output the processing results processed by the control unit 21. Examples of the output unit include, but are not limited to, a touch panel, a touch display, a speaker (an example of a sound output unit), optical components (examples of which include, but are not limited to, components such as lenses and media for 3D (three dimensions) output and hologram output), and a printer. These output processing results, such as notifying the user of information or presenting information.

[0035] When the input / output unit 23 is a touch panel, the input / output unit 23 and the display unit 24 may be disposed opposite each other and have approximately the same size and shape.

[0036] The display unit 24 is realized by any one of all types of devices or a combination thereof that can display according to the display data written to the frame buffer. Examples of the display unit 24 include, but are not limited to, a touch panel, a touch display, a monitor (for example, but not limited to, a liquid crystal display or an organic electroluminescence display (OELD)), a head mounted display (HMD), projection mapping, a hologram, and a device that can display images, text information, etc. in air (which may or may not be a vacuum). Note that these display units 24 may or may not be capable of displaying display data in 3D.

[0037] The clock unit 29A is a built-in clock of the terminal 20 and outputs time information (timekeeping information). The clock unit 29A is configured, for example and without limitation, with a clock that uses a crystal oscillator. The clock unit 29A can also be expressed, for example and without limitation, as a timekeeping unit or a time information detection unit.

[0038] The clock unit 29A may or may not have a clock that conforms to the NITZ (Network Identity and Time Zone) standard or the like.

[0039] The position calculation information detection unit 29B is a functional unit that detects (measures) information (hereinafter referred to as "position calculation information") necessary for the control unit 21 to calculate (measure) the position of the own terminal 20. The position calculation information detection unit 29B can also be expressed as a position calculation sensor unit, for example and without limitation.

[0040] The position calculation information detection unit 29B includes, by way of example and not limitation, a satellite positioning sensor (satellite positioning unit), which is a sensor or unit for calculating the position of the terminal 20 using a satellite positioning system such as GPS (Global Positioning System), and an inertial measurement sensor (inertial measurement unit (IMU)), which is a sensor or unit for calculating the position of the terminal 20 using an inertial navigation system.

[0041] The satellite positioning unit includes, by way of example and not limitation, an RF receiving circuit that converts RF (Radio Frequency) signals, including positioning satellite signals transmitted from positioning satellites and received by an antenna (not shown), into digital signals, and a baseband processing circuit that performs correlation calculation processing or the like on the digital signals output from the RF receiving circuit to capture the positioning satellite signals, and outputs information such as satellite orbit data and time data extracted from the positioning satellite signals as information for position calculation.

[0042] The inertial measurement unit has an inertial sensor that is a sensor that detects information necessary for calculating the position of the terminal 20 by inertial navigation calculation. The inertial sensor includes, but is not limited to, a three-axis acceleration sensor and a three-axis gyro sensor, and outputs the acceleration detected by the acceleration sensor and the angular velocity detected by the gyro sensor as information for position calculation.

[0043] For example, but not by way of limitation, the control unit 21 calculates the position of its own terminal 20 at regular intervals or specific intervals based on the position calculation information detected by the position calculation information detection unit 29B. The terminal position is referred to as the "terminal position," and the calculated terminal position is referred to as the "calculated terminal position." The control unit 21 then associates the calculated terminal position with the date and time when the calculated terminal position was calculated, and stores the calculated terminal position history data in the storage unit 28. (3) Other

[0044] Furthermore, the program P (for example, but not limited to, a software program, computer program, or program module) of each embodiment of the present disclosure may or may not be provided in a state stored in a computer-readable storage medium. The storage medium can store the program P in a "non-transitory tangible medium." The program P may or may not be intended to realize part of the functions of each embodiment of the present disclosure. Furthermore, the program P may or may not be a so-called difference file (difference program) that can realize the functions of each embodiment of the present disclosure in combination with a program P already recorded on a storage medium.

[0045] Storage media such as storage unit 15 and storage unit 28 may include any of the storage media described above, or a suitable combination of two or more of these. Storage media may be volatile, nonvolatile, or a combination of volatile and nonvolatile, as appropriate. Note that storage media are not limited to these examples and may be any device or medium capable of storing program P. Furthermore, storage media may or may not be referred to as memory.

[0046] Furthermore, the program P of the present disclosure may or may not be provided to the server 10 or the terminal 20 via any transmission medium capable of transmitting a program (such as a communication network or broadcast waves). For example, and not by way of limitation, the server 10 or the terminal 20 executes the program P downloaded via the Internet or the like to realize the functions of the multiple functional units shown in each embodiment. The same applies to other devices.

[0047] Furthermore, each embodiment of the present disclosure may be realized in the form of a data signal in which the program P is embodied by electronic transmission. At least a portion of the processing in the server 10 or the terminal 20 may, or may not, be realized by cloud computing consisting of one or more computers. At least a portion of the processing in the terminal 20 may, or may not, be configured to be performed by the server 10. In this case, at least a portion of the processing of each functional unit of the control unit 21 of the terminal 20 may, or may not, be configured to be performed by the server 10. At least a portion of the processing in the server 10 may, or may not, be configured to be performed by the terminal 20. In this case, at least a portion of the processing of each functional unit of the control unit 11 of the server 10 may, or may not, be configured to be performed by the terminal 20. Unless explicitly stated, each determination in the embodiments of the present disclosure is not essential, and a predetermined process may, or may not, be executed when a determination condition is met, or a predetermined process may, or may not, be executed when a determination condition is not met. Furthermore, unless explicitly stated, the configuration of each process in the embodiments of the present disclosure is not essential, and some of the processes disclosed in the embodiments may be skipped or not performed.

[0048] The programs of the present disclosure are implemented using, for example and without limitation, scripting languages ​​such as ActionScript and JavaScript (registered trademark), compiler languages ​​such as Objective-C and Java (registered trademark), and markup languages ​​such as HTML5.

[0049] First Embodiment The first embodiment discloses an example in which an information processing device such as a server 10 detects an obstruction to the security of an organization, which is performed by a user who uses a terminal 20 that is a device of the organization.

[0050] FIG. 2 shows an overall system diagram of the first embodiment. The overall system of the first embodiment includes the server 10, terminal 20, and display device 24 described above, and the server 10 and terminal 20 are capable of communicating with each other via a network 30. In the first embodiment, the server 10 is a server used by an organization, and the terminal 20 is a terminal used by a user belonging to the organization. Note that the organization in this embodiment may be an individual or a group of multiple people formed for a purpose. Examples of organizations are not limited to, and may include facilities such as accommodation facilities, government agencies, companies, factories, schools, medical institutions such as hospitals, and other organizations. Therefore, the organization's terminal 20 is a terminal used by a user belonging to the organization, and the server 10 communicates information with the organization's terminal 20 via the network 30 to detect user disruptive behavior against the organization's security, as described below.

[0051] Next, an example of functions realized by the server 10 and the terminal 20 according to the first embodiment will be described with reference to Fig. 3. The server 10 includes the control unit 21, communication unit 22, input / output unit 23, and storage unit 28 described above. The storage unit 28 stores a user input log 281. The user input log 281 stores operations performed by a user who uses the terminal 20.

[0052] 4, the data structure of the user input log 281 is composed of a user name, a user ID, an operation log, and other information. The user name is the name of the user who uses the terminal 20, and may be, for example and without limitation, a name input by an administrator who manages an organization, or information input by the user who uses the terminal 20 himself.

[0053] The user ID may be information for identifying a user who uses the terminal 20, or information for identifying a terminal 20 that the user can use (has the right to use). The user input log 281 is expressed in alphabets and numbers as an example of a user ID, but is not limited to this. Alternatively, the user ID may be expressed in other languages ​​such as kanji, or symbols.

[0054] Next, the operation log is an item for recording operations performed on the terminal 20 by the user using the terminal 20. For example, the operation log of the user input log 281 records that the user of the terminal 20 performed an operation to delete antivirus software, which is an action that interferes with the security of the organization, on the Nth day of the Nth month.

[0055] Here, security is something set up by an organization to safely protect the organization. Security may be configured with hardware or software. Software-based security may include, but is not limited to, antivirus software to counter external attacks, a firewall set up in the organization, an intrusion detection system that detects external intrusions into the organization's system, or an intrusion prevention system that prevents external intrusions based on the detection. Security may also be something that protects the organization's network using the specific security systems described above.

[0056] Furthermore, security may be set uniformly for all terminals 20 in an organization. For example, an organization may have multiple terminals 20, each distributed to multiple users. Antivirus software, firewalls, and the like are set uniformly for all of these terminals 20. In this manner, the same security may be set for the entire organization. Although the above description describes the same security, the security level does not need to be the same for all terminals 20; different security levels may be set. For example, a higher security level may be set for users with higher job responsibilities, and a lower security level may be set for users with lower job responsibilities. This is because users with higher job responsibilities are more likely to store important information on their terminals 20, so the security level may be set higher to strictly protect the information. Conversely, the security level may be set lower for users with higher job responsibilities, and higher for users with lower job responsibilities.

[0057] Furthermore, an action that disrupts the security of an organization is an action that a user takes to disrupt the above-mentioned security established by the organization using the terminal 20. By way of example and not limitation, an action that disrupts the security of an organization includes an action that investigates the security established by the organization, an action that circumvents the security established by the organization, and the like.

[0058] Actions to investigate the security of an organization include actions by a user of terminal 20 to investigate the security itself set up in the organization, and actions to investigate logs of operations performed on the security set up in the organization.

[0059] By way of example and not limitation, the behavior of investigating the security set up in an organization includes the behavior of investigating the location where antivirus software set up in the terminal 20 available to the user is stored, the location where a firewall is installed, etc. Such behavior may later lead to circumvention of the set security (details will be described later, but as an example and not limitation, the deletion of antivirus software shown in the user input log 281 in FIG. 4 ), and therefore is treated as behavior that interferes with the security of the organization.

[0060] Furthermore, as will be described later, the action of investigating the log of operations performed on the security set for the organization may involve investigating the log or the operation log stored in the database, which stores the history of operations performed by the user of the terminal 20 in the user input log 281 or the user management database 152. Such an action may later lead to the deletion of the recorded security operation log (as an example, and not a limitation, the deletion of the operation log showing the removal of antivirus software shown in the user input log 281 in FIG. 4), and therefore may be included in the actions that interfere with the security of the organization.

[0061] Actions to circumvent security set by an organization may include actions to disable security set by the organization or actions to delete operation logs that have performed operations against security set by the organization.

[0062] Examples of actions that disable security set by an organization include, but are not limited to, uninstalling security software that is security set by an organization, installing software that harms the security set by an organization, etc. These actions directly harm the security set by an organization, and therefore may be included in actions that disrupt the security of an organization.

[0063] Furthermore, the action of deleting an operation log in which an operation was performed against the security set by an organization is the action of deleting the above-mentioned user input log 281 or the operation log stored in the user management database 152. Such an action is an action that conceals an action that the user of the terminal 20 performed himself that interferes with security, and therefore may be included in the action that interferes with the security of the organization.

[0064] 4, the operation log of the user input log 281 may not only record disruptive behavior that disrupts security set by the organization, but may also record operations that are normally performed using the terminal 20 by the user of the terminal 20. As an example, the user input log 281 in Fig. 4 records an operation indicating that user A.A. logged in to a community within the organization on month L, day L. Such information may be recorded, or the data may be configured not to store such information and to record only disruptive behavior that disrupts security.

[0065] The user input log 281 may also include other information. The other information is information related to user A. The information about user A may include, for example, the date user A joined the company and the work the user performs at the organization, without being limited thereto. User A's years of service can be calculated from the date user A joined the company. Since a long year of service generally indicates a trustworthy user, this information can be used to determine whether the actions recorded in user A's operation log were performed by mistake. Furthermore, the work the user performs at the organization can be used to determine whether the actions recorded in the operation log are required for user A's work. The other information does not need to be included in the user input log 281, and it can be included or not. The other items may also include information about the location of the terminal 20. If the terminal 20 is not located where normal work is performed, there is a possibility that fraudulent activity may have occurred. This information can be used to determine whether the actions recorded in user A's operation log were performed by mistake. The detection of the position information can be performed using the position calculation detection unit 29B described in FIG. 1, and if necessary, it may be attached to the terminal 20 as appropriate so that the position can be detected.

[0066] In this way, the user input log 281 records the history of operations of the terminal 20 by the user of the terminal 20. The user input log 281 records operations of the user of the terminal 20 by input to the input / output unit 23 of the terminal 20.

[0067] The control unit 21 of the terminal 20 controls the communication unit 22 to transmit the information recorded in the user input log 281 to the server 10 via the network 30. Under the control of the control unit 21, the information recorded in the user input log 281 in the storage unit 28 is transmitted to the server 10. The information stored in the user input log 281 to be transmitted may or may not be all of the information contained in the user input log 281. For example, only the user ID and operation log information contained in the user input log 281 may be transmitted to the server 10. If the receiving server has already recorded the user's name, the user name need not be transmitted. While the case where the user ID is transmitted is described, if the user can be uniquely identified by the user name, the user name may be transmitted together with the operation log instead of the user ID. Therefore, if the user can be uniquely identified by the user name, the user ID is not necessarily required. Furthermore, if other information contained in the user input log 281 is not used in subsequent processing by the server 10, it need not be transmitted.

[0068] Next, the server 10 includes the control unit 11, communication unit 14, and storage unit 15 described above. The storage unit 15 includes a security processing program 151 and a user management database 152. The security processing program 151 is a program for executing the detection processing described below in the first embodiment, and the control unit 11 can execute the detection processing by reading the security processing program 151. The user management database 152 stores, in a database format for each user, information such as each user input log 281 transmitted from each user's terminal 20 via the network 30.

[0069] The communication unit 14 of the server 10 receives information based on the user input log 281 transmitted from the terminal 20. The control unit 11 of the server 10 controls the storage of the information based on the user input log 281 received by the communication unit 14 in the user management database 152 stored in the storage unit 15. Under the control of the control unit 11, operation logs performed by each user are stored in the user input log 281 in a database format.

[0070] FIG. 5 is a diagram showing the data configuration of the user management database 152 stored in the storage unit 15. The user management database 152 is configured based on the information in the user input log 281 transmitted from each user's terminal 20, and thus, like the user input log 281, includes the user name, user ID, operation log, and other information. Note that the user management database 152 shown in FIG. 5 is illustrated as having a similar configuration to the user input log 281, but they do not have to be the same. For example, unlike the input log 281, the user management database 152 may or may not include other information. On the other hand, even if the user management database 152 includes an item for other information, the input log 281 may not include such an item.

[0071] The user name, user ID, operation log, and other information are based on the input log 281 described above and may be the same information as the input log 281, or may be information added to or partially deleted from the information in the input log 281. The user management database 152 is information that aggregates the information in the input log 281 transmitted from each terminal 20, and therefore includes the user name, user ID, operation log, and other information for each user. For example, the user management database 152 in FIG. 5 stores in its operation log the deletion of antivirus software on Nth month and Nth day, which is included in the operation log of the input log 281 stored in the terminal 20 of user A. Furthermore, the user management database 152 stores in its operation log the operation of the U application on Qth month and Qth day, which is included in the operation log of the input log 281 stored in the terminal 20 of user B. In this way, the user management database 152 is configured with information that aggregates the information in the input log 281 transmitted from each terminal 20.

[0072] Next, the detection process according to the first embodiment of the present invention will be described with reference to Fig. 6. Fig. 6 shows the functions included in the server 10, which includes a control unit 11 and a storage unit 15. The control unit 11 includes a detection unit 111, and the storage unit 15 includes the security processing program 151 and the user management database 152.

[0073] The control unit 11 reads the security processing program 151 stored in the storage unit 15 and executes a detection process in accordance with the security processing program 151. The detection unit 111 included in the control unit 11 accesses the user management database 152 stored in the storage unit 15 in accordance with the security processing program 151 and executes a process of checking the operation log of each user.

[0074] The detection unit 111 included in the control unit 11 checks the operation logs of each user in the user management database 152, and then performs processing to determine whether or not there is any operation log that corresponds to behavior that interferes with the security of the organization. If there is any operation log that corresponds to behavior that interferes with the security of the organization, processing to detect the corresponding operation log is performed. An example of the detection processing will be described with reference to FIG. 5. Since the operation log of user A.A includes the behavior of deleting antivirus software, which is included in the behavior that interferes with security, the detection unit 111 included in the control unit 11 performs processing to detect this behavior as a behavior that interferes with security. Furthermore, the operation log of user D.D includes the behavior of investigating security, which is to perform a search for security software on month P, day P, and the detection unit 111 included in the control unit 11 performs processing to detect this behavior as a behavior that interferes with security.

[0075] After performing the detection process, the detection unit 111 included in the control unit 11 may or may not perform control to store the detection results in the user management database 152. When performing the storage control, as a non-limiting example, the detection unit 111 included in the control unit 11 may perform control to store the fact that an action that interferes with the security of the organization has been detected in the other information item of the user management database 152. Furthermore, the control unit 11 may perform control to store the detection results not only in the user management database 152 but also in another storage area of ​​the storage unit 15. Note that this storage control is not essential in the first embodiment, and the storage control may or may not be performed.

[0076] Next, a process according to the first embodiment will be described using the sequence diagram shown in FIG. 7 . The process shown in FIG. 7 is executed by the server 10 and the terminal 20. The process by the server 10 may be implemented by the control unit 11 reading and executing code of the security processing program 151 stored in the storage unit 15. The process by the terminal 20 may be implemented by the control unit 21 reading and executing code of the program stored in the storage unit 28. Note that the process described below is merely an example of a process for implementing the method of the present disclosure and is not limited thereto. Other steps may be added to the process described below, or some steps may be omitted (deleted or skipped) from the process described below. For simplicity, FIG. 7 illustrates the process using one terminal 20, but the process shown in FIG. 7 may be executed by two or more terminals 20. In this case, the server 10 receives information based on the user input log 281 described below from the multiple terminals 20. The information based on the user input log 281 transmitted from the multiple terminals 20 is stored in the management database 152.

[0077] First, the control unit 21 of the terminal 20 determines whether or not there is an input from the input / output unit 23 by the user of the terminal 20 (A100). If there is no input (A100: NO), the control unit 21 again determines whether there is an input from the input / output unit 23. If there is an input (A100: YES), the control unit 21 controls to store the operation information input by the input / output unit 23 in the user input log 281 included in the storage unit 28.

[0078] The control unit 21 then controls the communication unit 22 to transmit information based on the user input log 281 via the network 30 (A120). In the sequence diagram shown in FIG. 7 , the control unit 21 performs step A120 consecutively after step A110, but this is not a limitation. The process of step A120 may be performed as needed and may be executed independently of step A110. For example, the information recorded in the user input log 281 may be transmitted periodically or aperiodically at a set time after 11:00 PM, when the user's work is finished. Furthermore, it is not necessary to transmit all of the information in the user input log 281. Information already transmitted to the server 10 does not need to be transmitted. Only updated information not stored in the server 10 may be transmitted.

[0079] The control unit 11 of the server 10 controls the communication unit 14 of the server 10 to receive information based on the user input log 281 transmitted by the communication unit 22 of the terminal 20 (S200).

[0080] After receiving the information based on the user input log 281 via the communication unit 14 of the server 10, the control unit 11 controls the storage of the information based on the received user input log 281 in the user management database 152 stored in the memory unit 15 of the server 10 (S210).

[0081] Next, the detection unit 111 included in the control unit 11 of the server 10 performs a process of accessing the user management database 152 to execute the detection process (S220). Note that, although step S220 is executed following the process of step S210 in FIG. 7, it does not have to be executed consecutively. It may be executed independently of step S210, or, like step A120, may be executed at a set timing. For example, the process of accessing the user management database 152 may be executed periodically or aperiodically at a set time, such as after 10:00 PM when the user's work is finished.

[0082] The detection unit 111 included in the control unit 11 accesses the user management database 152, and then determines whether or not the user management database 152 contains any behavior that violates security (S230). If the user management database 152 does not contain any behavior that violates security (S230: NO), the detection process ends.

[0083] On the other hand, if the detection unit 111 included in the control unit 11 determines that the behavior includes behavior that interferes with security (S230: YES), it performs control to detect interference behavior that interferes with the relevant organization from the operation log of the user management database 152 (S235). After performing step S235, the detection process described in FIG. 7 ends.

[0084] As described above, after the processing of step 235, the control unit 11 may or may not control the storage of the detected disruptive behavior in association with the user who committed the disruptive behavior. If the control unit 11 performs the storage, the control unit 11 may or may not control the storage of information that the disruptive behavior has been detected in the other information section of the user who committed the disruptive behavior, which is included in the user management database 152. As described above, the control unit 11 may also perform control to store the information in an area of ​​the storage unit 15 that is different from the user management database 152.

[0085] <Effects of First Embodiment> This embodiment illustrates a configuration in which an information processing device such as the server 10 detects disruptive behavior, which is behavior related to disrupting security set on the organization's terminal 20, by a user who uses the organization's terminal 20 (not limited to, but an example of an organization's device), using the detection unit 111 included in the control unit 11. As an example of an effect of the embodiment obtained by such a configuration, it becomes possible to detect information intended to disrupt the organization's security, and therefore to detect users who directly harm the organization's security.

[0086] Furthermore, in this embodiment, behavior related to the disruption of security includes behavior of investigating the security set in the terminal 20 (which is not limited to the terminal 20 and is an example of an organization's device). With this configuration, it becomes possible to detect behavior by a user of investigating security, which is a precursor to the disruption of security, and therefore to detect behavior by a user that may harm the security of an organization before the user disrupts security.

[0087] Furthermore, in this embodiment, actions related to the interference with security include an operation by the user of the terminal 20 to check the security set in the terminal 20 (which is not limited to the terminal 20 but is an example of an organization's device) or an action to check the operation log for security. With this configuration, it becomes possible to detect actions by a user that may harm the security of an organization before the user interferes with security.

[0088] Furthermore, in this embodiment, behavior related to the disruption of security includes behavior by a user of the terminal 20 that circumvents security set on the terminal 20 (an example of an organization's equipment, but not limited to this). With this configuration, it is possible to detect malicious behavior by a user that circumvents security. Furthermore, before a user who has circumvented the organization's security measures performs further malicious behavior, such as launching a specific attack against the organization (a cyber attack, for example, but not limited to this), it is possible to detect a user who is likely to perform further malicious behavior, thereby minimizing damage to the organization.

[0089] Furthermore, in this embodiment, actions related to the interference with security include actions by a user of the terminal 20 to disable security set on the terminal 20 (an example of an organization's device, but not limited to this) or actions to delete an operation log of an operation performed on security. With this configuration, it is possible to detect malicious actions by a user circumventing security. Furthermore, it is possible to detect users who are likely to perform further malicious actions before a user who has circumvented the organization's security measures performs further malicious actions, such as launching a specific attack against the organization (a cyber attack, for example, but not limited to this), thereby minimizing damage to the organization.

[0090] Furthermore, this embodiment may include, as security, security for protecting the organization's network set by the organization. With such a configuration, as security, it is possible to detect behavior that interferes with the protection of the organization's network, thereby making it possible to detect users that interfere with the organization's network, and therefore to protect the organization's network from interference.

[0091] Furthermore, in this embodiment, security may be set on the terminals 20 (not limited to this, but is an example of organizational devices) distributed to each of a plurality of users belonging to an organization. With this configuration, the target of security for detecting interference is set uniformly for the organization, so that by detecting an act of interference with security, it is possible to detect interference with the security set for the organization and protect the entire organization from interference with the security set for the organization.

[0092] Furthermore, in this embodiment, the security may be software-based security. With this configuration, it becomes possible to protect against software-based interference with security by detecting software-based interference with security.

[0093] <Embodiment 1, Variant 1> The behaviors that compromise the security of an organization shown in the first embodiment may be input by an administrator who manages the terminals 20 of the organization, and what constitutes behavior that compromises security may be input, or the behaviors included in the behaviors that compromise the security of the organization may be acquired from outside via the network 30.

[0094] When input by a user who manages the organization's terminal 20, the input is made through the input / output unit 23 of the organization's terminal 20 or the input / output unit 12 provided in the server 10. As a non-limiting example, when an action of deleting the organization's firewall is added as a specific action included in the above-mentioned actions to circumvent security, the action is input through the input / output unit 23 of the organization's terminal 20 or the input / output unit 12 provided in the server 10 and added as a new action that violates security. The added new action that violates security is stored in the storage unit 15 or the like.

[0095] Furthermore, when acquiring behaviors included in the behaviors that disrupt the security of the organization from the outside via the network 30, the communication unit 14 of the server 10 receives new behaviors included in the behaviors that disrupt the security of the organization and stores them in the storage unit 15 or the like. As a non-limiting example, the added new behavior that disrupts security is stored in the security program 151 stored in the storage unit 15. This allows the control unit 11, when reading the security program 151, to acquire information indicating what behaviors disrupt the security of the organization, including the newly added disruptive behavior.

[0096] By executing the processing described in variant example 1 of embodiment 1, it becomes possible to appropriately update behaviors that disrupt the security of an organization, and it becomes possible to add newly occurring disruptive behaviors and newly occurring behaviors that disrupt security, thereby making it possible to appropriately detect behaviors that disrupt the security of an organization.

[0097] Second Embodiment In the first embodiment, a configuration was disclosed in which an information processing device such as the server 10 detects disruptive behavior against the security of an organization by a user who uses an organization's device using the detection unit 111 included in the control unit 11. In the second embodiment, after detection by the detection unit 111, a device control unit 114 included in the control unit 11, which will be described later, controls notification and the use of the terminal 20.

[0098] 8 is a block diagram showing an example of the functional configuration of the server 10 according to the second embodiment. Focusing on the differences between the second embodiment and the first embodiment, the server 10 according to the second embodiment includes a determination unit 113 and a device control unit 114. As will be described later, the determination unit 113 is not necessarily required, and may be present or absent.

[0099] The determination unit 113 executes a process of determining whether to control the device based on the result of detection by the detection unit 111. If it is determined that device control is to be executed, the device control unit 114 executes the device control. In the second embodiment, the device control will be described using an example of control that notifies information indicating that an action that violates security has been detected, but as described in a modified example below, the device control is not limited to this.

[0100] Next, FIG. 9 is a sequence diagram illustrating an example of the flow of processing executed by each device in this embodiment. Here, the content shown in FIG. 9 will be described, focusing on the differences from the first embodiment. First, unlike the first embodiment, the second embodiment is configured with two terminals 20 and a server 10. Note that while the description uses an example of two terminals, terminal 20A and terminal 20B, this is not limited thereto. There may be two or more terminals performing processing equivalent to terminal 20A, or there may be two or more terminals performing processing equivalent to terminal 20B. Note that in the example shown in FIG. 9, the user using terminal 20A is assumed to be a user belonging to an organization, and the user using terminal 20B is assumed to be a user (which may be referred to as an administrator) who manages terminals 20A and the like of the organization. However, this is not limited thereto. The user using terminal 20B may be a user belonging to the same organization as the user using terminal 20A, or may be a user belonging to a different organization from the organization to which terminal 20A belongs.

[0101] Next, in the second embodiment, the processing flow that differs from the first embodiment is that there are no particular differences in terminal 20A, but in server 10, it differs from the first embodiment in that it includes steps S240 and S245, and in terminal 20B, it differs from the first embodiment in that it includes processing in steps B300 and B310.

[0102] In order to focus on the differences between the second embodiment and the first embodiment, the following description will begin with the processing after step S235, which is similar to the processing in the first embodiment and is executed by the detection unit 111 included in the control unit 11 of the server 10. As the processing after step S235, the determination unit 113 included in the control unit 11 determines whether to control the device based on the detection of the disruptive behavior detected in step S235 (S240). Note that, as described above, the description here will be given using an example of device control in which notification is sent to the terminal 20A. Note that, although FIG. 9 illustrates an example in which the determination in step S240 is executed, this is not limiting. Step S240 is not essential, and processing may be executed after step S235 by skipping step S240.

[0103] If the determination unit 113 determines that the device control should not be to notify terminal 20B (S240: NO), the control by the control unit 11 in Fig. 9 is terminated as the device control should not be performed. On the other hand, if the determination unit 113 determines that the device control should be to notify terminal 20B (S240: YES), the device control unit 114 executes control to notify indicating that a security interference behavior has been detected (S245). As the control to notify, the device control unit 114 controls the communication unit 14 to transmit information for the notification to terminal 20B via the network 30.

[0104] Here, the information for sending a notification includes at least information for causing terminal 20B to execute the notification, and when terminal 20B receives this information, terminal 20B sends a notification indicating that a security interference behavior has been detected. Note that the information for sending a notification may or may not include notification content consisting of text information. If the information includes the notification content, as described below, the notification content is displayed on display unit 24 of terminal 20B, by way of example and not limitation.

[0105] Next, the control unit 21 of the terminal 20B determines whether the communication unit 22 of the terminal 20B has received information for notification, which is included in the information regarding device control sent from the server 10, via the network 30 (B300).

[0106] If the information for sending a notification has not been received (B300: NO), the control unit 21 of the terminal 20B again determines whether or not the information for sending a notification has been received. If the information for sending a notification has been received (B300: YES), the control unit 21 of the terminal 20B executes a process of sending a notification to the user of the terminal 20B based on the information for sending a notification.

[0107] 10 is a diagram showing that, upon receiving information for notification by terminal 20B, notification of information indicating that interference with security has been detected is executed on display unit 24 of terminal 20B. As shown in Fig. 10, display unit 24 displays "User A. A may be engaging in interference with security" as notification of information indicating that interference with security has been detected.

[0108] As mentioned above, the user using terminal 20B may be an administrator who manages an organization, and so by checking the contents of this notification, the user using terminal 20B will be able to immediately know that user A.A. is engaging in disruptive behavior.

[0109] Although the notification content has been described using a display as an example, it is not limited thereto. The notification here may be a sound notification or a vibration notification. The control unit 21 of the terminal 20B may perform different control depending on the type of notification and control the notification appropriately. A sound notification or a tactile notification may be performed by the input / output unit 23 shown in FIG. 1. The sound notification may be a buzzer sound or chime that is an alarm sound indicating that a security breach has been detected, or a synthesized voice corresponding to text indicating that a security breach has been detected.

[0110] Effect of Second Embodiment This embodiment illustrates a configuration in which an information processing device such as the server 10 detects disruptive behavior, which is behavior related to disrupting security set on the organization's terminal 20 (not limited to this example), by a user who uses the organization's terminal 20 (not limited to this example, an example of an organization's device), using a detection unit 111 included in the control unit 11, and controls the device (not limited to this example, an example of control) based on the detection using a device control unit 114 included in the control unit 11. As an example of an effect of this embodiment obtained by such a configuration, it is possible to perform control based on the detection of information intended to disrupt the organization's security, and it is possible to appropriately deal with disruptive behavior against the organization's security.

[0111] Furthermore, in this embodiment, as control of the device (not limited to this, but an example of control), control of notifying of disruptive behavior is shown to be performed by the device control unit 114 included in the control unit 11. As an example of the effect of this embodiment obtained by such a configuration, it is possible to notify that an action to disrupt security is being taken based on the detection of information intended to disrupt the security of an organization, and to deal with the disruption at an early stage.

[0112] <Embodiment 2, Modification 1> In the examples shown in FIGS. 9 and 10 of the second embodiment, notification has been used as an example of device control, but this is not limited thereto. Device control may also be performed to restrict the use of terminal 20B by a user who has engaged in disruptive behavior based on the detection of disruptive behavior. In the example shown in FIG. 9 , the user using terminal 20B is assumed to be a user (administrator) who manages terminals 20A and the like in an organization. However, in Modification 1, the user using terminal 20B is assumed to be a user who belongs to the organization, just like the user using terminal 20A. Furthermore, while the following example is described using terminals 20A and 20B, the description will be given assuming that terminal 20B has already executed the processing performed by terminal 20A in the sequence diagram shown in FIG. 9 , which will be described below. In other words, since terminal 20B has already executed the processing performed by terminal 20A in FIG. 9 , the user management database 152 already stores information based on the user's input log stored in terminal 20B. Furthermore, as described below, the terminal 20B may be read as the terminal 20A, and the processing of the first modification of the second embodiment may be executed.

[0113] A specific description will be given using Fig. 9. In the sequence diagram of Fig. 9, the processing is the same up to step S240. When device control is performed in step S240, control may be performed by the device control unit 114 included in the control unit 11 in step S245 to restrict the use of the terminal 20B of the user who has engaged in disruptive behavior.

[0114] The control to restrict the use of terminal 20B of a user who has engaged in disruptive behavior is control to transmit information for restricting the use of terminal 20B from server 10 to terminal 20B. When terminal 20B receives the information restricting the use of terminal 20B, the use of terminal 20B is restricted, and operations by the user of terminal 20B are no longer accepted, making terminal 20B unusable. Note that it is not necessary to be limited to not accepting all operations, and it is also possible to prevent the acceptance of some operations. As a non-limiting example, only some functions, such as internet functions, email functions, and chat functions, or software that constitutes some functions may be made unusable, or all functions or all software may be made unusable.

[0115] Furthermore, without being limited to the above example, when terminal 20B receives this information, the user of terminal 20B may be deprived of the authority to use terminal 20B, and may not be able to log in to terminal 20B.

[0116] Therefore, when performing device control, in step S245, device control unit 114 controls communication unit 14 of server 10 to transmit information for restricting the use of terminal 20B. Thereafter, in step B300, if control unit 21 determines that information for restricting the use of terminal 20B has been received by communication unit 22 of terminal 20B, in step B310, control unit 21 executes the above-mentioned control for restricting the use of terminal 20B as device control.

[0117] While an example of restricting the use of terminal 20B has been described above, a notification indicating that the use of terminal 20B has been restricted may also be sent. Fig. 11 shows the display unit 24 of terminal 20B on which control to restrict the use of terminal 20B has been executed. The display unit 24 displays a message indicating that user B may be engaging in disruptive behavior and that the use of the terminal has been restricted. In this way, a notification may also be sent to the user of terminal 20B informing them that the use of the terminal has been restricted, triggered by the user of terminal 20B engaging in disruptive behavior against the security of the organization.

[0118] In this way, the device control may not only perform the control for sending a notification described in the second embodiment, but also perform control to restrict the use of terminal 20B. Although the description of the first modification of the second embodiment has been given using information for restricting the use of terminal 20B, the processing may be executed by replacing terminal 20B with terminal 20A. That is, the example of the first modification of the second embodiment described above has been described using processing executed by two terminals, terminal 20A and terminal 20B, and server 10. However, the processing may be executed by terminal 20A and server 10, or the processing executed by terminal 20B may be modified so that only terminal 20A executes the processing. Furthermore, the processing of the first modification of the second embodiment may be executed by multiple terminals in accordance with the description of the second embodiment. That is, there may be multiple terminals corresponding to terminal 20A described in the first modification of the second embodiment, or there may be multiple terminals corresponding to terminal 20B described in the first modification of the second embodiment.

[0119] In the example of the first modification of the second embodiment, the device control executed on terminal 20B is to restrict the use of terminal 20B. However, this is not limiting. Alternatively, the device control may be to transmit information to terminal 20B inquiring whether to restrict the use of a terminal other than terminal 20B (e.g., terminal 20A). In this case, the user of terminal 20B may be a user (administrative user) who manages the organization's devices. For example, if disruptive behavior by a user of a terminal other than terminal 20B (e.g., terminal 20A) is detected in step S235, the device control unit 114 of the server 10 transmits information inquiring whether to restrict the use of a terminal other than terminal 20B (e.g., terminal 20A) as the device control in step S240. Then, terminal 20B receives the information inquiring whether to restrict the use from the server 10. Then, terminal 20B displays corresponding information on the display unit 24 of terminal 20B. When the user of terminal 20B confirms this and inputs permission to restrict use, control unit 11 of server 10 may execute control to restrict use of a terminal other than terminal 20B (for example, terminal 20A). That is, referring to the example of Modification 1 of Embodiment 2, server 10 may transmit information inquiring whether to restrict use as device control.

[0120] <Effects of Modification 1 of Second Embodiment> This modification also illustrates a configuration in which, as device control (not limited to this, but an example of control), control to restrict the use of a device used by a user or control to restrict software on a device used by a user is performed by the device control unit 114 included in the control unit 11. As an example of an effect of the embodiment obtained by such a configuration, it is possible to restrict the use of a terminal that is interfering with security based on the detection of information that appears to be intended to interfere with the security of an organization, thereby making it possible to prevent a user who has interfered with security from engaging in further malicious behavior.

[0121] Third Embodiment The first embodiment discloses a configuration in which an information processing device such as the server 10 detects disruptive behavior against the security of an organization by a user who uses an organization's device using a detection unit 111 included in the control unit 11. The third embodiment is configured to perform detection by the detection unit 111, and then evaluate a risk value of the disruptive behavior by an evaluation unit 112 included in the control unit 11, which will be described later, and quantitatively evaluates the risk of the disruptive behavior performed by a user who uses the organization's device.

[0122] The configuration of the third embodiment will be described with reference to Fig. 12. As a difference from the first embodiment, as described above, the control unit 11 includes an evaluation unit 112. This evaluation unit 112 quantitatively evaluates the risk of disruptive behavior against the security of the organization, detected by the detection unit 111 included in the control unit 11. The evaluated value, etc. may be stored in the user management database 152 included in the storage unit 15, or may be stored in a separate storage area of ​​the storage unit 15.

[0123] FIG. 13 shows an example in which the evaluations made by the evaluation unit 112 are stored in the user management database 152. Unlike the user management database 152 shown in FIG. 5 described above, the user management database 152 shown in FIG. 13 includes an item for inputting an evaluation score for each user. An evaluation value based on the behavior of each user is input into this item for inputting an evaluation score. Note that although the evaluation values ​​are shown numerically here, evaluations may be made using a method other than numerical values. As a non-limiting example, evaluations may be made in multiple stages, such as high, normal, and low risk, or the magnitude of risk may be indicated in alphabetical order (for example, without limitation, evaluations may be made such that A indicates the greatest risk and the risk decreases from A onwards).

[0124] 13 shows that user A.A. has been evaluated as minus 50 by the evaluation unit 112 because user A.A. has deleted antivirus software, which is an obstructive behavior against the organization's security. Also, FIG. 13 shows that user D.D. has been evaluated as minus 15 by the evaluation unit 112 because user A.A. has searched for the location where security software is stored, which is an obstructive behavior against the organization's security.

[0125] The evaluation here may be uniform or may vary depending on the behavior. For example, removing antivirus software is included in behaviors that circumvent organizational security. Avoiding behaviors may be determined to be riskier than investigating security, and the evaluation may be set higher (so that the negative evaluation is greater) than investigating behaviors. Specifically, in FIG. 9 , removing antivirus software, which is included in behaviors that circumvent security, is evaluated as minus 50 (not a limitation, but an example of a first value). On the other hand, performing a security search, which is included in behaviors that investigate security, is evaluated as minus 15 (not a limitation, but an example of a second value), which is a smaller negative evaluation than removing antivirus software. In this way, avoiding behaviors may be evaluated as having a higher negative evaluation than investigating behaviors (not a limitation, but an example of a second value having a higher negative evaluation than the first value), or vice versa.

[0126] Furthermore, since multiple types of behaviors to be avoided are set, the evaluation unit 112 may perform a different evaluation for each type. As a non-limiting example, the evaluation may be different for the removal of antivirus software and the deletion of security operation logs, which are included in the behaviors to be avoided. As a non-limiting example, the evaluation unit 112 may perform a minus 50 evaluation for the removal of antivirus software, and a minus 30 evaluation for the deletion of security operation logs. In this way, the evaluation unit 112 may perform a different evaluation for each type. Note that, similarly, with regard to behaviors to investigate security, the evaluation unit 112 may perform a different evaluation for each type included in the behavior to investigate security.

[0127] 13, user B.B. is given a rating of minus 5 by the evaluation unit 112. This does not constitute an action that would compromise the organization's security, but because user B.B. operates the terminal 20 more frequently than a typical user, the evaluation unit 112 gives this rating of minus 5. Therefore, the evaluation unit 112 gives a rating that is different from the rating for actions that compromise the organization's security. Also, in FIG. 13, user C.C. is given a rating of plus 15 by the evaluation unit 112. As described in the other information, user C.C. has not engaged in any particularly problematic actions since joining the company, so the evaluation unit 112 gives this rating as a positive. Also, while a positive rating is used as an example in the explanation here, the evaluation unit 112 may give a negative rating depending on the other information. Furthermore, a negative or positive rating may be given depending on the work content of the user of the terminal 20 and the location information of the terminal 20, as described in embodiment 1. As a non-limiting example, if the "other" field stores a location different from the location where the user of the terminal 20 normally performs work, the evaluation unit 112 may perform a negative or positive evaluation based on that location, time, and date and time. While the present disclosure discloses performing an evaluation unrelated to a security breach or a positive evaluation, this processing need not be performed. Furthermore, while the evaluation is performed using both positive and negative evaluations, it is also possible to perform evaluation using only one of them; for example, the evaluation may be performed using only negative evaluations and no positive evaluations.

[0128] Furthermore, when multiple actions are stored in the operation log, an evaluation may be performed for each action, and the sum of the evaluations may be used as the evaluation for the user. As a non-limiting example, if user A.A. deletes antivirus software and performs more operations than usual, the evaluation unit 112 may add minus 5 to minus 50, thereby evaluating user A.A. as minus 55, and may store this in the user database 152.

[0129] Next, the processing of the third embodiment will be described with reference to Fig. 14. The differences between the first and third embodiments will be mainly described. The processing up to step S235 is the same between the first and third embodiments, but the processing from step S250 onwards differs between the third embodiment and the first embodiment. Therefore, the processing from step S250 onwards will be described in detail.

[0130] After the detection unit 111 of the control unit 11 detects disruptive behavior in step S235, the evaluation unit 112 evaluates the detected disruptive behavior against the security of the organization (S250). After the evaluation by the evaluation unit 112 is performed, the evaluation is stored in the user management database 152 of the storage unit 15 (step S260). As described above, the evaluation may be stored in a storage area of ​​the storage unit 15 different from the user management database 152.

[0131] Effect of Third Embodiment In this embodiment, an information processing device such as the server 10 detects, by a user of an organization's terminal 20 (not limited to this, but an example of an organization's device), a disruptive behavior that is an behavior related to disrupting security set in the organization's terminal 20, using a detection unit 111 included in the control unit 11, an evaluation unit 112 included in the control unit 11 evaluates the detected disruptive behavior, and the evaluation by the evaluation unit 112 is stored in the storage unit 15 by the control unit 11. As an example of an effect of this embodiment obtained by such a configuration, it is possible to quantitatively evaluate the disruptive behavior performed by users and store the evaluation, thereby making it possible to confirm the degree to which each user has engaged in malicious behavior.

[0132] Furthermore, this embodiment shows a configuration in which, in the evaluation by the evaluation unit 112, different evaluations are made for an action that investigates the security set in the terminal 20 (not limited to this but an example of a device) of the organization and an action that circumvents the security set in the terminal 20. As an example of an effect of the embodiment obtained by such a configuration, by making different evaluations for an action that circumvents security and an action that investigates security, it becomes possible to appropriately evaluate the actions of malicious users.

[0133] Furthermore, this embodiment shows a configuration in which, in the evaluation by the evaluation unit 112, different evaluations are made for actions that disrupt security set in the terminal 20 (not limited to, but an example of a device) of the organization and user operations on the terminal 20 that are different from the disruptive actions. As an example of the effect of the embodiment obtained by such a configuration, by making different evaluations for actions that circumvent security and actions that investigate security, it becomes possible to appropriately evaluate the actions of malicious users.

[0134] <Third Embodiment, Modification 1> In the example of the third embodiment, in step S260, the evaluation by the evaluation unit 112 is stored in the user management database 152, and then the processing ends. However, the processing described in the second embodiment may be added thereafter. In the second embodiment, in step S240, it is determined whether or not to control the device. This determination of whether or not to control the device may be made based on the evaluation points stored in the storage unit 15.

[0135] The following describes a first modification of the third embodiment using an example and not a limitation. The process of step S240 of FIG. 9 described in the second embodiment may be added after step S260 in the sequence diagram shown in FIG. 14 . At this time, the evaluations stored for each user are stored in the user management database 152 included in the storage unit 15. The device control unit 114 uses the evaluations stored in the user management database 152 to determine whether to control the device. As a non-limiting example, the device control unit may control the device when the evaluation score falls below a set threshold value of minus 50. When the evaluation score falls below, exceeds, or is equal to a set value (for example, not a limitation), the device control unit 114 may determine to control the device. Note that the process from step S240 onward may be performed according to FIG. 9 described in the second embodiment.

[0136] Note that the above example is not limited to this, and the device control unit 114 may determine to control the device when a specific disruptive behavior is performed regardless of the evaluation score. As a non-limiting example, when the detection unit 111 detects behavior that disrupts security set for an organization, the device control unit 114 may determine to control the device regardless of the evaluation by the evaluation unit 112 (or skip the evaluation). For example, assume that a user's evaluation score exceeds +100 based on the evaluation by the evaluation unit 112 described above, and then the user performs an action that circumvents security and is deducted by 50. In this case, the user's evaluation score is deducted by 50 from +100, so that the user's evaluation score is still positive at +50. However, regardless of this evaluation, the device control unit 114 may determine to control the device because the user has performed an action that disrupts security.

[0137] Note that when executing device control, the device control unit 114 may or may not execute device control regardless of the evaluation by the evaluation unit 112 (or by skipping the evaluation) only when it detects behavior that circumvents security. In other words, when it detects behavior that investigates security, it controls the device based on the evaluation by the evaluation unit 112, and only when it detects behavior that circumvents security, it executes device control regardless of the evaluation by the evaluation unit 112 (or by skipping the evaluation). Also, when executing device control, the device control unit 114 may or may not execute device control regardless of the evaluation by the evaluation unit 112 (or by skipping the evaluation) only when it detects behavior that investigates security.

[0138] Although an example of combining the third embodiment with the second embodiment has been described above, the present invention is not limited to this example and the contents described in the present embodiment may be combined in any manner. Furthermore, when combining the third embodiment and the second embodiment, it is not necessary to execute all steps, and unnecessary steps may be skipped as appropriate, or other steps may be added as appropriate.

[0139] <Third Embodiment, Modification 2> In the third embodiment, the evaluation unit 112 gave a constant evaluation for each of the behaviors that circumvent security and the behaviors that investigate security. However, this evaluation may vary depending on the situation. As a non-limiting example, when the detection unit 111 detects multiple behaviors that circumvent security or multiple behaviors that investigate security per set time (or period) or per unit time (or unit period), the evaluation may be different from when the same multiple behaviors are detected at intervals longer than the set time or unit time.

[0140] As a non-limiting example, assume that the above-mentioned set time is set to 72 hours. Assume that the detection unit 111 detects three security-investigating behaviors within this set time. In this case, the evaluation unit 112 may evaluate the first behavior as minus 15, but the second behavior may be evaluated as minus 20, and the third behavior may be evaluated as minus 50, with different evaluation values ​​assigned to each behavior. The reason for this is that even if a security-investigating behavior is detected once within 72 hours, a user may mistakenly perform such an operation without malicious intent. On the other hand, if the same behavior is performed multiple times within the set time, it is likely that the behavior is performed with the intent to disrupt. Therefore, if the same behavior is performed multiple times within the set time, the negative evaluation may be increased compared to when the same behavior is performed at intervals greater than the set time, thereby enabling a more accurate evaluation of disruptive behavior. The clock unit 16 or clock unit 29A shown in FIG. 1 may be used to calculate whether or not a behavior occurred within the set time. Therefore, the terminal 20 or the server 10 may be appropriately equipped with the above-described configuration when calculating whether or not a behavior occurred within the set time. This allows the terminal 20 or the server 10 to calculate whether or not a detected security-investigating behavior occurred within the set time. Instead of providing the above-described configuration in the device itself, the device may be configured to acquire time information and the like via a network.

[0141] Furthermore, without being limited to the above example, a configuration may be adopted in which, each time multiple similar behaviors are detected within a set time, an additional minus 10 is added to the evaluation of each behavior. As such, any evaluation method may be used as long as multiple behaviors performed within a set time are evaluated to receive a greater negative evaluation than multiple behaviors performed outside the set time. While the above description focuses on multiple identical behaviors, different types of behaviors may also be evaluated to receive a greater negative evaluation. As a non-limiting example, if a security investigation behavior and a security evasion behavior are performed, the evaluation unit 112 would normally be evaluated as minus 15 and minus 50, totaling minus 65. However, if the above behaviors are performed within the set time of 72 hours, the evaluation unit 112 may evaluate them as minus 100, which is greater than minus 65, or as minus 130, which is twice the value.

[0142] As described above, a set time is set and an evaluation is made based on the disruptive behavior detected at the set time, but the evaluation may be different for each set time. As a non-limiting example, the evaluation unit 112 may make a normal evaluation between 9:00 and 18:00 when normal business is performed, but may make a different evaluation during other periods.

[0143] As a non-limiting example, the late night hours between 12:00 and 3:00 are times when normal business operations are not performed. If the detection unit 111 detects an action that interferes with security during this time period, it is highly likely to be malicious. Therefore, if the above-mentioned action is detected between 12:00 and 3:00 in the late night hours, the evaluation unit 112 will give a larger negative evaluation than normal. For example, the evaluation may be set to twice the normal evaluation.

[0144] Variation 2 of the third embodiment shows a configuration in which the evaluation unit 112 performs evaluation based on disruptive behavior detected at a set time. As an example of an effect of the embodiment obtained by such a configuration, it becomes possible to accurately evaluate whether a user is intentionally disrupting security.

[0145] Furthermore, Modification 2 of the third embodiment shows a configuration in which, when the detection unit 111 detects multiple security evasion behaviors or multiple investigation behaviors per set time or per unit time, the evaluation by the evaluation unit 112 is different from when the same multiple behaviors are detected at intervals longer than the set time or unit time. As an example of an effect of the embodiment obtained by such a configuration, it becomes possible to accurately evaluate whether a user is intentionally violating security.

[0146] Fourth Embodiment In the first embodiment, a configuration was disclosed in which an information processing device such as the server 10 detects disruptive behavior against the security of an organization by a user who uses the organization's equipment using a detection unit 111 included in the control unit 11. In a fourth embodiment, a configuration is shown in which an information processing device such as a terminal 20, instead of the server 10, detects disruptive behavior against the security of an organization by a user who uses the organization's equipment using a detection unit 211 included in the control unit 21 of the terminal.

[0147] FIG. 15 is a diagram illustrating an example of functions realized by the control unit 21 of the terminal 20 according to the fourth embodiment. Focusing on the differences between the fourth embodiment and the first embodiment, the terminal 20 illustrated in FIG. 15 includes a control unit 21, which in turn includes a detection unit 211. The detection unit 211 may have the same configuration as the detection unit 111 described above. The storage unit 28 stores, in addition to the user input log described in the first embodiment, a terminal security processing program 282 that the control unit 21 reads and the detection unit 211 executes the detection process. The terminal security processing program 282 may have the same configuration as the security processing program 151 provided in the server 10 described in the first embodiment. However, the terminal security processing program 282 is a program for processing on the terminal 20. Compared to the first embodiment, the communication unit 22 is described here as being detached because communication with the server 10 is not required. However, the communication unit 22 may or may not be provided.

[0148] As described above, the terminal 20 described in the fourth embodiment is capable of reading the terminal security processing program 282 stored in the storage unit 28 by the control unit 20 and executing detection processing in accordance with the terminal security processing program 282. After reading the terminal security processing program 282, the detection unit 211 accesses the user input log 281 and executes processing to check the operation log included in the user input log 281. Then, if the operation log contains any disruptive behavior against the security of the organization, the detection unit 211 executes processing to detect the disruptive behavior.

[0149] Next, the processing of the fourth embodiment will be described using the flowchart shown in FIG. 16 . Focusing on the differences from the content described in the first embodiment, the processing up to step A110 is the same, but the processing thereafter is different. After step A110, the detection unit 211 of the control unit 21 accesses the user input log 281 (step A130). After accessing the user input log 281, the detection unit 211 executes a process of determining whether any sabotage of security has been recorded in the operation log included in the user input log 281 (step A140). For simplicity, the description here assumes that step A140 is executed immediately after step A130, but this is not intended to be limiting. As described in the first embodiment, step A140 may be executed independently of step A130. For example, and not limiting, step A140 may be executed periodically, for example, at a set time, separate from step A130.

[0150] If the operation log does not contain any disruptive behavior against security, the detection process ends (step A140: NO). On the other hand, if the detection unit 211 determines that the operation log contains any disruptive behavior against security, the detection unit 211 executes a process to detect the disruptive behavior (step A145).

[0151] As described above, the fourth embodiment shows that the detection process of the above-described embodiments is executed by the terminal 20 instead of the server 10. Therefore, the present embodiment also includes execution by an information processing device such as the terminal 20 without using the server 10.

[0152] Effect of Fourth Embodiment This embodiment illustrates a configuration in which an information processing device such as the terminal 20 detects disruptive behavior, which is behavior related to disrupting security set in the organization's terminal 20, by a user who uses the organization's terminal 20 (not limited to, but an example of an organization's device), by the detection unit 211 included in the control unit 21. As an example of an effect of the embodiment obtained by such a configuration, by executing the detection process by the information processing device such as the terminal 20, it becomes possible to perform the detection process on the own terminal.

[0153] Fifth Embodiment In the fifth embodiment, in addition to the components of the fourth embodiment, an information processing device such as the terminal 20 may be provided with components corresponding to the determination unit 113 and the device control unit 114 described in the second embodiment. The configuration of the fifth embodiment will be described with a focus on the differences from the fourth embodiment. FIG. 17 is a diagram illustrating an example of functions implemented by the control unit 21 of the terminal 20 according to the fifth embodiment. In addition to the components of the fourth embodiment, FIG. 17 adds a determination unit 213 and a device control unit 214. Note that the determination unit 213 may have the same function as the determination unit 113 described in the second embodiment, and the device control unit 214 may have the same function as the device control unit 114 described in the second embodiment. Furthermore, in the fifth embodiment, a communication unit 22 is provided for communication, but this is not necessarily required. In the case of processing executed only by the terminal 20, the communication unit 22 may or may not be detached.

[0154] FIG. 17 also illustrates a server 10, which includes a communication unit 14, a control unit 11, and an input / output unit 12. The control unit 11 includes a device control unit 114. When the control unit 11 receives notification information, which is an example of device control information transmitted from the device control unit 214, via the communication unit 14, the notification control unit 114 executes notification control based on the notification information. While the example described here is an example in which notification is sent to the input / output unit 12 included in the server 10, notification may be sent to another terminal 20 instead of the server 10. In this case, the information received by the server may be information restricting terminal use, as described in the second embodiment, instead of notification information. The assumed output to the input / output unit 12 of the server 10 is a case in which a notification is sent to a user who manages an organization and is located near the input / output unit 12 of the server 10, but this example is not limiting. Notification or usage restrictions may also be sent to the user's own terminal 20, rather than to another terminal 20. In this case, the device control unit 214 may be configured to control the device itself (for example, but not limited to, control of notifications and control of limiting the use of the device itself). In this case, since there is no need to communicate information for device control, the terminal 20 may or may not include the communication unit 22.

[0155] FIG. 18 is a sequence diagram illustrating the processing of the fifth embodiment. Focusing on the differences from the fourth embodiment, the processing up to step A145 is the same as that of the fourth embodiment. After step A145, the determination unit 213 determines whether or not device control is necessary based on the detection of disruptive behavior (step A160). If it is determined that device control is not necessary, the processing of the fifth embodiment is terminated (step A160: NO). On the other hand, if the determination unit 213 determines that device control is necessary (step A160: YES), the device control unit 214 of the control unit 21 executes device control (step A165). As device control, the device control unit 214 performs control such as transmitting information related to device control to the server 10 via the communication unit 22. Note that the example here is not limited to control such as transmitting information for notification.

[0156] Next, the control unit 11 of the server 10 controls the communication unit 14 to receive the device-related information transmitted via the network 30 (step S250). Then, the device control unit 114 included in the control unit 11 controls the device based on the received device-related information (step S260). Here, as a non-limiting example, the device control unit 114 controls the input / output unit to notify the input / output unit that it has detected an action that violates security, based on the information for notification.

[0157] As described above, the fifth embodiment illustrates a configuration in which an information processing device such as the terminal 20, instead of the server 10, executes the detection process and the device control process. In this manner, the process described in the second embodiment may be executed by an information processing device such as the terminal 20, instead of the server 10. While the above-described embodiment describes a configuration in which the information processing device such as the terminal 20 includes the detection unit 211, the present invention is not limited to this configuration and may include other configurations described in the third embodiment. As a non-limiting example, the control unit 21 may include a configuration corresponding to the evaluation unit 112 described in the third embodiment. Furthermore, in addition to the configuration corresponding to the evaluation unit 112, the control unit 21 may or may not include a configuration corresponding to the determination unit 213 or the device control unit 214 described above. Furthermore, the control unit 21 may include a configuration corresponding to the evaluation unit 112, and the server 10 may include a configuration corresponding to the determination unit 113 and the device control unit 114. In this case, the configuration corresponding to the evaluation unit 112 included in the control unit 21 of the terminal 20 evaluates the user of the terminal 20, and the terminal 20 transmits the evaluation result to the server 10. The server 10 may be configured to perform device control as described in embodiment 2 using the determination unit 113 and device control unit 114 based on the received evaluation results from the terminal 20. These combinations may be freely made as appropriate, and all combinations described in this embodiment are within the scope of the disclosure of this specification.

[0158] Effect of Fifth Embodiment This embodiment illustrates a configuration in which an information processing device such as the terminal 20 detects, by a user of an organization's terminal 20 (not limited to this, but an example of an organization's device), a disruptive behavior that is a behavior related to disrupting security set in the organization's terminal 20, using the detection unit 211 included in the control unit 21, and performs device control using the device control unit 114. As an example of an effect of the embodiment obtained by such a configuration, by performing device control using the information processing device such as the terminal 20, it becomes possible to perform device control at the terminal itself without going through a network.

[0159] As explained above, the embodiments may be freely combined, or any of the components of the embodiments may be modified, or any of the components may be omitted from the embodiments. The present disclosure is not limited to the above-described embodiments and modifications, and other forms conceivable within the scope of the technical idea of ​​the present disclosure are also included within the scope of the present disclosure.

[0160] Various aspects of the present disclosure are summarized below as appendices.

[0161] (Supplementary Note 1) An information processing device comprising: a detection unit that detects disruptive behavior, which is behavior related to disruption of security set in an organization's device, by a user who uses the device. (Supplementary Note 2) The information processing device according to Supplementary Note 1, wherein the disruptive behavior includes behavior of investigating the security set in the device. (Supplementary Note 3) The information processing device according to Supplementary Note 2, wherein the investigating behavior includes an operation by the user to investigate the security set in the device, or behavior of investigating an operation log for the security. (Supplementary Note 4) The information processing device according to any one of Supplements 1 to 3, wherein the disruptive behavior includes behavior of circumventing the security set in the device. (Supplementary Note 5) The information processing device according to Supplementary Note 4, wherein the circumventing behavior includes behavior for disabling the security, or behavior of deleting an operation log for performing an operation on the security. (Supplementary Note 6) The information processing device according to any one of Supplements 1 to 5, comprising: a control unit that performs control based on detection of the disruptive behavior. (Supplementary Note 7) The information processing device according to Supplementary Note 6, wherein the control unit performs the control of notifying the disruptive behavior based on detection of the disruptive behavior. (Supplementary Note 8) The information processing device according to Supplementary Note 6 or Supplementary Note 7, wherein the control unit performs the control of restricting use of the device used by the user or software of the device based on the detection of the disruptive behavior. (Supplementary Note 9) The information processing device according to any one of Supplementary Notes 1 to 8, further comprising an evaluation unit that evaluates the user based on the detection of the disruptive behavior, and the control unit controls to store the evaluation in a storage unit in association with the user. (Supplementary Note 10) The information processing device according to Supplementary Note 9, wherein the evaluation unit evaluates the user based on the disruptive behavior detected at a set time. (Supplementary Note 11) The information processing device according to Supplementary Note 9 or Supplementary Note 10, wherein the evaluation unit evaluates the user based on the disruptive behavior detected at a set time. (Supplementary Note 11) The disruptive behavior includes behavior of investigating the security set in the device and behavior of circumventing the security set in the device, and the evaluation unit performs different evaluations when the investigating behavior is detected and when the circumventing behavior is detected.(Supplementary Note 12) The information processing device according to any one of Supplementary Notes 9 to 11, wherein the detection unit detects an operation by the user on a device of the organization that is different from the disruptive behavior, and the evaluation unit performs different evaluations when the disruptive behavior is detected and when the user operates on a device of the organization that is different from the disruptive behavior. (Supplementary Note 13) The information processing device according to any one of Supplementary Notes 1 to 12, wherein the information processing device is a server, and comprises a control unit that controls transmission of information based on the detection of the disruptive behavior to a terminal of the organization. (Supplementary Note 14) The information processing device according to any one of Supplementary Notes 1 to 12, wherein the information processing device is the device used by the user. (Supplementary Note 15) The information processing device according to any one of Supplementary Notes 1 to 14, wherein the security includes security set by the organization to protect a network of the organization. (Supplementary Note 16) The information processing device according to any one of Supplementary Notes 1 to 15, wherein the security is set for a plurality of devices of the organization including the device. (Supplementary Note 17) The information processing device according to any one of Supplementary Notes 1 to 16, wherein the security includes security provided by software. (Supplementary Note 18) An information processing method for an information processing device, comprising a step in which a detection unit detects disruptive behavior, by a user of an organization's device, that is behavior related to disrupting security set in the device. (Supplementary Note 19) A program for causing a computer to execute a process for detecting disruptive behavior, by a user of an organization's device, that is behavior related to disrupting security set in the device.

[0162] The present disclosure is suitable for information processing, an information processing method, and a program.

[0163] 10 Server, 11 Control unit, 12 Input / output unit, 13 Display unit, 14 Communication I / F (communication unit), 15 Memory unit, 16 Clock unit, 20 Terminal, 21 Control unit, 22 Communication unit I / F (communication unit), 23 Input / output unit, 24 Display unit, 25 Sound input unit, 26 Sound output unit, 27 Imaging unit, 28 Memory unit, 29A Clock unit, 29B Position detection unit, 30 Network, 111 Detection unit, 112 Evaluation unit, 113 Determination unit, 114 Device control unit, 151 Security processing program, 152 User management database, 211 Detection unit, 213 Determination unit, 214 Device control unit, 281 User input log, 282 Terminal security processing program.

Claims

1. An information processing apparatus comprising a detection unit that detects an interference action, which is an action related to interference with security set in the device, by a user who uses the device of the organization.

2. The information processing apparatus according to claim 1, wherein the interference action includes an action of investigating the security set in the device.

3. The information processing apparatus according to claim 2, wherein the action of investigating includes an operation by the user to investigate the security set in the device or an action of investigating an operation log for the security.

4. The information processing apparatus according to any one of claims 1 to 3, wherein the interference action includes an action of avoiding the security set in the device.

5. The information processing apparatus according to claim 4, wherein the action of avoiding includes an action for invalidating the security or an action of deleting an operation log of an operation performed on the security.

6. The information processing apparatus according to any one of claims 1 to 5, further comprising a control unit that performs control based on detection of the interference action.

7. The information processing apparatus according to claim 6, wherein the control unit performs the control of notifying the interference action based on detection of the interference action.

8. The information processing apparatus according to claim 6 or 7, wherein the control unit performs the control of restricting use of the device used by the user or software of the device based on detection of the interference action.

9. An information processing apparatus according to any one of claims 1 to 8, further comprising an evaluation unit that evaluates the user based on detection of the interference action, and the control unit performs control of storing the evaluation in a storage unit in association with the user.

10. The information processing apparatus according to claim 9, wherein the evaluation unit evaluates the user based on the interference action detected at a set time.

11. The information processing apparatus according to claim 9 or 10, wherein the interference action includes an action of investigating the security set in the device and an action of avoiding the security set in the device, and the evaluation unit performs different evaluations when the action of investigating is detected and when the action of avoiding is detected.

12. The detection unit detects an operation of the user on the device of the organization that is different from the interfering action, and the evaluation unit performs different evaluations based on whether the interfering action is detected and an operation of the user on the device of the organization that is different from the interfering action. The information processing apparatus according to any one of claims 9 to 11.

13. The information processing apparatus is a server, and includes a control unit that performs control to transmit information based on the detection of the interfering action to a terminal of the organization. The information processing apparatus according to any one of claims 1 to 12.

14. The information processing apparatus is the device used by the user. The information processing apparatus according to any one of claims 1 to 12.

15. The security includes security for protecting the network of the organization set by the organization. The information processing apparatus according to any one of claims 1 to 14.

16. The security is set for a plurality of devices of the organization including the device. The information processing apparatus according to any one of claims 1 to 15.

17. The security includes software-based security. The information processing apparatus according to any one of claims 1 to 16.

18. An information processing method of an information processing apparatus, including a step of detecting, by a detection unit, an interfering action that is an action related to interfering with the security set for the device by a user who uses a device of an organization.

19. A program for causing a computer to execute a process of detecting an interfering action that is an action related to interfering with the security set for the device by a user who uses a device of an organization.

Citation Information

Patent Citations

  • User authority controller, user authority control method and user authority control program

    JP2006178855A

  • Fraud detection system, fraud detection device, fraud detection method, and non-volatile medium

    WO2012153746A1

  • Information processing device, information processing method, and program

    WO2015097889A1