Automatic transaction device detecting unauthorized access and malicious program
Abstract
Problem to be solved.To suppress unauthorized access and computer virus infection via a network in an automatic transaction device such as an ATM.
Solution.An automatic transaction system connects an automatic teller machine (ATM) 1, a monitoring device 2 and a service terminal 3 via a LAN 4, and the devices can access a host computer 7 connected to a given communication line 6 such as an ISDN line via a gateway 5. The ATM 1 comprises a detection part 208, a countermeasure part 209 and a setting storage part 210. The detection part 208 detects a malicious program infecting a hard disk of the ATM 1 and an unauthorized access via the LAN 4. If any of them is detected, the countermeasure part 209 follows settings stored in the setting storage part 210 to, for example, shut down the network, print on journal paper and stop a customer transaction.
Copyright (C)2005,JPO&NCIPI
Term
Term ended
Projected expiry passed 2 June 2023, 3.3 years ago.
- Priority and filed
- Published
- Projected expiry
- Today
8 claims: 2 independent, 6 dependent
- 1At least an automated teller machine connected to a network, a control unit that controls the automated teller machine based on a predetermined control program, unauthorized access via the network, and an automated teller machine existing in the automated teller machine. An automated teller machine comprising a detection unit that detects one of them and a countermeasure unit that controls the operation of the automated teller machine when the unauthorized access or program is detected based on a predetermined setting. ネットワークに接続される自動取引装置であって、所定の制御プログラムに基づき前記自動取引装置の制御を行う制御部と、前記ネットワークを介した不正アクセスと前記自動取引装置内に存在する不正プログラムの少なくとも一方を検知する検知部と、前記不正アクセスまたは不正プログラムが検知された場合の前記自動取引装置の動作を所定の設定に基づき制御する対策部と、を備える自動取引装置。
- 8A control method for an automated teller machine connected to a network, wherein the automated teller machine includes a control unit that controls the automated teller machine based on a predetermined control program, and unauthorized access via the network and the automated teller machine. A control method including a step of detecting at least one of fraudulent programs existing in the trading device and a step of controlling the operation of the automated teller machine when the fraudulent access or the fraudulent program is detected based on a predetermined setting. .. ネットワークに接続される自動取引装置の制御方法であって、前記自動取引装置は、所定の制御プログラムに基づき該自動取引装置の制御を行う制御部を備え、前記ネットワークを介した不正アクセスと前記自動取引装置内に存在する不正プログラムの少なくとも一方を検知する工程と、前記不正アクセスまたは不正プログラムが検知された場合の前記自動取引装置の動作を所定の設定に基づき制御する工程と、を含む制御方法。
Independent claims2
101 paragraphs in 1 section, as filed
【0001】
[Technical field to which the invention belongs]
The present invention relates to an automated teller machine that detects unauthorized access and unauthorized programs.
【0002】
[Conventional technology]
At financial institutions, automated teller machines (hereinafter referred to as ATMs) are used for deposits and withdrawals to customers. In recent years, ATMs have a built-in computer equipped with a CPU, RAM, hard disk, etc., and in addition to reading and writing recording media such as flexible disks and CD-ROMs, they also use networks using general-purpose protocols such as TCP / IP. Communication is also possible (see, for example, Patent Document 1). Such recent ATMs are often designed by applying general-purpose personal computer technology.
【0003】
By the way, in the field of personal computers, unauthorized access from a third party via a network and computer virus infection have become problems. These problems are becoming more serious with the spread of the Internet, and the damage is increasing year by year.
【0004】
[Patent Document 1]
Japanese Unexamined Patent Publication No. 2001-16273 [0005]
[Problems to be Solved by the Invention]
As described above, ATMs in recent years may use general-purpose personal computer technology, and therefore ATMs may also be subject to unauthorized access or computer virus infection. Such issues are not limited to ATMs, but are common to all automatic trading devices designed by applying personal computer technology, such as various vending machines and ticket vending machines.
【0006】
The present invention has been made in view of such a problem, and an object of the present invention is to suppress unauthorized access and computer virus infection via a network in an automated teller machine represented by an ATM.
【0007】
[Means for solving problems]
In order to solve the above problems, the automated teller machine of the present invention was configured as follows. That is, an automated teller machine connected to a network, a control unit that controls the automated teller machine based on a predetermined control program, unauthorized access via the network, and an unauthorized program existing in the automated teller machine. It is a gist to include a detection unit that detects at least one of the above, and a countermeasure unit that controls the operation of the automatic teller machine when the unauthorized access or the unauthorized program is detected based on a predetermined setting.
【0008】
With an automated teller machine having such a configuration, it is possible to detect unauthorized access via a network or an unauthorized program such as a computer virus and take countermeasures against it.
【0009】
The predetermined setting may be, for example, a setting that disables a transaction by a customer when the unauthorized access or an unauthorized program is detected. By doing so, it is possible to suppress leakage of customer account information and falsification of transaction details.
【0010】
Further, when the unauthorized access or the unauthorized program is detected, the communication to the network may be blocked. By doing so, it is possible to suppress the spread of the malicious program to the outside and the unauthorized access to other devices by using the automated teller machine as a stepping stone.
【0011】
Further, when the unauthorized access or the unauthorized program is detected, the detection may be set to be displayed on a predetermined display unit. The predetermined display unit is, for example, a display device that provides an operation screen to a customer, a display device for maintenance provided on the back side of an automated teller machine, or the like. By doing so, it is possible to promptly notify that an unauthorized access or an unauthorized program has been detected.
【0012】
Further, in the automated teller machine having the above configuration, a monitoring device for monitoring the operation of the automated teller machine is connected to the automated teller machine, and when the unauthorized access or the unauthorized program is detected, the said. It may be set to notify the monitoring device of the detection. The monitoring device is a device for the administrator of the automated teller machine to check the operating status of the automated teller machine. Therefore, with such a setting, it is possible to promptly notify the administrator that an unauthorized access or an unauthorized program has been detected.
【0013】
Further, the automated teller machine having the above configuration includes a journal printing unit for printing the contents of transaction processing executed by the automated teller machine on journal paper, and when the unauthorized access or program is detected, the detection is performed. It may be set to print the fact that it has been done on the journal paper. In addition, the journal paper may record the details of the measures taken when an unauthorized access or an unauthorized program is detected, and as a result, all communication records after the detection of the unauthorized access or the unauthorized program. By doing so, for example, even if the electronic log file recorded in the automated teller machine is lost by a fraudulent program, the record can be surely left. In addition, if such a record is made into a journal paper, it can be used as a reference for recovery processing and countermeasures after infection with an unauthorized program.
【0014】
Further, in the automated teller machine having the above configuration, the detection unit may perform the detection when the automated teller machine is activated. By doing so, it is possible to reduce the hardware load of the automated teller machine during normal business.
【0015】
The various aspects described above in the present invention can be appropriately combined or partially omitted. In addition to the above-described configuration as an automated teller machine, the present invention also includes, for example, a control method for an automated teller machine, a computer program for controlling the automated teller machine, a computer-readable recording medium on which such a computer program is recorded, and the like. Can also be configured as. In any of the configurations, each of the above-described aspects can be appropriately applied. As the recording medium that can be read by a computer, for example, various media such as a flexible disk, a CD-ROM, a DVD-ROM, a magneto-optical disk, a memory card, and a hard disk can be used.
【0016】
BEST MODE FOR CARRYING OUT THE INVENTION
Hereinafter, embodiments of the present invention will be described in the following order based on examples. A. Outline configuration of automated teller machine: B. Hardware configuration of automated teller machine: C. Software configuration of automated teller machine: D. Detection processing: [0017]
A. Schematic configuration of an automated trading system: FIG. 1 is an explanatory diagram showing a schematic configuration of an automated trading system as an example. The automatic teller machine (ATM) 1 and the monitoring device 2 and the business terminal 3 are connected by LAN4, and these devices are connected to a predetermined ISDN line or the like via a gateway 5. You can access the host computer 7 connected to the communication line 6 of. TCP / IP was used as the network protocol used in LAN4.
【0018】
The ATM1 is a device for depositing / withdrawing cash, transferring money, etc., and the monitoring device 2 is a device for monitoring the operating state of the ATM1. If multiple ATMs are installed, monitor all ATMs. The business terminal 3 is a computer terminal used by the staff of a store in which an automatic trading system is installed.
【0019】
B. Hardware configuration of automated teller machine: ATM1 is equipped with various mechanical units as shown by the broken line in the figure. The card handling mechanism 230 is a mechanism for reading a customer's account number or the like from an inserted cash card. The passbook handling mechanism 240 is a mechanism for reading information such as an account number and a balance recorded in a passbook, and also prints transaction details.
【0020】
The touch panel 270 is an interface for displaying a menu for transactions and inputting operations from customers. In this embodiment, a touch panel is used, but it may be configured by a combination of a display and a push button switch.
【0021】
The banknote handling mechanism 260 is a mechanism for exchanging and receiving banknotes with and from customers. At the time of deposit, the banknotes inserted by the customer are identified, sorted by denomination and stored. At the time of withdrawal, the amount of banknotes instructed by the customer is withdrawn and delivered to the customer through the deposit / withdrawal port.
【0022】
The contents of the transaction with the customer are sequentially printed on a predetermined journal paper by the journal printing mechanism 280.
【0023】
FIG. 2 is an explanatory view showing the back surface of the ATM 1. As shown, the ATM1 has a maintenance panel 250 on the back door, which serves as an interface for the administrator to perform maintenance. The maintenance panel is also composed of a touch panel, which displays the operating status of each unit and accepts input of settings related to the operation of each unit.
【0024】
The ATM1 may include various units in addition to the mechanical units shown above. For example, it may be provided with a coin handling mechanism for depositing and withdrawing coins, and may be provided with a recording medium handling mechanism for inputting and outputting information to and from flexible discs, CD-ROMs, DVDs, and magneto-optical discs. You may.
【0025】
The operation of each unit is controlled by the control unit 200. The control unit 200 is configured as a computer having a network interface such as a CPU, a memory, a hard disk, and 10BASE-T.
【0026】
C. Software configuration of automated teller machine: A control program for controlling ATM1 is installed on the hard disk of control unit 200. The CPU uses memory as a work area to execute this program. At the bottom of the figure, various functional parts realized by software by such a program are shown.
【0027】
The main control unit 201 executes various transaction processes while controlling each of the illustrated functional units according to an instruction from the customer. The transaction process includes a process executed by the ATM 1 alone and a process executed while communicating with the host computer 7 via the communication unit 202.
【0028】
The touch panel control unit 203 controls the operation of the touch panel 270, displays information, and inputs operations from the customer. The card mechanism control unit 204 controls the card handling mechanism 230, and the passbook mechanism control unit 205 controls the passbook handling mechanism 240.
【0029】
The maintenance panel control unit 206 controls the maintenance panel 250, displays the operating status of the ATM1, and receives operation settings based on the operation of maintenance personnel. The journal management unit 207 prints the transaction details on the journal paper. For example, the name, account number, transaction date and time, transaction amount, etc. of the customer who made the transaction are printed on the journal paper.
【0030】
The ATM1 of this embodiment is provided with a detection unit 208, a countermeasure unit 209, and a setting storage unit 210 as shown in order to suppress unauthorized access via a network and infection of an unauthorized program such as a computer virus.
【0031】
The detection unit 208 detects unauthorized access from the outside by monitoring the communication unit 202. Unauthorized access may be received from, for example, a business terminal 3 or a terminal illegally connected to LAN 4. In TCP / IP-based communication, the port used for each application is predetermined, so if there is access to a port that is not being used, it can be detected that there was unauthorized access. In addition, if the IP address and MAC address of a device that can access ATM1 are registered in advance, access from an unregistered device can be detected as unauthorized access.
【0032】
The detection unit 208 further detects a malicious program that has infected the hard disk that stores the control program. The malicious program may be infected from a recording medium such as a business terminal 3 or a flexible disk. The malicious program is detected by comparing the program existing in the hard disk with a predetermined pattern file. The pattern file can be updated regularly via a network, a flexible disk, or the like. When the detection unit 208 detects a malicious program, it also removes the malicious program.
【0033】
When the detection unit 208 detects an unauthorized access or an unauthorized program, the detection unit 208 notifies the countermeasure unit 209 of a predetermined message. In this embodiment, the following four types of messages are notified. (1) "Unauthorized access detection message" to notify that unauthorized access has been detected. (2) "Illegal program detection message" to notify that a malicious program has been detected. (3) "Illegal program removal message" indicating that the malicious program has been successfully removed. (4) "Unauthorized program removal message" indicating that the malicious program could not be removed.
【0034】
The operation of ATM1 executed in response to the above message is set in the setting storage unit 210. The countermeasure unit 209 controls the operation of the ATM1 when an unauthorized access or an unauthorized program is detected by referring to the setting storage unit 210. The settings recorded in the setting storage unit 210 can be flexibly changed by using the maintenance panel 250.
【0035】
FIG. 3 is an explanatory diagram showing a setting example recorded in the setting storage unit 210. In the illustrated number, 0 indicates that the operation is not performed, and 1 to 5 indicate the priority for executing the operation. According to such a setting example, for example, when an unauthorized access detection message is received from the detection unit 208, the countermeasure unit 209 prints the fact on the journal paper and notifies the monitoring device. In this case, the contents to be printed on the journal paper include, for example, the date and time when the unauthorized access was received, the port number, the IP address of the unauthorized access source, and the like.
【0036】
In addition, according to the setting example of FIG. 3, when a malicious program detection message is received from the detection unit 208, the countermeasure unit 209 prints on the journal paper that the malicious program has been detected. When the malicious program removal message is received, the fact that the malicious program has been removed is printed on the journal paper. When a malicious program removal impossible message is received, (1) printing on a journal sheet indicating that the malicious program removal failed, (2) reporting to monitoring device 2, (3) network interruption, (4) Stop handling ATM1 and (5) display on maintenance panel 250.
【0037】
FIG. 4 is an explanatory diagram showing a display example of the maintenance panel 250. By displaying as shown in the figure, it is possible to notify the maintenance personnel and the like that the malicious program could not be removed. Further, FIG. 5 is an explanatory diagram showing a display example on the touch panel 270 when the handling of the ATM1 is stopped. In this way, by displaying a message such as "I can't handle it right now" and stopping the reception of operations, it is possible to disable the operation from the customer.
【0038】
D. Detection processing: FIG. 6 is a flowchart of the detection processing executed when ATM1 is started. The detection process shown in the figure is assumed to be executed according to the setting example shown in FIG. First, the ATM1 searches for malicious programs when the power is turned on (step S10). If no malicious program is detected (step S11: No), then unauthorized access is detected (step S12). When an unauthorized access is detected (step S12: Yes), it is printed on the journal paper (step S14), and further notified to the monitoring device 2 (step S15). If no unauthorized access is detected (step S13: No), the above steps S14 and S15 are skipped. Then, the normal transaction business process is executed (step S16).
【0039】
As described above, when the malicious program is not detected, ATM1 executes the normal transaction business processing even if the unauthorized access is detected. This is because even if there is unauthorized access, the ATM1 is provided with sufficient measures against unauthorized access, such as stopping unnecessary service applications and strict file access restrictions. However, of course, even when an unauthorized access is detected, it may be displayed on the touch panel 270 or the maintenance panel 250, the network may be blocked, or the like, and the processing may be terminated without performing the normal transaction business processing.
【0040】
If a malicious program is detected in step S10 above (step S11: Yes), the fact that the malicious program has been detected is printed on the journal paper (step S17), and the malicious program is tried to be removed (step S18). If the removal is successful (step S19: Yes), the success is printed on the journal paper (step S20), and the process proceeds to step S12 above.
【0041】
If the malicious program could not be removed in step S18 (step S19: No), first, the fact that the program could not be removed is printed on the journal paper (step S21). Then, the monitoring device 2 is notified (step S22), and the network is cut off (step S23). By blocking the network, it is possible to prevent the spread of malicious programs to other devices. Next, the touch panel 270 indicates that the transaction is suspended (step S24), and the transaction is stopped. Finally, the maintenance panel 250 displays that a malicious program has been detected (step S25). As described above, if the malicious program cannot be removed, ATM1 terminates the process without performing normal trading operations.
【0042】
The detection process described above is to be executed when ATM1 is started. This is to reduce the CPU load during normal transaction business processing. However, if the processing power of the CPU is sufficient, the detection process may be executed constantly or periodically even during transaction business processing. Of course, the processing may be performed at a preset time.
【0043】
Although the examples of the present invention have been described above, it goes without saying that the present invention is not limited to these examples, and various configurations can be adopted without departing from the spirit of the present invention. For example, the functions realized by software may be realized by hardware. Further, in this embodiment, the automatic teller machine has been described as an automated teller machine, but a device for issuing various certificates at a public institution, a ticket vending machine, various vending machines, etc. are applied as the automatic teller machine. You may.
【0044】
[Effect of the invention]
According to the present invention, since the automated teller machine itself can detect unauthorized access and unauthorized programs, it is possible to suppress leakage, falsification, and the like of important data and programs inside the automated teller machine. In addition, since the information is printed on the journal paper when an unauthorized access or an unauthorized program is detected, recovery processing or countermeasures can be taken by using the information after the infection of the unauthorized program.
[Simple explanation of drawings]
FIG. 1 is an explanatory diagram showing a schematic configuration of an automatic trading system as an embodiment.
FIG. 2 is an explanatory view showing the back surface of the ATM1.
FIG. 3 is an explanatory diagram showing a setting example recorded in the setting storage unit 210.
FIG. 4 is an explanatory diagram showing a display example of the maintenance panel 250.
FIG. 5 is an explanatory diagram showing a display example on a touch panel when the handling of ATM1 is stopped.
FIG. 6 is a flowchart of a detection process executed when the ATM1 is started.
[Explanation of symbols]
1 ... ATM ATM 2 ... Monitoring device 3 ... Business terminal 4 ... LAN 5 ... Gateway 6 ... Communication line 7 ... Host computer 200 ... Control unit 201. .. Main control unit 202 ... Communication unit 203 ... Touch panel control unit 204 ... Card mechanism control unit 205 ... Book mechanism control unit 206 ... Maintenance panel control unit 207 ... Journal management unit 208 ... Detection unit 209 ... Countermeasure unit 210 ... Setting storage unit 230 ... Card handling mechanism 240 ... Passbook handling mechanism 250 ... Maintenance panel 260 ... Bill handling mechanism 270 ... Touch panel 280 ... Journal printing mechanism
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| JP2011139152A | Cited by | Japan | Examiner |
| WO2018100777A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| JP2012238254A | Cited by | Japan | Search report |
| JP2021099729A | Cited by | Japan | Search report |
| US8689057B2 | Cited by | United States of America | Applicant |
| US10891834B2 | Cited by | United States of America | Applicant |
| CN102779370A | Cited by | China | Search report |
| US9178665B2 | Cited by | United States of America | Applicant |
| JP2017062669A | Cited by | Japan | Search report |
| JP2018092269A | Cited by | Japan | Search report |
| JP2017062669A | Cited by | Japan | Search report |
| JP2011113144A | Cited by | Japan | Examiner |
| WO2012157199A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
2 priority claims, no other members on record
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 2003156197 | Japan | A | |
| JP20030156197 | – | – | – |
17 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of no payment of annual feesLAPS | LAPS | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Certificate of patent or registration of utility modelR150 | R150 | |
| First payment of annual fees (during grant procedure)A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)A01 | A01 | |
| Written decision to grant a patent or to grant a registration (utility model)A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Written amendmentA521 | A521 | |
| Notification of reasons for refusalA131 | A131 | |
| Written amendmentA521 | A521 | |
| Notification of reasons for refusalA131 | A131 | |
| Report on retrievalA977 | A977 | |
| Written request for application examinationA621 | A621 | |
| Notification of change in applicantA711 | A711 |
Numbers
- Publication
- 2004362012
- Publication, DOCDB
- 2004362012
- Publication, EPODOC
- JP2004362012
- Application
- 156197
- Application, DOCDB
- 2003156197
- Application, EPODOC
- JP20030156197
Titles3
- Japanese
- 不正アクセスや不正プログラムを検知する自動取引装置
- English
- An automated teller machine that detects unauthorized access and programs
- English
- AUTOMATIC TRANSACTION DEVICE DETECTING UNAUTHORIZED ACCESS AND MALICIOUS PROGRAM
Classification
- IPC, 2
- G07D9 00
- G07F19 00