JP4688472B2

Terminal control apparatus having a fragility detection unit

Abstract

This record has no abstract on file.

Term

Term ended

Expired 1 November 2024, 1.9 years ago.

  1. Priority and filed
  2. Granted
  3. Expired
  4. Today

8 claims: 3 independent, 5 dependent

  1. 1
    Vulnerability detection unit that detects vulnerability information related to program vulnerabilities, control content determination unit that determines the control content of the operation of the terminal device based on the vulnerability information, and the vulnerability information and the terminal device. Based on the terminal information, a terminal identification unit that identifies the terminal device affected by the vulnerability of the program and a control content notification unit that notifies the terminal device specified by the terminal identification unit of the control content. In preparation, the vulnerability information is information on a vulnerability that is a factor that hinders the proper execution of the program.At least the severity of the vulnerability and the status of its occurrenceIncluding, the vulnerability detection unitThe program identification information that identifies the program, the content of the vulnerability corresponding to the program identification information, and the occurrence status thereof are detected via the network, and an attack against the vulnerability is made based on the content of the vulnerability and the occurrence status. Judging the feasibility ofBased on the severity judgment information that associates the severity of the vulnerability with the content of the vulnerability and the feasibility of an attack against the vulnerability.The severity of the vulnerabilityA terminal control device characterized by detecting. プログラムの脆弱性に関する脆弱性情報を検出する脆弱性検出部と、 前記脆弱性情報に基づいて、端末装置の動作の制御内容を決定する制御内容決定部と、 前記脆弱性情報と前記端末装置に関する端末情報に基づいて、前記プログラムの脆弱性の影響を受ける端末装置を特定する端末特定部と、 該端末特定部により特定された端末装置に対して前記制御内容を通知する制御内容通知部とを備え、 前記脆弱性情報は、前記プログラムの適切な実行を阻害する要因である脆弱性に関する情報であって、前記脆弱性の深刻度と発生状況とを少なくとも含み、 前記脆弱性検出部は、ネットワークを介して、前記プログラムを識別するプログラム識別情報と前記プログラム識別情報に対応する前記脆弱性の内容とその発生状況を検出し、前記脆弱性の内容とその発生状況に基づいて脆弱性に対する攻撃の実現可能性を判断し、前記脆弱性の深刻度と前記脆弱性の内容と前記脆弱性に対する攻撃の実現可能性とを対応付けた深刻度判断情報に基づいて、前記脆弱性の深刻度を検出することを特徴とする端末制御装置。
  2. 4
    Any one of claims 1 to 3, wherein the control content determining unit determines at least one of the control content related to the system call, the control content related to the hardware, or the control content related to the middleware. The terminal control device according to. 前記制御内容決定部は、システムコールに関する前記制御内容、ハードウェアに関する前記制御内容、又は、ミドルウェアに関する前記制御内容の少なくとも1つを決定することを特徴とする請求項1乃至3のいずれか1項に記載の端末制御装置。
  3. 8
    Based on the step of detecting the vulnerability information related to the program vulnerability, the step of determining the control content of the operation of the terminal device based on the vulnerability information, and the step of determining the vulnerability information and the terminal information related to the terminal device. The vulnerability information includes a step of identifying a terminal device affected by the vulnerability of the program and a step of notifying the identified terminal device of the control content, and the vulnerability information is used to appropriately execute the program. Information about vulnerabilities that are the obstaclesAt least the severity of the vulnerability and the status of its occurrenceIncluding, the steps to detect the vulnerability information、 A step of detecting the program identification information that identifies the program, the content of the vulnerability corresponding to the program identification information, and the occurrence status thereof via the network. Steps to determine the feasibility of an attack against the vulnerability based on the content of the vulnerability and its occurrence status, Based on the severity judgment information that associates the severity of the vulnerability with the content of the vulnerability and the feasibility of an attack against the vulnerability.The severity of the vulnerabilityA terminal control method comprising a step of detecting. プログラムの脆弱性に関する脆弱性情報を検出するステップと、 前記脆弱性情報に基づいて、端末装置の動作の制御内容を決定するステップと、 前記脆弱性情報と前記端末装置に関する端末情報に基づいて、前記プログラムの脆弱性の影響を受ける端末装置を特定するステップと、 該特定された端末装置に対して前記制御内容を通知するステップとを備え、前記脆弱性情報は、前記プログラムの適切な実行を阻害する要因である脆弱性に関する情報であって、前記脆弱性の深刻度と発生状況とを少なくとも含み、 前記脆弱性情報を検出するステップは、 ネットワークを介して、前記プログラムを識別するプログラム識別情報と前記プログラム識別情報に対応する前記脆弱性の内容とその発生状況を検出するステップと、 前記脆弱性の内容とその発生状況に基づいて脆弱性に対する攻撃の実現可能性を判断するステップと、 前記脆弱性の深刻度と前記脆弱性の内容と前記脆弱性に対する攻撃の実現可能性とを対応付けた深刻度判断情報に基づいて、前記脆弱性の深刻度を検出するステップとを備えたことを特徴とする端末制御方法。