Terminal control apparatus having a fragility detection unit
Abstract
This record has no abstract on file.
Term
Term ended
Expired 1 November 2024, 1.9 years ago.
- Priority and filed
- Granted
- Expired
- Today
8 claims: 3 independent, 5 dependent
- 1Vulnerability detection unit that detects vulnerability information related to program vulnerabilities, control content determination unit that determines the control content of the operation of the terminal device based on the vulnerability information, and the vulnerability information and the terminal device. Based on the terminal information, a terminal identification unit that identifies the terminal device affected by the vulnerability of the program and a control content notification unit that notifies the terminal device specified by the terminal identification unit of the control content. In preparation, the vulnerability information is information on a vulnerability that is a factor that hinders the proper execution of the program.At least the severity of the vulnerability and the status of its occurrenceIncluding, the vulnerability detection unitThe program identification information that identifies the program, the content of the vulnerability corresponding to the program identification information, and the occurrence status thereof are detected via the network, and an attack against the vulnerability is made based on the content of the vulnerability and the occurrence status. Judging the feasibility ofBased on the severity judgment information that associates the severity of the vulnerability with the content of the vulnerability and the feasibility of an attack against the vulnerability.The severity of the vulnerabilityA terminal control device characterized by detecting. プログラムの脆弱性に関する脆弱性情報を検出する脆弱性検出部と、 前記脆弱性情報に基づいて、端末装置の動作の制御内容を決定する制御内容決定部と、 前記脆弱性情報と前記端末装置に関する端末情報に基づいて、前記プログラムの脆弱性の影響を受ける端末装置を特定する端末特定部と、 該端末特定部により特定された端末装置に対して前記制御内容を通知する制御内容通知部とを備え、 前記脆弱性情報は、前記プログラムの適切な実行を阻害する要因である脆弱性に関する情報であって、前記脆弱性の深刻度と発生状況とを少なくとも含み、 前記脆弱性検出部は、ネットワークを介して、前記プログラムを識別するプログラム識別情報と前記プログラム識別情報に対応する前記脆弱性の内容とその発生状況を検出し、前記脆弱性の内容とその発生状況に基づいて脆弱性に対する攻撃の実現可能性を判断し、前記脆弱性の深刻度と前記脆弱性の内容と前記脆弱性に対する攻撃の実現可能性とを対応付けた深刻度判断情報に基づいて、前記脆弱性の深刻度を検出することを特徴とする端末制御装置。
- 4Any one of claims 1 to 3, wherein the control content determining unit determines at least one of the control content related to the system call, the control content related to the hardware, or the control content related to the middleware. The terminal control device according to. 前記制御内容決定部は、システムコールに関する前記制御内容、ハードウェアに関する前記制御内容、又は、ミドルウェアに関する前記制御内容の少なくとも1つを決定することを特徴とする請求項1乃至3のいずれか1項に記載の端末制御装置。
- 8Based on the step of detecting the vulnerability information related to the program vulnerability, the step of determining the control content of the operation of the terminal device based on the vulnerability information, and the step of determining the vulnerability information and the terminal information related to the terminal device. The vulnerability information includes a step of identifying a terminal device affected by the vulnerability of the program and a step of notifying the identified terminal device of the control content, and the vulnerability information is used to appropriately execute the program. Information about vulnerabilities that are the obstaclesAt least the severity of the vulnerability and the status of its occurrenceIncluding, the steps to detect the vulnerability information、 A step of detecting the program identification information that identifies the program, the content of the vulnerability corresponding to the program identification information, and the occurrence status thereof via the network. Steps to determine the feasibility of an attack against the vulnerability based on the content of the vulnerability and its occurrence status, Based on the severity judgment information that associates the severity of the vulnerability with the content of the vulnerability and the feasibility of an attack against the vulnerability.The severity of the vulnerabilityA terminal control method comprising a step of detecting. プログラムの脆弱性に関する脆弱性情報を検出するステップと、 前記脆弱性情報に基づいて、端末装置の動作の制御内容を決定するステップと、 前記脆弱性情報と前記端末装置に関する端末情報に基づいて、前記プログラムの脆弱性の影響を受ける端末装置を特定するステップと、 該特定された端末装置に対して前記制御内容を通知するステップとを備え、前記脆弱性情報は、前記プログラムの適切な実行を阻害する要因である脆弱性に関する情報であって、前記脆弱性の深刻度と発生状況とを少なくとも含み、 前記脆弱性情報を検出するステップは、 ネットワークを介して、前記プログラムを識別するプログラム識別情報と前記プログラム識別情報に対応する前記脆弱性の内容とその発生状況を検出するステップと、 前記脆弱性の内容とその発生状況に基づいて脆弱性に対する攻撃の実現可能性を判断するステップと、 前記脆弱性の深刻度と前記脆弱性の内容と前記脆弱性に対する攻撃の実現可能性とを対応付けた深刻度判断情報に基づいて、前記脆弱性の深刻度を検出するステップとを備えたことを特徴とする端末制御方法。
Independent claims3
68 paragraphs, as filed
The present invention relates to a terminal control device for controlling a terminal device and a terminal control method.
Program vulnerabilities affect the entire system of terminal devices. Therefore, various countermeasures against vulnerabilities have been proposed conventionally. For example, there is a technique in which the operating system of a terminal device forcibly restricts access rights to valuable information such as files and hardware resources such as network interfaces to programs that may have vulnerabilities.
Program vendors, experts, and user groups are also discovering and disclosing program vulnerabilities. However, it may take some time for vendors to develop a patch that fixes the target program after the vulnerability of the program is disclosed.
Therefore, along with the discovered vulnerabilities, emergency measures for dealing with the vulnerabilities are often disclosed. However, it is difficult for many users to always check all of the information about program vulnerabilities, even if they are disclosed. In addition, even if the user obtains the information, he / she lacks specialized knowledge and cannot take appropriate measures, and can judge whether the information affects his / her terminal device and how dangerous it is. It may not be possible. Further, even after the patch has been developed, the user of the terminal device may leave the vulnerability unattended without introducing the patch to the terminal device.
Therefore, a technique has been proposed in which the operation of a program is automatically restricted without the user being aware of it, and the damage caused by the vulnerability is reduced. For example, when the operating status of program A is monitored and an abnormal operation of program A is detected, program A during abnormal operation is forcibly terminated, and program B operating in conjunction with program A is also terminated normally. However, a terminal device that restarts the operating system has been proposed (see, for example, Patent Document 1).<patcit num="1"><text>Japanese Unexamined Patent Publication No. 2001-229032</text></patcit>
<p> However, in a terminal device that monitors the operating state of a program and forcibly terminates it when an abnormal operation is detected, the damage caused by the vulnerability of the program may have already spread when the abnormal operation is detected. Therefore, even if the program was forcibly terminated after the abnormal operation was detected, it was not an effective countermeasure against the vulnerability.</p><p> Further, since the terminal device detects the abnormal operation by determining whether or not it matches the known abnormal operation pattern and whether or not it deviates from the normal operation, the terminal device causes an unknown abnormal operation. On the other hand, it may not be an effective means. Further, the terminal device can only forcibly terminate the program when it detects an abnormal operation, and cannot flexibly control it.</p><p> Therefore, an object of the present invention is to swiftly and flexibly take appropriate measures for a terminal device that needs to deal with a program vulnerability.</p>
<p> The terminal control device according to the present invention has a vulnerability detection unit that detects vulnerability information related to a program vulnerability, a control content determination unit that determines the control content of the operation of the terminal device based on the vulnerability information, and a vulnerability. Based on the sex information and the terminal information related to the terminal device, the terminal identification unit that identifies the terminal device affected by the vulnerability of the program and the control content notification that notifies the control content to the terminal device specified by the terminal identification unit. It is characterized by having a part.</p><p> According to such a terminal control device, the vulnerability information of the program can be detected, and the control content of the operation of the terminal device can be determined according to the detected vulnerability information. Therefore, the terminal control device can flexibly control the operation of the terminal device as a countermeasure against the vulnerability. Moreover, when the vulnerability information of the program is detected, the terminal control device can identify the terminal device affected by the vulnerability and notify the control content. Therefore, the terminal control device can quickly and flexibly take appropriate measures for the terminal device that needs to deal with the vulnerability of the program.</p><p> It is preferable that the vulnerability detection unit verifies the validity of the detected vulnerability information. Then, it is preferable that the control content determination unit determines the control content based on the vulnerability information determined to be valid by the verification. According to this, the terminal control device can control the terminal device using only the vulnerability information determined to be legitimate, and can surely perform appropriate control on the terminal device.</p><p> It is preferable that the terminal specifying unit identifies the terminal device whose program has been updated, and the control content determining unit determines the control content according to the program update. According to this, the terminal control device can flexibly control the terminal device according to the update of the program.</p><p> It is preferable that the control content determination unit determines at least one of the control content related to the system call, the control content related to the hardware, or the control content related to the middleware. According to this, the terminal control device can flexibly control the operation of the terminal device related to system calls, hardware, and middleware.</p><p> Vulnerability information includes the content of the vulnerability, the situation in which the vulnerability occurs, the operating system affected by the vulnerability, the hardware affected by the vulnerability, the middleware affected by the vulnerability, or the severity of the vulnerability. It is preferably at least one of. According to this, the terminal controller appropriately controls the content according to the content of the vulnerability, the situation in which the vulnerability occurs, the operating system and hardware affected by the vulnerability, the middleware, and the severity of the vulnerability. Be able to make decisions and properly identify the affected terminals.</p><p> The terminal information includes the operating system of the terminal device, the hardware of the terminal device, the middleware of the terminal device, the program of the terminal device, the update time of the program in the terminal device, the notification time of the control content to the terminal device, or the notification. It is preferable that it is at least one of the controlled contents. According to this, the terminal control device is vulnerable according to the operating system and hardware of the terminal device, middleware, the program of the terminal device, the update time of the program in the terminal device, the notification time of the control content to the terminal device, and the like. It is possible to appropriately identify the terminal device affected by sex.</p><p> The terminal control method according to the present invention detects vulnerability information related to a program vulnerability, determines the control content of the operation of the terminal device based on the vulnerability information, and is based on the vulnerability information and the terminal information related to the terminal device. Therefore, the terminal device affected by the vulnerability of the program is identified, and the control content is notified to the specified terminal device.</p>
<p> As described above, according to the present invention, it is possible to quickly and flexibly take appropriate measures for a terminal device that needs to deal with a program vulnerability.</p>
As shown in FIG. 1, the terminal control device 100 includes a vulnerability information storage unit 110, a terminal information storage unit 120, a policy determination unit 130, a terminal identification unit 140, a policy notification unit 150, and a vulnerability detection unit. It is equipped with 160 and a terminal information registration unit 170. The terminal control device 100 controls the operation of the terminal device 200 by using the control content (hereinafter referred to as control policy) of the operation of the terminal device, which is how to control the operation of the terminal device. The terminal control device 100 and the terminal device 200 are connected via, for example, a network 400.
Vulnerability information is stored in the vulnerability information storage unit 110. Vulnerability information is information about a program's vulnerability. Program vulnerabilities are factors that exist in a program and prevent it from executing properly. For example, vulnerabilities include data transfer to unintended processes, devices, and means, buffer overflows that are often found in various programs related to operating systems (OS) and applications, and program code from external devices that poses a security problem. There is execution etc. The vulnerability is caused by, for example, a coding bug.
Figure 2 shows an example of the vulnerability information storage unit 110. The vulnerability information storage unit 110 stores the update date of the vulnerability information, the program identification information of the program having the vulnerability, the vulnerability information, and the like in association with each other.
The program identification information is information that identifies the program. The program identification information includes, for example, a program name, a program version, and the like. As shown in FIG. 2, the program includes, for example, a program for executing processing related to a browser, processing related to e-mail, processing related to a scheduler, processing related to a game, and the like.
Vulnerability information includes, for example, the content of the vulnerability, the situation in which the vulnerability occurs (hereinafter referred to as the "occurrence situation"), the operating system affected by the vulnerability (hereinafter referred to as the "target system"), and the impact of the vulnerability. There are the hardware to be received (hereinafter referred to as "target hardware"), the middleware affected by the vulnerability (hereinafter referred to as "target middleware"), the severity of the vulnerability, and the like.
The contents of the vulnerability include the hardware resources of the terminal device 200 (hereinafter referred to as "terminal resources"), the transfer of data such as files to unintended processes, devices, and means, and the terminal device 200. Arbitrary program code may be executed, or arbitrary program code of the terminal device 200 may be executed by an external device via the network 400.
Occurrence status includes data reception and data transmission in interprocess communication, data writing and reading of files and the like, processing execution, network use, execution of a specific program, and the like. When a specific program is executed, it means that the vulnerability appears when it is linked with the specific program.
The target system can be represented by using system identification information that can identify the operating system, such as the system name of the operating system (OS) and its version. Further, the target hardware and the target middleware can also be represented by using a hardware name, a middleware name, or the like.
The severity of the vulnerability indicates the degree of influence that the vulnerability has on the terminal device 200. For example, the severity of the vulnerability may be a security severity or a continuous operation severity.
For example, in the vulnerability information storage unit 110, the update date "2004/08/26", the program name "Browser_1", the version "2.4", and the occurrence status "Socket for Mailer_1" are used for interprocess communication. "When sending data in" and the content of the vulnerability "There is a risk that the sent data will be sent to a specific website", the target systems "A (ver.1)" and "B (ver.2)", Severity "4" is associated and accumulated. In Fig. 2, the severity is set in 5 levels, with "1" being the lowest and "5" being the highest.
Vulnerability detection unit 160 detects vulnerability information. The vulnerability detection unit 160 can detect the vulnerability information by receiving the program identification information and the vulnerability information from the terminal device 200 or the server 300 via the network 400, for example. Server 300 provides vulnerability information. The server 300 is provided, for example, by a security expert, an organization of users who actually use the program, a vendor who developed and provided the program, and the like.
Further, the vulnerability detection unit 160 receives the program identification information and the operating status of the program from the terminal device 200 via the network 400, for example. Then, the vulnerability detection unit 160 can determine the vulnerability from the received operating status and detect the vulnerability information.
Further, the vulnerability detection unit 160 can determine other vulnerability information based on the received vulnerability information and detect the vulnerability information. For example, the vulnerability detection unit 160 can detect the severity based on the content of the vulnerability and the feasibility of an attack against the vulnerability.
For example, the vulnerability detection unit 160 can set the severity determination information in which the severity as shown in FIG. 3, the content of the vulnerability, and the feasibility of the attack are associated with each other. The vulnerability detection unit 160 can determine the feasibility of an attack based on the content and occurrence status of the vulnerability, the target system, the target hardware, the target middleware, and the like.
Vulnerability detection unit 160 can judge the severity by comparing the content of the vulnerability, the feasibility of the attack, and the severity judgment information. For example, the vulnerability detection unit 160 determines that the severity is "1" when the feasibility is low even if the content of the same vulnerability is "consumption of terminal resources", and when the feasibility is high. Judges that the severity is "3". In this way, the severity can be set higher in proportion to the feasibility.
In addition, the vulnerability detection unit 160 determines that the severity is "3" when the content of the vulnerability is "consumption of terminal resources" even if the feasibility is "high", and the content of the vulnerability is "3". If is "Send a specific file", the severity is judged to be "4". In this way, the severity can be set higher, for example, for contents that are more affected by security problems and malfunctions.
Furthermore, the vulnerability detection unit 160 determines the feasibility when the content of the vulnerability is such that the content of the vulnerability is "execution of arbitrary program code via the network" and the content has a very large security problem. You may judge that the severity is the highest value "5" without doing so.
The vulnerability detection unit 160 stores the detected vulnerability information in the vulnerability information storage unit 110. The vulnerability detection unit 160 stores the update date of the vulnerability information, the program identification information, and the vulnerability information in association with each other in the vulnerability information storage unit 110.
It is preferable that the vulnerability detection unit 160 verifies the validity of the detected vulnerability information. For example, there is a risk that the terminal device 200 or server 300 itself, which is the source of the vulnerability information or program operating status, is unreliable, or the information is falsified in the transmission path to the terminal control device 100 of the vulnerability information or program operating status. There is a risk that it will end up. Therefore, the vulnerability detection unit 160 can verify the validity of the vulnerability information and store only the vulnerability information that is determined to be valid in the vulnerability information storage unit 110.
For example, the vulnerability detection unit 160 determines the content of a possible vulnerability based on the received program identification information, the target system, the target hardware, or the target middleware included in the vulnerability information, and the occurrence status. Generate. Then, the vulnerability detection unit 160 can determine whether or not the content of the received vulnerability matches the content of the generated vulnerability and can actually occur, and can verify the validity.
Further, when the vulnerability detection unit 160 receives the operation status of the program, the vulnerability detection unit 160 can verify the validity of the vulnerability information detected from the operation status by verifying the validity of the program. Similarly, in this case as well, the vulnerability detection unit 160 can verify the validity of the received program identification information by determining whether or not the received operation status can occur based on the received program identification information and the operation status.
The terminal information storage unit 120 stores terminal information related to the terminal device. The terminal information includes information for identifying the terminal device (hereinafter referred to as "terminal identification information"), an operating system included in the terminal device, hardware provided in the terminal device, middleware provided in the terminal device, a program possessed by the terminal device, and a terminal. There are the update time of the program in the device, the notification time of the control content (control policy) to the terminal device, the notified control content (control policy), and the like. The terminal identification information includes a terminal device number, a terminal device name, and the like.
FIG. 4 shows an example of the terminal information storage unit 120. The terminal information storage unit 120 contains the update date of the terminal information, the name of the terminal device, the program update date, the system identification information of the operating system included in the terminal device, the program name and the program version of the program of the terminal device, and the like. The policy notification date and the notified control policy are stored in association with each other.
For example, as shown in FIG. 4, the terminal information storage unit 120 has the terminal information update date 2004/8/28, the terminal device name Machine_1, and the program update date 2004/8/26. Operating system "A (ver.1)", program name "Browser_1" and its program version "2.4", program name "Mailer_1" and its program version "1.0", program name "Game_1" and its program version "1.0" , The policy notification date "2004/8/28" and the control policy "AAA" are accumulated in association with each other.
The terminal information registration unit 170 acquires terminal information and stores it in the terminal information storage unit 120. The terminal information registration unit 170 can acquire terminal information by receiving terminal information from the terminal device 200 via the network 400, for example. In the terminal device 200, the installed program is updated (version upgraded) and a new program is introduced. Therefore, the terminal information registration unit 170 acquires terminal information from the terminal device 200 every time a program is updated or newly introduced, or periodically. The terminal information registration unit 170 stores the acquired terminal information in the terminal information storage unit 120 to update the terminal information so that the latest terminal information is stored in the terminal information storage unit 120.
The terminal information registration unit 170 may verify the validity of the acquired terminal information and store only the terminal information determined to be valid in the terminal information storage unit 120. For example, the terminal information registration unit 170 can verify the validity by using an encryption technique such as a hash value. For example, the terminal information registration unit 170 receives the terminal information and the hash value calculated using the terminal information from the terminal device 200, and calculates the hash value from the received terminal information. The terminal information registration unit 170 compares the received hash value with the calculated hash value, and if they match, it can be determined that the terminal information has not been tampered with and is valid.
The policy determination unit 130 is a control content determination unit that determines the control content that controls the operation of the terminal device, that is, the control policy based on the vulnerability information. From the vulnerability information, the policy determination unit 130 determines as a control policy the content of the operation control to be performed on the terminal device in which the program having the vulnerability is introduced in order to deal with the vulnerability.
The policy determination unit 130 can determine, for example, a control policy for system calls, a control policy for hardware, and a control policy for middleware. According to this, the terminal control device 100 can flexibly control the operation of the terminal device regarding system calls and access to hardware and middleware.
For example, as a control policy, the policy determination unit 130 includes system calls to be controlled, types of hardware, middleware, etc. (hereinafter referred to as control targets), and details of processing and restrictions to be performed on the control target (hereinafter referred to as control target). Hereinafter, "processing / restriction contents") can be set.
The policy decision unit 130 can set the policy decision information in which the restriction target, the processing / restriction content, and the vulnerability information are associated with each other. For example, as shown in FIG. 5, the policy determination unit 130 can set policy determination information in which the occurrence status is associated with the control target and the severity is associated with the processing / restriction content. The policy determination unit 130 acquires vulnerability information from the vulnerability information storage unit 110. The policy determination unit 130 can determine the control policy based on the acquired vulnerability information and the policy determination information.
For example, the policy determination unit 130 transmits data from the vulnerability information storage unit 110 in interprocess communication using the occurrence status Socket for Mailer_1 as vulnerability information of the program Browser_1 shown in FIG. , And get a severity level of "4". The policy decision unit 130 refers to the policy decision information shown in FIG. 5 based on the acquired vulnerability information, and associates the control target with "when data is transmitted from the specific partner X using a socket". Determined as "write system call (Write system call) to the transmission socket whose destination address is the specific destination X".
Further, the policy determination unit 130 determines the processing / restriction content to be "not allowed to process related to the vulnerability" associated with the severity level "4". Then, the policy determination unit 130 integrates the control target and the processing / restriction contents, and has a control policy of "completely prohibiting the write system call (Write system call) to the transmission socket whose destination address is Mailer_1". To determine. In this way, the terminal control device 100 can limit the system calls allowed to the program. As described above, the policy determination unit 130 can select an appropriate control policy from a plurality of control policy candidates according to the vulnerability information and determine the control policy to be applied.
In FIG. 5, a control policy related to a system call is shown as an example of a control policy, but in the case of a control policy related to hardware or middleware, the policy determination unit 130 sets, for example, "access to memory" as a control target. Can be set. Then, the policy determination unit 130 can determine, for example, a control policy that "issues a warning when trying to access the memory" when the severity level is "3". Further, the policy determination unit 130 may determine a control policy for controlling the operation of the resource manager that manages the resources of the hardware as the control policy for the hardware.
In addition, there are programs that are vulnerable when linked with a specific program. Therefore, the policy determination unit 130 can determine a control policy that prohibits the execution of a program that causes a vulnerability by interlocking with the execution of a specific program.
Further, it is preferable that the policy determination unit 130 determines the control policy according to the update of the program. In this case, the policy determination unit 130 acquires the terminal identification information of the terminal device whose program has been updated from the terminal identification unit 140. The policy determination unit 130 acquires the program identification information and the control policy already notified to the terminal device from the terminal information storage unit 120 based on the acquired terminal identification information.
The policy decision unit 130 has a program in which the vulnerability has been removed or a program in which the vulnerability information has been changed by updating the program based on the vulnerability information, the program identification information, and the notified control policy. Decide whether to do it or not.
The policy determination unit 130 determines a new control policy when there is a program in which the vulnerability has been removed or a program in which the vulnerability information has been changed. For example, when a program vulnerability is removed and the terminal device no longer has a program subject to operation control, the policy determination unit 130 releases the processing and restrictions performed to deal with the vulnerability. You can decide the control policy. Further, when the vulnerability information is changed, the policy determination unit 130 can determine the control policy based on the new vulnerability information.
According to this, the terminal control device 100 can flexibly control the terminal device according to the update of the program. Therefore, for example, it is possible to prevent the terminal device from which the vulnerability of the program is removed and the operation control is no longer required to execute unnecessary control forever by introducing a correction program or the like.
The policy determination unit 130 associates the determined control policy with the program identification information and inputs the determined control policy to the policy notification unit 150. The policy determination unit 130 may set the policy determination information by itself. For example, the policy determination unit 130 may use the policy determination information set by another device such as the terminal device 200 or the server 300 and provided via the network 400. May be good.
Further, the policy determination unit 130 is preferably realized by hardware having tamper resistance. According to this, it is possible to prevent the policy decision unit 130 itself from being attacked. Therefore, for example, it is possible to prevent the policy determination unit 130 from generating an erroneous control policy or a malicious control policy by falsifying the policy determination information or the like.
When the vulnerability information detected by the vulnerability detection unit 160 is verified and only the vulnerability information that is determined to be valid is stored in the vulnerability information storage unit 110, the policy determination unit 130 is used. By determining the control policy using the vulnerability information accumulated in the vulnerability information storage unit 110, the control policy can be determined based on the vulnerability information determined to be valid by the verification. Therefore, the terminal control device 100 can control the terminal device using only the vulnerability information determined to be legitimate, and can reliably perform appropriate control on the terminal device. That is, the terminal control device 100 can avoid performing erroneous control by using the vulnerability information whose reliability is guaranteed.
The terminal identification unit 140 identifies the terminal device affected by the vulnerability of the program based on the vulnerability information and the terminal information. The terminal identification unit 140 acquires vulnerability information from the vulnerability information storage unit 110, and acquires terminal information from the terminal information storage unit 120.
For example, the terminal identification unit 140 compares the program identification information included in the vulnerability information with the system identification information of the target system, and the program identification information and the system identification information included in the terminal information. The terminal identification unit 140 identifies the terminal device in which the program identification information and the system identification information included in the vulnerability information are present in the terminal information as the terminal device affected by the vulnerability.
For example, when the vulnerability information shown in FIG. 2 and the terminal information shown in FIG. 4 are compared, the terminal identification unit 140 includes an operating system "A (Ver.1)" and programs "Browser_1" and "Mailer_1". A terminal device with the terminal device name "Machine_1" having a set and further having "Game_1" is specified as a terminal device affected by the vulnerabilities of the programs "Browser_1" and "Game_1".
When the terminal identification unit 140 specifies the terminal device based on the target hardware or the target middleware, the terminal identification unit 140 can specify the terminal device in the same manner as when the terminal device is specified based on the target system. In this way, the terminal identification unit 140 identifies the terminal device affected by the vulnerability based on the operating system, hardware, and middleware of the terminal device, considering the vulnerabilities that occur depending on these. can do.
Further, it is preferable that the terminal identification unit 140 identifies the terminal device whose program has been updated and notifies the policy determination unit 130. The terminal identification unit 140 acquires the program update date and the policy notification date from the terminal information storage unit 120, and compares the two. The terminal identification unit 140 identifies a terminal device whose program update date is newer than the policy notification date as a terminal device whose program has been updated. The terminal identification unit 140 inputs the terminal identification information of the specified terminal device to the policy determination unit 130.
In addition, a vulnerability may occur when a specific program is linked. Therefore, the terminal specifying unit 140 can specify the terminal device including all the specific programs and the programs that are vulnerable when linked with the specific programs as the affected terminal devices.
The terminal identification unit 140 inputs the terminal identification information of the specified terminal device and the program identification information of the affected program into the policy notification unit 150 in association with each other.
The policy notification unit 150 is a control content notification unit that notifies a control policy (control content) to the terminal device specified by the terminal identification unit 140. The policy notification unit 150 acquires the control policy associated with the program identification information from the policy determination unit 130. The policy notification unit 150 acquires the terminal identification information associated with the program identification information from the terminal identification unit 140.
The policy notification unit 150 matches the program identification information associated with the control policy with the program identification information associated with the terminal identification information, and programs the terminal device 200 identified by the terminal identification information. Notify the control policy with matching identification information via network 400.
After notifying the control policy, the policy notification unit 150 stores the policy notification date (notification time of the control content) and the notified control policy in the terminal information storage unit 120.
(Terminal control method) FIG. 6 shows the procedure of the terminal control method. First, the terminal control device 100 detects the vulnerability information of the program and stores it in the vulnerability information storage unit 110 (S101). Next, the terminal control device 100 determines the operation control policy of the terminal device 200 based on the vulnerability information (S102). Further, the terminal control device 100 identifies the terminal device affected by the vulnerability of the program based on the vulnerability information and the terminal information (S103). Then, the terminal control device 100 notifies the terminal device 200 specified in step (S103) of the control policy (S104). The order of steps (S102) and (S103) may be reversed.
(effect) According to such a terminal control device 100 and a terminal control method, vulnerability information of a program can be detected, and a control policy for the operation of the terminal device 200 can be determined according to the detected vulnerability information. Therefore, the terminal control device 100 can flexibly control the operation of the terminal device 200 as a countermeasure against the vulnerability. Moreover, when the vulnerability information of the program is detected, the terminal control device 100 can identify the terminal device 200 affected by the vulnerability and notify the control policy. Therefore, the terminal control device 100 can quickly and flexibly take appropriate measures for the terminal device 200 that needs to deal with the vulnerability of the program.
That is, in a terminal device that monitors the operating status of a program and forcibly terminates it when an abnormal operation is detected, the damage caused by the vulnerability of the program may have already spread when the abnormal operation is detected. According to the terminal control device 100, it is possible to take prompt action when the vulnerability information can be detected. Moreover, since the terminal control device 100 detects not an abnormal operation but a vulnerability that causes the abnormal operation, it is an effective means for an unknown abnormal operation. Furthermore, since various control policies can be determined according to the vulnerability information, it is possible to perform extremely flexible control as compared with the conventional method in which the program can only be forcibly terminated.
Further, unlike the method of forcibly restricting the access right to the program, the operation of the program is not restricted even during normal operation. That is, it can be limited only until the vulnerability is detected and removed. In addition, appropriate control can be performed regardless of the user's consciousness or unconsciousness of the terminal device 200. From the above, for example, when a vulnerable program operates, a malicious attack on the program gives the attacker even the administrator authority of the terminal device 200, and the terminal device 200 is inside. It is possible to prevent the leakage of important information and attacks on other terminal devices using the terminal device 200 as a stepping stone. It is a very effective technique because it is difficult to eradicate the bug itself.
Moreover, the terminal controller 100 includes the content of the vulnerability, the situation in which the vulnerability occurs, the operating system affected by the vulnerability, the hardware affected by the vulnerability, the middleware affected by the vulnerability, and the seriousness of the vulnerability. Depending on the degree, it is possible to determine an appropriate control content and appropriately identify the terminal device affected.
Further, the terminal control device 100 includes an operating system included in the terminal device, hardware included in the terminal device, middleware included in the terminal device, a program included in the terminal device, a program update time in the terminal device, and a control policy notification time to the terminal device. Therefore, the terminal device affected by the vulnerability can be appropriately identified.
<figref num="1">It is a block diagram which shows the structure of the terminal control device which concerns on embodiment of this invention.</figref><figref num="2">It is a figure which shows the vulnerability information storage part which concerns on embodiment of this invention.</figref><figref num="3">It is a figure which shows the seriousness determination information which concerns on embodiment of this invention.</figref><figref num="4">It is a figure which shows the terminal information storage part which concerns on embodiment of this invention.</figref><figref num="5">It is a figure which shows the policy decision information which concerns on embodiment of this invention.</figref><figref num="6">It is a flow chart which shows the procedure of the terminal control method which concerns on embodiment of this invention.</figref>
Code description
100 ... Terminal controller 110 ... Vulnerability Information Storage Department 120 ... Terminal information storage unit 130 ... Policy Decision Department 140 ... Terminal identification part 150 ... Policy notification section 160 ... Vulnerability detector 170 ... Terminal information registration department 200 ... terminal device 300 ... server 400 ... network
Every citation, both waysCites: the store holds 2 of 3
| Document | Relation | Office |
|---|---|---|
| JP2003108521A | Cites | Japan |
| JP2006018766A | Cites | Japan |
8 members in 4 offices
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 2004318490 | Japan | A | |
| JP20040318490 | – | – | – |
Members8
| Document | Office | Kind | |
|---|---|---|---|
| CN1770122A | China | A | |
| US2006099847A1 | United States of America | A1 | |
| JP2006127422A | Japan | A | |
| EP1662393A2 | European Patent Office (EPO) | A2 | |
| CN100390753C | China | C | |
| EP1662393A3 | European Patent Office (EPO) | A3 | |
| US7845010B2 | United States of America | B2 | |
| JP4688472B2This record | Japan | B2 |
16 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of no payment of annual feesLAPS | LAPS | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Written request for application examinationJAPANESE INTERMEDIATE CODE: A621A621 | A621 |
Numbers
- Publication
- 4688472
- Publication, DOCDB
- 4688472
- Publication, EPODOC
- JP4688472B
- Application
- 318490
- Application, DOCDB
- 2004318490
- Application, EPODOC
- JP20040318490
Titles2
- English
- Terminal control device and terminal control method
- Japanese
- 端末制御装置及び端末制御方法
Classification
- CPC, 1
- G06F11/327
- IPC, 4
- G06F21 22
- G06F21 20
- G06F21 00
- G06F21 12