200905584 九、發明說明: 【發明所屬之技術領域】 本發明為提供一種具監視功能之資安事件控管系 統,尤指一種結合監視功能及側錄功能,以記錄資安事 =的發生,並能夠同步記錄事件發生時的周遭環境,使 遠端控制者能透過網路同步觀看所發生資安事件之電 腦的側錄晝面以及監視器所拍攝之畫面。 【先前技術】 Γ; 一般企業内常見的資訊安全裝置包括了防火 牆、防毒軟體等機制,但隨著web2. 〇時代來臨,「資 料外齡護」也成為企㈣安維護的重點課題。過去 貧料外_防護措施多半要借助高價、高複雜度的軟 體工具來解決。在f金與奸人力無法提高的情況 下,如何有效率的保護公司内部的機密資料, 近來企業主所關注的議題。 … 目前市面上資安控衫統僅雄f安事件,並沒 :監視系統結合,因此只能查财資安問題的電 證明發生資安事件時何人在使用電腦,缺 錄)證(監視系統晝面),對於防護 一貝女事件必能有更大之效果。 ^前市面上資安控 存網頁職歷程與程式:霸⑽ 需Γ。匕在資安防護效能上打了折扣,無法滿足企業 另外, 安事俾斜4 彡監視系統常是備而不用,在資 2件發生後’才以人 2 ”、、其他查§旬機制,搜尋過程往往費時費 200905584 ’近幾年陸續有國内業者也希望在資安控管 人辨識功能。但由於目前的即時辨識技術尚 =常;峨理器大量的運算資源,實用 無法述,發明人有感目前之資安控管系統 {•方:止、,強大的安全防護,因此依據多年來從 :術且;究’並配合相關 具監視功能之資 改善上述習用缺點之 【發明内容】 的提及目前資訊安全的重要性,而現行 咖的;因此,上 =;=== 終於·並配合相關學理, 控管系統」。 之種具監視功能之資安事件200905584 IX. Description of the invention: [Technical field of the invention] The present invention provides a security control system with monitoring function, in particular, a combination monitoring function and a side recording function to record the occurrence of the security event, and It can synchronously record the surrounding environment when the event occurs, so that the remote controller can simultaneously view the side of the computer and the picture taken by the monitor through the network. [Prior Art] Γ; The common information security devices in the general enterprise include mechanisms such as fire wall and anti-virus software. However, with the advent of the web2. 〇 era, “materials aging protection” has become a key issue for enterprise (4) security maintenance. In the past, poor materials and other protective measures were mostly solved with high-priced, high-complexity software tools. In the case that f-gold and rape manpower cannot be improved, how to effectively protect confidential information within the company, and recent issues of concern to business owners. ... At present, the market security control shirts are only male, and there is no monitoring system. Therefore, it is only possible to check the electricity security problem. Who is using the computer when the security incident occurs?昼面), for the protection of a female event can have a greater effect. ^Pre-market security control website history and program: hegemony (10) need to be.打 The discount on the security protection effectiveness of the company has not been able to meet the needs of the enterprise. The search process often takes 200,905,584 times. In recent years, domestic companies have also hoped to identify functions in the security control. However, because the current real-time identification technology is still normal; the processor has a large amount of computing resources, and the utility cannot be described. People have a sense of the current security control system {• party: stop, strong security protection, so based on years of experience: from the surgery; and with the relevant monitoring functions to improve the above-mentioned shortcomings of the invention [invention] The reference to the current importance of information security, and the current coffee; therefore, on =; === finally · and with the relevant academic, control system." The security incident with monitoring function
L 資安,m供^種具監視功能之 器及-資安事件監控單—電腦、至少-監視 取並側_至少·_ 二t事件監控單元完整擷 被存入當時崎幕ΪΓ有輸出、 新狀態,並可以即時通知的指; 本發明之次一目的,gp丢炒 查詢資安事件的方式,協助紀錄、管理、 資料的使用與存取狀況,以有=:= 200905584 女威脅’才能保障公司重要無形資產的安全。 【實施方式】 ' h 於、餘查委員能對本發明之技術手段及運 -1有更進—步之認識與瞭解’絲-實施例配合圖 示,詳細說明如下。 餘係一種「具監視功能之資安事件控管系 由」可應用於企業或重視資訊安全之電腦網絡 Τ,其係包括: Ο 至少一電腦10’該至少—電腦10可為一般桌上型 個人電腦或筆記型電腦,侧以執行應練式之電腦; 岑機fTC 11 ’該至少—監視器11係為網路攝 =機IPC總ra),其可裝設於辦公室中,並以能拍攝 -電腦10螢幕為較佳之裝設處,_以攝錄該 至少一電腦10周遭環境之晝面; 有二if事=控單元12,其功能為控管公司内所 有貝文事件,该-貝安事件監控單元12係包括: -編碼模組12G,係分卿以記_ 1〇内程式事件之資料(如:執行EXCEL、MSN等應= ,萬用串列匯流埠(Universal Series Bus專,’② in料)、麟晝面及駐少—監彳如1攝錄之 ^全碼,包括該至少—電腦1G f安事編碼、 」錄旦面擷取、,碼及該至少―監視器u攝錄之晝面編 馬,以供後續資安事件或畫面檢索時使用; 至少係藉由該編碼模組120以整合該 •^側錄資訊製作索引,以方便檢索,並能將瘦 t ,120編碼後之資訊予以解碼’其整合功能包括、Ύ 效,至少-電腦1G所執行的指令、禁止特定程式j 丁(如禁止執行多媒體影音播放器等)、執行程式之事 200905584 收發郵件等)、針對該至 ί二上晝 解碼,及針對該至少- 電細10使用萬用串列匯流埠(USB) 錄,並將資料備份; X子·^貝#做侧 121 麵組122,細以接㈣整合模組 魏’並將該至少—電腦10側錄之書 面及該至少-監視H η攝錄之畫面難出,且^ 收-使用者設定該至少—電腦1Q發生資 ί條ΐ顯如特定程式時發出通知,、提醒管理者注 m/16格’能同時監看多台電腦之晝面;並能控制 mUs電腦10之通訊蚊,如:簡訊服務(ShortL 资安, m for the kind of monitoring function device and - Zi'an event monitoring list - computer, at least - monitoring and taking side _ at least _ two t event monitoring unit is completely stored in the time, there is output, The new state, and can be immediately notified; the second purpose of the present invention, gp throws the way to query the security incident, assists in the use of records, management, data usage and access, with =:= 200905584 female threats Safeguard the company's important intangible assets. [Embodiment] The 'h Yu, Yucha Committee can understand the technical means of the present invention and the knowledge and understanding of the present invention. The details of the silk-embodiment are as follows. A system of "control security incident control system" can be applied to enterprises or computer networks that emphasize information security. The system includes: 至少 at least one computer 10' at least - computer 10 can be a general desktop type PC or laptop, side to perform the computer should be practiced; 岑 machine fTC 11 'This at least - monitor 11 is the network camera = machine IPC total ra), which can be installed in the office, and can Shooting - the computer 10 screen is the preferred installation, _ to record the at least one computer 10 weeks after the environment; there are two if = control unit 12, its function is to control all the Bewen events in the company, the - The Beian event monitoring unit 12 includes: - an encoding module 12G, which is used by the secretary to record the information of the program events (eg, executing EXCEL, MSN, etc. =, universal serial confluence (Universal Series Bus) , '2 in material', 昼 昼 及 及 驻 驻 — — — — — — — — 摄 摄 摄 摄 摄 摄 摄 摄 摄 摄 摄 摄 摄 摄 摄 摄 摄 摄 摄 摄 摄 摄 摄 摄 摄 摄 摄 摄 摄 摄 摄 摄 摄 摄u 摄 摄 摄 编 编 编 编 编 编 编 编 编 编 编 编 编 编 编 编 编 编 编 编 编 编The coding module 120 integrates the index of the information to make an index for easy retrieval, and can decode the information encoded by the thin t and 120 codes. The integrated function includes, and is effective, at least - executed by the computer 1G. Command, prohibit specific program j (such as prohibiting the execution of multimedia video player, etc.), execute the program, 200905584 send and receive mail, etc.), decode the video to the top, and use the universal serial for the at least Confluence 埠 (USB) record, and data backup; X sub·^ 贝# do side 121 面 122, fine to connect (four) integration module Wei 'and at least - computer 10 side recorded written and the at least - monitoring H η video recording is difficult, and ^ Receive - user set this at least - computer 1Q generates a message, such as a specific program to send a notice, remind the manager to note m / 16 grid 'can monitor multiple at the same time The face of the computer; and can control the communication mosquitoes of the mUs computer 10, such as: newsletter service (Short
Message Senace,SMS)、P〇P3、s 機簡訊、電子郵件等收發。 、手 求作監視安事件控衫統根據需 安事件監控單元尚可外接至少一儲 ^ 120 疋以,本發明具監視功能之資安 , 2其二習用技術相互比較時’更具備下列之u 一、中發側S司内部電腦所有應用程式使用 T破輸出、被存入當時的螢幕書 内部人員活動、進出狀況 伙為貝女事件發生時,舉證的有利工且。 μ f 2件仏索早位,本發明另外將每個、'執 為特殊事件’方便管理者可快速查 ί勃ifΪ的所有發生時間點、持續時間,以 執仃此&式時的電腦榮幕晝面;由於整合了網 200905584 路攝影機(IP Camera)的系統功能,除了可側錄 特殊事件發生時的晝面,尚可配合了解當時之週 邊人事物相關活動,快速而完整的掌握資安事 資料。 、 τ 二、般的影像錄製系統通常是在啟動後即全程錄影, 當錄影空間不足時,會自動刪除最早的傻^ iff。而本發明除了建置一般側錄系統要求的功 循$錄影、排程錄影)外,更在系統内新增、、警 ,錄影’’功能,此項功能有助彈性化的^ ^ Γ ^行檔案的使用畫面’―旦這些執行槽^被啟 S管i發明技術則開始進行同步錄製,方便ί蹤 動作及記錄,然後設定警報即時 管理 本系統為方便管理者分析公司内= ί 的影像結果皆可在系統内進 麵使=形㈣者了解公51内部電腦執行檔 —每>上述洋細說明為針對本發明之一種鲂估夕-Τ fmZm ^ w =;二=倾•峨 :[圖式簡單說明】 第一圖係為本發明之架構圖。 【主要元件符號說明】 1〇至少一電腦 ^至少一監視器 200905584 12 資安事件監控單元 120 121 整合模組 122 123儲存裝置 編碼模組 顯示及控制模組Message Senace, SMS), P〇P3, s machine newsletter, email, etc. According to the demand monitoring unit, the monitoring unit can be connected to at least one storage unit. The invention has the monitoring function of the security, and the second one has the following characteristics. 1. All the applications in the internal computer of the S-Senior side use the T-breaking output, the internal activities of the screen book that were deposited at the time, and the entry and exit status when the incident occurred. f f 2 pieces of 仏 早 早 , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , After the integration of the system function of the network camera 200905584 IP Camera (IP Camera), in addition to the side events that can be recorded when special events occur, it is still possible to cooperate with the activities of the surrounding people at that time, and quickly and completely grasp the capital. Security information. τ Second, the general image recording system usually records the whole process after starting. When the video space is insufficient, the earliest silly iff will be deleted automatically. In addition to the functions required by the general side recording system to follow the video recording and scheduling recording, the present invention adds a new, police, and video function to the system. This function helps to flexibly ^ ^ Γ ^ The use screen of the line file '------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- The results can be made in the system to make the shape of the internal computer executable file - each of the above-mentioned details are for the purpose of the present invention - Τ fmZm ^ w =; two = tilt • 峨: BRIEF DESCRIPTION OF THE DRAWINGS The first figure is an architectural diagram of the present invention. [Main component symbol description] 1〇At least one computer ^At least one monitor 200905584 12 Security incident monitoring unit 120 121 Integrated module 122 123 storage device Encoding module Display and control module
1010