WO2005050421A1 - 証拠画面保存プログラム、証拠画面保存方法及び証拠画面保存装置 - Google Patents

証拠画面保存プログラム、証拠画面保存方法及び証拠画面保存装置 Download PDF

Info

Publication number
WO2005050421A1
WO2005050421A1 PCT/JP2004/015081 JP2004015081W WO2005050421A1 WO 2005050421 A1 WO2005050421 A1 WO 2005050421A1 JP 2004015081 W JP2004015081 W JP 2004015081W WO 2005050421 A1 WO2005050421 A1 WO 2005050421A1
Authority
WO
WIPO (PCT)
Prior art keywords
evidence
computer
screen
display data
unauthorized
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/JP2004/015081
Other languages
English (en)
French (fr)
Japanese (ja)
Inventor
Osamu Aoki
Hiroaki Kawano
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Intelligent Wave Inc
Original Assignee
Intelligent Wave Inc
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Intelligent Wave Inc filed Critical Intelligent Wave Inc
Publication of WO2005050421A1 publication Critical patent/WO2005050421A1/ja
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/50Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
    • G06F21/55Detecting local intrusion or implementing counter-measures
    • G06F21/554Detecting local intrusion or implementing counter-measures involving event detection and direct action

Definitions

  • the present invention relates to an evidence screen saving program, an evidence screen saving method, and an evidence screen saving device for saving an evidence screen of an unauthorized operation performed on a computer.
  • a fraud is detected by the above method
  • processing such as interrupting the operation being performed, reporting to the administrator, and warning to the operator are executed.
  • processing such as interrupting the operation being performed, reporting to the administrator, and warning to the operator are executed.
  • a method is disclosed in which, when monitoring unauthorized operation in a network, communication is cut off, and a notification report is sent to an administrator and a warning report is sent to an operator (see Patent Document 1).
  • a method of issuing a warning message to a monitor when monitoring operations on a computer is disclosed (see Patent Document 2).
  • Patent Document 1 Japanese Unexamined Patent Application Publication No. 2002-232232, paragraph number 0005
  • Patent Document 2 JP-A-2002-258972, paragraph number 0034
  • Such evidences must be identified by recording logs in the event that a fraudulent event occurs.
  • the accessed file has been changed or the file has been deleted, there is a problem that the operation status at the time when the unauthorized operation was performed cannot be reproduced. In the event that fraud occurs, it is preferable to save credible evidence as soon as possible.
  • the present invention has been made in response to such a problem, and it is possible to quickly save an evidence screen at the time of occurrence of an unauthorized operation performed on a computer. It is intended to provide a screen storage program, a evidence screen storage method, and a evidence screen storage device.
  • a first invention for solving the above-mentioned problem is a proof screen storage program for storing a proof screen of an unauthorized operation performed on a computer, wherein the computer accepts the proof screen by the computer. Determining whether the operation performed is an unauthorized operation; obtaining the display data displayed on the screen of the computer by the operation if the operation is determined to be an unauthorized operation; And storing the evidence data with the information specifying the operation in the evidence data storage unit in the evidence data storage unit.
  • the computer is caused to execute a step of recording at least one log of a keystroke, a network, an application, or an operation system applied to the computer. You can also.
  • the evidence of the unauthorized operation can be saved quickly.
  • the operation history of the computer may be recorded as a log at all times.However, by recording the log after it is determined that the operation is unauthorized, the evidence that the operation has been performed together with the data displayed on the screen is effective. Can be saved
  • any judging method may be used for judging an unauthorized operation, such as judging based on a pre-registered rule base or judging based on a user profile obtained by analyzing a user's operation tendency.
  • the file format of the display data to be saved is not limited to a specific format as long as it can reproduce the screen display.
  • the information for specifying the operation uses the user ID of the user who performed the operation, the time when the operation was performed, and the like.
  • a second invention for solving the above-mentioned problem is a proof screen storage program for storing a proof screen of an unauthorized operation performed on a computer, wherein the computer accepts the proof screen by the computer. Determining whether the operation performed is an unauthorized operation; obtaining the display data displayed on the screen of the computer by the operation if the operation is determined to be an unauthorized operation; And transmitting, to the management server via a network, evidence data with information specifying the operation. And causing the computer to execute a step of transmitting at least one log of a keystroke, a network, an application, or an operation system applied to the computer to the management server when the operation is determined to be an unauthorized operation. It may be characterized.
  • the acquired display data is transmitted to the management server, and the management server monitors the unauthorized operation centrally, thereby saving the evidence of the unauthorized operation.
  • the administrator can take quick and quick responses.
  • the requirements for the ability to record logs to increase the evidentiality, the method of determining unauthorized operation, the file format of the display data, and the information for specifying the operation are the same as in the first invention.
  • the step of obtaining the display data the data written by the operation in the virtualized display area is obtained as display data. It can also be a feature.
  • the force required to identify the display data displayed on the screen by an unauthorized operation as evidence is that the display data displayed on the screen is written in a virtual display area such as a device context. It can be specified from the issued data.
  • the step of obtaining the display data in the step of obtaining the display data, the data written by the operation in a buffer for displaying a screen of the computer is written. It can also be obtained as display data.
  • the first invention and the second invention can also be grasped as an evidence screen saving method that can be performed by executing the above-described evidence screen saving program. Further, it can be configured as an evidence screen storage device using the above evidence screen storage program.
  • the evidence screen saving method is an evidence screen saving method for saving an evidence screen of an unauthorized operation performed on a computer, wherein the computer A step of determining whether the received operation is an unauthorized operation; and a step of the computer acquiring display data displayed on a screen of the computer by the operation when the operation is determined to be an unauthorized operation. And storing the evidence data in which the information specifying the operation is added to the display data in the evidence data storage unit.
  • An evidence screen saving method is an evidence screen saving method for saving an evidence screen of an unauthorized operation performed on a computer, wherein the computer accepts the evidence screen.
  • An evidence screen storage device corresponding to the first invention is an evidence screen storage device for saving an evidence screen of an unauthorized operation performed on a computer, wherein the operation received by the computer is an unauthorized operation.
  • Operation means for judging whether the operation is illegal, and when the operation is judged to be an illegal operation by the illegal operation judgment means, display data displayed on the screen of the computer is acquired by the operation.
  • Evidence data storage means comprising: display data acquisition means; and evidence data storage means for storing evidence data obtained by adding information for specifying the operation to the display data acquired by the display data acquisition means.
  • the information processing apparatus further comprises a log recording means for recording at least one log of a keystroke, a network, an application, or an operation system of the computer. You can also.
  • An evidence screen storage device is an evidence screen storage device for saving an evidence screen of an unauthorized operation performed on a computer, wherein the operation received by the computer is an unauthorized operation.
  • Operation means for judging whether the operation is illegal, and when the operation is judged to be an illegal operation by the illegal operation judgment means, display data displayed on the screen of the computer is acquired by the operation.
  • Display data acquisition means, and evidence data transmission means for transmitting, via a network, evidence data in which display data acquired by the display data acquisition means with information specifying the operation is transmitted to a management server.
  • This is the evidence screen storage device.
  • the unauthorized operation determining means determines that the operation is an unauthorized operation, at least one log of a keystroke, a network, an application, or an operation system concerning the computer is transmitted to the management server. It can be characterized by having no transmission means.
  • the evidence screen storage device corresponding to the first invention and the second invention is characterized in that the display data storage device
  • the data acquisition means may acquire data written by the operation in the virtualized display area as display data.
  • the display data obtaining means obtains, as display data, data written by the operation in a buffer for displaying a screen of the computer.
  • FIG. 1 is a diagram showing an overall configuration of an example in which the evidence screen storage device according to the present invention is used for monitoring a terminal connected to a network.
  • FIG. 2 is a diagram showing a monitoring position on a network in an example in which the evidence screen storage device according to the present invention is used for monitoring a terminal connected to the network.
  • FIG. 3 is a diagram showing an outline of a function of an example in which the evidence screen storage device according to the present invention is used for monitoring a terminal connected to a network.
  • FIG. 4 is a block diagram showing a configuration of a fraud monitoring system using the evidence screen storage program according to the present invention.
  • FIG. 5 is a diagram showing an outline of the processing by the evidence screen saving program which is useful in the present invention.
  • FIG. 6 is a diagram showing an example of a table for storing the evidence data acquired by the evidence screen saving program according to the present invention.
  • FIG. 7 is a flowchart showing a processing procedure of an evidence screen storage program that is useful in the present invention.
  • the evidence screen storage device saves an evidence screen of an unauthorized operation performed on a computer, but may be used in a stand-alone computer. To monitor computers connected to the network May be. In the former case, the data related to the evidence screen is stored in the combi- ter used by the user.
  • FIG. 1 shows an example used for monitoring a computer connected to the latter network.
  • a plurality of user terminals are connected by an in-house network such as a LAN, and the in-house network is connected to the Internet.
  • the fraud monitoring server monitors data flowing on the network and monitors activities such as sending and receiving unauthorized information to and from the Internet.
  • the evidence screen storage device working on the present invention monitors illegal operations in two parts.
  • One is to monitor the operation performed on the user terminal, and if it is determined that the operation is unauthorized, capture the operation screen at the time of the unauthorized operation and store it in the user terminal or the unauthorized monitoring server.
  • the other is that when the fraud monitoring server monitors data flowing through the network and detects data that corresponds to an unauthorized operation, it identifies the user terminal that sends and receives the data and displays the operation displayed on the user terminal based on the data. Capture the screen and store it on the user terminal or the fraud monitoring server.
  • the position where the fraud monitoring server monitors the data on the network is, in addition to the monitoring of the data executed in the user terminal, the segment unit of the network. It can be placed in various locations, such as monitoring data transmitted and received by a mail server, monitoring data at a mail server, and monitoring data at a gateway.
  • FIG. 3 shows an example of the respective functions of the user terminal and the fraud monitoring server in the case where the evidence screen storage device according to the present invention is used for monitoring a computer connected to a network.
  • the evidence screen storage program according to the present invention is executed, and when an unauthorized operation is detected, a warning message is displayed on a display and a warning sound is generated.
  • the screen displayed by the unauthorized operation is captured, and the display data of the screen together with the information such as the time of occurrence is transmitted to the fraud monitoring server as evidence data with the identification information of the terminal.
  • the fraud monitoring server information such as terminal identification information and occurrence time is classified as a key. Evidence data is stored. In addition to the evidence data, it is also possible to obtain and store from the user terminal various types of operations after the fraud has occurred.
  • the fraud monitoring server may also display a warning message on the display and generate a warning sound to promptly notify the administrator of the occurrence of an illegal operation.
  • the user terminal 10 includes a CPU 11, a RAM 12, a ROM 13, a HDD 14, and a video board 15.
  • the HDD 14 stores a fraud monitoring program 141 for monitoring for fraudulent operations including a evidence screen saving program that is useful for the present invention, and stores fraud rules for storing rules for judging fraudulent operations.
  • Unit 142 is provided with an evidence data storage unit 143 that stores data related to an evidence screen when an unauthorized operation is performed.
  • the video board 15 includes a VRAM 16 which is a buffer for writing screen content to be displayed on the display 17. It should be noted that the HDD 14 storing the fraud monitoring program 141 may use another storage medium such as a flash memory capable of storing a program!
  • the display data of the screen to be captured is specified by acquiring the data written in the virtualized display area such as the device context in the arithmetic processing in the CPU 11 and the RAM 12. can do.
  • the data written by the operation in the VRAM 16 which is a buffer for displaying on the display 17 can be acquired and specified.
  • Display data of the captured screen includes data for identifying the operation, such as the time when the ID operation of the user who performed the operation was received. This is added to and stored in the evidence data storage unit 143.
  • Figure 6 shows an example of a table that stores the evidence data obtained in this way.Records provided for each operation to be processed are displayed on the display together with the date and time of receipt of the operation and the user ID. The file name of the displayed data is recorded.
  • the format of the powerful file stored in the evidence data storage unit 143 may be any format.
  • logs of operations performed on the computer such as keystrokes, networks, applications, or operation systems, in addition to the direct operations of performing the fraudulent operations, are recorded. You can also record it.
  • Such a log can be used to prove the operation history of the user and prove that unauthorized operation has been performed in conjunction with the evidence screen.
  • the log is recorded after the occurrence of the fraud.
  • the fraud rule storage unit 142 provided in the user terminal 10 may be provided as the fraud rule storage unit 21 in the fraud monitoring server 20 that monitors the network including the user terminal 10.
  • a common rule is applied to a plurality of terminals belonging to the same network, where it is preferable to use the fraud rule storage unit 142 provided in the user terminal 10.
  • the acquired evidence data may be stored in the evidence data storage unit 143 in the user terminal 10, but in order to reduce the risk of deleting the evidence data, the acquired evidence data is under the control of the administrator. It is preferable to use the evidence data storage unit 22 provided in the fraud monitoring server 20.
  • FIG. 5 shows an outline of the processing by the evidence screen storage program that is useful in the present invention.
  • the components described below are not physically separated, but are stored in the HDD 14 as a part of the fraud monitoring program 141 that executes each component as shown in FIG.
  • the arithmetic processing may be executed by the CPU 11 while the RAM 12 functions as a work area.
  • the fraud determining unit determines the operation. It is determined whether or not the racing is an illegal operation. Such a determination can be made in comparison with a rule stored in a fraudulent rule storage unit created based on a general fraudulent pattern pattern, but is not limited to a rule-based determination and can be performed by a user. Pattern power Compared with the created user profile or the like, an illegal operation may be determined from unique behavioral power.
  • the display data acquisition unit acquires display data to be displayed on the display of the user terminal by the operation.
  • the display data to be acquired is specified from the data written to VRAM or device context.
  • the display data is saved as an image file and stored in the evidence data storage unit with information identifying the operation, such as the date and time of receipt of the operation and the user ID. Further, such evidence data may be transmitted to a management server or the like via a network and stored. Further, in order to stop the unauthorized operation, the stop processing execution unit may execute processing such as displaying a warning message, generating a warning sound, stopping the operation, and disconnecting the network.
  • the display of the warning message and the generation of the warning sound may be performed on the user terminal side or may be performed on the management server side.
  • various settings such as specific time, random, startup, etc. are performed and a dummy warning message or warning sound is emitted and monitoring is performed. It is possible to increase the deterrence effect on the user by clarifying that the information is being checked. In this case, it is possible to actually perform even the capture of the screen.
  • the user checks whether the computer operated by the user is capable of generating a warning sound or a warning message (S04). Is set to occur In this case, a warning sound or a warning message is generated (S05). Subsequently, display data to be displayed by the operation of performing the fraud determination is obtained from the device context (S06). The display data is attached with information for identifying unauthorized operations such as a date (S07), and is stored as evidence in a database or the like (S08). Further, the setting of whether or not to transmit the display data to the management server is confirmed (S09), and if the transmission is set, it is also transmitted to the management server (S10).
  • FIG. 1 A proof screen storage device according to the present invention is used for monitoring terminals connected to a network.
  • V is a diagram illustrating an entire configuration of an example.
  • FIG. 2 is a diagram showing a monitoring position on a network in an example in which the evidence screen storage device according to the present invention is used for monitoring a terminal connected to the network.
  • the evidence screen storage device is used for monitoring terminals connected to a network.
  • FIG. 5 is a diagram showing an outline of functions of an example.
  • FIG. 4 is a block diagram showing a configuration of a fraud monitoring system using a proof screen storage program that is useful in the present invention.
  • FIG. 5 is a diagram showing an outline of a process performed by the evidence screen storage program according to the present invention.
  • FIG. 6 is a diagram showing an example of a table for storing evidence data obtained by an evidence screen saving program according to the present invention.
  • FIG. 7 is a flowchart showing a processing procedure of an evidence screen storage program that is useful in the present invention.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Software Systems (AREA)
  • Theoretical Computer Science (AREA)
  • Computer Hardware Design (AREA)
  • Physics & Mathematics (AREA)
  • General Engineering & Computer Science (AREA)
  • General Physics & Mathematics (AREA)
  • Debugging And Monitoring (AREA)
PCT/JP2004/015081 2003-11-18 2004-10-13 証拠画面保存プログラム、証拠画面保存方法及び証拠画面保存装置 Ceased WO2005050421A1 (ja)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
JP2003-387671 2003-11-18
JP2003387671A JP2005149267A (ja) 2003-11-18 2003-11-18 証拠画面保存プログラム、証拠画面保存方法及び証拠画面保存システム

Publications (1)

Publication Number Publication Date
WO2005050421A1 true WO2005050421A1 (ja) 2005-06-02

Family

ID=34616166

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/JP2004/015081 Ceased WO2005050421A1 (ja) 2003-11-18 2004-10-13 証拠画面保存プログラム、証拠画面保存方法及び証拠画面保存装置

Country Status (2)

Country Link
JP (1) JP2005149267A (https=)
WO (1) WO2005050421A1 (https=)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN109471625A (zh) * 2018-09-28 2019-03-15 北京金山云网络技术有限公司 网页生成方法、装置、电子设备及计算机可读存储介质

Families Citing this family (10)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP5041516B2 (ja) * 2007-01-22 2012-10-03 力 松田 コンピュータの画面監視用usbメモリ
JP4216881B2 (ja) * 2007-02-02 2009-01-28 Sky株式会社 端末監視装置と端末監視装置のためのプログラム
JP3954642B1 (ja) * 2007-02-26 2007-08-08 Sky株式会社 画面保存システム
JP4264113B2 (ja) * 2007-04-23 2009-05-13 Sky株式会社 端末監視装置及び端末監視プログラム
JP4066033B1 (ja) * 2007-08-22 2008-03-26 Sky株式会社 クライアント端末監視システム
JP5334739B2 (ja) * 2009-08-10 2013-11-06 株式会社日立ソリューションズ ログ監視プログラム、ログ監視システム
JP2011048547A (ja) * 2009-08-26 2011-03-10 Toshiba Corp 異常行動検知装置、監視システム及び異常行動検知方法
JP6003969B2 (ja) * 2013-11-28 2016-10-05 キヤノンマーケティングジャパン株式会社 情報処理装置、情報処理システム、制御方法、プログラム
JP6852379B2 (ja) * 2016-12-14 2021-03-31 富士通株式会社 操作ログ出力プログラム、操作ログ出力方法、および情報処理装置
JP7519283B2 (ja) 2020-12-08 2024-07-19 株式会社日立ソリューションズ・クリエイト 不正操作検知システム

Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JPH10222274A (ja) * 1997-02-03 1998-08-21 Sefuto Kenkyusho:Kk 入力情報記録装置
JP2000112890A (ja) * 1998-09-30 2000-04-21 Mitsubishi Electric Corp 不正操作防止と追跡装置
JP2002026935A (ja) * 2000-07-11 2002-01-25 Lac Co Ltd フレーム監視装置および記憶媒体
JP2002149602A (ja) * 2000-11-13 2002-05-24 Ntt Software Corp 不正アクセスを防御するためのネットワーク接続装置
JP2002232451A (ja) * 2001-02-02 2002-08-16 Layer Seven Co Ltd 通信管理方法、通信監視装置、および、コンピュータシステム
JP2003066826A (ja) * 2001-08-22 2003-03-05 Nippon Telegr & Teleph Corp <Ntt> 不正行為監視方法及びシステム及び装置及び不正行為監視プログラム及び不正行為監視プログラムを格納した記憶媒体

Patent Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JPH10222274A (ja) * 1997-02-03 1998-08-21 Sefuto Kenkyusho:Kk 入力情報記録装置
JP2000112890A (ja) * 1998-09-30 2000-04-21 Mitsubishi Electric Corp 不正操作防止と追跡装置
JP2002026935A (ja) * 2000-07-11 2002-01-25 Lac Co Ltd フレーム監視装置および記憶媒体
JP2002149602A (ja) * 2000-11-13 2002-05-24 Ntt Software Corp 不正アクセスを防御するためのネットワーク接続装置
JP2002232451A (ja) * 2001-02-02 2002-08-16 Layer Seven Co Ltd 通信管理方法、通信監視装置、および、コンピュータシステム
JP2003066826A (ja) * 2001-08-22 2003-03-05 Nippon Telegr & Teleph Corp <Ntt> 不正行為監視方法及びシステム及び装置及び不正行為監視プログラム及び不正行為監視プログラムを格納した記憶媒体

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN109471625A (zh) * 2018-09-28 2019-03-15 北京金山云网络技术有限公司 网页生成方法、装置、电子设备及计算机可读存储介质

Also Published As

Publication number Publication date
JP2005149267A (ja) 2005-06-09

Similar Documents

Publication Publication Date Title
TWI678616B (zh) 文件檢測方法、裝置及系統
CN108121914B (zh) 一种文档泄密防护追踪系统
CN100590613C (zh) 非法监视方法及非法监视系统
US7673324B2 (en) Method and system for tracking an operating performed on an information asset with metadata associated therewith
US20080281962A1 (en) Information asset management system, log analysis server, log analysis program, and portable medium
CN101888311B (zh) 一种防止网络内容被篡改的设备、方法和系统
KR20100002592A (ko) 정보보안 감사방법, 이를 수행하기 위한 프로그램이 저장된컴퓨터가 판독가능한 기록매체 및 이를 수행하기 위한시스템
WO2005050421A1 (ja) 証拠画面保存プログラム、証拠画面保存方法及び証拠画面保存装置
US20070283166A1 (en) System and method for state transition intrusion detection
KR20010078840A (ko) 컴퓨터저장매체를 통한 정보유출을 감시하는 보안시스템
JP2010146457A (ja) 情報処理システムおよびプログラム
JPWO2005048119A1 (ja) 不正操作判定システム、不正操作判定方法及び不正操作判定プログラム
US20080201464A1 (en) Prevention of fraud in computer network
CN117150453A (zh) 网络应用检测方法、装置、设备、存储介质及程序产品
JP6636605B1 (ja) 履歴監視方法、監視処理装置および監視処理プログラム
CN105930740B (zh) 软体文件被修改时的来源追溯方法、监测方法、还原方法及系统
JP2005242754A (ja) セキュリティ管理システム
JP6851212B2 (ja) アクセス監視システム
US12164625B2 (en) Context based authorized external device copy detection
JP4256107B2 (ja) データサーバへの不正侵入対処方法、及びプログラム
JP4653150B2 (ja) ファイル制御システム
CN111753286A (zh) 终端设备监测方法、装置、终端设备及存储介质
JP2010055566A (ja) クライアント/サーバシステムとクライアント/サーバシステムの監査方法
JP4857199B2 (ja) 情報資産管理システム、ログ分析装置、及びログ分析用プログラム
JP2009053896A (ja) 不正操作検出装置およびプログラム

Legal Events

Date Code Title Description
AK Designated states

Kind code of ref document: A1

Designated state(s): AE AG AL AM AT AU AZ BA BB BG BR BW BY BZ CA CH CN CO CR CU CZ DE DK DM DZ EC EE EG ES FI GB GD GE GH GM HR HU ID IL IN IS JP KE KG KP KR KZ LC LK LR LS LT LU LV MA MD MG MK MN MW MX MZ NA NI NO NZ OM PG PH PL PT RO RU SC SD SE SG SK SL SY TJ TM TN TR TT TZ UA UG US UZ VC VN YU ZA ZM ZW

AL Designated countries for regional patents

Kind code of ref document: A1

Designated state(s): GM KE LS MW MZ NA SD SL SZ TZ UG ZM ZW AM AZ BY KG KZ MD RU TJ TM AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HU IE IT LU MC NL PL PT RO SE SI SK TR BF BJ CF CG CI CM GA GN GQ GW ML MR NE SN TD TG

121 Ep: the epo has been informed by wipo that ep was designated in this application
NENP Non-entry into the national phase

Ref country code: DE

WWW Wipo information: withdrawn in national office

Country of ref document: DE

122 Ep: pct application non-entry in european phase
NENP Non-entry into the national phase

Ref country code: JP