WO2006035478A1 - コンピュータシステムおよびその方法 - Google Patents
コンピュータシステムおよびその方法 Download PDFInfo
- Publication number
- WO2006035478A1 WO2006035478A1 PCT/JP2004/014067 JP2004014067W WO2006035478A1 WO 2006035478 A1 WO2006035478 A1 WO 2006035478A1 JP 2004014067 W JP2004014067 W JP 2004014067W WO 2006035478 A1 WO2006035478 A1 WO 2006035478A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- address
- node
- communication
- nodes
- server
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1441—Countermeasures against malicious traffic
- H04L63/145—Countermeasures against malicious traffic the attack involving the propagation of malware through the network, e.g. viruses, trojans or worms
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L61/00—Network arrangements, protocols or services for addressing or naming
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L61/00—Network arrangements, protocols or services for addressing or naming
- H04L61/50—Address allocation
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L2101/00—Indexing scheme associated with group H04L61/00
- H04L2101/60—Types of network addresses
- H04L2101/668—Internet protocol [IP] address subnets
Definitions
- the present invention relates to a computer system including a computer that performs communication using a netmasked IP address, and a method therefor.
- TCP / IP Transmission Control Protocol / Internet Protocol
- nodes computers performing information processing and the like may be collectively referred to as nodes.
- Each node is assigned a 32-bit IP address for TCP / IP communication.
- This IP address includes a network part used to identify the network to which each node belongs, and a host part used to identify each node in the network to which it belongs.
- the network portion and the host portion of the IP address are identified by a 32-bit netmask, and each bit of the netmask takes a value of 1 when the corresponding IP address bit is included in the network portion, When included in the host section, it takes a value of 0 (hereinafter, the number of bits taking a value of 1 is referred to as the number of bits in the net mask).
- DHCP Dynamic Host Configuration Protocol
- Patent Document 1 discloses a method for preventing unauthorized access to a DHCP server providing a DHCP function in a network using the above-described IP address and DHCP.
- Patent Document 1 can not prevent the spread of viruses among computers connected to a network.
- Patent Document 1 Japanese Patent Application Laid-Open No. 2004-228799
- the present invention has been made as the background described above, and a computer system and method improved so that IP addresses can be more flexibly used in a network by devising the method of using net masks. Intended to provide.
- the present invention is an improved computer that can provide various functions to a computer connected to a network by devising a method of assigning a netmask and an IP address to which it is assigned.
- the purpose is to provide a system and its method.
- Another object of the present invention is to provide a computer system and method capable of easily taking measures against computer viruses.
- a computer system is different from a first IP address provided with a first netmask of a predetermined number of bits and the first netmask.
- the first IP With respect to one or more first nodes performing communication, one or more second nodes performing communication using the second IP address, and the first node, the first IP And a third node for selectively assigning an address or the second IP address.
- the first node is a network computer that performs communication in a network to which the first net mask and the second net mask are applied.
- Node is a first gateway server that performs communication control between the network computers, and the third node transmits the first IP address or the second IP to the network computer. It is a DHCP server that selectively assigns addresses.
- it further comprises a fourth node communicating with the first node.
- the first IP address is an IP address used for communication between the group including one or more of the first nodes and the fourth node.
- the second IP address is an IP address for communication between any of the first node and the second node, and the first node is configured to receive the assigned first address. Communicate with the fourth node using the IP address of the second node, and the second node communicates with any of the first node using the assigned second IP address Communicate.
- the fourth node is a second gateway server that performs communication control for security measures with respect to the first node.
- the third node transmits the communication request to the first node.
- the first IP address is assigned a first net mask of a bit number less than the second net mask.
- a fifth node for communicating with the first node via the fourth node is further provided, wherein the first node is assigned the assigned The first IP address is used to further communicate with the fifth node via the fourth node.
- the fifth node provides a predetermined function to the first node via the fourth node.
- the first node requests assignment of an IP address to the third node at predetermined time intervals, and the third node assigns the IP address.
- the first IP address or the second IP address is assigned to the requested first node.
- an IP address assignment apparatus assigns an IP address used for communication in the network to a communication node performing communication in the network and a specific node other than the communication node.
- An address assignment apparatus said communication node Assigning means for requesting the reassignment of the IP address at a predetermined timing, and assigning to each of the communication nodes a general-purpose IP address that can be used for communication between any of the communication nodes; When communication between the specific node and the communication node is performed on the communication node that has requested the reassignment of the IP address in response to a request for reassignment of the IP address from the communication node. And reassigning means for reassigning the general-purpose IP address, and reassigning the particular IP address used for communication between the particular node and the communication node, otherwise.
- the reassignment unit sequentially performs all the above-mentioned operations in response to a request for IP address reassignment from the communication node.
- the specific IP address is reassigned to the communication node.
- the assigning unit assigns, to each of the communication nodes, a general-purpose IP address with a general-purpose netmask that can be used for communication between any of the communication nodes.
- the assigning means causes the communication node that has requested the reassignment of the IP address to communicate between the specific node and the communication node in response to a request for reassignment of the IP address from the communication node.
- the specific IP address with a specific netmask used for communication between the specific node and the communication node is reassigned, otherwise, for communication between any of the communication nodes. Reassign the generic IP address with a generic netmask that may be used for
- the first IP address to which the first net mask of a predetermined number of bits is attached and the second IP address of which the number of bits is different from that of the first net mask.
- a communication method for performing communication in a network in which a second IP address to which a netmask is attached is used, wherein the network includes one or more first to third nodes, respectively; Each node communicates using the first IP address or the second IP address, each second node communicates using the second IP address, and the third node A node selectively assigns the first IP address or the second IP address to the first node.
- the first IP address is an IP address used for communication between the group including one or more of the first nodes and the fourth node.
- Said second IP An address is an IP address for communication between any of the first node and the second node, the first node using the assigned first IP address. Communicating with the fourth node, wherein the second node communicates with any of the first nodes using the assigned second IP address.
- an IP address used for communication in the network is assigned to a communication node performing communication in the network and a specific node other than the communication node.
- the communication node requests re-assignment of the IP address at a predetermined timing, and transmits the general-purpose IP address that can be used for communication between any of the communication nodes.
- Communication is performed between the specific node and the communication node with respect to the communication node that has been assigned to each node and requested the reassignment of the IP address in response to a request for reassignment of the IP address from the communication node.
- it reassigns a specific IP address used for communication between the specific node and the communication node.
- the general-purpose IP address is assigned to a communication node performing communication in the network and a specific node other than the communication node.
- a first IP address to which a first net mask of a predetermined number of bits is attached and a first IP address having a number of bits different from the first net mask have A program for performing communication in a network in which a second IP address with a second network mask is used, wherein the network includes one or more first to third nodes, respectively, Performing communication using the first IP address or the second IP address in each of one node; and performing communication using the second IP address in each of the second nodes; Selectively assigning the first IP address or the second IP address to the first node at the third node. That.
- the first IP address is an IP address used for communication between the group including one or more of the first nodes and the fourth node.
- the second IP address is an IP address for communication between any one of the first nodes and the second node, and the step of performing communication at each of the first nodes is: Communication with the fourth node is performed using the assigned first IP address, and In each of the two nodes, the step of communicating performs communication with any one of the first nodes using the assigned second IP address.
- a second program according to the present invention is a program for assigning an IP address used for communication in the network to a communication node performing communication in the network and a specific node other than the communication node.
- the communication node requests reassignment of the IP address at a predetermined timing, and a general-purpose IP address that can be used for communication between any of the communication nodes, Communication between the specific node and the communication node with respect to the communication node which requested the reassignment of the IP address in response to the step of assigning to the IP address and the request of the IP address reassignment from the communication node.
- it reassigns the specific IP address used for communication between the specific node and the communication node, and The case other than, and a step of re-allocating the universal IP address to the computer.
- a computer system and its method are provided which are improved to be able to be used more flexibly than the IP address in the network.
- a computer system and method capable of easily taking measures against computer security.
- FIG. 1 is a diagram illustrating the configuration of a computer network system to which the present invention is applied.
- FIG. 2 is a first view illustrating an aspect of communication in the computer network system shown in FIG. 1.
- FIG. 2 shows a form of normal communication in the computer network system 1.
- FIG. 3 illustrates an aspect of communication in the computer network system shown in FIG. It is a 2nd figure, Comprising: The aspect of communication between 2nd GW 'clients is shown.
- FIG. 4 is a third diagram illustrating an aspect of communication in the computer network system shown in FIG. 1, and illustrates an aspect during security countermeasure communication.
- FIG. 5 A diagram exemplifying the hardware configuration of the DHCP Sano, the first GW Sano, the second GW Sano, the security countermeasure Sano, the security inspection server and the client computer shown in FIG.
- FIG. 6 is a diagram showing a client program operating on the client computer shown in FIG.
- FIG. 7 A diagram showing a DHCP server program operating on the DHCP server shown in FIG.
- FIG. 8 is a flowchart showing processing (S10) of the DHCP server program shown in FIG.
- FIG. 9 A diagram showing a GW server program operating on / off the second GW server shown in FIG.
- FIG. 10 is a diagram showing an anti-virus program 40 operating on the anti-virus server shown in FIG.
- FIG. 11 is a communication sequence diagram showing an operation (S12) at the time of normal communication (FIG. 2) in the computer network system shown in FIG.
- FIG. 12 is a communication sequence diagram showing an operation (S14) at the start of anti-virus communication (FIG. 4) in the computer network system shown in FIG.
- FIG. 13 is a communication sequence diagram showing an operation (S18) at the end of the anti-virus communication (FIG. 4) in the computer network system shown in FIG.
- FIG. 14 is a communication sequence diagram showing an operation (S18) at the end of the security countermeasure communication (FIG. 4) in the computer network system shown in FIG.
- FIG. 1 is a diagram illustrating the configuration of a computer network system 1 according to the present invention. Ru.
- client computers 10-1 to 10-n (first node; n is an integer of 1 or more), DHCP server 2 (third node) and security
- the inspection server 5 is communicably connected via a first network 100 such as a LAN or WAN.
- a second network 102 similar to the network 100 such as the security countermeasure server 4 (fifth node) and other specific nodes such as a DNS (Domain Name Server) server.
- the security countermeasure server 4 the security countermeasure server 4
- other specific nodes such as a DNS (Domain Name Server) server.
- a general first gateway server (second node; first GW server) 28, which performs processing such as protocol conversion between them, and a second gateway server 3 It is communicably connected via (the fourth node; the second GW server 3 (described later with reference to FIG. 9 and the like)).
- the networks 100 and 102 may be connected to other network systems such as another LAN, WAN, or the Internet.
- the computer network system 1 can adopt various configurations such as integrally configuring the DHCP server 2, the first GW server 28, and the security inspection server 5.
- client computer 10-1-10-n a plurality of component parts, such as the client computer 10-1-10-n, will be simply referred to as the client computer 10 when specifying one of them without specifying it.
- FIGS. 2 to 4 are first to third diagrams illustrating communication modes in computer network system 1 shown in FIG. 1, and FIG. 2 is a diagram showing normal communication in computer network system 1. 3 shows an aspect of second GW 'client communication, and FIG. 4 shows an aspect of security countermeasure communication.
- these components perform IP address assignment and communication (1) (3) using the assigned IP address as described below.
- the computer network system 1 for the first GW server 28 and the client computer 10, use an IP address with a 24-bit netmask (allowing communication with up to 256 other nodes). Communication with any other node is permitted.
- the second GW server 3 is allowed to communicate with all the other nodes by using the 22 bit netmasked IP address, and the client computer 10 Each communication with the second GW server 3 and the second GW server 3 by using an IP address with a 30-bit netmask (allowing communication with other nodes at maximum 1) Communication with other nodes is permitted.
- IP address As shown in FIG. 4, when an abnormality such as a virus infection occurs in the computer network system 1, the assignment of the IP address to the first GW server 28 remains as it is to each of the client computers 10 , IP address with a net mask (for example, 30 bits) that allows communication only with the security countermeasure server via the second GW server 3 is assigned.
- a net mask for example, 30 bits
- the security measures are simultaneously implemented for all the client computers 10 (during security countermeasure communication).
- the number of bits of the net mask may be any value other than 24 and 30.
- the IP address assigned to the client computer 10 during normal communication (FIG. 2) is attached.
- the number of bits of the netmask is 24 and the number of bits of the netmask attached to the IP address assigned to the client computer 10 at other times (FIGS. 3 and 4) is 30, the first GW server 28
- a specific example is when the number of bits of the netmask assigned to the assigned IP address is always 24 and the number of bits of the netmask assigned to the IP address assigned to the second GW server 3 is always 22.
- FIG. 5 exemplifies the hardware configuration of the DHCP server 2, the first GW server 28, the second GW server 3, the security countermeasure server 4, the security inspection server 5, the client computer 10 and the other node 18 shown in FIG. 1.
- FIG. 5 exemplifies the hardware configuration of the DHCP server 2, the first GW server 28, the second GW server 3, the security countermeasure server 4, the security inspection server 5, the client computer 10 and the other node 18 shown in FIG. 1.
- each node of the computer network system 1 is a computer main body 120 including a CPU 122 and a memory 124, a display device 'display device 126 including a display device' keyboard and the like, and other nodes via a network 100. And a communication device 128 for communicating with each other, and a recording device 130 such as an HD device 'CD device.
- each node of the computer network system 1 includes components as computers capable of communicating with other nodes via the networks 100 and 101.
- Each program shown below is supplied to each node via, for example, the recording medium 132 (FIG. 5), loaded into the memory 124, and generally, on an operating system (OS) operating on each node. It is executed by specifically using the hardware of each node.
- OS operating system
- FIG. 6 is a diagram showing a client program 14 operating on the client computer 10 shown in FIG.
- the client program 14 comprises a DHCP client unit 140, a communication processing unit 150, an application program (AP) 160, and a user interface (UI) unit 162.
- a DHCP client unit 140 the client program 14 comprises a DHCP client unit 140, a communication processing unit 150, an application program (AP) 160, and a user interface (UI) unit 162.
- AP application program
- UI user interface
- the client program 14 receives an IP address assignment from the DHCP server 2, communicates with other nodes, and provides various functions to the user.
- the DHCP client unit 140 realizes a function as a general DHCP client in accordance with DHCP.
- the DHCP client unit 140 requests the client program 14 for an IP address, and in response to this request, receives an IP address assigned from the DHCP server 2 and its net mask (24-bit general purpose net mask).
- the DHCP client unit 140 requests the DHCP server 2 to reassign an IP address at predetermined intervals (for example, every few minutes) according to the setting from the DHCP server 2, and according to this request, the DHCP server 2.
- the IP address reassigned from 2 and its net mask (general net mask for normal communication (Fig. 2), and 30-bit specific net mask for other (security countermeasure communication; Fig. 4 for other measures) receive.
- the DHCP client unit 140 receives from the DHCP server 2 an IP address of the DHCP server 2, an IP address of the first GW server 28 and an IP address of the second GW server 3, an interval for reassignment request and It further receives information required for communication in the computer network system 1, such as the IP address of the DNS server.
- the communication processing unit 150 communicates with other nodes using the IP address and the net mask input from the DHCP client unit 140 in the manner shown in FIGS. That is, when the number of bits of the net mask input from the DHCP client unit 140 is 24 in the client computer 10, as shown in FIG. 2, the communication processing unit 150 communicates with any other node. Communicate.
- the communication processing unit 150 transmits the client computer 10 via the DHCP server 2 in the manner shown in FIG. Communicate with the security countermeasure server 4.
- the AP 160 provides application functions such as a web browser and a word processor to the user.
- the UI unit 162 accepts the user's operation on the display and input device 126 (FIG. 5) etc., and outputs the accepted user's operation to other component parts.
- the UI unit 162 controls the processing of other components according to the received operation. Also, the UI unit 162 displays information obtained as a result of processing of other component parts on the display / input device 126 and shows it to the user.
- FIG. 7 is a diagram showing a DHCP server program 20 operating in the DHCP server 2 shown in FIG.
- the DHCP server program 20 comprises a UI unit 162, communication switching control 200, security countermeasure control unit 210, normal communication control unit 212, DHCP server processing unit 22 and communication processing unit 150. .
- the DHCP server unit 22 includes a DHCP server processing unit 220, an information management unit network management unit 230, a network database (network DB) 232, an IP address management unit 240, an IP address DB 242, a net mask management unit 250, a net mask table 252, It comprises a reallocation cycle management unit 260 and a reallocation cycle DB 262.
- the DHCP server 20 provides each node of the computer network system 1 with a general DHCP server function in accordance with DHCP. That is, the DHCP server program 20 performs normal communication (FIG. 2) in the computer network system 1, and when security measures (FIG. 4) in the computer network system 1 are successfully completed.
- the client computer 10 is assigned a general-purpose IP address with a 24-bit general-purpose netmask.
- the DHCP server program 20 connects all the client computers 10 to the security countermeasure server 4 via the second GW server 3 when security communication (FIG. 4) is being performed in the computer network system 1. Security measures for the client computer 10.
- the communication switching control unit 200 activates the normal communication control unit 212 when normal communication (FIG. 2) is performed in the computer network system 1.
- the communication switching control unit 200 activates the security countermeasure control unit 210.
- the timing at which the communication switching control unit 200 starts up the security countermeasure control unit 210 is as follows:
- P server unit 22 controls each client computer 10 to reassign a specific IP address to which a specific net mask is attached when reassigning an IP address.
- the normal communication control unit 212 controls the DHCP server unit 22 when activated by the communication switching control unit 200, and transmits a general-purpose IP address with a general-purpose net mask to each node of the computer network system 1. Assign
- the network management unit 230 manages information of the computer network caching system 1 used for the DHCP processing, and stores it in the network DB 232.
- the network management unit 230 provides the stored information of the computer network system 1 according to the necessity of the process in the DHCP server processing unit 220.
- the IP address management unit 240 stores an IP address which can be assigned or reassigned to each node of the computer network system 1 in the IP address DB 242, and manages the stored IP address.
- the IP address management unit 240 provides the stored IP address according to the necessity of the process in the DHCP server processing unit 220.
- the net mask management unit 250 stores and manages, in the net mask table 252, a general purpose net mask used in normal communication and a specific net mask used in security countermeasure communication.
- the netmask management unit 250 provides the stored netmask as required by the processing in the DHCP server processing unit 220.
- the reallocation cycle management unit 260 stores the reallocation cycle of the IP address set for each node of the computer network system 1 in the reallocation cycle DB 262 and manages the allocation cycle when it is stored.
- the reallocation cycle management unit 260 provides the stored net mask according to the necessity of processing in the DHCP server processing unit 220.
- the DHCP server processing unit 220 is controlled by the network management unit 230, the IP address management unit 240, and the network manager according to the control of the security countermeasure control unit 210 or the normal communication control unit 212.
- An IP address is assigned to each node of the computer network system 1 using the information provided from the screen management unit 250 and the reallocation cycle management unit 260.
- the DHCP server processing unit 220 assigns and reassigns a general-purpose IP address to each client computer 10 under the control of the normal communication control unit 212.
- the DHCP server processing unit 220 reassigns the specific IP address to the client computer 10 according to the control of the security countermeasure control unit 210.
- the DHCP server processing unit 220 sets the IP address reassignment cycle to each node of the computer network system 1, notifies the client computer 10 of the IP address of the first GW server 28, the second GW server 3 and the DHCP server 2. Also, it performs notification of IP address of DNS server to each node of computer network system 1, etc.
- FIG. 8 is a flowchart showing the process (S 10) of the DHCP server program 20 shown in FIG.
- step 100 the communication switching control unit 200 of the DHCP server 2 is notified by the user of the DHCP server 2 or the security inspection server 5 that the computer network system 1 is It is necessary to determine the security measures required by
- the DHCP server program 20 proceeds to the process of S102 when security measures are required, and otherwise proceeds to the process of S110.
- step 102 the communication switching control unit 200 of the DHCP server 2 performs the security measures in the computer network system 1 by the user operation of the DHCP server 2 or the end of the processing in the security inspection server 5. Determine if it has completed.
- the DHCP server program 20 proceeds to the process of S110 when the security measure is finished, and proceeds to the process of S104 otherwise.
- step 104 the communication switching control unit 200 activates the security countermeasure control unit 210.
- the security countermeasure control unit 210 controls the DHCP server unit 22 to cause the client computer 10 to assign an IP address (specific IP address) used for security countermeasure.
- step 110 the communication switching control unit 200 activates the normal communication control unit 212.
- the normal communication control unit 212 controls the DHCP server unit 22 to cause the client computer 10 to assign and reassign an IP address (general-purpose IP address) used for normal communication.
- IP address general-purpose IP address
- processing of the DHCP server program 20 shown in FIG. 8 can be selectively performed on some of the client computers 10 that can be uniformly performed on all of the client computers 10.
- FIG. 9 is a diagram showing a GW server program 30 operating in the second GW server 3 shown in FIG.
- the GW2 server program 30 includes a communication processing unit 150, a UI unit 162, a communication switching control unit 300, a normal communication control unit 312, a security countermeasure control unit 310, and a GW server unit 32. .
- the GW server unit 32 includes a GW server processing unit 320, a network management unit 330, a network DB 332, an IP address management unit 340, an IP address DB 342, a net mask management unit 350, and a net mask table 352.
- the GW server program 30 connects between the client computer 10 and the security countermeasure server 4 at the time of anti-virus communication, and performs communication between them.
- the communication switching control unit 300 activates the security countermeasure control unit 310 when the security countermeasure communication (FIG. 4) is performed in the computer network access system 1.
- the timing when the communication switching control unit 300 activates the security countermeasure control unit 310 is the same as the timing when the communication switching control unit 200 of the DHCP server program 20 (FIG. 7) activates the security countermeasure control unit 210.
- the security countermeasure control unit 310 controls the GW server unit 32 to cause the client computer 10 to provide the functions required for security countermeasure communication. .
- the network management unit 330 manages information of the computer network system 1 used for processing as a GW server, and stores the information in the network DB 332.
- the network management unit 330 provides the stored information of the computer network system 1 in accordance with the necessity of processing in the GW server processing unit 320.
- the IP address management unit 340 stores in the IP address DB 342 an IP address that is assigned to the GW client computer 10 and used for processing as a GW server, and manages the stored IP address.
- the IP address management unit 340 provides the stored IP address according to the necessity of processing in the GW server processing unit 320.
- Net mask management unit 350 stores, in net mask table 352, a general-purpose net mask used during normal communication and a specific net mask used during anti-virus communication.
- the net mask management unit 350 provides the stored net mask according to the necessity of processing in the GW server processing unit 320.
- GW server processing unit 320 serves as a firewall, database, program server, etc. in addition to the processing required to connect client computer 10 and the security countermeasure server.
- the other functions of are suitably provided to the client computer 10.
- FIG. 10 is a diagram showing a security countermeasure program 40 operating on the security countermeasure server 4 shown in FIG.
- the security countermeasure program 40 comprises a communication processing unit 150, a UI unit 162, a security countermeasure unit 400, a network management unit 430, a network DB 432, an IP address management unit 440 and an IP address DB 442.
- the security countermeasure program 40 has a computer network by these components. At the time of security measures communication in the system 1 (FIG. 4), security measures for the client computer 10 are performed.
- the network management unit 430 manages information of the computer network system 1 used for security measures, and stores the information in the network DB 432.
- the network management unit 430 provides the stored information of the computer network system 1 according to the need for processing in the security countermeasure unit 400.
- the IP address management unit 440 stores in the IP address DB 442 an IP address assigned to the GW client computer 10 and used for security measures, and manages the stored IP address.
- the IP address management unit 340 provides the stored IP address according to the necessity of the process in the security countermeasure unit 400.
- the security countermeasure unit 400 is sequentially connected to the client computer 10 to perform communication, and performs security countermeasure on the client computer 10.
- FIG. 11 is a view showing a security inspection program 50 operating on the security inspection server 5 shown in FIG.
- the security inspection program 50 includes a communication processing unit 150 and a UI unit 162. , Security inspection unit 500, other node control unit 510, network management unit 530, network DB 532, IP address management unit 540, and IP address DB 542.
- the security inspection program 50 performs security inspection (such as detection of computer viruses) on the client computer 10 at all times in the computer system 1.
- the communication processing unit 150 receives the security related information from the client computer 10 and notifies the security inspection unit 500.
- the security inspection unit 500 periodically processes the security related information received from the communication processing unit 150 to perform security inspection of the client computer 10.
- the security inspection unit may have detected (failed) a security problem (such as a virus infection) on one or more of the client computers 10 as a result of the security inspection, or a security condition problem on any of the client computers 10.
- the other node control unit 510 is notified whether it has passed or not.
- the other node control unit 510 controls the DHCP server 2, the second GW server 3 and the anti-virus according to the user's operation on the security inspection server 5 or according to the result of the security inspection by the security inspection unit 500.
- the server 4 is controlled to perform processing for security measures or its termination.
- FIG. 12 is a communication sequence diagram showing an operation (S12) at the time of normal communication (FIG. 2) in the computer network system 1 shown in FIG.
- step 130-1 130-n the client computer 10-1-10-n sequentially requests an IP address from the DHCP server 2.
- step 132-1-132-n the DHCP server 2 sequentially assigns a general-purpose IP address to the client computer 10-1-10-n.
- the first GW server 28 and the client computer 10 are divided by the DHCP server 2 Communicate with any other node using the assigned general IP address.
- FIG. 13 is a communication sequence diagram showing an operation (S14) at the start of the security countermeasure communication (FIG. 4) in the computer network system 1 shown in FIG.
- step 140, 142 (S140, S 142) ⁇
- the security inspection server 5 fails when the security inspection on the client computer 10 is failed. Notify DHCP server 2 and second GW server 3 of the start of security measures.
- step 150-1-150-n (S 150-1-S 150-n), the client computer 10-1-10-n to which the general-purpose IP address is assigned by the process of S 12 is sequentially transmitted to the DH CP server 2. Request an IP address reassignment.
- step 152-1-152-n the DHCP server 2 sequentially assigns specific IP addresses to the client computer 10-1-10-n.
- the client computer 10 to which the specific IP address is reassigned communicates with the security countermeasure server via the second GW server 3 and receives the security countermeasure by the security countermeasure server 4.
- FIG. 14 is a communication sequence diagram showing an operation (S18) at the end of the security countermeasure communication (FIG. 4) in the computer network system 1 shown in FIG.
- Fig. 14 This, ⁇ Steps 180, 182 (S180, S182) ⁇ The security inspection server 5 that has judged that the security inspection for the client computer 10 has passed the DHCP server 2 and the DHCP server 2 Notify the second GW server 3 that security measures have been completed.
- Step 190-1-190-n (S 190-1-S 190-n) [Process of S14 [This is a client computer to which a specific IP address is assigned 10-1 10-n Requests that the DH CP server 2 reassign an IP address sequentially.
- step 192-1-192-n the DHCP server 2 sequentially assigns a general-purpose IP address to the client computer 10-1-10-n.
- the client computer 10 to which the general-purpose IP address is reassigned resumes communication with any other node.
- the present invention can be utilized for IP address assignment in a computer network, virus countermeasure, and the like.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Health & Medical Sciences (AREA)
- General Health & Medical Sciences (AREA)
- Virology (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
- Small-Scale Networks (AREA)
Abstract
Description
Claims
Priority Applications (3)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| PCT/JP2004/014067 WO2006035478A1 (ja) | 2004-09-27 | 2004-09-27 | コンピュータシステムおよびその方法 |
| JP2006537572A JP4219956B2 (ja) | 2004-09-27 | 2004-09-27 | コンピュータシステムおよびその方法 |
| US11/576,045 US7761539B2 (en) | 2004-09-27 | 2004-09-27 | Computer system and method thereof |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| PCT/JP2004/014067 WO2006035478A1 (ja) | 2004-09-27 | 2004-09-27 | コンピュータシステムおよびその方法 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2006035478A1 true WO2006035478A1 (ja) | 2006-04-06 |
Family
ID=36118630
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/JP2004/014067 Ceased WO2006035478A1 (ja) | 2004-09-27 | 2004-09-27 | コンピュータシステムおよびその方法 |
Country Status (3)
| Country | Link |
|---|---|
| US (1) | US7761539B2 (ja) |
| JP (1) | JP4219956B2 (ja) |
| WO (1) | WO2006035478A1 (ja) |
Cited By (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JPWO2025004260A1 (ja) * | 2023-06-29 | 2025-01-02 |
Families Citing this family (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| DE102005060601A1 (de) * | 2005-12-17 | 2007-06-21 | Dr. Johannes Heidenhain Gmbh | Verfahren zur Inbetriebnahme einer numerischen Steuerung für Werkzeug- oder Produktionsmaschinen |
| US7966650B2 (en) * | 2008-02-22 | 2011-06-21 | Sophos Plc | Dynamic internet address assignment based on user identity and policy compliance |
| US9350754B2 (en) | 2013-07-18 | 2016-05-24 | Lenovo Enterprise Solutions (Singapore) Pte. Ltd. | Mitigating a cyber-security attack by changing a network address of a system under attack |
| JP6364999B2 (ja) * | 2014-06-24 | 2018-08-01 | ブラザー工業株式会社 | 通信システム、サーバ装置、及びクライアント装置 |
| US9392019B2 (en) | 2014-07-28 | 2016-07-12 | Lenovo Enterprise (Singapore) Pte. Ltd. | Managing cyber attacks through change of network address |
Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2001326696A (ja) * | 2000-05-18 | 2001-11-22 | Nec Corp | アクセス制御方法 |
| JP2003234755A (ja) * | 2002-02-07 | 2003-08-22 | Nec Corp | ネットワーク管理装置及びアドレス割り当て方法 |
| JP2003273889A (ja) * | 2002-03-12 | 2003-09-26 | Kita Denshi Corp | サブネットマスク設定装置、サブネットマスク設定方法及びサブネットマスク設定プログラム |
| JP2004064379A (ja) * | 2002-07-29 | 2004-02-26 | Nec Corp | ルータ装置およびプログラム |
Family Cites Families (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US5812819A (en) * | 1995-06-05 | 1998-09-22 | Shiva Corporation | Remote access apparatus and method which allow dynamic internet protocol (IP) address management |
| US6982953B1 (en) * | 2000-07-11 | 2006-01-03 | Scorpion Controls, Inc. | Automatic determination of correct IP address for network-connected devices |
| JP4002844B2 (ja) | 2003-01-21 | 2007-11-07 | 株式会社エヌ・ティ・ティ・ドコモ | ゲートウェイ装置及びネットワーク接続方法 |
| US7318101B2 (en) * | 2003-11-24 | 2008-01-08 | Cisco Technology, Inc. | Methods and apparatus supporting configuration in a network |
-
2004
- 2004-09-27 WO PCT/JP2004/014067 patent/WO2006035478A1/ja not_active Ceased
- 2004-09-27 JP JP2006537572A patent/JP4219956B2/ja not_active Expired - Fee Related
- 2004-09-27 US US11/576,045 patent/US7761539B2/en not_active Expired - Fee Related
Patent Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2001326696A (ja) * | 2000-05-18 | 2001-11-22 | Nec Corp | アクセス制御方法 |
| JP2003234755A (ja) * | 2002-02-07 | 2003-08-22 | Nec Corp | ネットワーク管理装置及びアドレス割り当て方法 |
| JP2003273889A (ja) * | 2002-03-12 | 2003-09-26 | Kita Denshi Corp | サブネットマスク設定装置、サブネットマスク設定方法及びサブネットマスク設定プログラム |
| JP2004064379A (ja) * | 2002-07-29 | 2004-02-26 | Nec Corp | ルータ装置およびプログラム |
Cited By (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JPWO2025004260A1 (ja) * | 2023-06-29 | 2025-01-02 | ||
| WO2025004260A1 (ja) * | 2023-06-29 | 2025-01-02 | 三菱電機株式会社 | アドレス設定装置、冷凍サイクルシステムおよびアドレス設定方法 |
Also Published As
| Publication number | Publication date |
|---|---|
| US7761539B2 (en) | 2010-07-20 |
| US20080059615A1 (en) | 2008-03-06 |
| JP4219956B2 (ja) | 2009-02-04 |
| JPWO2006035478A1 (ja) | 2008-07-31 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US8312270B1 (en) | DHCP-based security policy enforcement system | |
| JP5276073B2 (ja) | ストレージシステム、ストレージ制御方法及びストレージ制御プログラム | |
| US8001245B2 (en) | System and method for autonomically configurable router | |
| US7698388B2 (en) | Secure access to remote resources over a network | |
| US7831692B2 (en) | Method and system for automatically associating an address with a target device | |
| US20020138614A1 (en) | Method and apparatus to manage network addresses | |
| US7734738B2 (en) | Automatic configuration of client and server networking | |
| US20200366648A1 (en) | Configuring hostname based firewall policies | |
| JP2019512791A (ja) | クラウド環境における動的かつ一時的な仮想マシンインスタンスの保護 | |
| JP2009009566A (ja) | アクセス制御システムおよびアクセス制御方法 | |
| CN107257332B (zh) | 大型防火墙集群中的定时管理 | |
| CN118043784B (zh) | 提供商网络中的分布式数据处理应用程序服务 | |
| JP2006262141A (ja) | Ipアドレス適用方法、vlan変更装置、vlan変更システム、および検疫処理システム | |
| JP2008504776A (ja) | 動的デバイスアドレス管理のための方法およびシステム | |
| WO2006035478A1 (ja) | コンピュータシステムおよびその方法 | |
| JP2004030204A (ja) | 負荷分散装置及びそれに接続するノードコンピュータ | |
| US7752317B1 (en) | Workstation virus lockdown in a distribution environment | |
| US20040139226A1 (en) | Method for assigning an IP address to a network connectable device | |
| US20080127168A1 (en) | Setup of workloads across nodes | |
| JP2009157435A (ja) | ライセンス管理装置及びライセンス管理方法 | |
| US20070100977A1 (en) | Methods and apparatus for re-provisioning a server of a data center | |
| CN109218265A (zh) | 四层分布式拒绝服务攻击检测方法及装置 | |
| JP4255451B2 (ja) | 代理サーバ割り当てシステム、代理サーバ割り当て方法、ネットワークシステム、およびプログラム | |
| CN100562025C (zh) | 基于全局地址池的dhcp池策略的创建方法及管理方法 | |
| JP7484624B2 (ja) | ネットワーク制御装置およびプログラム |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| AK | Designated states |
Kind code of ref document: A1 Designated state(s): AE AG AL AM AT AU AZ BA BB BG BR BW BY BZ CA CH CN CO CR CU CZ DE DK DM DZ EC EE EG ES FI GB GD GE GH GM HR HU ID IL IN IS JP KE KG KP KR KZ LC LK LR LS LT LU LV MA MD MG MK MN MW MX MZ NA NI NO NZ OM PG PH PL PT RO RU SC SD SE SG SK SL SY TJ TM TN TR TT TZ UA UG US UZ VC VN YU ZA ZM ZW |
|
| AL | Designated countries for regional patents |
Kind code of ref document: A1 Designated state(s): BW GH GM KE LS MW MZ NA SD SL SZ TZ UG ZM ZW AM AZ BY KG KZ MD RU TJ TM AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HU IE IT LU MC NL PL PT RO SE SI SK TR BF BJ CF CG CI CM GA GN GQ GW ML MR NE SN TD TG |
|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application | ||
| WWE | Wipo information: entry into national phase |
Ref document number: 2006537572 Country of ref document: JP |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 11576045 Country of ref document: US |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase | ||
| WWP | Wipo information: published in national office |
Ref document number: 11576045 Country of ref document: US |