Information processing device, information processing method, and computer-readable recording medium

By designing an information processing device in the information system, analyzing the communication path of the equipment and the application of the exempted security evaluation project, and selecting appropriate security evaluation projects, the problem of the inability to select appropriate security evaluation projects based on the characteristics of the equipment in the prior art is solved, and more efficient and targeted security evaluation is achieved.

CN113168471BActive Publication Date: 2025-05-16MITSUBISHI ELECTRIC CORP
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN201880099828.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2018-12-03
Publication Date
2025-05-16
Estimated Expiration
2038-12-03

AI Technical Summary

Technical Problem

The prior art applies the same security evaluation items to all devices in the information system, and cannot select appropriate security evaluation items based on the characteristics of the device, resulting in the inability to select appropriate security evaluation items corresponding to the characteristics of the device.

Method used

An information processing device is designed, including a candidate acquisition unit and a project selection unit. The candidate acquisition department obtains multiple candidate security evaluation items. The project selection department analyzes the communication path of the equipment and whether there is an application of the exempted security evaluation item, and selects an appropriate security evaluation item based on the analysis results.

Benefits of technology

It realizes the selection of appropriate safety evaluation items based on the characteristics of the equipment, improves the pertinence and efficiency of safety evaluation, and avoids useless safety evaluation items for unwanted equipment applications.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113168471B_ABST
    Figure CN113168471B_ABST
Patent Text Reader

Abstract

The evaluation item generation unit (107) obtains a plurality of candidates for security evaluation items applied to a plurality of devices included in the information system. In addition, the evaluation item generation unit (107) analyzes whether each of the plurality of devices has a communication path with an external communication device that is a device within the information system and communicates with the outside of the information system, and whether each of the plurality of devices has at least one security evaluation item that is exempted from application due to application to other devices within the information system, and selects a security evaluation item to be applied from the plurality of candidates for security evaluation items for each of the plurality of devices based on the analysis result.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The invention relates to a security evaluation of an information system. Background Art

[0002] Patent document 1 discloses that a management monitoring program is executed in a device that is a target of security evaluation in an information system. Then, the management monitoring program obtains information such as the version of software installed in the device. In addition, an inspection device different from the device that is the target of security evaluation performs security evaluation on the device based on the information obtained by the management monitoring program.

[0003] Patent Document 2 discloses a technique in which a client device sends a set security level to a server. The server then returns a determination result on the security level to the client device, thereby evaluating the security measures of the client device.

[0004] Patent Document 1: Japanese Patent Application Publication No. 2001-273388

[0005] Patent Document 2: Japanese Patent Application Publication No. 2014-106920 Summary of the invention

[0006] Problem that the invention aims to solve

[0007] In the techniques of Patent Documents 1 and 2, the same safety evaluation items are applied to all devices to be subject to safety evaluation. However, since each device has different characteristics, it is desirable to select appropriate safety evaluation items according to the characteristics of each device.

[0008] For example, the possibility of being attacked from the outside is greatly different between a device that has the possibility of communicating with the outside of the information system and a device that has no possibility of communicating with the outside of the information system.

[0009] In addition, there is a security evaluation item that can be exempted from application to another device (hereinafter referred to as device B) if it is applied to a certain device in the information system (hereinafter referred to as device A). In such a case, if the security evaluation item is applied to device A and device B, useless processing will occur for device B.

[0010] In the techniques of Patent Documents 1 and 2, the same safety evaluation items are applied to all devices, so there is a problem that appropriate safety evaluation items cannot be selected according to the characteristics of the devices.

[0011] One of the main objects of the present invention is to solve such a problem. More specifically, the main object of the present invention is to enable selection of appropriate safety evaluation items according to the characteristics of a device.

[0012] Solutions for solving problems

[0013] The information processing device involved in the present invention has:

[0014] a candidate acquisition unit that acquires a plurality of candidates for security evaluation items applied to a plurality of devices included in the information system; and

[0015] The project selection unit analyzes whether each of the multiple devices has a communication path with an external communication device that is a device within the information system and communicates with the outside of the information system, and whether each of the multiple devices has at least one security assessment item that is exempted from application due to application to other devices within the information system, and based on the analysis results, selects a security assessment item to be applied from multiple security assessment item candidates for each of the multiple devices.

[0016] Effects of the Invention

[0017] In the present invention, the security evaluation items are selected for each device in consideration of at least one of the possibility of communication with the outside of the information system and the possibility of being exempted from the application of the security evaluation items due to application to other devices in the information system. Therefore, according to the present invention, appropriate security evaluation items can be selected according to the characteristics of the device. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] Figure 1 This is a diagram showing an example of the functional configuration of the inspection device according to the first embodiment.

[0019] Figure 2 This is a diagram showing a hardware configuration example of the inspection device according to the first embodiment.

[0020] Figure 3 This is a flowchart showing an example of the operation of the inspection device according to the first embodiment.

[0021] Figure 4 This is a flowchart showing an example of the operation of the inspection device according to the first embodiment.

[0022] Figure 5 This is a diagram showing an example of a structure tree according to the first embodiment.

[0023] Figure 6 This is a diagram showing an example of system information involved in Implementation Example 1.

[0024] Figure 7 This is a flowchart showing an example of the operation of the inspection device according to the first embodiment.

[0025] Figure 8This is a diagram showing examples of safety evaluation items according to the first embodiment.

[0026] Fig. 9 This is a diagram showing an example of a security policy check list according to the first embodiment.

[0027] Fig.10 This is a flowchart showing an example of the operation of the inspection device according to the first embodiment.

[0028] Fig.11 This is a flowchart showing an example of the operation of the inspection device according to the first embodiment.

[0029] Fig.12 This is a diagram showing an example of a functional configuration of an inspection device according to the second embodiment.

[0030] Fig.13 This is a flowchart showing an example of the operation of the inspection device involved in the second embodiment.

[0031] Fig.14 This is a flowchart showing an example of the operation of the inspection device involved in the second embodiment.

[0032] (Explanation of Reference Numerals)

[0033] 100: Inspection device; 101: Network information; 102: Equipment information; 103: System information generation unit; 104: System information; 105: Security evaluation items; 106: Candidate security evaluation items; 107: Evaluation item generation unit; 108: Select security evaluation items; 109: Active scanning unit; 110: Active scanning results; 111: Security evaluation unit; 112: Security evaluation results; 201: Processor; 202: Communication device; 203: Storage device; 701: Security evaluation history record data; 702: Implemented evaluation items; 703: Implemented security evaluation results; 901: Security policy checklist. DETAILED DESCRIPTION

[0034] Hereinafter, embodiments of the present invention will be described using drawings. In the following description of the embodiments and drawings, parts with the same reference numerals represent the same parts or corresponding parts.

[0035] Implementation method 1.

[0036] ***Description of the structure***

[0037] In this embodiment, a configuration for selecting a security evaluation item to be applied to a plurality of devices included in an information system is described. Hereinafter, the security evaluation item is also referred to simply as an evaluation item.

[0038] In this embodiment, a control system is used as an example of an information system. In the control system, PLC (Programmable Logic Controller), HMI (Human Machine Interface), field devices, etc. are connected via Ethernet (registered trademark) or a control network.

[0039] Hereinafter, PLC, HMI, field devices, etc. included in the control system are collectively referred to as devices or evaluation target devices.

[0040] Figure 1 A functional configuration example of the inspection device 100 according to the present embodiment is shown.

[0041] in addition, Figure 2 A hardware configuration example of the inspection device 100 is shown.

[0042] The inspection device 100 selects a safety evaluation item for each of the plurality of devices included in the control system.

[0043] The inspection device 100 may be a device constituting the control system, or may be a device not included in the control system.

[0044] The inspection device 100 is an example of an information processing device. In addition, the operation performed by the inspection device 100 is an example of an information processing method and an information processing program.

[0045] like Figure 1 As shown, the inspection device 100 includes a system information generating unit 103 , an evaluation item generating unit 107 , an active scanning unit 109 , and a security evaluating unit 111 .

[0046] Each part is described below.

[0047] The system information generation unit 103 acquires the network information 101 and the device information 102 and generates the system information 104. Then, the system information generation unit 103 outputs the generated system information 104 to the evaluation item generation unit 107 and the security evaluation unit 111.

[0048] The network information 101 indicates the network structure and connection relationship in the control system. The device information 102 indicates the status, function, communication address, etc. of each device included in the control system.

[0049] The system information 104 shows, for each device, a communication path from the device to the inspection apparatus 100, a communication path from the device to an external communication device, etc. The external communication device is a device in the control system that communicates with the outside of the control system. Figure 6This shows an example of the system information 104. The details of the system information 104 will be described later.

[0050] The evaluation item generation unit 107 acquires the system information 104, the candidate security evaluation items 106, and the security policy checklist 901. Then, the evaluation item generation unit 107 generates the selected security evaluation item 108 based on the system information 104, the candidate security evaluation items 106, and the security policy checklist 901. Then, the evaluation item generation unit 107 outputs the selected security evaluation item 108 to the active scanning unit 109 and the security evaluation unit 111.

[0051] The selected safety evaluation items 108 are safety evaluation items selected for each device.

[0052] The candidate safety evaluation item 106 is a candidate of a safety evaluation item extracted from the safety evaluation item 105 . Figure 8 106 shows an example of the candidate safety evaluation item 106. The details of the candidate safety evaluation item 106 will be described later. The evaluation item generation unit 107 acquires a plurality of candidate safety evaluation items 106 for a plurality of devices.

[0053] The safety evaluation items 105 are all safety evaluation items applicable to the control system. The candidate safety evaluation items 106 are candidates for safety evaluation items that are selected from the safety evaluation items 105 according to the characteristics of the control system and that are likely to be applied to the equipment included in the control system. The selection of the candidate safety evaluation items 106 from the safety evaluation items 105 can be performed manually by the user of the inspection device 100 or by the user of the inspection device 100. Figure 1 The security evaluation items 105 are stored in a database outside the inspection device 100. The security evaluation items 105 may be stored on the Internet, for example.

[0054] The safety policy checklist 901 shows a selection criterion for selecting the selected safety evaluation item 108 from the plurality of candidate safety evaluation items 106. The safety policy checklist 901 is generated by a user of the inspection device 100, for example. Fig. 9 This shows an example of the security policy check list 901. The details of the security policy check list 901 will be described later.

[0055] The evaluation item generation unit 107 acquires candidates of safety evaluation items applied to a plurality of devices included in the control system as candidate safety evaluation items 106 . The evaluation item generation unit 107 corresponds to a candidate acquisition unit.

[0056] In addition, the evaluation item generation unit 107 selects the safety evaluation item to be applied for each device, and the evaluation item generation unit 107 is equivalent to the item selection unit. More specifically, the evaluation item generation unit 107 analyzes at least one of the following situations: whether each device has a communication path with an external communication device; and whether each device has a safety evaluation item that is exempted from application due to application to other devices in the control system. Based on the analysis results, the evaluation item generation unit 107 selects the safety evaluation item to be applied from the candidates of the safety evaluation item for each device.

[0057] Note that the operation performed by the evaluation item generating unit 107 corresponds to the candidate acquisition process and the item selection process.

[0058] The active scanning unit 109 acquires the selected security evaluation item 108 and performs an active scan on each device using the selected security evaluation item 108. Then, the active scanning unit 109 outputs the result of the active scan as an active scan result 110 to the security evaluation unit 111.

[0059] The security evaluation unit 111 acquires the system information 104 , selects the security evaluation items 108 and the active scanning results 110 , evaluates the security setting status of each device, and outputs the evaluation result as a security evaluation result 112 .

[0060] Next, refer to Figure 2 The hardware structure of the inspection device 100 will be described.

[0061] ***Description of the structure***

[0062] The inspection device 100 according to the present embodiment is a computer.

[0063] The inspection device 100 includes a processor 201 , a communication device 202 , and a storage device 203 as hardware.

[0064] The storage device 203 stores the implementation Figure 1 The system information generation unit 103, the evaluation item generation unit 107, the active scanning unit 109 and the security evaluation unit 111 are shown as functional programs.

[0065] The processor 201 executes these programs to perform operations of the system information generation unit 103 , the evaluation item generation unit 107 , the active scanning unit 109 , and the security evaluation unit 111 .

[0066] exist Figure 2 , a state in which the processor 201 is executing a program that realizes the functions of the system information generation unit 103 , the evaluation item generation unit 107 , the active scanning unit 109 , and the security evaluation unit 111 is schematically shown.

[0067] The communication device 202 receives the Figure 1 The communication device 202 is used when the network information 101, device information 102, and security evaluation item 105 shown are displayed. In addition, it is used when the active scanning unit 109 performs active scanning. In addition, the communication device 202 is used when the security evaluation result 112 is sent to an external device. Therefore, the communication device 202 has an interface corresponding to Ethernet (registered trademark), a control network protocol, etc. The communication device 202 has one or more such interfaces as needed.

[0068] ***Description of the action***

[0069] Next, use Figure 3 An operation example of the inspection device 100 will be described.

[0070] Figure 3 FIG. 1 is an example of the operation of the inspection device 100. The operation flow of the inspection device 100 need not be as follows. Figure 3 shown.

[0071] When a security evaluation request is received from a user of the inspection device 100 , the system information generation unit 103 acquires the network information 101 and the device information 102 in step S1001 .

[0072] Next, in step S1002 , the system information generation unit 103 generates the system information 104 using the network information 101 and the device information 102 .

[0073] Note that the details of the process of generating the system information 104 in step S1002 will be described later.

[0074] Next, in step S1003, the evaluation item generation unit 107 acquires the candidate safety evaluation items 106 and the safety policy check list 901. In addition, the evaluation item generation unit 107 also acquires the system information 104.

[0075] Next, in step S1004, the evaluation item generation unit 107 selects a security evaluation item for each device based on the system information 104, the candidate security evaluation items 106, and the security policy checklist 901. Then, the evaluation item generation unit 107 outputs the selected security evaluation item 108 indicating the selection result to the active scanning unit 109 and the security evaluation unit 111.

[0076] The details of the safety evaluation item selection process in step S1004 will be described later.

[0077] In step S1005 , the active scanning unit 109 checks whether active scanning is necessary for each device with respect to the selected security evaluation item 108 .

[0078] If active scanning is required (YES in step S1005 ), the process proceeds to step S1006 . On the other hand, if active scanning is not required (NO in step S1005 ), the process proceeds to step S1007 .

[0079] In step S1006 , the active scanning unit 109 performs active scanning in order to acquire information on an evaluation target required in the evaluation method described in the corresponding safety evaluation item.

[0080] Note that the details of the active scan execution process in step S1006 will be described later.

[0081] In step S1007 , the security evaluation unit 111 evaluates the security setting status of each device using the device information 102 , the selected security evaluation items 108 , and the active scan results 110 .

[0082] Note that the details of the safety evaluation process in step S1007 will be described later.

[0083] When the evaluation of all the safety evaluation items of the selected safety evaluation item 108 is completed ("Yes" in step S1009), in step S1010, the safety evaluation unit 111 outputs the safety evaluation result 112. The safety evaluation unit 111 outputs the safety evaluation result 112 to, for example, a display device connected to the inspection device 100. In addition, the safety evaluation unit 111 may send the safety evaluation result 112 to an external device using the communication device 202.

[0084] On the other hand, if there is a safety evaluation item whose evaluation has not been completed (No in step S1009), the process returns to step S1005. The process from step S1005 to step S1009 is repeated until the evaluation of all safety evaluation items is completed.

[0085] Next, refer to Figure 4 To illustrate Figure 3 The details of the generation process of the system information 104 in step S1002 are described below.

[0086] In addition, the generation process of the system information 104 may not necessarily be as follows. Figure 4 shown.

[0087] First, in step S2001 , the system information generation unit 103 acquires information on a list of devices constituting the control system.

[0088] Next, in step S2002, the system information generation unit 103 acquires the network information 101. The network information 101 shows the connection relationship between each device and the network shown in the device list information acquired in step S2001, and the connection relationship between the devices.

[0089] Next, in step S2003 , the system information generation unit 103 acquires the device information 102 .

[0090] The device information 102 shows the function, status, communication address, etc. of each device shown in the device list information acquired in step S2001.

[0091] Next, in step S2004 , the system information generating unit 103 combines the information acquired in steps S2001 to S2003 to generate a structure tree starting from the inspection device 100 .

[0092] At this time, the system information generation unit 103 generates a structure tree so that the device communicating with the outside of the control system, that is, the external communication device, can be distinguished from other devices. For example, the system information generation unit 103 sets a flag for the external communication device to generate the structure tree.

[0093] exist Figure 5 An example of the structure tree generated in step S2004 is shown in FIG.

[0094] exist Figure 5 In the example shown, the inspection device 100 is included in the control system. Figure 5 The structure tree shown shows the inspection apparatus 100, the devices included in the control system, the network between the inspection apparatus 100 and the devices, and the network between the devices. In addition, a flag such as "external communication" is set for devices that can communicate with the outside of the control system (external communication devices).

[0095] Next, in step S2005 , the system information generation unit 103 extracts the communication path from each device to the inspection apparatus 100 .

[0096] More specifically, the system information generation unit 103 analyzes the structure tree generated in step S2004 to extract the communication path from each device to the inspection device 100. When there are multiple communication paths from a device to the inspection device 100, the system information generation unit 103 extracts all the communication paths. For example, when the same device exists in multiple locations in the structure tree, the system information generation unit 103 determines that there are multiple communication paths and extracts all the communication paths. Figure 5 In the example of , device E and device F exist in two locations respectively, so the system information generation unit 103 extracts two communication paths for device E and two communication paths for device F as well.

[0097] Next, in step S2006, the system information generation unit 103 extracts a communication path from each device to an external communication device.

[0098] More specifically, the system information generating unit 103 extracts the external communication device from the structure tree generated in step S2004, and extracts the communication path from each device to the extracted external communication device.

[0099] The system information generation unit 103 further extracts a communication path from the device to the external communication device via the inspection apparatus 100. In this case, a communication path consisting of a communication path from the device to the inspection apparatus 100 and a communication path from the inspection apparatus 100 to the external communication device is extracted.

[0100] In step S2006, when the same device exists in multiple locations in the structure tree, the system information generation unit 103 determines that there are multiple communication paths and extracts all the communication paths. Figure 5 In the example of , device E and device F exist in two locations respectively, so the system information generation unit 103 extracts two communication paths for device E and two communication paths for device F as well.

[0101] When the extraction of the communication paths in step S2005 and the extraction of the communication paths in step S2006 are completed for all the devices shown in the device list information acquired in step S2001 (YES in step S2007 ), the process proceeds to step S2008 .

[0102] On the other hand, if there is a device for which the extraction of the communication path has not been completed (No in step S2007), the processing from step S2005 to step S2007 is repeated until the extraction of the communication path is completed for all the devices.

[0103] In step S2008 , the system information generation unit 103 generates the system information 104 for each device.

[0104] Figure 6 An example of the system information 104 is shown.

[0105] exist Figure 6 The system information 104 shown includes information such as the IP address of the evaluation target device, all communication paths from the evaluation target device to the inspection apparatus 100 , and all communication paths from the evaluation target device to external communication devices.

[0106] Next, use Figure 7 To illustrate Figure 3 The details of the safety evaluation item selection process in step S1004 are shown.

[0107] In step S3010 , the evaluation item generating unit 107 acquires the system information 104 .

[0108] Next, in step S3001 , the evaluation item generation unit 107 acquires the candidate safety evaluation items 106 .

[0109] Figure 8 Examples of candidate safety evaluation items 106 are shown.

[0110] exist Figure 8 The candidate security evaluation items 106 include an evaluation item number, an evaluation item name, an object device name, a required item flag, an option flag, an option condition, an evaluation method, a required scan flag, a scan object, a confirmation item, an evaluation reference value, a corresponding threat example, and a countermeasure example.

[0111] The evaluation item number is used to correspond to the security policy.

[0112] The required item flag indicates whether the target device must satisfy the evaluation item. When the required item flag is ON, the target device must satisfy the evaluation item.

[0113] The option flag indicates whether or not an option condition exists. When the option flag is ON, the option condition exists.

[0114] The optional conditions indicate the conditions for determining whether the evaluation item is selected for the target device. The optional conditions include, for example, external access conditions. The external access conditions refer to conditions that select the evaluation item for the target device only when there is a communication path from the target device to the external communication device. In addition, the optional conditions include, for example, application exemption conditions. The application exemption conditions refer to conditions that exempt the application of the evaluation item when the evaluation item is applied to other devices within the control system. The application exemption conditions are, for example, conditions that exempt the target device from the application of the evaluation item when the evaluation item is applied to the external communication device. In addition, the application exemption conditions also include conditions that exempt the target device from the application of the evaluation item when the evaluation item is applied to other devices that are closer to the external communication device. In addition, the evaluation items for which the application exemption conditions are described in the optional conditions are referred to as exempted evaluation items. In addition, the other devices that are closer to the external communication device are determined, for example, by the number of hops to the external communication device. In Figure 5 In the structure tree of , for device A as an external communication device, device D and device E are closer than device F.

[0115] The evaluation method indicates an evaluation method performed by the active scanning unit 109 .

[0116] The scan-needed flag indicates whether active scanning is required.

[0117] Scan objects represent objects that are actively scanned.

[0118] The confirmation item indicates the content to be confirmed in the device information 102 or the result of the active scan.

[0119] The evaluation reference value indicates a reference value to be compared with the device information 102 or the result of the active scan.

[0120] The corresponding threat examples indicate examples of threats that can be assumed when the device information 102 or the result of the active scan does not satisfy the evaluation reference value.

[0121] The countermeasure example shows an example of a countermeasure to be implemented when the device information 102 or the result of the active scan does not satisfy the evaluation reference value.

[0122] The candidate security assessment items 106 are described in a language that can be used for security checks, such as OVAL (Open Vulnerability and Assessment Language) based on XML (Extensible Markup Language). Figure 8 In addition to the items shown, storage locations of values ​​extracted from devices by active scanning and the like are described in XML format.

[0123] The evaluation item generation unit 107 obtains the following information for each device included in the control system: Figure 8 The candidate safety evaluation items 106 are exemplified in FIG.

[0124] Next, in step S3002 , the evaluation item generation unit 107 acquires the security policy check list 901 .

[0125] The safety policy checklist 901 shows selection criteria for selecting the selected safety evaluation item 108 from the plurality of candidate safety evaluation items 106. The safety policy checklist 901 can be manually generated by the user of the inspection device 100 or automatically generated by the user selecting a category based on international standards.

[0126] Fig. 9 An example of the security policy check list 901 is shown.

[0127] The security policy checklist 901 is described in a description format that can express a security setting checklist, such as XCCDF (eXtensible Configuration Checklist Description Format). In addition, the security policy checklist 901 is described in a structured form, such as XML. Thus, check items such as the validity period of a password and the password update history can be listed together with information of an identification number such as CCE (Common Configuration Enumeration) to generate a check item.

[0128] The security policy numbers and the numbers of the evaluation items to be extracted are listed in the security policy check list 901. The security policy check list 901 shows the evaluation item numbers of the security evaluation items to be extracted for implementing the security policy for each security policy.

[0129] exist Fig. 9 In the example, in order to implement the security policy of policy number "1", it is necessary to extract the candidate security evaluation item 106 with the evaluation item number "1" and the candidate security evaluation item 106 with the evaluation item number "2". In addition, in order to implement the security policy of policy number "2", it is necessary to extract the candidate security evaluation item 106 with the evaluation item number "2", the candidate security evaluation item 106 with the evaluation item number "3", and the candidate security evaluation item 106 with the evaluation item number "4".

[0130] Next, in step S3003 , the evaluation item generation unit 107 extracts the security evaluation item of the evaluation item number corresponding to the “evaluation item number” of the security policy check list 901 .

[0131] Furthermore, even when the same evaluation item number is repeatedly recorded in the security policy check list 901 , the evaluation item generating unit 107 extracts the corresponding security evaluation item only once.

[0132] exist Fig. 9 In the example of , the safety evaluation item with the evaluation item number “2” is recorded repeatedly, and the evaluation item generating unit 107 extracts the safety evaluation item with the evaluation item number “2” only once.

[0133] Next, in step S3004 , the evaluation item generating unit 107 determines for each device whether or not a communication path to an external communication device is described in the corresponding system information 104 .

[0134] If the communication path of the external communication device is not recorded in the system information 104 of the device currently being determined (No in step S3004), the evaluation item generation unit 107 deletes the security evaluation item related to the external access in step S3005. In addition, the evaluation item generation unit 107 refers to the required flag and the optional condition of the security evaluation item to determine whether to delete the security evaluation item in step S3005.

[0135] For example, it is assumed that the communication path of the external communication device is not recorded in the system information 104 of the device x ("No" in step S3004). In addition, it is assumed that the external access condition is recorded in the option conditions of the security evaluation item extracted for the device x in step S3003. In this case, the evaluation item generation unit 107 deletes the security evaluation item in step S3005. In this way, the evaluation item generation unit 107 does not select the security evaluation item related to the communication with the outside of the information system for the device that does not have a communication path with the external communication device.

[0136] On the other hand, if the required flag of the security evaluation item extracted for device x in step S3003 is ON, the evaluation item generation unit 107 does not delete the security evaluation item. In addition, if the external access condition is not described in the optional conditions of the security evaluation item extracted for device x in step S3003, the evaluation item generation unit 107 does not delete the security evaluation item.

[0137] If the answer is "NO" in step S3004, the evaluation item generating unit 107 determines in step S3006 whether or not there is an exemption evaluation item in the device currently being determined.

[0138] That is, the evaluation item generating unit 107 determines whether or not the application exemption condition is described in the optional conditions of the security evaluation item extracted in step S3003 for the device currently being the determination target.

[0139] When there is an exemption evaluation item in the device currently being judged ("Yes" in step S3006), the evaluation item generation unit 107 determines in step S3007 whether to apply the exemption evaluation item to the external communication device. In addition, the evaluation item generation unit 107 determines whether to apply the exemption evaluation item to other devices that are closer to the external communication device than the device currently being judged. Then, when the exemption evaluation item is applied to the external communication device or other devices that are closer to the external communication device, the evaluation item generation unit 107 deletes the exemption evaluation item for the device currently being judged. In this way, the evaluation item generation unit 107 does not select the safety evaluation item to be exempted from application for a device that has a safety evaluation item that is exempted from application due to application to other devices in the control system.

[0140] In a case where the exemption evaluation item is not applied to the external communication device or other devices closer to the external communication device, the process of step S3008 is performed.

[0141] When a plurality of safety evaluation items are extracted for the device currently serving as the determination target, the evaluation item generating unit 107 performs the processing of steps S3004 to S3007 for each safety evaluation item.

[0142] In step S3008 , the evaluation item generating unit 107 finally selects the safety evaluation items extracted in step S3003 for the device currently being determined, which safety evaluation items have not been deleted in steps S3005 and S3007 .

[0143] Next, the evaluation item generating unit 107 determines in step S3009 whether the selection of the safety evaluation items has been completed for all the devices constituting the control system.

[0144] If the selection of safety evaluation items is completed for all devices ("Yes" in step S3009), the process ends. On the other hand, if there is a device that has not completed the selection of safety evaluation items ("No" in step S3009), the evaluation item generation unit 107 repeats the processing of steps S3003 to S3009 until the selection of safety evaluation items is completed for all devices.

[0145] Next, use Fig.10 To illustrate Figure 3 Details of the execution process of the active scan in step S1006 are described below.

[0146] In step S4001 , the active scanning unit 109 acquires evaluation items that need to be scanned.

[0147] More specifically, the active scanning unit 109 acquires the safety evaluation items whose necessary scanning flags are ON among the selected safety evaluation items 108 .

[0148] Next, in step S4002 , the active scanning unit 109 refers to the scanning target of the security evaluation item acquired in step S4001 , and determines the scanning method to be performed.

[0149] Specifically, the active scanning unit 109 determines in step S4002 whether the scan object is related to IP communication. That is, the active scanning unit 109 confirms whether IP communication is recorded in the scan object of the security evaluation item. In the case where IP communication is recorded in the scan object ("Yes" in step S4002), the process proceeds to step S4004. On the other hand, in the case where IP communication is not recorded in the scan object ("No" in step S4002), the process proceeds to S4003.

[0150] In step S4003 , the active scanning unit 109 determines whether the scanning method to be implemented is related to the application.

[0151] Specifically, the active scanning unit 109 checks whether an application is recorded in the scan object of the security evaluation item. If an application is recorded in the scan object ("Yes" in step S4003), the process proceeds to step S4005. On the other hand, if an application is not recorded in the scan object ("No" in step S4003), that is, if the scan object is a control protocol or a unique service, the process proceeds to S4006.

[0152] In step S4004 , the active scanning unit 109 performs scanning using IP communication.

[0153] In step S4004, the active scanning unit 109 sends a scanning packet to the IP address indicated in the system information 104. Scanning related to IP communication includes port scanning, etc. In addition, the active scanning unit 109 refers to the evaluation method of the security evaluation item and performs a scan in accordance with the evaluation method.

[0154] In step S4005 , the active scanning unit 109 performs a scan of the application program.

[0155] In step S4005, the active scanning unit 109 sends a scanning packet to the IP address shown in the system information 104 or the address corresponding to the application shown in the system information 104 as the destination. As a scanning related to the application, there is access to FTP (File Transfer Protocol), and in this case, the active scanning unit 109 uses the IP address. In addition, in step S4005, the active scanning unit 109 also refers to the evaluation method of the security evaluation item and performs a scan in accordance with the evaluation method.

[0156] In step S4006 , the active scanning unit 109 performs scanning of control protocols or services.

[0157] In step S4006, the active scanner 109 transmits a scan packet to the address of the other protocol indicated in the system information 104. In step S4006, the active scanner 109 also refers to the evaluation method of the security evaluation item and performs a scan in accordance with the evaluation method.

[0158] Finally, in step S4007 , the active scanning unit 109 outputs the scanning results performed in steps S4004 , S4005 , and S4006 to the security assessment unit 111 .

[0159] Next, use Fig.11 To illustrate Figure 3 Details of the safety evaluation process of step S1007 are shown.

[0160] In step S5001 , the security evaluation unit 111 acquires the device information 102 , the selected security evaluation item 108 , and the active scan result 110 .

[0161] Next, in step S5002 , the safety evaluation unit 111 extracts the confirmation item of the selected safety evaluation item 108 , and confirms which value is the evaluation target.

[0162] Next, in step S5003 , the security assessment unit 111 extracts a corresponding value from the device information 102 or the active scan result 110 as a value of the confirmation item extracted in step S5002 .

[0163] Next, in step S5004 , the safety evaluation unit 111 extracts an evaluation reference value from the selected safety evaluation item 108 .

[0164] Next, in step S5005 , the safety evaluation unit 111 determines whether the value extracted in step S5003 satisfies the evaluation reference value extracted in step S5004 .

[0165] If the value extracted in step S5003 satisfies the evaluation reference value (YES in step S5005 ), the device has already taken security measures. In this case, the process proceeds to step S5006 .

[0166] On the other hand, if the value extracted in step S5003 does not satisfy the evaluation reference value (No in step S5005), the device has not taken security measures or has not correctly taken security measures. In this case, the process proceeds to step S5007.

[0167] In step S5006, since the security measures have been implemented in the device, the security evaluation unit 111 generates a security evaluation result 112 indicating that there is no problem, and the process ends.

[0168] In step S5007 , since the security measures are not implemented in the device or the security measures are not correctly implemented in the device, the security evaluation unit 111 generates a security evaluation result 112 indicating that there is a problem.

[0169] Furthermore, in step S5008, the security evaluation unit 111 extracts threat examples and countermeasure examples that are conceivable when security countermeasures are not implemented or are not correctly implemented from the "corresponding threat examples" and "countermeasure examples" of the selected security evaluation item 108. Then, the security evaluation unit 111 adds the extracted threat examples and countermeasure examples to the security evaluation result 112, and ends the processing.

[0170] ***Description of the Effects of the Implementation Method***

[0171] As described above, in this embodiment, the security evaluation item is selected for each device by considering at least one of the possibility of communication with the outside of the information system and the possibility of being exempted from the application of the security evaluation item due to application to other devices in the information system. Therefore, according to this embodiment, it is possible to select an appropriate security evaluation item according to the characteristics of the device.

[0172] That is, the inspection device according to the present embodiment generates security evaluation items required for the information system according to the configuration of the information system, and thus can appropriately perform security evaluation on the entire information system.

[0173] In addition, since the inspection device according to the present embodiment performs all operations automatically, omissions and errors caused by human intervention can be eliminated. Furthermore, by performing all operations automatically, the safety evaluation can be made more efficient.

[0174] Furthermore, the inspection device according to the present embodiment extracts safety evaluation items in accordance with the safety policy selected by the user. Therefore, appropriate safety evaluation items can be extracted simply by changing the selection of the safety policy based on the system's unique rules or international standard rules.

[0175] Furthermore, even if there is a change in the security policy required for the information system, it is possible to extract security evaluation items that comply with the new security policy without performing a configuration change or the like.

[0176] In addition, the inspection device according to the present embodiment checks the status of the device by active scanning. Therefore, the status of the device can be checked without changing the device settings or adding programs. Therefore, the security evaluation of the existing information system can be implemented by simply connecting the inspection device to the existing information system.

[0177] In addition, the inspection device according to the present embodiment outputs the safety evaluation result to a device that can access the inspection device, so that the user can check the safety evaluation result anywhere such as in the office.

[0178] Implementation method 2.

[0179] ***Description of the structure***

[0180] Fig.12 This is an example of the functional configuration of the inspection device 100 according to the second embodiment.

[0181] To Figure 1 The same elements are denoted by the same reference numerals. In addition, although the security policy check list 901 is not shown for reasons of drawing, the evaluation item generation unit 107 acquires the security policy check list 901 in the same manner as in the first embodiment.

[0182] exist Fig.12 In, with Figure 1 Compared to the above, safety evaluation history data 701 , implemented evaluation items 702 , and implemented safety evaluation results 703 are added.

[0183] In addition, the hardware structure of the inspection device 100 is as follows Figure 2 shown.

[0184] In addition, matters not described below are the same as those in Implementation 1.

[0185] The safety evaluation history data 701 includes a structure tree generated in the past, selected safety evaluation items 108, and safety evaluation results 112. That is, the structure tree generated in the past, the selected safety evaluation items 108, and the safety evaluation results 112 are stored in the database as the safety evaluation history data 701. The safety evaluation history data 701 is stored in a database outside the inspection device 100, for example.

[0186] The performed evaluation items 702 are the past selected safety evaluation items 108 extracted from the safety evaluation history data 701 .

[0187] The performed safety evaluation results 703 are past safety evaluation results 112 extracted from the safety evaluation history data 701 .

[0188] Furthermore, in the present embodiment, when a change occurs in a device included in the control system, the system information generation unit 103 changes the system information 104 in accordance with the change.

[0189] Furthermore, when a change occurs in a device included in the control system, the evaluation item generating unit 107 changes the safety evaluation item to be selected according to the change.

[0190] Similarly, when a change occurs in a device included in the control system, the active scanning unit 109 newly performs an active scan in accordance with the change.

[0191] Furthermore, when a change occurs in a device included in the control system, the safety evaluation unit 111 performs a new safety evaluation in accordance with the change.

[0192] ***Description of the action***

[0193] Next, use Fig.13 and Fig.14 An operation example of the inspection device 100 according to the present embodiment will be described.

[0194] Fig.13 and Fig.14 This is an example of the re-evaluation operation in the inspection device 100. The operation flow of the inspection device 100 may not necessarily be as follows. Fig.13 and Fig.14 shown.

[0195] When a request for safety evaluation is made from the user of the inspection device 100, the system information generation unit 103 determines in step S6001 whether the request from the user is a request for re-evaluation. A request for re-evaluation is a request for safety evaluation based on the changed content when there is a change in the device structure of the control system or a change in the setting of the device. The system information generation unit 103 determines that it is a request for re-evaluation if a change in the control system is indicated in the request from the user. Changes in the control system include changes in the device structure (addition of devices, deletion of devices, changes in the connection relationship of devices, replacement of devices) and changes in the settings of devices (addition of settings, deletion of settings, changes in setting values).

[0196] If the user's request is a request for re-evaluation (YES in step S6001 ), the process proceeds to step S6005 . On the other hand, if the user's request is not a request for re-evaluation (NO in step S6001 ), the process proceeds to step S6002 .

[0197] In step S6002 , the system information generation unit 103 determines whether a safety evaluation has been performed in the past.

[0198] More specifically, the system information generation unit 103 refers to the safety evaluation history data 701. If the past safety evaluation result 112 exists in the safety evaluation history data 701, the system information generation unit 103 determines that the safety evaluation was performed in the past. On the other hand, if the past safety evaluation result 112 does not exist in the safety evaluation history data 701, the system information generation unit 103 determines that the safety evaluation was not performed in the past.

[0199] If the safety evaluation has been performed in the past (YES in step S6002 ), the process proceeds to step S6004 . On the other hand, if the safety evaluation has not been performed in the past (NO in step S6002 ), the process proceeds to step S6003 .

[0200] In step S6003, the safety evaluation of the control system is performed. In this case, it becomes a new evaluation of the control system.

[0201] In step S6003 , the system information 104 is generated, the security evaluation items 108 are selected, an active scan is performed, and a security evaluation is performed through the process described in the first embodiment, and finally a security evaluation result 112 is generated.

[0202] In step S6004 , the system information generation unit 103 extracts the past security evaluation results 112 from the security evaluation history data 701 as the performed security evaluation results 703 , and outputs the extracted performed security evaluation results 703 .

[0203] As an output destination of the performed safety evaluation result 703 , for example, a display connected to the inspection device 100 , a terminal device used by a user of the inspection device 100 , an external database, etc. may be considered.

[0204] In step S6005 , the system information generation unit 103 determines whether there is a change in the device configuration.

[0205] For example, if the user's request in step S6001 records the content of the device configuration change, the system information generation unit 103 determines that there is a change in the device configuration. In addition, the system information generation unit 103 may also determine whether the network information 101 and the device information 102 have been revised since the time when the system information 104 was last generated. In this case, if the network information 101 and the device information 102 have been revised, the system information generation unit 103 determines that there is a change in the device configuration.

[0206] If there is a change in the device configuration (Yes in step S6005), the process proceeds to step S6006. On the other hand, if there is no change in the device configuration, that is, if there is a change in the device settings (No in step S6005), the process proceeds to step S6010.

[0207] In step S6006 , the system information generation unit 103 obtains the revised network information 101 and device information 102 .

[0208] Next, in step S6007, the system information generation unit 103 generates system information 104 corresponding to the current device configuration.

[0209] Specifically, the system information generation unit 103 extracts the structure tree ( Figure 5 ). In addition, the system information generation unit 103 adds or deletes networks, adds or deletes devices, or changes the connection relationship to the extracted structure tree in accordance with the revised network information 101 and device information 102. Then, the system information generation unit 103 generates new system information 104 based on the new structure tree. The process of generating new system information 104 based on the new structure tree is the same as the process described in Implementation 1.

[0210] Then, the system information generating unit 103 outputs the new system information 104 to the evaluation item generating unit 107 .

[0211] Next, in step S6008 , the evaluation item generator 107 acquires the safety evaluation items of the changed device from the safety evaluation items 105 based on the new system information 104 .

[0212] When there is a change in the equipment constituting the control system, the safety evaluation items also need to be changed. Therefore, the evaluation item generation unit 107 acquires the safety evaluation items of the equipment with the change.

[0213] Next, in step S6009 , the evaluation item generating unit 107 changes the safety evaluation items in accordance with the change in the device configuration of the control system.

[0214] Specifically, the evaluation item generation unit 107 extracts the safety evaluation items before the change generated last time from the safety evaluation history data 701. Then, the evaluation item generation unit 107 deletes the safety evaluation items before the change extracted from the safety evaluation history data 701, and adds the safety evaluation items after the change acquired in step S6008. In addition, in step S6009, Figure 7 That is, if there is an external access condition in the changed security evaluation item, the system information generation unit 103 deletes the security evaluation item. Similarly, if the changed security evaluation item is an exemption evaluation item and the security evaluation item is applied to other devices, the system information generation unit 103 deletes the security evaluation item.

[0215] In step S6010, the evaluation item generating unit 107 confirms the range of the re-evaluation target.

[0216] That is, the evaluation item generation unit 107 confirms whether the scope of the re-evaluation object is limited to a part of the safety evaluation items. For example, when the user specifies a part of the safety evaluation items as the scope of the re-evaluation object, the evaluation item generation unit 107 determines that the scope of the re-evaluation object is limited to a part of the safety evaluation items. In addition, when the scale of the change (change in the device structure or change in the setting of the device) is small and it is sufficient to perform the safety evaluation using only the safety evaluation items related to the change, the evaluation item generation unit 107 determines that the scope of the re-evaluation object is limited to a part of the safety evaluation items.

[0217] If the scope of the re-evaluation object is limited to a part of the safety evaluation items ("Yes" in step S6010), the process proceeds to step S6011. On the other hand, if the scope of the re-evaluation object is all the safety evaluation items ("No" in step S6010), the process proceeds to step S6011.

[0218] In step S6011, the evaluation item generating unit 107 specifies the range of the re-evaluation target.

[0219] That is, the active scanning unit 109 specifies a part of the safety evaluation items to be re-evaluated.

[0220] When step S6009 is performed, the evaluation item generating unit 107 specifies some of the safety evaluation items obtained by performing step S6009.

[0221] On the other hand, when step S6009 is not performed (when the device settings are changed), the evaluation item generator 107 obtains the previously selected safety evaluation items 108 from the safety evaluation history data 701 and specifies some of the obtained selected safety evaluation items 108 .

[0222] Next, in step S6012 , the evaluation item generation unit 107 outputs the security evaluation item specified in step S6011 to the active scanning unit 109 and the security evaluation unit 111 as a new selected security evaluation item 108 .

[0223] In step S6013 , the evaluation item generating unit 107 outputs all the security evaluation items to the active scanning unit 109 .

[0224] When step S6009 is performed, the evaluation item generation unit 107 outputs the security evaluation item obtained by performing step S6009 to the active scanning unit 109 as a new selected security evaluation item 108 .

[0225] On the other hand, when step S6009 is not performed (when the device settings are changed), the evaluation item generation unit 107 obtains the previously selected security evaluation item 108 from the security evaluation history data 701, and outputs the obtained previously selected security evaluation item 108 to the active scanning unit 109 and the security evaluation unit 111.

[0226] In step S6014 , the active scanning unit 109 checks the scanning necessity flag described in the selected safety evaluation item 108 acquired from the evaluation item generating unit 107 , and determines whether scanning is necessary.

[0227] If the scan-required flag is OFF, scanning is not required for the selected safety evaluation item 108. In this case, the process proceeds to S6016. On the other hand, if the scan-required flag is ON, scanning is required for the selected safety evaluation item 108. In this case, the process proceeds to S6015.

[0228] In step S6015, the active scanning unit 109 scans the security evaluation items determined to be required to be scanned in step S6014. Fig.10 Follow the process shown.

[0229] Furthermore, the active scanning unit 109 generates an active scanning result 110 indicating a scanning result, and outputs the generated active scanning result 110 to the security assessment unit 111 .

[0230] In step S6016 , the security evaluation unit 111 evaluates the security setting status of each device using the device information 102 , the selected security evaluation item 108 , and the active scan result 110 .

[0231] In step S6016, Fig.11 action.

[0232] When the evaluation of all the safety evaluation items of the selected safety evaluation item 108 is completed (Yes in step S6017 ), in step S6018 , the safety evaluation unit 111 outputs the safety evaluation result 112 .

[0233] The safety evaluation unit 111 may output the safety evaluation result 112 to, for example, a display device connected to the inspection device 100. In addition, the safety evaluation unit 111 may use the communication device 202 to transmit the safety evaluation result 112 to an external device.

[0234] On the other hand, if there is a safety evaluation item whose evaluation has not been completed (No in step S6018), the process returns to step S6014. The process from step S6014 to step S6017 is repeated until the evaluation of all safety evaluation items is completed.

[0235] ***Description of the Effects of the Implementation Method***

[0236] As described above, when a change occurs in the information system, the inspection device according to the present embodiment can perform a necessary safety evaluation in accordance with the changed portion, thereby making it possible to perform the safety evaluation appropriately and efficiently.

[0237] Furthermore, the inspection device according to the present embodiment effectively utilizes safety evaluation items generated in the past and evaluation results generated in the past when performing re-evaluation, and thus can perform re-evaluation in a short time and with few resources.

[0238] Although the embodiment of the present invention has been described above, the two embodiments may be combined and implemented.

[0239] Alternatively, one of the two embodiments may be partially implemented.

[0240] Alternatively, these two embodiments may be partially combined and implemented.

[0241] In addition, the present invention is not limited to these embodiments, and various changes can be made as needed.

[0242] ***Description of the hardware structure***

[0243] Finally, a supplementary explanation of the hardware structure of the inspection device 100 is given.

[0244] Figure 2 The processor 201 shown is an IC (Integrated Circuit) that performs processing.

[0245] The processor 201 is a CPU (Central Processing Unit), a DSP (Digital Signal Processor), or the like.

[0246] Figure 2 The storage device 203 shown is a RAM (Random Access Memory), a ROM (Read Only Memory), a flash memory, a HDD (Hard Disk Drive), or the like.

[0247] Figure 2 The communication device 202 shown is an electronic circuit that performs communication processing of data.

[0248] The communication device 202 is, for example, a communication chip or a NIC (Network Interface Card).

[0249] Furthermore, the storage device 203 also stores an OS (Operating System).

[0250] Furthermore, at least a part of the OS is executed by the processor 201 .

[0251] The processor 201 executes a program that realizes the functions of the system information generation unit 103 , the evaluation item generation unit 107 , the active scanning unit 109 , and the security assessment unit 111 while executing at least a part of the OS.

[0252] By executing the OS on the processor 201 , task management, memory management, file management, communication control, and the like are performed.

[0253] In addition, at least any one of the information, data, signal values ​​and variable values ​​representing the results of processing by the system information generation unit 103, the evaluation item generation unit 107, the active scanning unit 109 and the security evaluation unit 111 is stored in at least one of the storage device 203, the registers within the processor 201 and the cache.

[0254] In addition, the program that implements the functions of the system information generation unit 103, the evaluation item generation unit 107, the active scanning unit 109 and the security evaluation unit 111 can also be stored in removable recording media such as disks, floppy disks, optical disks, high-density disks, Blu-ray (registered trademark) optical disks, DVDs, etc.

[0255] In addition, the “units” of the system information generating unit 103 , the evaluation item generating unit 107 , the active scanning unit 109 , and the security evaluating unit 111 may be referred to as “circuits,” “processes,” “procedures,” or “processes.”

[0256] In addition, the inspection device 100 may be realized by a processing circuit, such as a logic IC (Integrated Circuit), a GA (Gate Array), an ASIC (Application Specific Integrated Circuit), or an FPGA (Field-Programmable Gate Array).

[0257] In addition, in this specification, the general concept of a processor and a processing circuit is referred to as a "processing circuit".

[0258] That is, a processor and a processing circuit are each specific examples of a “processing circuit”.

Claims

1. An information processing device, comprising: a candidate acquisition unit that acquires, for each designated security policy, a plurality of candidates for security evaluation items to be extracted and applied to a plurality of devices included in the information system in order to implement the security policy; as well as The item selection unit analyzes at least one of the following situations: whether each of the plurality of devices has a communication path with an external communication device; and whether each of the plurality of devices has a security evaluation item that is exempted from application due to application to other devices in the information system, wherein The external communication device is a device in the information system that communicates with the outside of the information system, and the item selection unit selects a security evaluation item to be applied from a plurality of security evaluation item candidates for each of the plurality of devices based on the analysis result. the item selection unit does not select the security evaluation item exempted from the application for at least any one of the following devices: a device having a security evaluation item exempted from application due to application to the external communication device; And there is a device that is exempted from the security evaluation item of application due to application to a device with fewer hops to the external communication device.

2. The information processing device according to claim 1, wherein: The item selection unit does not select a security evaluation item related to communication with the outside of the information system for a device that does not have a communication path with the external communication device.

3. The information processing device according to claim 1, wherein: The item selection unit does not select the security evaluation item exempted from application for a device having a security evaluation item exempted from application due to application to another device in the information system.

4. The information processing device according to claim 1, wherein: The candidate acquisition unit acquires candidates for the plurality of security evaluation items according to a security policy designated by a user of the information processing device.

5. The information processing device according to claim 1, wherein: The information processing apparatus further includes a security evaluation unit configured to perform security evaluation on each of the plurality of devices using the corresponding security evaluation item selected by the item selection unit.

6. The information processing device according to claim 1, wherein: When a change occurs in a device included in the information system, the item selection unit changes a safety evaluation item to be selected according to the change.

7. The information processing device according to claim 5, wherein: When a change occurs in a device included in the information system, the security evaluation unit performs a new security evaluation in accordance with the change.

8. An information processing method, wherein: The computer obtains, for each designated security policy, a plurality of candidates for security evaluation items to be extracted and applied to a plurality of devices included in the information system in order to implement the security policy. The computer analyzes at least any one of the following situations: whether each of the multiple devices has a communication path with an external communication device; and whether each of the multiple devices has a security assessment item that is exempted from application due to application to other devices within the information system, wherein the external communication device is a device within the information system that communicates with the outside of the information system, and based on the analysis result, the computer selects a security assessment item to be applied from a plurality of candidates for security assessment items for each of the multiple devices, wherein the security assessment item that is exempted from application is not selected for at least any one of the following devices: a device that has a security assessment item that is exempted from application due to application to the external communication device; and a device that has a security assessment item that is exempted from application due to application to a device with fewer jumps to the external communication device.

9. A computer-readable recording medium having an information processing program recorded thereon, the information processing program causing a computer to execute: a candidate acquisition process of acquiring, for each designated security policy, a plurality of candidates of security evaluation items to be extracted and applied to a plurality of devices included in the information system in order to implement the security policy; and The item selection process analyzes at least one of the following situations: whether each of the plurality of devices has a communication path with an external communication device, and whether each of the plurality of devices has a security evaluation item that is exempted from application due to application to other devices in the information system, wherein: The external communication device is a device within the information system that communicates with the outside of the information system; Based on the analysis result, for each of the plurality of devices, a security evaluation item to be applied is selected from a plurality of candidates for the security evaluation items, wherein the security evaluation item exempted from the application is not selected for at least any one of the following devices: a device having a security evaluation item exempted from application due to application to the external communication device; And there is a device that is exempted from the security evaluation item of application due to application to a device with fewer hops to the external communication device.

Citation Information

Patent Citations

  • System and method for security management

    JP2001273388A

  • Security management system, input control equipment, security management method and program

    JP2014106920A

  • Fault processing method and system and computer program product

    CN107526647A

  • Safety evaluation system and safety evaluation method

    JP2013218531A

  • System and Method for Providing Data and Device Security Between External and Host Devices

    US20080276302A1