Information processing device and information processing method
The information processing device and method address the challenge of identifying software vulnerabilities by using a dictionary to map varying software names to specific identifiers, allowing for effective retrieval of vulnerability information from a database.
Patent Information
- Application Number
- JP2024062272
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-04-08
- Publication Date
- 2025-05-16
AI Technical Summary
Existing technologies face challenges in identifying vulnerability information for software due to variations in software names, making it difficult to accurately retrieve relevant data.
An information processing device and method that utilize a dictionary to associate specific software names with reference names, allowing for the identification of specific software names and corresponding identifiers, which are then used to search a vulnerability database for relevant information.
Enables appropriate identification of vulnerability information even with variations in software names, ensuring accurate retrieval and management of software vulnerabilities.
Smart Images

Figure 2025076974000001_ABST
Abstract
Description
[Technical field]
[0001] The present invention relates to an information processing device and an information processing method. [Background technology]
[0002] Conventionally, techniques for identifying information related to software vulnerabilities have been proposed (for example, Patent Document 1). [Prior art documents] [Patent documents]
[0003] [Patent Document 1] JP 2007-58514 A Summary of the Invention [Problem to be solved by the invention]
[0004] However, in cases where there are variations in the spelling of software names, it can be difficult to identify information about vulnerabilities and other information about the software.
[0005] Therefore, the present invention has been made to solve the above-mentioned problems, and aims to provide an information processing device and an information processing method that enable appropriate identification of information related to vulnerabilities and information related to software. [Means for solving the problem]
[0006] An aspect of the disclosure is an information processing device comprising a storage unit that stores dictionary information that corresponds a specific name of software with a reference name that indicates the same software as the software having the specific name, an acquisition unit that acquires a reference name of target software, and a control unit that refers to the dictionary information to identify a specific name of the target software that corresponds to the reference name of the target software and identifies a first identifier of the target software that corresponds to the identified specific name of the target software, wherein the storage unit stores a vulnerability database that corresponds to the first identifier of the software and vulnerability information, and the control unit identifies the vulnerability information of the target software from the vulnerability database using the first identifier of the target software as a search key.
[0007] An aspect of the disclosure is an information processing method comprising: a step A of storing dictionary information that corresponds a specific name of software with a reference name that indicates software identical to the software having the specific name; a step B of acquiring a reference name of target software; a step C of referring to the dictionary information to identify a specific name of the target software that corresponds to the reference name of the target software and to identify a first identifier of the target software that corresponds to the identified specific name of the target software; a step D of storing a vulnerability database that stores the first identifier of the software in association with vulnerability information; and a step E of identifying vulnerability information of the target software from the vulnerability database using the first identifier of the target software as a search key. Effect of the Invention
[0008] According to the present invention, it is possible to provide an information processing device and an information processing method that enable vulnerability information to be appropriately identified. [Brief description of the drawings]
[0009] [Figure 1] FIG. 1 is a diagram showing an information processing system 100 according to an embodiment. [Diagram 2]FIG. 2 is a diagram showing the information processing device 10 according to the embodiment. [Diagram 3] FIG. 3 is a diagram illustrating an example of software information according to the embodiment. [Figure 4] FIG. 4 is a diagram illustrating an example of dictionary information according to the embodiment. [Diagram 5] FIG. 5 is a diagram illustrating an example of vulnerability information according to the embodiment. [Figure 6] FIG. 6 is a diagram illustrating an example of information stored in the vulnerability DB according to the embodiment. [Figure 7] FIG. 7 is a diagram illustrating an example of information stored in the vulnerability DB according to the embodiment. [Figure 8] FIG. 8 is a diagram for explaining triage according to the embodiment. [Figure 9] FIG. 9 is a diagram illustrating an information processing method according to the embodiment. [Figure 10] FIG. 10 is an example of information stored in the master DB according to the first modification. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0010] Hereinafter, embodiments will be described with reference to the drawings. In the following description of the drawings, the same or similar parts are denoted by the same or similar reference numerals.
[0011] However, it should be noted that the drawings are schematic and the ratios of the dimensions may differ from the actual ones. Therefore, the specific dimensions should be determined with reference to the following explanation. In addition, the drawings may of course include parts with different dimensional relationships or ratios.
[0012] [Disclosure Summary] An information processing device according to the disclosed summary includes a storage unit that stores dictionary information that corresponds a specific name of software with a reference name that indicates the same software as the software having the specific name, an acquisition unit that acquires a reference name of target software, and a control unit that refers to the dictionary information to identify a specific name of the target software that corresponds to the reference name of the target software and identifies a first identifier of the target software that corresponds to the identified specific name of the target software, wherein the storage unit stores a vulnerability database that corresponds to the first identifier of the software and vulnerability information, and the control unit identifies the vulnerability information of the target software from the vulnerability database using the first identifier of the target software as a search key.
[0013] The information processing method disclosed in the summary includes a step A of storing dictionary information that corresponds a specific name of software with a reference name that indicates software identical to the software having the specific name, a step B of acquiring a reference name of target software, a step C of referring to the dictionary information to identify a specific name of the target software that corresponds to the reference name of the target software and to identify a first identifier of the target software that corresponds to the identified specific name of the target software, a step D of storing a vulnerability database that stores the first identifier of the software in association with vulnerability information, and a step E of identifying vulnerability information of the target software from the vulnerability database using the first identifier of the target software as a search key.
[0014] In the outline of the disclosure, an information processing device refers to dictionary information to identify a specific name of the target software corresponding to the reference name of the target software, identifies a first identifier of the target software corresponding to the identified specific name of the target software, and identifies vulnerability information of the target software from a vulnerability database using the first identifier of the target software as a search key. According to such a configuration, even in cases where there are variations in the spelling of the software name, etc., it is possible to appropriately identify vulnerability information of the target software by referring to dictionary information to identify the first identifier of the target software from the reference name of the target software.
[0015] [Embodiment] (Information Processing System) An information processing system according to an embodiment will be described below. Fig. 1 is a diagram showing an information processing system 100 according to an embodiment.
[0016] 1, the information processing system 100 includes an information processing device 10, a terminal 20, a system server 30, and a vulnerability server 40. The information processing device 10, the terminal 20, the system server 30, and the vulnerability server 40 are connected by a network. Although not particularly limited, the network 200 may be configured by the Internet. The network 200 may include a local area network, a mobile communication network, or a VPN (Virtual Private Network).
[0017] The information processing device 10 is a device that identifies vulnerability information of software. The software may be software that runs on the system server 30. In the following, software for which vulnerability information is identified may be referred to as target software. Details of the information processing device 10 will be described later.
[0018] The terminal 20 is a terminal used by an administrator who manages software vulnerabilities. The terminal 20 may be a personal computer, a smartphone, or a tablet terminal. The terminal 20 may have a display unit 21. The display unit 21 may be configured with a display such as a liquid crystal panel, an organic EL (Electroluminescence) panel, or an LED (Light Emitting Diode).
[0019] The system server 30 is a server on which a system including various software programs is built and provided. The software programs that run on the system server 30 may include OSS (Open Source Software).
[0020] The software that runs on the system server 30 may be managed by a list of components that make up the software. The list of components (software parts) that make up the software may be called a Software Bill of Materials (SBOM). The components included in the SBOM may be read as software.
[0021] The software that runs on the system server 30 may include software that is managed by a package management tool (package manager). The package management tool is a tool that manages parts such as components used in software development as packages, and has functions such as distributing software packages, providing means for installation, uninstallation, and version upgrades, and managing dependencies between packages. The package management tool may be a tool provided by a third party other than the user of the software.
[0022] The vulnerability server 40 is an external server that manages vulnerability information of software. The vulnerability server 40 may be configured by one or more servers. The one or more vulnerability servers 40 may include a server connected to one or more websites selected from external vulnerability information websites (databases) such as NVD (National Vulnerability Database), ICAT (IPA Cyber security Alert Service) Metabase, JVN (Japan Vulnerability Notes), JVN iPedia, OSVDB (Open Source Vulnerability Database), etc. The one or more vulnerability servers 40 may include a server that stores vulnerability information (e.g., security advisories) that is independently provided by software suppliers.
[0023] (Information processing device) The information processing device 10 according to the embodiment will be described below. Fig. 2 is a diagram showing the information processing device 10 according to the embodiment.
[0024] As shown in FIG. 2, the information processing device 10 includes a transmitting unit 11, a receiving unit 12, a storage unit 13, and a control unit .
[0025] The transmitter 11 may be configured by a communication module. The communication module may be a wireless communication module conforming to a standard such as IEEE802.11a / b / g / n / ac / ax, LTE, 5G, or 6G, or may be a wired communication module conforming to a standard such as IEEE802.3.
[0026] For example, the transmission unit 11 transmits display data for displaying a processing result of the information processing device 10 to the terminal 20. The transmission unit 11 may transmit data to the system server 30 and the vulnerability server 40.
[0027] The receiver 12 may be configured by a communication module. The communication module may be a wireless communication module conforming to a standard such as IEEE802.11a / b / g / n / ac / ax, LTE, 5G, or 6G, or may be a wired communication module conforming to a standard such as IEEE802.3.
[0028] First, the receiving unit 12 may receive information (hereinafter, software information) relating to software (target software) running on the system server 30 from the system server 30. The software information may be an SBOM, or may be information on the target software managed by a package management tool. The software information may include version information of the target software. The receiving unit 12 may scan the software running on the system server 30 using a software analysis tool or the like to automatically identify components (software parts) included in the software and create an SBOM.
[0029] SBOM is a software bill of materials, which lists components (software parts) including OSS (Open Source Software) used inside the software, and includes information showing the dependency relationships of each component (AAAA ver.xxx, BBBB ver.xxx, CCCC ver.xxx, DDDD ver.xxx) as shown in Figure 3. Specifically, SBOM is information that associates component names, supplier names, versions, authors, hashes, dependencies, etc. Also, SBOM may be output or displayed in formats such as json format or xml format.
[0030] The component name is the name of the component. The component is an example of target software. The supplier name is the name of the provider of the component. The version is information that uniquely identifies the version of the component. The version is an example of version information of the target software. The author is the name of the author of the SBOM for the component. The hash is the hash value of the component. The dependency is information that indicates the dependency of the component.
[0031] Furthermore, the SBOM may include a timestamp indicating the date and time when the SBOM was created. The SBOM may also be acquired by importing a file created outside the information processing device 10, such as in another system, into the information processing device 10.
[0032] For example, the information on the target software managed by the package management tool may include a second identifier of the target software managed by the package management tool. The second identifier is an identifier that uniquely identifies the software managed by the package management tool. The second identifier may be a package universal resource locator (purl). The purl may be called a Package URL, which is a unified rule for notating the package name and version information of the package management tool, and is an identifier that uniquely identifies the software managed by the package management tool. The information on the target software managed by the package management tool may include version information of the target software together with the second identifier of the target software. Here, the second identifier may include a portion indicating the name of the package and a portion indicating the version information.
[0033] Secondly, the receiving unit 12 receives vulnerability information from the vulnerability server 40. The vulnerability information received from the vulnerability server 40 may include a vulnerability identifier that uniquely identifies a software vulnerability, software affected by the vulnerability, whether or not an attack code (PoC: Proof of Concept code) for the software vulnerability is in circulation, score information indicating the level of the software vulnerability, and the like.
[0034] For example, if the vulnerability server 40 is a server related to the NVD, as shown in FIG. 4, the vulnerability information may include a vulnerability identifier (CVE-2021-xxxx), an overview, score information, response methods, and affected software.
[0035] The summary may include a description of the vulnerability. For example, the description may include the events that are caused by the vulnerability.
[0036] The score information may be information indicating the level of vulnerability of the software (hereinafter, referred to as a score value). For example, the score information may be a score value (for example, a base score) defined by the Common Vulnerability Scoring System (CVSS).
[0037] The countermeasures may include information indicating a countermeasure against the vulnerability (for example, an update, etc.), a website URL where the countermeasures are described, and the like.
[0038] The affected software may include information indicating the software affected by the vulnerability, and the software may be identified by an identifier such as a Common Platform Enumeration (CPE) described later. The software affected by the vulnerability may be software included in the SBOM, or may be software managed by a package management tool.
[0039] The affected software may include version information of the software affected by the vulnerability. The version information may be information that directly indicates a single version or may be information that indicates a range of versions. In addition, when the software is identified by a CPE, the version information may be one of the pieces of information included in the CPE.
[0040] In the embodiment, the receiving unit 12 constitutes an acquiring unit that acquires a reference name of the target software. Acquiring may be interpreted as receiving. The reference name means the name of the target software received by the receiving unit 12, and may be a name that may include spelling variations depending on the creator of the SBOM.
[0041] The storage unit 13 is configured with a storage medium such as a solid state drive (SSD) or a hard disk drive (HDD), and stores various information.
[0042] First, the storage unit 13 stores dictionary information that associates a specific name of software with a reference name that indicates the same software as the software having the specific name. The specific name means the name of the software used in the information processing device 10, and may be a name that uniquely identifies the software. The specific name may be composed of the name of the software supplier and the name of the asset.
[0043] Furthermore, the dictionary information may include information that associates a specific name of software with a first identifier of the software having the specific name. The first identifier may be an identifier that uniquely identifies the software. The first identifier may be an identifier that can be associated with vulnerability information stored in the vulnerability server 40. The first identifier may be an identifier that can be associated with a vulnerability identifier (e.g., CVE) stored in the vulnerability server 40. For example, the first identifier may be a Common Platform Enumeration (CPE). CPE is a unified rule regarding the notation of software names and version information, and is an identifier of software that includes information such as a supplier name, a product name, and version information. The first identifier may include a software name and version information. In addition, the first identifier may include a supplier name, information about updates, information about an edition (free version, standard version, etc.), information about a language, and the like.
[0044] Specifically, the storage unit 13 may store dictionary information shown in Fig. 5. As shown in Fig. 5, the dictionary information may be information that associates a specific name, a supplier name, a reference name, and a first identifier. As described above, the reference name may be a name that may include spelling variations depending on the creator of the SBOM.
[0045] In the embodiment, the storage unit 13 constitutes a storage unit that stores dictionary information that associates a specific name of software with a reference name that indicates the same software as the software having the specific name.
[0046] Secondly, the storage unit 13 stores a vulnerability database (hereinafter, vulnerability DB). The vulnerability DB may store information based on the vulnerability information received from the vulnerability server 40. The vulnerability DB may store information obtained by extracting various information from the vulnerability information received from the vulnerability server 40. In addition, the vulnerability DB may store information obtained by the user from other websites such as security-related news sites and blogs, which the user inputs and registers, and may store the vulnerability DB, or the vulnerability information obtained from the vulnerability server 40 may be corrected. In this way, it is possible to collect information that is not published on external vulnerability information websites such as NVD and store it in the vulnerability DB, and even if the information on the vulnerability information site is incorrect due to a clerical error or the like, it is possible to store correct information in the vulnerability DB. The following options are possible for information to be stored in the vulnerability DB.
[0047] In option 1-1, the vulnerability DB stores the information shown in Fig. 6. As shown in Fig. 6, the vulnerability DB may store information that associates a vulnerability identifier, a first identifier, and vulnerability information.
[0048] As described above, the vulnerability identifier is an identifier that uniquely identifies a software vulnerability. The vulnerability identifier may include a CVE. The vulnerability identifier may be extracted from the vulnerability information received from the vulnerability server 40.
[0049] The first identifier may be an identifier that uniquely identifies software, such as a CPE, as described above. The first identifier may be an identifier that can be associated with vulnerability information stored in the vulnerability server 40, and indicates software affected by a vulnerability identified by the vulnerability identifier. The first identifier may be an identifier that can be associated with a vulnerability identifier (e.g., CVE) stored in the vulnerability server 40. The first identifier may be extracted from vulnerability information received from the vulnerability server 40 (e.g., "Affected Software" shown in FIG. 4).
[0050] The first identifier may include a software version. As described above, the version is information (version information) that uniquely identifies the software version. The version may be information that directly indicates one version (e.g., “1.1” in cpe:x:x:xxxxx:xxxx:1.1) or information that indicates a range of versions (e.g., “from ver.xxx1 up to ver.xxxN” corresponding to cpe:y:y:yyyyy:yyyy:*). The version may be extracted from vulnerability information received from the vulnerability server 40 (e.g., “Affected Software” shown in FIG. 4).
[0051] Vulnerability information may include PoC information, score information, response information, and the like.
[0052] The PoC information may include information indicating a circulating attack code. The PoC information may be considered as information indicating whether an attack code for a software vulnerability is circulating or not. For example, when the PoC information includes information indicating a circulating attack code, the information may indicate that an attack code is circulating, and when the PoC information does not include information indicating a circulating attack code, the information may indicate that an attack code is not circulating. The PoC information may be extracted from the vulnerability information received from the vulnerability server 40.
[0053] The score information may be a score value indicating the level of vulnerability of the software, as described above. The score information may be a score value defined by CVSS (e.g., Base Score). The score information may be extracted from vulnerability information received from the vulnerability server 40 (e.g., “Score Information” shown in FIG. 4).
[0054] As described above, the countermeasure method may include information indicating a countermeasure method for the vulnerability (e.g., software update, etc.). The countermeasure method may be extracted from the vulnerability information received from the vulnerability server 40 (e.g., “Countermeasure method” shown in FIG. 4).
[0055] The "others" may be information other than the PoC information, score information, and response method. Although not particularly limited, the "others" may include information indicating that exploitation of a vulnerability has been confirmed. The information indicating that exploitation of a vulnerability has been confirmed may be read as information indicating that circulating attack code has been exploited. The information indicating that exploitation of a vulnerability has been confirmed may be acquired from a vulnerability server 40 (e.g., a Known Exploited Vulnerabilities Catalog). The "others" may include information indicating the magnitude of the impact on business if an attack against a vulnerability is made. The magnitude of the impact on business may be expressed in two stages, that is, large or small.
[0056] In option 1-2, the vulnerability DB stores the information shown in Fig. 7. As shown in Fig. 7, the vulnerability DB may store information that associates a vulnerability identifier, a second identifier, and vulnerability information. The second identifier that is associated with the vulnerability information stored in the vulnerability DB may be information collected from security advisories provided by software suppliers or information on open source security advisories.
[0057] The second identifier is an identifier that uniquely identifies software managed by the package management tool. The second identifier may be purl. The second identifier may be extracted from vulnerability information received from the vulnerability server 40 (e.g., "Affected Software" shown in FIG. 4).
[0058] Here, the vulnerability information may be the same as in option 1-1.
[0059] The control unit 14 may include at least one processor. The at least one processor may be configured by a CPU (Central Processing Unit), an MPU (Micro Processing Unit), a GPU (Graphics Processing Unit), one or more integrated circuits, one or more discrete circuits, or a combination thereof.
[0060] First, the control unit 14 identifies vulnerability information of the target software from the vulnerability DB stored in the storage unit 13. As a method of identifying vulnerability information, the following options are considered.
[0061] Option 2-1 describes a case where a reference name that may include spelling variations is obtained. The reference name may be the name of the software obtained from the SBOM. In such a case, the vulnerability DB described in Option 1-1 (see, for example, FIG. 6) may be used as the vulnerability DB. Here, the name of the software may be a combination of the supplier's name and the name of the asset such as the software.
[0062] The control unit 14 refers to dictionary information (e.g., see FIG. 5) to identify a specific name of the target software corresponding to the reference name of the target software, and identifies a first identifier of the target software corresponding to the identified specific name of the target software. The control unit 14 uses the first identifier of the target software as a search key to identify vulnerability information of the target software from a vulnerability DB (e.g., see FIG. 6).
[0063] Here, the reference name is a name that is a variation of a specific name, and includes names that differ from the specific name due to, for example, character types (uppercase and lowercase letters, half-width katakana and full-width katakana, etc.), typing errors such as typos, synonyms, or similar words, etc.
[0064] Furthermore, the control unit 14 determines whether the version information included in the first identifier of the target software is included in the version information included in the first identifier associated with the vulnerability information in the vulnerability DB. If the control unit 14 determines that the version information included in the first identifier of the target software is included, the control unit 14 identifies the vulnerability information of the target software. On the other hand, if the control unit 14 determines that the version information included in the first identifier of the target software is not included, the control unit 14 does not identify the vulnerability information of the target software.
[0065] In option 2-1, the acquired reference information is not used as it is as a search key for the vulnerability DB, but a specific name corresponding to the reference name is identified, and a first identifier corresponding to the specific name is used. The acquired reference information may be used to directly identify the corresponding first identifier. Specifically, the control unit 14 refers to dictionary information (e.g., see FIG. 5) to identify the first identifier of the target software corresponding to the reference name of the target software. The control unit 14 uses the first identifier of the target software as a search key to identify vulnerability information of the target software from the vulnerability DB (e.g., see FIG. 6).
[0066] Furthermore, when version information of the target software is acquired, the specific name is identified using the specific name and the version information. Here, for the version information of the target software, spelling variations may also be registered in the dictionary information in association with the correct spelling. In this case, when the version information of the target software is acquired, the dictionary information is referenced to identify the version information of the target software with the correct spelling. The first identifier may be identified using the identified version information of the target software.
[0067] In Option 2-1, after the first identifier is identified, vulnerability information can be identified by using the first identifier as a search key. Even if the name of the acquired target software has spelling variations from the official software name, the spelling variations can be absorbed and vulnerability information can be identified.
[0068] In option 2-2, a case will be described in which a second identifier (e.g., purl) of software managed by a package management tool is acquired. In such a case, the vulnerability DB described in option 1-2 (e.g., see FIG. 7) may be used as the vulnerability DB.
[0069] The control unit 14 identifies vulnerability information of the target software from the vulnerability DB (see FIG. 7) using the second identifier of the target software as a search key.
[0070] Furthermore, the control unit 14 determines whether the version information included in the second identifier associated with the vulnerability information in the vulnerability DB includes the version information included in the second identifier of the target software. If the control unit 14 determines that the version information included in the second identifier of the target software is included, the control unit 14 identifies the vulnerability information of the target software. On the other hand, if the control unit 14 determines that the version information included in the second identifier of the target software is not included, the control unit 14 does not identify the vulnerability information of the target software.
[0071] In option 2-2, for software managed by a package management tool, the obtained second identifier can be used as a search key to identify the vulnerability DB.
[0072] Secondly, the control unit 14 determines the priority of taking measures against the vulnerability corresponding to the identified vulnerability information. The process of determining the priority of taking measures against the vulnerability information may be called triage. The priority may be called Level.
[0073] 8, the Level may be expressed in five stages, from Level 0 to Level 4. The higher the Level value, the higher the priority of taking measures against the vulnerability. Vulnerabilities may be narrowed down in the order of Level 0 to Level 4.
[0074] Level 0 includes all vulnerabilities whose score value (for example, the Base Score defined by CVSS) is below a threshold. Level 0 vulnerabilities may be considered as vulnerabilities for which no special countermeasures are required.
[0075] Level 1 or higher vulnerabilities may include vulnerabilities whose score value is equal to or greater than a threshold. Level 1 vulnerabilities are Level 1 or higher vulnerabilities excluding Level 2 or higher vulnerabilities. Level 1 vulnerabilities may be determined as vulnerabilities for which countermeasures are implemented during regular maintenance (e.g., once a month), and the priority of responding to Level 1 vulnerabilities is higher than the priority of Level 0 vulnerabilities.
[0076] Level 2 or higher vulnerabilities may include vulnerabilities in the target software that are accessible from the outside, among Level 1 or higher vulnerabilities. Level 2 may include vulnerabilities in the target software that have a large impact on business operations when attacked, among Level 1 or higher vulnerabilities. Level 2 vulnerabilities are Level 2 or higher vulnerabilities excluding Level 3 or higher vulnerabilities. Level 2 vulnerabilities may be determined as vulnerabilities for which countermeasures should be implemented within a first deadline (e.g., within two weeks), and the priority of responding to Level 2 vulnerabilities is higher than the priority of responding to Level 1 vulnerabilities.
[0077] Level 3 or higher vulnerabilities may include Level 2 or higher vulnerabilities for which attack code is in circulation. Level 3 vulnerabilities are Level 3 or higher vulnerabilities excluding Level 4 vulnerabilities. Level 3 vulnerabilities may be determined as vulnerabilities for which countermeasures should be implemented within a second deadline (e.g., within one day) that is shorter than the first deadline, and the priority of responding to Level 3 vulnerabilities is higher than the priority of responding to Level 2 vulnerabilities.
[0078] Level 4 vulnerabilities may include vulnerabilities of Level 3 or higher that have been observed to be actually attacked and have been confirmed to be exploited. Level 4 vulnerabilities may be determined to be vulnerabilities for which measures should be taken within a third deadline (e.g., immediately) that is shorter than the second deadline, and the priority of responding to Level 4 vulnerabilities is higher than the priority of responding to Level 3 vulnerabilities. In other words, Level 4 vulnerabilities have the highest priority.
[0079] The information indicating that the exploitation of a vulnerability has been confirmed may be obtained from a vulnerability server 40 (for example, a Known Exploited Vulnerabilities Catalog).
[0080] In order to realize the above-described triage, it may be expressed that the control unit 14 executes the following processes.
[0081] First, the control unit 14 sets a priority for the vulnerability information of the identified target software based on at least one of the following information for the vulnerability corresponding to the vulnerability information of the target software: information indicating the vulnerability level set by a third-party organization, information indicating whether the target software is accessible from outside, information indicating whether an attack against the vulnerability will have a significant impact on business operations, information indicating whether attack code against the vulnerability is in circulation, and information indicating whether exploitation of the vulnerability has been confirmed.
[0082] Secondly, when the vulnerability information of the target software is specific vulnerability information and the target software is accessible from the outside, the control unit 14 sets the highest priority (Level 4 shown in FIG. 8) as the priority of the vulnerability information of the target software. Specific vulnerability information is vulnerability information in which exploitation of the vulnerability corresponding to the vulnerability information of the target software has been confirmed.
[0083] Third, when the control unit 14 determines, based on the vulnerability information of the identified target software, that attack code is in circulation against a vulnerability corresponding to the vulnerability information of the target software, the control unit 14 sets a first priority (Level 3 shown in FIG. 8) as the priority of the vulnerability information of the target software. When the vulnerability information of the target software is specific vulnerability information and the target software is accessible from outside, the control unit 14 sets a second priority (Level 4 shown in FIG. 8), which is higher than the first priority, as the priority of the vulnerability information of the target software. Specific vulnerability information is vulnerability information in which exploitation of a vulnerability has been confirmed.
[0084] Fourth, when the control unit 14 determines, based on the vulnerability information of the identified target software, that attack code against the vulnerability corresponding to the vulnerability information of the target software is in circulation and the target software is accessible from the outside, it sets the priority of the vulnerability information of the target software to a third priority (Level 3 or higher shown in FIG. 8). When the vulnerability information of the target software is specific vulnerability information and the target software is not accessible from the outside, the control unit 14 sets the priority of the vulnerability information of the target software to a fourth priority (Level 2 shown in FIG. 8), which is lower than the third priority. Specific vulnerability information is vulnerability information in which exploitation of the vulnerability has been confirmed.
[0085] (Information processing method) An information processing method according to an embodiment will be described below. Fig. 9 is a diagram showing the information processing method according to an embodiment.
[0086] 9, in step S10, the information processing device 10 stores dictionary information that associates specific names with reference names. The dictionary information may include information that associates specific names with first identifiers (see FIG. 5). Although not particularly limited, the information processing device 10 may collect SBOMs created by various creators and include names included in the collected SBOMs as reference names in the dictionary information.
[0087] In step S11, the information processing device 10 receives vulnerability information from the vulnerability server 40 (see, for example, FIG. 4).
[0088] In step S12, the information processing device 10 stores the vulnerability information in the vulnerability DB. The information processing device 10 may store information obtained by extracting various information from the vulnerability information received from the vulnerability server 40 in the vulnerability DB (see FIG. 6 or FIG. 7).
[0089] In step S13, the information processing device 10 receives software information from the system server 30. The software information is information about software target software operating on the system server 30. The system information may be an SBOM or may be information about the target software managed by a package management tool. The software information may include version information of the target software.
[0090] In step S14, the information processing device 10 stores software information relating to the target software operating on the system server 30.
[0091] In step S20, the information processing device 10 receives a request for information on vulnerabilities. The information on vulnerabilities may include the results of the triage described above.
[0092] In step S21, the information processing device 10 executes a name matching process. The name matching process is a process of identifying a specific name from a reference name by referring to dictionary information. The name matching process may include a process of identifying a first identifier from the specific name.
[0093] In step S22, the information processing device 10 identifies vulnerability information. In option 2-1, the information processing device 10 identifies vulnerability information of the target software from the vulnerability DB (see, for example, FIG. 6) using the first identifier of the target software as a search key. In option 2-2, the information processing device 10 identifies vulnerability information of the target software from the vulnerability DB (see FIG. 7) using the second identifier of the target software as a search key.
[0094] In step S23, the information processing device 10 executes triage on the vulnerabilities corresponding to the identified vulnerability information. The details of the triage are as described above (see FIG. 8).
[0095] In step S24, the information processing device 10 transmits display data displaying information regarding the vulnerability to the terminal 20. The information regarding the vulnerability may include the result of the triage described above.
[0096] (Action and Effects) In the embodiment, the information processing device 10 refers to the dictionary information to identify a specific name of the target software corresponding to the reference name of the target software, identifies a first identifier of the target software corresponding to the identified specific name of the target software, and identifies vulnerability information of the target software from the vulnerability database using the first identifier of the target software as a search key. According to such a configuration, even in a case where there are variations in the spelling of the software name, etc., it is possible to match the target software with the vulnerability database by referring to the dictionary information to identify the first identifier of the target software from the reference name of the target software, and it is possible to appropriately identify vulnerability information of the target software.
[0097] In an embodiment, the information processing device 10 may identify vulnerability information of target software included in the SBOM from a vulnerability DB (see, for example, FIG. 6) using the first identifier of the target software as a search key (option 2-1). In option 2-1, although the process of identifying a specific name from a reference name (name matching process) is complicated, after identifying the first identifier, it is possible to identify vulnerability information using the first identifier as a search key.
[0098] In the embodiment, for target software managed by a package management tool, the information processing device 10 may specify vulnerability information of the target software from a vulnerability DB (see FIG. 7) using the second identifier of the target software as a search key (option 2-1). In option 2-2, although it is cumbersome to extract the second identifier from the vulnerability information received from the vulnerability server 40 (for example, "affected software" shown in FIG. 4) and construct the vulnerability DB, the acquired second identifier can be used as it is as a search key.
[0099] In the embodiment, the information processing device 10 may set the highest priority (for example, Level 4 shown in FIG. 8) as the priority for executing measures against the vulnerability for the vulnerability information in which exploitation of the vulnerability has been confirmed. However, when the target software corresponding to the vulnerability information in which exploitation of the vulnerability has been confirmed is not accessible from the outside, the information processing device 10 may set a low priority (for example, Level 1 shown in FIG. 8) as the priority for executing measures against the vulnerability. With such a configuration, triage can be appropriately performed.
[0100] [Change Example 1] Modification 1 of the embodiment will be described below. Differences from the embodiment will be mainly described below.
[0101] In the first modification, an alert regarding software support will be described. Generally, software maintenance and support ends a certain period of time after the software is no longer on sale. Here, software maintenance and support includes software updates for vulnerabilities, inquiries, and maintenance when a failure occurs. The date on which software support ends may be called the EOL (End of Life) date. For software that has passed the EOL date, patches are not applied even when vulnerabilities are discovered, increasing the risk of attack. Therefore, from a security perspective, users usually need to take measures such as upgrading the software or switching to another software before the EOL date.
[0102] Under such a premise, the information processing device 10 (storage unit 13) may store a master DB that stores the information shown in Fig. 10. As shown in Fig. 9, the master DB may store information that associates an ID, a software name, related information, an EOL date, a first identifier (e.g., CPE), and a second identifier (e.g., purl).
[0103] The ID is an identifier used to identify software in the information processing device 10. The ID may be associated with at least one of two or more first identifiers and second identifiers in a one-to-many relationship (for example, "PAxxxx" and "PBxxxx" associated with "XXXX"). The ID may be associated with at least one of one first identifier and second identifier in a one-to-one relationship (for example, "PAyyyy" associated with "YYYY").
[0104] The software name is the name of the software corresponding to the ID, and may be a specific name of the software. In addition, when two or more first identifiers or second identifiers are associated with an ID, the software name may be a comprehensive name that includes each of the software indicated by the two or more first identifiers or second identifiers.
[0105] The related information is information related to the software corresponding to the ID, and may include the release date of the software.
[0106] The EOL date is the date when support for the software ends, and is information provided by the software supplier, etc. The EOL date may be managed for each ID or software name.
[0107] The first identifier and the second identifier may be extracted from vulnerability information (e.g., “Affected Software” shown in FIG. 4) received from the vulnerability server 40. The extracted first identifier and second identifier are associated with an ID or name of a master DB that manages the EOL date and the like.
[0108] The information processing device 10 (control unit 14) refers to the master DB and outputs an alert regarding the target software based on the EOL date when support for the target software ends. Specifically, the information processing device 10 acquires at least one of the first identifier and the second identifier of the target software based on the scan result of the target software or the SBOM imported from outside. The control unit 14 acquires the specific name and EOL date of the target software from the master DB using at least one of the first identifier and the second identifier of the target software as a search key, and outputs an alert based on the EOL date. Here, a comprehensive name including two or more software may be acquired as the specific name of the target software. More specifically, the control unit 14 identifies the specific name of the corresponding target software using at least one of the first identifier and the second identifier of the target software as a search key. Thereafter, the control unit 14 acquires the EOL date corresponding to the identified specific name. The control unit 14 may also directly acquire the corresponding EOL date using at least one of the first identifier and the second identifier of the target software as a search key. The alert may be visually displayed in the EOL date column of the master DB. The alerts may be issued in stages according to the number of days remaining until the EOL date, which may be interpreted as a priority for implementing measures to deal with the end of support.
[0109] The search key used to search for the EOL date is not limited to the first identifier (eg, CPE) and the second identifier (eg, purl), and may be an identifier or name that can identify the target software.
[0110] For example, the information processing device 10 may output an alert 6 months before the EOL date to the effect that support will end in 6 months, may output an alert 3 months before the EOL date to the effect that support will end in 3 months, or may output an alert to the effect that support will end when the EOL date arrives. The information processing device 10 may output an alert to the effect that support has expired after the EOL date.
[0111] The EOL date may be called the EOS (End of Support) date or the EOSL (End of Service Life) date. It may also be read as the EOS (End of Sale) date indicating the end of sales of a service or the EOE (End of Engineering) date indicating the end of technical support.
[0112] (Action and Effects) In the first modification, an alert is output regarding the target software based on the EOL date when support for the target software ends for the information processing device 10. With this configuration, measures such as software upgrades and software changes can be appropriately taken for the target software for which support ends.
[0113] [Other embodiments] Although the present invention has been described by the above-mentioned embodiment, the description and drawings forming a part of this disclosure should not be understood as limiting the present invention. From this disclosure, various alternative embodiments, examples and operating techniques will become apparent to those skilled in the art.
[0114] In the above disclosure, the information processing device 10 receives software information from the system server 30. However, the above disclosure is not limited to this. The software information may be input via a user interface of the information processing device 10. The software information may be acquired by importing the SBOM. Terms such as receive, input, import, and acquire may be read as interchangeable terms.
[0115] In the above disclosure, the vulnerability DB is stored in the storage unit 13 of the information processing device 10. However, the above disclosure is not limited to this. One or more vulnerability servers 40 may be used as the vulnerability DB as they are.
[0116] In the above disclosure, the triage priority level is expressed in five stages. However, the above disclosure is not limited to this. The triage priority level may be expressed in four stages or less, or in six stages or more.
[0117] Although not particularly mentioned in the above disclosure, a program may be provided that causes a computer to execute each process performed by the information processing device 10. The program may also be recorded in a computer-readable medium. Using the computer-readable medium, it is possible to install the program in a computer. Here, the computer-readable medium on which the program is recorded may be a non-transient recording medium. The non-transient recording medium is not particularly limited, and may be, for example, a recording medium such as a CD-ROM or a DVD-ROM.
[0118] Alternatively, a chip may be provided that is configured by a memory that stores a program for executing each process performed by the information processing device 10 and a processor that executes the program stored in the memory.
[0119] [Note] A first feature is an information processing device comprising: a storage unit that stores dictionary information that corresponds a specific name of software with a reference name that indicates software identical to the software having the specific name; an acquisition unit that acquires a reference name of target software; and a control unit that refers to the dictionary information to identify a specific name of the target software that corresponds to the reference name of the target software and identifies a first identifier of the target software that corresponds to the identified specific name of the target software, wherein the storage unit stores a vulnerability database that corresponds to the first identifier of the software and vulnerability information, and the control unit identifies the vulnerability information of the target software from the vulnerability database using the first identifier of the target software as a search key.
[0120] A second feature is an information processing device in which, in the first feature, the acquisition unit acquires version information of the target software along with a reference name of the target software, and the control unit identifies a first identifier of the target software corresponding to the specific name of the target software and the version information of the target software, determines whether the version information included in the first identifier associated with the vulnerability information in the vulnerability database includes the version information included in the first identifier of the target software, and if it is determined that the version information is included, identifies vulnerability information of the target software.
[0121] A third feature is an information processing device according to the first or second feature, wherein the vulnerability database stores a second identifier of software managed by a package management tool in association with vulnerability information, the acquisition unit acquires the second identifier of the target software managed by a package management tool, the storage unit stores the second identifier of the software in association with the vulnerability information in the vulnerability database, and the control unit identifies the vulnerability information of the target software from the vulnerability database using the second identifier of the target software as a search key.
[0122] A fourth feature is the information processing device of the third feature, wherein the acquisition unit acquires version information of the target software included in a second identifier of the target software, and the control unit determines whether the version information included in the second identifier that is associated with the vulnerability information in the vulnerability database includes the version information included in the second identifier of the target software, and if it is determined that the version information is included, identifies the vulnerability information of the target software.
[0123] A fifth feature is an information processing device according to the third or fourth feature, wherein the storage unit stores at least one of a first identifier of the target software and a second identifier of the target software in association with a specific name of the target software, and stores the specific name of the target software in association with a date on which support for the target software will end, and the control unit identifies the specific name of the target software and the date on which support for the target software will end based on at least one of the first identifier of the target software and the second identifier of the target software, and outputs an alert regarding the target software based on the date on which support for the target software will end.
[0124] A sixth feature is an information processing device in which, in at least one of the first to fifth features, the acquisition unit acquires a list of components that constitute the software by importing it from outside, and acquires a reference name of the target software from the list of components.
[0125] A seventh feature is an information processing device in which, in at least one of the first feature to the sixth feature, the control unit sets a priority of the vulnerability information of the target software based on at least one of information indicating a vulnerability level set by a third party organization for a vulnerability corresponding to the identified vulnerability information of the target software, information indicating whether the target software is accessible from outside, information indicating whether an attack against the vulnerability will have a significant impact on business operations, information indicating whether attack code against the vulnerability is in circulation, and information indicating whether exploitation of the vulnerability has been confirmed.
[0126] An eighth feature is an information processing device in which, in at least one of the first to seventh features, the control unit sets the highest priority as a priority for the vulnerability information of the target software when the vulnerability information of the target software is specific vulnerability information and the target software is accessible from outside, and the specific vulnerability information is vulnerability information in which exploitation of a vulnerability corresponding to the vulnerability information of the target software has been confirmed.
[0127] A ninth feature is an information processing device in which, in at least one of the first feature to the eighth feature, when the control unit determines, based on the vulnerability information of the identified target software, that attack code is in circulation for a vulnerability corresponding to the vulnerability information of the target software, set a first priority as the priority of the vulnerability information of the target software, and when the vulnerability information of the target software is specific vulnerability information and is accessible from outside the target software, set a second priority higher than the first priority as the priority of the vulnerability information of the target software, and the specific vulnerability information is vulnerability information in which exploitation of the vulnerability has been confirmed.
[0128] A tenth feature is an information processing device in which, in at least one of the first feature to the ninth feature, the control unit identifies, based on the identified vulnerability information of the target software, that attack code is in circulation for a vulnerability corresponding to the vulnerability information of the target software, and if the target software is accessible from outside, sets a third priority as the priority of the vulnerability information of the target software, and if the vulnerability information of the target software is specific vulnerability information and the target software is not accessible from outside, sets a fourth priority lower than the third priority as the priority of the vulnerability information of the target software, and the specific vulnerability information is vulnerability information in which exploitation of the vulnerability has been confirmed.
[0129] An eleventh feature is an information processing method comprising: a step A of storing dictionary information that corresponds a specific name of software with a reference name that indicates software identical to the software having the specific name; a step B of acquiring a reference name of a target software; a step C of referring to the dictionary information to identify a specific name of the target software that corresponds to the reference name of the target software and to identify a first identifier of the target software that corresponds to the identified specific name of the target software; a step D of storing a vulnerability database that stores the first identifier of the software in correspondence with vulnerability information; and a step E of identifying vulnerability information of the target software from the vulnerability database using the first identifier of the target software as a search key. [Explanation of symbols]
[0130] 10...information processing device, 11...transmission unit, 12...reception unit, 13...storage unit, 14...control unit, 20...terminal, 30...system server, 40...vulnerability server, 100...information processing system, 200...network
Claims
1. a storage unit for storing dictionary information that associates a specific name of software with a reference name that indicates the same software as the software having the specific name; an acquisition unit for acquiring a reference name of the target software; a control unit that refers to the dictionary information, identifies a specific name of the target software corresponding to a reference name of the target software, and identifies a first identifier of the target software corresponding to the identified specific name of the target software; the storage unit stores a vulnerability database that stores a first identifier of the software and vulnerability information in association with each other; The control unit identifies vulnerability information of the target software from the vulnerability database using a first identifier of the target software as a search key.
2. The acquisition unit acquires version information of the target software together with a reference name of the target software, The information processing device of claim 1, wherein the control unit identifies a first identifier of the target software corresponding to a specific name of the target software and version information of the target software, determines whether the version information contained in the first identifier associated with the vulnerability information in the vulnerability database includes the version information contained in the first identifier of the target software, and if it is determined that the version information is included, identifies the vulnerability information of the target software.
3. the vulnerability database stores a second identifier of software managed by a package management tool in association with vulnerability information; The acquisition unit acquires a second identifier of the target software managed by a package management tool, the storage unit stores in the vulnerability database a second identifier of the software and vulnerability information in association with each other, The information processing apparatus according to claim 1 , wherein the control unit identifies vulnerability information of the target software from the vulnerability database by using the second identifier of the target software as a search key.
4. The acquisition unit acquires version information of the target software included in a second identifier of the target software, The information processing device of claim 3, wherein the control unit determines whether the version information included in the second identifier associated with the vulnerability information in the vulnerability database includes the version information included in the second identifier of the target software, and if it determines that the version information is included, identifies the vulnerability information of the target software.
5. the storage unit stores at least one of a first identifier of the target software and a second identifier of the target software in association with a specific name of the target software, and also stores the specific name of the target software in association with a date on which support for the target software will end; The information processing device of claim 3, wherein the control unit identifies a specific name of the target software and a date on which support for the target software will end based on at least one of a first identifier of the target software and a second identifier of the target software, and outputs an alert regarding the target software based on the date on which support for the target software will end.
6. The information processing apparatus according to claim 1 , wherein the acquisition unit acquires a list of components constituting the software by importing the list from an external device, and acquires a reference name of the target software from the list of components.
7. The information processing device of claim 1, wherein the control unit sets a priority of the vulnerability information of the target software based on at least one of information indicating a level of the vulnerability set by a third party organization for the vulnerability corresponding to the identified vulnerability information of the target software, information indicating whether the target software is accessible from outside, information indicating whether an attack against the vulnerability will have a significant impact on business operations, information indicating whether attack code against the vulnerability is in circulation, and information indicating whether exploitation of the vulnerability has been confirmed.
8. the control unit, when the vulnerability information of the target software is specific vulnerability information and the target software is accessible from the outside, sets the highest priority as the priority of the vulnerability information of the target software; The information processing apparatus according to claim 1 , wherein the specific vulnerability information is vulnerability information in which exploitation of a vulnerability corresponding to the vulnerability information of the target software has been confirmed.
9. The control unit is When it is identified that an attack code for a vulnerability corresponding to the vulnerability information of the target software is in circulation based on the identified vulnerability information of the target software, a first priority is set as a priority of the vulnerability information of the target software; when the vulnerability information of the target software is specific vulnerability information and the target software is accessible from the outside, setting a second priority higher than the first priority as the priority of the vulnerability information of the target software; The information processing apparatus according to claim 1 , wherein the specific vulnerability information is vulnerability information in which exploitation of the vulnerability has been confirmed.
10. The control unit is based on the identified vulnerability information of the target software, it is identified that an attack code for a vulnerability corresponding to the vulnerability information of the target software is in circulation, and when the target software is accessible from the outside, a third priority is set as a priority of the vulnerability information of the target software; when the vulnerability information of the target software is specific vulnerability information and the target software is not accessible from the outside, setting a fourth priority level, which is lower than the third priority level, as the priority level of the vulnerability information of the target software; The information processing apparatus according to claim 1 , wherein the specific vulnerability information is vulnerability information in which exploitation of the vulnerability has been confirmed.
11. A step A of storing dictionary information that associates a specific name of software with a reference name that indicates the same software as the software having the specific name; A step B of obtaining a reference name for the subject software; A step C of referring to the dictionary information to identify a specific name of the target software corresponding to a reference name of the target software, and identifying a first identifier of the target software corresponding to the identified specific name of the target software; A step D of storing a vulnerability database in which the first identifier of the software and vulnerability information are stored in association with each other; A method for processing information comprising: a step E of identifying vulnerability information of the target software from the vulnerability database using the first identifier of the target software as a search key.
Citation Information
Patent Citations
Information processor, information processing method and program
JP2007058514A
Cited By
Software parts bill generation device and software parts bill generation method
JP7799888B1