Risk assessment system and risk assessment program
The risk assessment system adjusts attack feasibility based on asset owner skills to enhance cybersecurity risk evaluation accuracy and enable effective countermeasures.
Patent Information
- Application Number
- JP2023190808
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-11-08
- Publication Date
- 2025-05-20
AI Technical Summary
Existing cybersecurity risk assessment methods fail to accurately evaluate the impact and feasibility of cyber attacks due to insufficient cybersecurity skills, leading to underestimated risks and inadequate countermeasures.
A risk assessment system and program that includes asset information storage, skill storage, attack feasibility calculation, impact calculation, and adjustment based on skill levels, and risk assessment to provide a more accurate evaluation of cyber attack risks.
Enables more accurate risk assessment by adjusting attack feasibility based on asset owner skills, allowing for appropriate countermeasures against cyber threats.
Smart Images

Figure 2025078330000001_ABST
Abstract
Description
[Technical field]
[0001] The present invention relates to a risk assessment system and a risk assessment program for assessing the risk of a cyber attack. [Background technology]
[0002] Many automobiles are equipped with numerous electronic control devices called ECUs (Electronic Control Units), and the main functions of the automobile are electronically controlled by the ECUs connecting to an in-vehicle network called CAN (Controller Area Network) and communicating with each other. CAN is connected to smartphones and external servers via external networks such as Wi-Fi (registered trademark). Therefore, vehicles are constantly exposed to the threat of server attacks from outside.
[0003] In recent years, the United Nations Economic Commission for Europe (UN / ECE) has issued a regulation called "UN-R155" that requires cybersecurity measures for automobiles, forcing automobile manufacturers and parts manufacturers to take measures to ensure cybersecurity. In order to meet this "UN-R155," it is necessary to comply with the automotive cybersecurity standard "ISO / SAE21434," but since "ISO / SAE21434" does not include specific details about cybersecurity measures, each company must establish its own procedures.
[0004] It is important for automobile manufacturers and other such companies to analyze vulnerabilities to cyber attacks during product development and make improvements to areas with high risk. "ISO / SAE21434" introduces a method for assessing risk from two perspectives: the impact (severity) of an attack and the feasibility of an attack, and Patent Document 1 discloses a method and system for performing threat analysis using these two evaluation criteria. [Prior art documents] [Patent documents]
[0005] [Patent Document 1] JP 2023-047569 A Summary of the Invention [Problem to be solved by the invention]
[0006] Incidentally, when analyzing cybersecurity risks as described above, how the impact and feasibility of an attack are evaluated greatly influences the analysis results. However, if the skills (knowledge) of cybersecurity are insufficient, there is a problem that the impact and feasibility of an attack cannot be evaluated appropriately. For example, if the skills (knowledge) of cybersecurity are low, there is a tendency to underestimate the feasibility of an attack, in which case the risk is evaluated low and appropriate measures against cyberattacks cannot be taken.
[0007] Therefore, an object of the present invention is to provide a risk assessment system and a risk assessment program that enable more accurate risk assessment of cyber attacks. [Means for solving the problem]
[0008] In order to solve the above problem, the invention of claim 1 includes an asset information storage means for storing asset information on assets that are targets of cyber-attacks, a skill storage means for storing skill information that is a result of comparing the cybersecurity skills of the owner of the asset with predetermined skills, an attack feasibility calculation means for calculating the attack feasibility for each asset based on the asset information, and a cyber-attack impact level for each asset based on the asset information. This risk assessment system is characterized by comprising an impact calculation means, an attack feasibility adjustment means for adjusting the attack feasibility based on the skill information to calculate an adjusted attack feasibility, and a risk assessment means for evaluating the risk of a cyber attack against the asset based on the adjusted attack feasibility and the impact.
[0009] The invention of claim 2 is a risk assessment program characterized by causing a computer to function as an asset information storage means for storing asset information regarding assets that are targets of cyber-attacks, a skill storage means for storing skill information that is the result of comparing the cybersecurity skills of the asset holder with predetermined skills, an attack feasibility calculation means for calculating the attack feasibility for each asset based on the asset information, an impact calculation means for calculating the impact of a cyber-attack for each asset based on the asset information, an attack feasibility adjustment means for adjusting the attack feasibility based on the skill information to calculate an adjusted attack feasibility, and a risk assessment means for evaluating the risk of a cyber-attack on the assets based on the adjusted attack feasibility and the impact. Effect of the Invention
[0010] According to the inventions of claims 1 and 2, the feasibility of an attack is adjusted taking into account the skills of the owner of the asset that is the target of a cyber attack, thereby enabling a more accurate risk assessment of a cyber attack, and ultimately making it possible to take more appropriate measures against a cyber attack. [Brief description of the drawings]
[0011] [Figure 1] 1 is a schematic block diagram showing a risk assessment system according to an embodiment of the present invention. [Diagram 2] 2 is a diagram for explaining a method for adjusting attack feasibility by an attack feasibility adjustment task in the system of FIG. 1. [Diagram 3] FIG. 2 is a diagram for explaining a method of evaluating risk by a risk evaluation task in the system of FIG. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0012] Hereinafter, the present invention will be described based on the illustrated embodiment.
[0013] (Embodiment 1) 1 to 3 show an embodiment of the present invention, and FIG. 1 is a schematic block diagram showing a risk assessment system 1 according to this embodiment. This risk assessment system 1 is a system for assessing the risk of a cyber-attack, and mainly includes an input unit 2, a display unit 3, an asset information database (asset information storage means) 4, a skill database (skill storage means) 5, an attack feasibility calculation task (attack feasibility calculation means) 6, an impact calculation task (impact calculation means) 7, an attack feasibility adjustment task (attack feasibility adjustment means) 8, a risk assessment task (risk assessment means) 9, and a central processing unit 10 for controlling these. Here, in this embodiment, the risk assessment system 1 is configured with one computer, but some of the configuration, for example, the asset information database 4 and the skill database 5, may be configured with another server computer. In this embodiment, a case of assessing the risk of a cyber-attack on an automobile will be described as an example.
[0014] The input unit 2 is an interface for inputting various information, for example, asset information. Here, in this embodiment, the case where asset information is input from the input unit 2 will be mainly described, but asset information may be received and acquired from a server that collects and manages information on assets.
[0015] The display unit 3 is a display that displays various information and images / videos, and displays, for example, a list of asset information and skill information, and the results of risk assessment.
[0016] The asset information database 4 is a database that stores information on assets that are targets of cyber attacks. Assets are broadly divided into two categories: information assets and functional assets. Information assets include information that must be protected, such as personal information, vehicle registration numbers, and various data held by on-board devices, while functional assets include functions that must not be infringed, such as the driving control function, parking function, and wireless LAN function of on-board devices.
[0017] The skill database 5 is a database that stores skill information that is a result of comparing the cybersecurity skills of the asset owner with predetermined skills. The skills stored in the skill database 5 may be the overall cybersecurity skills of the asset owner, or may be individual skills. For example, individual skills may be skills for each attack method of a cyber attack. In the case of skills for each attack method, it is advisable to store them together with information on assets that may be attacked by that attack method. In addition, the evaluation format of the result of comparing the skills of the asset owner with the predetermined skills is not particularly limited, but in this embodiment, the evaluation is made in three stages: "low, medium, and high". In addition, the predetermined skills that are the basis for comparing the skills of the asset owner can be set arbitrarily. In addition, examples of "attack methods" of cyber attacks include eavesdropping, analysis, and unauthorized operation using CAN.
[0018] The attack feasibility calculation task 6 is a task program that calculates the attack feasibility for each asset based on the asset information. This task 6 is started when the asset information to be the target of risk assessment is input from the input unit 2.
[0019] Attack feasibility is an index that indicates the possibility that a corresponding asset will be subjected to a cyber attack, and is calculated for each asset using an evaluation method that complies with ISO / SAE21434. In this evaluation method, the evaluation of four items, "time required to attack," "knowledge required to attack," "opportunity to attack," and "availability of infrastructure required to attack," is scored, and the attack feasibility is evaluated based on the total score. In this embodiment, the evaluation is performed in three stages, "low, medium, and high," but the evaluation format is not limited to this. The final evaluation of attack feasibility is obtained by adjustment using attack feasibility adjustment task 8, which will be described later.
[0020] The attack feasibility may be stored, for example, in the asset information database 4 or in a separate database.
[0021] The impact calculation task 7 is a task program that calculates the impact of a cyber attack on each asset based on the asset information. This task 7 is started when the asset information to be subjected to risk assessment is input from the input unit 2.
[0022] The impact level is an index showing the impact on the user when the relevant asset is subjected to a cyber-attack, and is calculated for each asset using an evaluation method compliant with ISO / SAE21434. In this evaluation method, the evaluation is performed from four perspectives: safety, finance, operation, and privacy. The evaluation results may be evaluated for each of the four perspectives, or may be evaluated by combining the four perspectives. In this embodiment, the evaluation is performed in the latter format. Also, in this embodiment, the evaluation is performed in three stages: "small, medium, and large," but the evaluation format is not limited to this.
[0023] The evaluation result of the impact level may be stored in, for example, the asset information database 4 or may be stored in a separate database. The information may be stored in a database.
[0024] The attack feasibility adjustment task 8 is a task program that adjusts the attack feasibility based on the skill of the asset holder stored in the skill database 5 and calculates the adjusted attack feasibility. Specifically, when the skill of the asset holder is not higher than a predetermined skill in the skill information, the attack feasibility is adjusted to be higher. Here, "not higher than the predetermined skill" refers to a state lower than the predetermined skill or equivalent to the predetermined skill, for example, when the skill level is evaluated in three stages of "low, medium, high", it refers to the cases of "low" and "medium". On the other hand, when the skill of the asset holder is higher than the predetermined skill (for example, when the skill level is evaluated in three stages of "low, medium, high", it is "high"), there is no need to change the attack feasibility.
[0025] FIG. 2 is a diagram for explaining the attack feasibility adjustment method by the attack feasibility adjustment task 8. In this example, it is assumed that the skills of the asset holder are evaluated as "low, medium, high" for each attack method. In this case, for an attack method with a "low" skill level, an adjustment to increase the attack feasibility is required, so the attack feasibility is changed from "low" and "medium" to "high". Similarly, for an attack method with a "medium" skill level, the attack feasibility is changed from "low" to "medium" and from "medium" to "high". On the other hand, for an attack method with a "high" skill level, none of the attack feasibility is changed from "low", "medium", or "high". This makes it possible to avoid a situation in which the attack feasibility is evaluated low when the security skills for cyber-attack attack methods are not high.
[0026] The adjusted attack feasibility adjusted by attack feasibility adjustment task 8 is treated as the final evaluation result of the attack feasibility, and is used in risk assessment task 9, which will be described later. Note that if the attack feasibility is not changed by attack feasibility adjustment task 8, the attack feasibility becomes the adjusted attack feasibility.
[0027] The feasibility of a coordinated attack may be stored, for example, in the asset information database 4 or in a separate database.
[0028] The risk assessment task 9 is a task program for assessing the risk of a cyber attack on an asset based on the adjusted attack feasibility calculated by the attack feasibility adjustment task 8 and the impact calculated by the impact calculation task 7.
[0029] The contents of the risk assessment task 9 will be explained with a concrete example. For example, a case where the attack feasibility of a cyber attack is "low", the impact is "small", and the risk of a cyber attack on asset X that may be attacked by attack methods A and B will be explained as an example. In this case, if the skill of the owner of asset X against attack method A is "low" and the skill of the owner of asset X against attack method B is "high", the attack feasibility of attack for attack method A is changed from "low" to "high" by the attack feasibility adjustment task 8, and the attack feasibility of attack method B remains unchanged at "low". In the risk assessment task 9, using these results, the risk is evaluated as follows based on the matrix shown in FIG. 3. The risk of a cyber attack against asset X by attack method A is evaluated as "P" because the impact is "small" and the adjusted attack feasibility is "high", and the risk of a cyber attack against asset X by attack method B is evaluated as "Q" because the impact is "small" and the adjusted attack feasibility is "low". Although the risk values are assumed to be "P" and "Q" here, the risk values may be expressed as numbers according to the degree of risk.
[0030] As described above, according to the risk assessment system 1 of the present embodiment, the feasibility of an attack is adjusted taking into account the skills of the owner of the asset that is the target of the cyber attack. This will enable more accurate risk assessment of attacks, which will in turn enable more appropriate measures to be taken against cyber attacks.
[0031] (Embodiment 2) Next, a risk assessment system 1 according to a second embodiment of the present invention will be described. Note that the same components as those in the first embodiment will be denoted by the same reference numerals and detailed description thereof will be omitted.
[0032] The risk assessment system 1 according to this embodiment differs from the first embodiment in that the predetermined skills that are used as the basis for comparison when comparing the skills of asset holders are the cybersecurity skills of other companies in the industry to which the product related to the asset belongs (i.e., other companies in the same industry). In this embodiment, other companies in the same industry refer to automobile manufacturers and automobile parts manufacturers other than the own company.
[0033] The comparison with the skills of other companies in the same industry is performed, for example, using an external server. The external server may be a server that provides a service for comparing the cybersecurity skills of the company with those of other companies in the same industry and evaluating the level of the company's skills comprehensively or individually. The results obtained from the server are then loaded into the skill database 5 as skill information.
[0034] As described above, the risk assessment system 1 according to the present embodiment can derive a more accurate skill level by comparing the skills of the asset owner (i.e., the company) with the skills of other companies in the same industry, making it possible to perform risk assessment more appropriately. In addition, since the skill comparison is performed using an external server, it becomes possible to easily update the company's skill level.
[0035] Although the embodiment of the present invention has been described above, the specific configuration is not limited to the above embodiment, and even if there are design changes within the scope of the present invention, they are included in the present invention. For example, the above embodiment has been described as an example of evaluating the risk of cyber attacks against automobiles, but the target of risk evaluation is not limited to automobiles, and may be, for example, a mobile terminal such as a smartphone.
[0036] On the other hand, the risk assessment system 1 as described above may be configured by installing the following risk assessment program in a general-purpose computer. That is, the computer is made to function as an asset information storage means (asset information database 4) for storing asset information on assets that are targets of cyber-attacks, a skill storage means (skill database 5) for storing skill information that is a result of comparing the cybersecurity-related skills of asset owners with predetermined skills, an attack feasibility calculation means (attack feasibility calculation task 6) for calculating the attack feasibility for each asset based on the asset information, an impact calculation means (impact calculation task 7) for calculating the impact of a cyber-attack for each asset based on the asset information, an attack feasibility adjustment means (attack feasibility adjustment task 8) for adjusting the attack feasibility based on the skill information to calculate an adjusted attack feasibility, and a risk assessment means (risk assessment task 9) for assessing the risk of a cyber-attack on an asset based on the adjusted attack feasibility and the impact. [Explanation of symbols]
[0037] 1. Risk Assessment System 2 Input section 3 Display section 4. Asset information database (asset information storage means) 5. Skill database (skill storage means) 6. Attack feasibility calculation task (Method of calculating attack feasibility) 7 Impact calculation task (means of calculating impact) 8. Attack Feasibility Adjustment Task (Attack Feasibility Adjustment Method) 9 Risk assessment tasks (risk assessment tools) 10 Central Processing Unit
Claims
1. An asset information storage means for storing asset information relating to assets that are targets of cyber attacks; A skill storage means for storing skill information that is a result of comparing the cybersecurity skills of the asset owner with predetermined skills; an attack feasibility calculation means for calculating an attack feasibility for each of the assets based on the asset information; an impact calculation means for calculating an impact of a cyber-attack on each of the assets based on the asset information; an attack feasibility adjustment means for adjusting the attack feasibility based on the skill information to calculate an adjusted attack feasibility; a risk assessment means for assessing a risk of a cyber attack against the asset based on the feasibility of the coordinated attack and the impact degree; A risk assessment system comprising:
2. Computer, An asset information storage means for storing asset information relating to assets that are targets of cyber attacks; A skill storage means for storing skill information that is a result of comparing the cybersecurity skills of the asset owner with predetermined skills; an attack feasibility calculation means for calculating an attack feasibility for each of the assets based on the asset information; an impact calculation means for calculating an impact of a cyber-attack on each of the assets based on the asset information; an attack feasibility adjustment means for adjusting the attack feasibility based on the skill information to calculate an adjusted attack feasibility; a risk assessment means for assessing a risk of a cyber attack against the asset based on the feasibility of the coordinated attack and the impact degree; A risk assessment program characterized by functioning as a
Citation Information
Patent Citations
Threat analysis method, and threat analysis system
JP2023047569A