Evaluation apparatus, evaluation method, and program

The evaluation device accurately evaluates the security of information processing devices by determining logical and physical paths to access assets, assessing risk values, and considering vulnerabilities, thereby enhancing security assessment and countermeasure effectiveness.

JP2025093284AActive Publication Date: 2025-06-23PANASONIC AUTOMOTIVE SYST CO LTD
View PDF 12 Cites 0 Cited by

Patent Information

Application Number
JP2024131786
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-12-11
Filing Date
2024-08-08
Publication Date
2025-06-23
Estimated Expiration
2044-08-08

AI Technical Summary

Technical Problem

Existing security countermeasure support devices cannot accurately evaluate the security of information processing devices.

Method used

An evaluation device that assesses the security of a device by determining both logical and physical paths to access assets within the device, evaluating the risk value based on attack possibilities and impact levels, and re-evaluating risk values considering vulnerabilities and separation states.

Benefits of technology

The evaluation device provides an accurate assessment of the security risk of the evaluation target device, enabling more effective countermeasures by determining appropriate priorities for vulnerabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025093284000001_ABST
    Figure 2025093284000001_ABST
Patent Text Reader

Abstract

To provide an evaluation apparatus which can evaluate the safety of an evaluation object apparatus at high precision.SOLUTION: An evaluation apparatus 10 is used for evaluating an evaluation object apparatus 20 including plural physical components for executing processing in accordance with plural theoretical components, and comprises: an input unit 11 for acquiring apparatus information related to the evaluation object apparatus 20; a route determination unit 12 for determining a logical route consisting of an array of one or more logical components from the outside of the evaluation object apparatus 20 to an access to assets as the data or functions owned by the evaluation object apparatus 20 and a physical route consisting of an array of one or more physical components corresponding to the logical route based on the apparatus information; and a risk reevaluation unit 13 for evaluating the risk value of the assets based on the level of attack potential relative to the determined physical route and logical route and the level of impact if the assets are compromised.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to an evaluation device for evaluating a device to be evaluated, etc.

Background Art

[0002] For example, Patent Document 1 discloses a security countermeasure support device. This security countermeasure support device appropriately determines whether or not to implement security countermeasures quantitatively for an information processing device. Specifically, the security countermeasure support device compares specification information representing one or more specification items of the information processing device with item-vulnerability information representing one or more vulnerabilities for each of two or more specification items. Then, the security countermeasure support device determines the presence or absence of vulnerabilities for each of one or more specification items of the information processing device based on the comparison result. Further, the security countermeasure support device determines the urgency of correcting the vulnerability for each of one or more specification items for which a vulnerability is determined, and outputs the determination result. That is, such a security countermeasure support device can also be said to be an evaluation device for evaluating the vulnerability of an information processing device.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] However, the security countermeasure support device of Patent Document 1 above has a problem that it cannot accurately evaluate the security of the information processing device which is the device to be evaluated.

[0005] Therefore, the present disclosure provides an evaluation device etc. that can accurately evaluate the security of a device to be evaluated.

Means for Solving the Problems

[0006] An evaluation device according to one aspect of the present disclosure is an evaluation device that evaluates an evaluation target device including a plurality of physical components for executing processing according to a plurality of logical components, the evaluation device including: an input unit that acquires device information regarding the evaluation target device; a logical path composed of an array of one or more logical components from the outside of the evaluation target device to access an asset that is data or a function possessed by the evaluation target device based on the device information; and a path determination unit that determines a physical path composed of an array of one or more physical components corresponding to the logical path, and an evaluation unit that evaluates a risk value of the asset based on a level of attack possibility for the determined physical path and the logical path and a level of influence when the asset is infringed.

[0007] These general or specific aspects may be implemented in a system, a method, an integrated circuit, a computer program, or a recording medium such as a computer-readable CD-ROM, or may be implemented in any combination of a system, a method, an integrated circuit, a computer program, and a recording medium. The recording medium may be a non-transitory recording medium.

Advantages of the Invention

[0008] The evaluation device of the present disclosure can accurately evaluate the safety of the evaluation target device.

[0009] Furthermore, additional advantages and effects in one aspect of the present disclosure will be apparent from the specification and the drawings. Such advantages and / or effects are provided by the configurations described in the embodiments, the specification, and the drawings, but not all configurations are necessarily required.

Brief Description of the Drawings

[0010]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

[0011] The evaluation device according to the first aspect of the present disclosure is an evaluation device that evaluates an evaluation target device including a plurality of physical components for executing processing according to a plurality of logical components, and includes an input unit that acquires device information regarding the evaluation target device, and based on the device information, from outside the evaluation target device, a logical path composed of an array of one or more logical components until accessing an asset that is data or a function possessed by the evaluation target device, and a physical path composed of an array of one or more physical components corresponding to the logical path, a path determination unit that determines the physical path and the logical path, and an evaluation unit that evaluates the risk value of the asset based on the level of attack possibility for the determined physical path and logical path and the level of impact when the asset is infringed.

[0012] As a result, since the risk value of the asset is evaluated based on the physical path corresponding to the logical path, the accuracy of the evaluation of the risk value can be improved, and the safety of the evaluation target device can be evaluated with high accuracy. That is, the risk value evaluated only by the physical path can be re-evaluated with high accuracy.

[0013] Further, in the evaluation device according to the second aspect, the path determination unit includes a separation setting specifying unit that specifies the separation state set for the plurality of logical components, and a path combining unit that determines the logical path based on the specified separation state and determines the physical path corresponding to the logical path, thereby combining the physical path and the logical path. The evaluation unit may evaluate the risk value of the asset based on the combined physical path and logical path. Note that the second aspect may be dependent on the first aspect.

[0014] As a result, since the logical path is determined based on the separation state of the plurality of logical components, a more appropriate logical path can be determined, and the risk value of the asset can be evaluated with even higher accuracy.

[0015] Also, in the evaluation apparatus according to the third aspect, the input unit further acquires vulnerability evaluation information indicating the vulnerability of at least one of the plurality of logical components, and the path determination unit further re-determines the physical path and the logical path for each of the vulnerabilities of at least one of the logical components indicated by the vulnerability evaluation information based on the vulnerability. The evaluation unit further re-evaluates the risk value of the asset based on the re-determined physical path and logical path for each of the vulnerabilities of the at least one logical component, and the evaluation apparatus may further include a priority determination unit that determines the priority of countermeasures for each of the vulnerabilities of the at least one logical component based on the re-evaluated risk value of the asset. Note that the third aspect may be subordinate to the first aspect or the second aspect.

[0016] Thereby, for each vulnerability, the risk value of the asset is re-evaluated based on the logical path corresponding to the vulnerability, and the priority of countermeasures for the vulnerability is determined based on the re-evaluated risk value. Therefore, an appropriate priority for the vulnerability can be derived, and the safety of the device under evaluation can be improved by taking countermeasures according to the priority.

[0017] Also, in the evaluation apparatus according to the fourth aspect, the device under evaluation has a plurality of assets including the asset, and for each of the plurality of assets, (a) the path determination unit re-determines the physical path and the logical path for the asset, and (b) the evaluation unit re-evaluates the risk value of the asset based on the re-determined physical path and logical path. The priority determination unit may determine the priority for the vulnerability based on the risk values re-evaluated for each of the plurality of assets for each of the vulnerabilities of the at least one logical component. Note that the fourth aspect may be subordinate to the third aspect.

[0018] As a result, based on the risk values re-evaluated for each of the plurality of assets, the priority of countermeasures against vulnerabilities is determined, so that appropriate priorities can be derived from the perspective of the plurality of assets, and the safety of the device under evaluation can be effectively enhanced by taking countermeasures according to the priorities.

[0019] Further, in the evaluation device according to the fifth aspect, for each of the vulnerabilities of the at least one logical component, the priority determination unit may determine the priority for the vulnerability based on (a) the sum of the risk values re-evaluated for each of the plurality of assets, (b) the number of risk values indicating a predetermined maximum value among the risk values re-evaluated for each of the plurality of assets, or (c) the sum of the amounts of change in the risk values re-evaluated for each of the plurality of assets. Note that the fifth aspect may be dependent on the fourth aspect.

[0020] As a result, appropriate priorities according to the purpose can be derived.

[0021] Further, in the evaluation device according to the sixth aspect, the input unit further acquires vulnerability evaluation information indicating the vulnerability of at least one logical component among the plurality of logical components as a score value, the device under evaluation has a plurality of assets including the assets, the route determination unit determines the respective logical routes of the plurality of assets, and the evaluation device further includes a score calculation unit that calculates, as a priority score value, the priority of countermeasures against the vulnerability for each of the vulnerabilities of the at least one logical component indicated by the vulnerability evaluation information, based on the score value of the vulnerability and the usage status of the logical component corresponding to the vulnerability by the plurality of assets. Note that the sixth aspect may be dependent on any one of the first to fifth aspects.

[0022] As a result, the priority can be derived as a priority score value without using the risk value of the asset, and the degree of freedom in deriving the priority can be increased.

[0023] Also, in the evaluation device according to the seventh aspect, the evaluation device further includes a usage situation specifying unit that specifies the usage situation of the logical components corresponding to the vulnerability by the plurality of assets as the number of assets using the logical components, and the score calculation unit may calculate the priority score value by multiplying the score value by the number of assets. Note that the seventh aspect may be dependent on the sixth aspect.

[0024] As a result, the more assets use the logical components corresponding to the vulnerability, the higher the priority (i.e., the priority score value) for the vulnerability is derived, so that an appropriate priority can be derived.

[0025] Also, the evaluation device according to the eighth aspect is an evaluation device that evaluates an evaluation target that executes processing according to a plurality of logical components, and includes an input unit that acquires configuration information regarding the evaluation target, and based on the configuration information, from outside the evaluation target, a path determination unit that determines a logical path composed of an array of one or more logical components until accessing an asset that is data or a function possessed by the evaluation target, and an evaluation unit that evaluates the risk value of the asset based on the level of attack possibility for the determined logical path and the level of impact when the asset is infringed.

[0026] As a result, even when the physical path is unknown, the risk value based on the logical path can be derived. The derived risk value may be combined with the physical path later for risk re-evaluation. An effect of shortening the risk re-evaluation period in the derivative deployment to other physical configurations can be expected.

[0027] Hereinafter, embodiments will be specifically described with reference to the drawings.

[0028] Note that all the embodiments described below show comprehensive or specific examples. The numerical values, shapes, materials, components, arrangement positions and connection forms of the components, steps, order of steps, etc. shown in the following embodiments are merely examples and not intended to limit the present disclosure. Among the components in the following embodiments, the components not described in the independent claims indicating the top-level concept are described as optional components.

[0029] Also, each figure is a schematic diagram and not necessarily drawn precisely. In each figure, the same reference numerals are assigned to the same components.

[0030] (Embodiment 1) The evaluation device in this embodiment re-evaluates the risk value of the assets possessed by the device under evaluation. That is, the evaluation device in this embodiment re-evaluates the risk value of the assets evaluated by the threat analysis device at the development stage of the device under evaluation. Note that the process of evaluating the risk value can also be said to be the process of deriving the risk value, and the process of re-evaluating the risk value can also be said to be the process of re-deriving the risk value. Hereinafter, the evaluation of the risk value by the threat analysis device will be described, and then the evaluation device in this embodiment will be described.

[0031] FIG. 1 is a diagram for explaining the risk value evaluated by the threat analysis device.

[0032] As shown in Fig. 1(a), for example, the threat analysis device evaluates the risk values of assets A, B, and C of the device 20 to be evaluated. Assets A, B, and C are data or functions to be protected in the device 20 to be evaluated. Also, the device 20 to be evaluated is configured as, for example, an ECU (Electronic Control Unit) mounted on a vehicle and communicates wirelessly or via wire with external devices such as the smartphone 91 and the Diag92. Note that the smartphone 91 is a smartphone, and the Diag92 is a device for diagnosing vehicle malfunctions or defects, that is, a diagnosis. Such a device 20 to be evaluated includes physical components: a BT interface 21, a USB interface 22, a CAN interface 23, a Main microcomputer 24, and a CAN microcomputer 25. The BT interface 21 is also denoted as BT I / F and is an interface for Bluetooth (registered trademark). The USB interface 22 is also denoted as USB I / F and is an interface for USB (Universal Serial Bus). The CAN interface 23 is also denoted as CAN I / F and is an interface for CAN (Controller Area Network). The Main microcomputer 24 is a microcomputer that controls the device 20 to be evaluated. The Main microcomputer 24 has the above-mentioned assets A, B, and C. The CAN microcomputer 25 is a microcomputer that controls the CAN of the device 20 to be evaluated. Note that the physical components are hardware components.

[0033] Here, there are physical paths between the Main microcomputer 24 and each of the BT interface 21, the USB interface 22, and the CAN microcomputer 25. Also, there is a physical path between the BT interface 21 and the smartphone 91. There is also a physical path between the CAN microcomputer 25 and the CAN interface 23, and there is also a physical path between the CAN interface 23 and the Diag92. Note that the physical path is a physical connection path.

[0034] In addition, physical components may have an attackability level assigned to them. For example, the BT interface 21 has a Medium attackability level assigned to it. Also, the USB interface 22 has a Very Low attackability level assigned to it.

[0035] Moreover, for an asset, a level of impact on the device under evaluation 20 caused by an attack on that asset is set. For example, for asset A, a Moderate impact level is set, for asset B, a Severe impact level is set, and for asset C, a Major impact level is set.

[0036] The threat analysis device determines an attack path to each of asset A, asset B, and asset C. That is, the threat analysis device determines a physical path consisting of an array of one or more physical components from an external device to that asset for each of asset A, asset B, and asset C. Hereinafter, such a physical path is also referred to as a physical path to the asset.

[0037] For example, when the smartphone 91 attacks assets A, B, and C, the smartphone 91 may access the Main microcontroller 24 via the BT interface 21 to which an attackability level of "Medium" is assigned. Alternatively, the smartphone 91 may access the Main microcontroller 24 via the USB interface 22 to which an attackability level of "Very Low" is assigned. In this case, the threat analysis device determines an attack path via the physical component to which the highest attackability level is assigned. In the case of the above example, the highest attackability level is Medium. Therefore, the attack path determined by the threat analysis device indicates the physical path from the smartphone 91 to the Main microcontroller 24 via the BT interface 21.

[0038] The threat analysis device evaluates the risk value by referring to the risk matrix table shown in Fig. 1(b) and deriving the risk value of the asset using the level of attack possibility "Medium" and the level of impact on the asset.

[0039] As shown in Fig. 1(b), the risk matrix table shows the risk value corresponding to each combination of the level of attack possibility and the level of impact. The levels of attack possibility are distinguished as Very Low, Low, Medium, and High. Note that these levels are arranged in ascending order. Also, the levels of impact are distinguished as Severe, Major, Moderate, and Negligible. Note that these levels are arranged in descending order.

[0040] In the above example, the level of impact on Asset A is Moderate, the level of impact on Asset B is Severe, and the level of impact on Asset C is Major. Also, the level of attack possibility for the attack path to these assets is Medium. That is, on the attack path, i.e., the physical path leading to the asset, the highest level of attack possibility is Medium. Therefore, the risk reevaluation unit 13 refers to the risk matrix table and derives "2" as the risk value of Asset A, "4" as the risk value of Asset B, and "3" as the risk value of Asset C. Thereby, the respective risk values of Asset A, Asset B, and Asset C are evaluated. Note that the level of impact, the level of attack possibility, and the risk matrix table are defined, for example, by ISO (International Organization for Standardization) 21434.

[0041] The evaluation device 10 in the present embodiment reevaluates the risk value thus evaluated.

[0042] Fig. 2 is a block diagram showing an example of the configuration of the evaluation device in the present embodiment.

[0043] The evaluation device 10 in this embodiment is a device that evaluates the safety of the evaluation target device 20 including a plurality of physical components for executing processing according to a plurality of logical components, and re-evaluates the risk value of the assets evaluated by the threat analysis device as described above. Such an evaluation device 10 includes an input unit 11, a path determination unit 12, a risk re-evaluation unit 13, and an output unit 14.

[0044] The input unit 11 acquires the logical configuration information D1 and the threat analysis information D2, which are device information regarding the evaluation target device 20. The logical configuration information D1 indicates the logical configuration of the evaluation target device 20. The logical configuration can also be said to be a software configuration. Further, the logical configuration information D1 may indicate a software component list, that is, an SBOM (Software Bill Of Materials). The threat analysis information D2 indicates, for example, the risk value of each asset evaluated by the threat analysis device, the level of influence of each asset, and one or more attack paths. Note that the attack path may indicate the physical path leading to the asset and the level of attack possibility on the physical path.

[0045] The path determination unit 12 determines a physical path and a logical path. That is, based on the device information, the path determination unit 12 determines, from outside the evaluation target device 20, a logical path composed of an array of one or more logical components until accessing an asset that is data or a function possessed by the evaluation target device 20, and a physical path composed of an array of one or more physical components corresponding to the logical path. Note that the logical component is, for example, software. Also, the logical path is also called the logical path leading to the asset, and the physical path is the physical path leading to the above-described asset. Such a path determination unit 12 includes a separation setting identification unit 12a and a path combination unit 12b. The separation setting identification unit 12a identifies the separation state set in the logical configuration of the evaluation target device 20, that is, the separation state set in a plurality of logical components. The path combination unit 12b combines the physical path and the logical path by determining the logical path based on the identified separation state and determining the physical path corresponding to the logical path.

[0046] The risk re-evaluation unit 13 evaluates the risk value of an asset based on the physical path and the logical path combined by the path combination unit 12b. That is, the risk re-evaluation unit 13 evaluates the risk value of the asset based on the level of attack possibility against the physical path and the logical path determined by the path combination unit 12b and the level of impact when the asset is infringed. In this embodiment, since the risk value of the asset has been previously evaluated by the threat analysis device, the risk re-evaluation unit 13 re-evaluates the risk value of the asset evaluated by the threat analysis device. Note that if the risk value of the asset has not been previously evaluated by the threat analysis device, that is, if the risk value of the asset is not shown in the threat analysis information D2, the risk re-evaluation unit 13 may evaluate rather than re-evaluate the risk value. Such a risk re-evaluation unit 13 may be called an evaluation unit.

[0047] The output unit 14 generates information indicating the risk value of the asset evaluated or re-evaluated by the risk re-evaluation unit 13 as asset risk information D3 and outputs it to the outside of the evaluation device 10.

[0048] FIG. 3 is a diagram for explaining the processing operation of the path determination unit 12 in this embodiment.

[0049] The Main microcomputer 24 has a plurality of logical components. For example, as shown in FIG. 3, the Main microcomputer 24 has, as a plurality of logical components, a virtualization infrastructure 31, a BT driver 32, a USB driver 33, an I2C driver 34, a first OS 35, a second OS 36, a container 37, a first function 38, a second function 39, and a third function 40.

[0050] The virtualization infrastructure 31 is a hypervisor (also called HV) installed in the ECU. The BT driver 32 is a driver for controlling or operating the BT interface 21. The USB driver 33 is a driver for controlling or operating the USB interface 22. The I2C driver 34 is a driver for controlling or operating the communication interface of I2C (Inter-Integrated Circuit). The first OS 35 and the second OS 36 are operating systems. The container 37 is, for example, a container used in Docker. The first function 38 has asset A, the second function 39 has asset B, and the third function 40 has asset C.

[0051] Also, there are logical paths between the virtualization infrastructure 31 and each of the BT driver 32, the USB driver 33, and the I2C driver 34. There is also a logical path between the BT driver 32 and the first OS 35, and there is a logical path between the first OS 35 and the first function 38. Also, there are logical paths between the second OS 36 and each of the USB driver 33, the I2C driver 34, the container 37, the second function 39, and the third function 40. Furthermore, there is a logical path between the container 37 and the third function 40.

[0052] Here, a memory separation mechanism is set in the virtualization infrastructure 31 and the container 37. Note that the memory separation mechanism is also simply called the separation mechanism. By the separation mechanism of the virtualization infrastructure 31, the BT driver 32, the first OS 35, and the first function 38 are separated from the USB driver 33, the I2C driver 34, the second OS 36, the container 37, the second function 39, and the third function 40, and the logical paths between them are blocked. That is, the logical path between the BT driver 32 and the second OS 36 is blocked. Therefore, that logical path is regarded as non-existent. Also, by the separation mechanism of the container 37, the logical path between the second OS 36 and the third function 40 is blocked. Therefore, that logical path is regarded as non-existent. By such a separation mechanism of the logical components, a separated state is set for the plurality of logical components included in the device under evaluation 20.

[0053] The logical configuration information D1 acquired by the input unit 11 indicates a plurality of logical components included in the Main microcomputer 24, a logical path between those logical components, and a separation mechanism set for one or more of the plurality of logical components, as described above.

[0054] The threat analysis information D2 acquired by the input unit 11 indicates, for each of the assets A, B, and C of the evaluation target device 20, the level of impact set for that asset and one or more attack paths to that asset.

[0055] For each of the assets A, B, and C, if a plurality of attack paths are shown in the threat analysis information D2, the path determination unit 12 extracts one or more attack paths from the plurality of attack paths based on the logical configuration information D1 and determines the one or more attack paths as the attack paths to be evaluated. That is, the path determination unit 12 determines the physical path to each of the assets A, B, and C based on the logical configuration information D1. For example, the path determination unit 12 determines the physical path from the smartphone 91 to the asset A of the Main microcomputer 24 via the BT interface 21. Specifically, it is as follows.

[0056] The separation setting specifying unit 12a specifies the above-described separation states set for a plurality of logical components included in the Main microcomputer 24 based on the separation mechanism indicated in the logical configuration information D1. The path coupling unit 12b determines the logical path from outside the Main microcomputer 24 to each asset based on the separation state. That is, the path coupling unit 12b determines the logical paths from the virtualization infrastructure 31 to each of the asset A, asset B, and asset C. For example, the path coupling unit 12b determines, as the logical path to the asset A, the path from the virtualization infrastructure 31 through the BT driver 32 and the first OS 35 to the first function 38. Also, the path coupling unit 12b deems that there is no logical path between the BT driver 32 and the second OS 36 based on the above-described separation state. As a result, the path coupling unit 12b determines, as the logical path to the asset B, the path from the virtualization infrastructure 31 through the USB driver 33 or the I2C driver 34 and the second OS 36 to the second function 39. Similarly, the path coupling unit 12b deems that there is no logical path between the second OS 36 and the third function 40 based on the above-described separation state. As a result, the path coupling unit 12b determines, as the logical path to the asset C, the path from the virtualization infrastructure 31 through the USB driver 33 or the I2C driver 34, the second OS 36, and the container 37 to the third function 40.

[0057] Furthermore, the path coupling unit 12b couples the physical path and the logical path by determining a physical path corresponding to the determined logical path for each of the asset A, asset B, and asset C.

[0058] FIG. 4 is a diagram showing an example of the combined physical path and logical path.

[0059] For example, the path combiner 12b extracts an attack path corresponding to the logical path leading to the asset A from a plurality of attack paths to the asset A shown in the threat analysis information D2. As described above, the logical path leading to the asset A is a path from the virtualization infrastructure 31 to the first function 38 via the BT driver 32 and the first OS 35. Therefore, the path combiner 12b extracts, as an attack path corresponding to the logical path leading to the asset A, from a plurality of attack paths to the asset A shown in the threat analysis information D2, an attack path indicating the physical path from the smartphone 91 to the asset A of the Main microcomputer 24 via the BT interface 21. Thereby, a physical path corresponding to the logical path leading to the asset A is determined. That is, as shown in FIG. 4(a), as the path leading to the asset A, the physical path "smartphone 91, BT interface 21, Main microcomputer 24" + the logical path "virtualization infrastructure 31, BT driver 32, first OS 35, first function 38" is determined. In this way, the physical path and the logical path leading to the asset A are combined.

[0060] Also, for example, the path combiner 12b extracts an attack path corresponding to the logical path to the asset B from a plurality of attack paths to the asset B shown in the threat analysis information D2. As described above, the logical path to the asset B is a path from the virtualization infrastructure 31, through the USB driver 33 or the I2C driver 34, and the second OS 36, to the second function 39. Therefore, the path combiner 12b determines, as an attack path corresponding to the logical path to the asset B, from a plurality of attack paths to the asset B shown in the threat analysis information D2, an attack path indicating the physical path from the external device 90 to the asset B of the Main microcomputer 24 via the USB interface 22. As a result, a physical path corresponding to the logical path to the asset B is determined. As a result, the attack path determined by the threat analysis device, that is, the physical path from the smartphone 91 to the Main microcomputer 24 via the BT interface 21, is not determined as the physical path to be evaluated by the evaluation device 10. That is, as the path to the asset B, the physical path "external device 90, USB interface 22, Main microcomputer 24" + the logical path "virtualization infrastructure 31, USB driver 33, second OS 36, second function 39" is determined. In this way, the physical path and the logical path to the asset B are combined.

[0061] Similarly, the path combining unit 12b extracts an attack path corresponding to the logical path leading to the asset C from a plurality of attack paths to the asset C shown in the threat analysis information D2. As described above, the logical path leading to the asset C is a path from the virtualization infrastructure 31, through the USB driver 33 or the I2C driver 34, the second OS 36, and the container 37, to the third function 40. Therefore, the path combining unit 12b determines, as an attack path corresponding to the logical path leading to the asset C, from a plurality of attack paths to the asset C shown in the threat analysis information D2, an attack path indicating the physical path from the external device 90 to the asset C of the Main microcomputer 24 via the USB interface 22. As a result, the physical path corresponding to the logical path leading to the asset C is determined. As a result, the attack path determined by the threat analysis device, that is, the physical path from the smartphone 91 to the Main microcomputer 24 via the BT interface 21, is not determined as the physical path to be evaluated by the evaluation device 10. That is, as the path leading to the asset C, the physical path "external device 90, USB interface 22, Main microcomputer 24" + the logical path "virtualization infrastructure 31, USB driver 33, second OS 36, container 37, third function 40" is determined. In this way, the physical path and the logical path leading to the asset C are combined.

[0062] Based on the threat analysis information D2, the risk reevaluation unit 13 identifies the highest level from the levels of attack likelihood assigned to one or more physical components on the physical path determined for each of the assets A, B, and C. Then, while referring to the risk matrix table shown in FIG. 2(b), the risk reevaluation unit 13 uses the level of attack likelihood identified as the highest level and the level of impact of the asset to derive the risk value of the asset. As a result, the risk value is reevaluated.

[0063] For example, the risk reevaluation unit 13 specifies the level "Medium" of the attack possibility of the BT interface 21 as the highest level for the physical path leading to asset A. Then, in the risk matrix table shown in FIG. 2(b), the risk reevaluation unit 13 derives the risk value associated with the combination of the attack possibility level "Medium" and the impact level "Moderate" of asset A as the risk value "2" of asset A. As a result, the risk value of that asset A is reevaluated. That is, as shown in FIG. 3, the risk value "2" of asset A evaluated by the threat analysis device is also reevaluated as "2" by the evaluation device 10.

[0064] Also, the risk reevaluation unit 13 specifies the level "Very Low" of the attack possibility of the USB interface 22 as the highest level for the physical path leading to asset B. Then, in the risk matrix table shown in FIG. 2(b), the risk reevaluation unit 13 derives the risk value associated with the combination of the attack possibility level "Very Low" and the impact level "Severe" of asset B as the risk value "2" of asset B. As a result, the risk value of that asset B is reevaluated. That is, as shown in FIG. 3, the risk value "4" of asset B evaluated by the threat analysis device is reevaluated as "2" by the evaluation device 10.

[0065] Also, the risk reevaluation unit 13 specifies the level "Very Low" of the attack possibility of the USB interface 22 as the highest level for the physical path leading to asset C. Then, in the risk matrix table shown in FIG. 2(b), the risk reevaluation unit 13 derives the risk value associated with the combination of the attack possibility level "Very Low" and the impact level "Major" of asset C as the risk value "1" of asset C. As a result, the risk value of that asset C is reevaluated. That is, as shown in FIG. 3, the risk value "3" of asset C evaluated by the threat analysis device is reevaluated as "1" by the evaluation device 10.

[0066] FIG. 5 is a flowchart showing an example of the processing operation of the evaluation apparatus 10.

[0067] First, the input unit 11 of the evaluation apparatus 10 acquires the logical configuration information D1 and the threat analysis information D2 as device information (step S11). Next, the separation setting specifying unit 12a specifies the separation states set for the plurality of logical components included in the evaluation target device 20 based on the logical configuration information D1 (step S12).

[0068] Next, the path combining unit 12b combines, for each asset, the logical path and the physical path corresponding to the logical path based on the separation state (step S13). The risk re-evaluation unit 13 re-evaluates the risk value of each asset using the combined logical path and physical path (step S14). Then, the output unit 14 generates and outputs asset risk information D3 indicating the risk value for each re-evaluated asset (step S15). Note that the asset risk information D3 may indicate not only the risk value for each re-evaluated asset but also the risk value before the re-evaluation. The risk value before the re-evaluation is the risk value indicated by the threat analysis information D2.

[0069] As described above, in the present embodiment, since the risk value of an asset is evaluated based on the physical path corresponding to the logical path, the accuracy of the evaluation of the risk value can be improved, and the safety of the evaluation target device 20 can be evaluated with high accuracy. That is, the risk value evaluated only based on the physical path can be re-evaluated with high accuracy. Also, since the logical path is determined based on the separation states of the plurality of logical components, a more appropriate logical path can be determined, and the risk value of the asset can be evaluated with even higher accuracy.

[0070] Note that in the above example, the device 20 to be evaluated is an ECU, but it may be other devices without being limited to the ECU. Further, the device 20 to be evaluated may be a vehicle or a system equipped with an ECU. In this case, the above-mentioned Main microcomputer 24 may be an ECU or a server. Thereby, the risk value based on the separation mechanism and the logical path of the ECU can be re-evaluated.

[0071] Further, the separation states set for the plurality of logical components may be not only the state in which the plurality of logical components are separated into two or more element groups, but also a multi-stage separation state in which the inside of the element group is further separated. For example, the plurality of logical components are separated into two or more element groups by the virtualization platform 31, and the plurality of logical components included in one of the element groups are separated into two or more sub-element groups by containers.

[0072] Also, when vulnerabilities that are difficult to counter occur in software such as open source software (OSS), the risk value may be reduced by switching the logical path to an alternative logical path.

[0073] (Embodiment 2) FIG. 6 is a block diagram showing an example of the configuration of the evaluation apparatus in the present embodiment.

[0074] The evaluation apparatus 10a in the present embodiment includes each component that the evaluation apparatus 10 in Embodiment 1 has, and further includes a priority determination unit 15. Further, the input unit 11 in the present embodiment acquires not only the logical configuration information D1 and the threat analysis information D2, but also the vulnerability evaluation information D4. The vulnerability evaluation information D4 indicates the vulnerability of at least one of the plurality of logical components included in the device 20 to be evaluated.

[0075] In the evaluation apparatus 10a of the present embodiment, for example, when the device 20 to be evaluated has been shipped and is in operation, first, by performing the same processing operations as the evaluation apparatus 10 of the first embodiment, the risk value of the asset is re-evaluated. By this re-evaluation, the risk value evaluated by the threat analysis apparatus is re-evaluated by the evaluation apparatus 10a. Then, when the vulnerability evaluation information D4 is acquired by the input unit 11, the evaluation apparatus 10a in the present embodiment re-evaluates the risk value of the asset. By this re-re-evaluation, the risk value evaluated at the development stage is re-evaluated by the evaluation apparatus 10a based on the vulnerability evaluation information D4. That is, if the risk value of the asset has been evaluated by the threat analysis apparatus at the development stage, the evaluation and re-evaluation by the evaluation apparatus 10a correspond to the re-evaluation and re-re-evaluation, respectively.

[0076] Specifically, when the vulnerability evaluation information D4 is acquired by the input unit 11, the path determination unit 12 in the present embodiment re-determines the physical path and the logical path leading to the asset for each vulnerability of at least one logical component indicated by the vulnerability evaluation information D4 based on the vulnerability. Then, the risk re-evaluation unit 13 re-evaluates the risk value of the asset based on the re-determined physical path and logical path for each vulnerability of the at least one logical component.

[0077] The priority determination unit 15 determines the priority of the countermeasure against the vulnerability for each vulnerability of at least one logical component indicated by the vulnerability evaluation information D4 based on the re-evaluated risk value of the asset, that is, the re-re-evaluated risk value of the asset. That is, the priority determination unit 15 determines the priority against the vulnerability. The output unit 14 generates vulnerability priority information D5 regarding the priority determined for each vulnerability of at least one logical component indicated by the vulnerability evaluation information D4 and outputs it to the outside of the evaluation apparatus 10a.

[0078] When the device under evaluation 20 has a plurality of assets, the risk reevaluation unit 13 reevaluates the risk value of each of the plurality of assets. Then, the priority determination unit 15 determines the priority of countermeasures against vulnerabilities based on the risk values reevaluated for each of the plurality of assets. That is, for each of the plurality of assets, the path determination unit 12 re-determines the physical path and the logical path for the asset, and the risk reevaluation unit 13 reevaluates the risk value of the asset based on the re-determined physical path and logical path. Note that the physical path and the logical path are the physical path and the logical path leading to the asset. Then, the priority determination unit 15 determines the priority for each vulnerability of at least one logical component based on the risk values reevaluated for each of the plurality of assets.

[0079] FIG. 7 is a diagram for explaining the determination of priority.

[0080] For example, as shown in Fig. 7(a), the vulnerability assessment information D4 indicates the vulnerability D of the first OS 35, which is a logical component. Specifically, the vulnerability D is shown as the severity of the vulnerability, and more specifically, it is shown as the value of the CVSS (Common Vulnerability Scoring System) (i.e., the CVSS score value). Note that the vulnerability assessment information D4 may show the CVSS score value for each CVE (Common Vulnerabilities and Exposures) CVE identification number. The separation setting identification unit 12a of the route determination unit 12 identifies the separation state when the vulnerability D is shown for the first OS 35. In this case, the separation setting identification unit 12a identifies the same separation state as the separation state when the vulnerability D is not shown for the first OS 35. That is, the separation setting identification unit 12a identifies the same separation state as at the time of risk value evaluation. As a result, the route determination unit 12 determines the same logical route and physical route as at the time of risk value evaluation for each of the assets A, B, and C. Therefore, the risk reevaluation unit 13 derives the same risk value as at the time of evaluation for each of the assets A, B, and C. Thereby, the risk values of the assets A, B, and C are reevaluated.

[0081] In this case, since the change amount of each of the risk values of the asset A, the asset B, and the asset C is 0, the priority determination unit 15 calculates the risk value change amount "0" as the sum of those change amounts, as shown in Fig. 7(b). As a result, the priority determination unit 15 determines that the priority of the vulnerability D is "low".

[0082] Further, as shown in Fig. 7(a), the vulnerability assessment information D4 indicates the vulnerability E of the virtualization infrastructure 31, which is a logical component. The separation setting specifying unit 12a of the route determination unit 12 specifies the separation state when the vulnerability E is indicated for the virtualization infrastructure 31. In this case, the separation setting specifying unit 12a specifies a separation state different from the separation state when the vulnerability E is not indicated for the virtualization infrastructure 31. That is, the separation setting specifying unit 12a determines that there is no separation mechanism for the virtualization infrastructure 31 and only the separation mechanism for the container 37 exists. As a result, the separation setting specifying unit 12a specifies a separation state in which there is a logical path between the BT driver 32 and the second OS 36, and the logical path is blocked between the second OS 36 and the third function 40. In other words, the separation setting specifying unit 12a specifies a separation state in which the BT driver 32, the first OS 35, and the first function 38 are not separated from the USB driver 33, the I2C driver 34, the second OS 36, the container 37, the second function 39, and the third function 40, and the second OS 36 and the third function 40 are separated.

[0083] As a result, the route determination unit 12 determines the same logical and physical routes for Asset A as those at the time of risk value evaluation, but determines different logical and physical routes for each of Asset B and Asset C from those at the time of risk value evaluation. That is, as a route to Asset B, the route determination unit 12 determines a logical route passing through the BT driver 32 having a higher attack possibility level than the USB driver 33 and the I2C driver 34, and a physical route corresponding to the logical route. Specifically, as a route to Asset B, the physical route "smartphone 91, BT interface 21, Main microcomputer 24" + the logical route "virtualization infrastructure 31, BT driver 32, second OS 36, second function 39" is determined. Similarly, the route determination unit 12 determines a logical route passing through the BT driver 32 having a higher attack possibility level than the USB driver 33 and the I2C driver 34, and a physical route corresponding to the logical route as a route to Asset C. Specifically, as a route to Asset C, the physical route "smartphone 91, BT interface 21, Main microcomputer 24" + the logical route "virtualization infrastructure 31, BT driver 32, second OS 36, container 37, third function 40" is determined.

[0084] Therefore, the risk reevaluation unit 13 derives the same risk value "2" as at the time of evaluation for Asset A. On the other hand, the risk reevaluation unit 13 derives a risk value "4" different from the risk value "2" at the time of evaluation for Asset B, and also derives a risk value "3" different from the risk value "1" at the time of evaluation for Asset C. As a result, the risk values of Asset A, Asset B, and Asset C are reevaluated.

[0085] In this case, the change amount of the risk value of Asset A is "0", the change amount of the risk value of Asset B is "+2", and the change amount of the risk value of Asset C is "+2". Therefore, as shown in FIG. 7(b), the priority determination unit 15 calculates a risk value change amount of "+4" as the sum of those change amounts. As a result, the priority determination unit 15 determines that the priority of Vulnerability D is "high".

[0086] Note that, as shown in FIGS. 7(a) and 7(b), even when the vulnerability assessment information D4 indicates the vulnerability F of the USB driver 33, the same processing as when the vulnerability assessment information D4 indicates the vulnerability D of the first OS 35 is performed.

[0087] Also, in the above example, if the separation setting identification unit 12a determines that there is no separation mechanism set for the logical component if the vulnerability assessment information D4 indicates the vulnerability of the logical component, the separation setting identification unit 12a may determine that there is no separation mechanism set for the logical component corresponding to the vulnerability when the CVSS score value of the vulnerability is equal to or greater than the threshold value. Further, if the change amount of the risk value of the vulnerability is less than the first threshold value, the priority determination unit 15 may determine that the priority for the vulnerability is "low". Then, if the change amount of the risk value of the vulnerability is equal to or greater than the first threshold value and less than the second threshold value, the priority determination unit 15 may determine that the priority for the vulnerability is "medium", and if the change amount of the risk value of the vulnerability is equal to or greater than the second threshold value, the priority determination unit 15 may determine that the priority for the vulnerability is "high".

[0088] Also, in the above example, the priority determination unit 15 calculates the change amount of the risk value, but other parameters may be calculated. For example, the parameter may be the sum of the re-evaluated risk values of each of the plurality of assets, or the number of risk values indicating a predetermined maximum value "5" among the re-evaluated risk values of each of the plurality of assets. That is, for each vulnerability of at least one logical component indicated in the vulnerability assessment information D4, the priority determination unit 15 determines the priority for the vulnerability based on (a) the sum of the re-evaluated risk values for each of the plurality of assets, (b) the number of risk values indicating a predetermined maximum value "5" among the re-evaluated risk values for each of the plurality of assets, or (c) the sum of the change amounts of the re-evaluated risk values for each of the plurality of assets. Note that the sum of the change amounts of the risk values is the change amount of the risk value described above.

[0089] FIG. 8 is a flowchart showing an example of the processing operation of the evaluation device 10a.

[0090] First, the evaluation device 10a executes a risk value evaluation process (step S10). That is, the evaluation device 10a executes the processes of steps S11 to S14 or steps S11 to S15 of the flowchart shown in FIG. 5.

[0091] Next, the input unit 11 of the evaluation device 10a acquires vulnerability evaluation information D4 (step S21). Next, the separation setting specifying unit 12a specifies, for each of the plurality of vulnerabilities indicated in the vulnerability evaluation information D4, the separation state set for the plurality of logical components included in the evaluation target device 20 based on the vulnerability and the logical configuration information D1 (step S22).

[0092] Next, for each of the plurality of vulnerabilities, the path combining unit 12b combines, for each asset, the logical path leading to the asset and the physical path corresponding to the logical path based on the separation state corresponding to the vulnerability (step S23). The risk re-evaluation unit 13 re-evaluates the risk value of each asset using the combined logical path and physical path for each of the plurality of vulnerabilities (step S24). Subsequently, the priority determination unit 15 determines the priority for each of the plurality of vulnerabilities based on the risk values of the plurality of re-evaluated assets (step S25). At this time, the priority determination unit 15 may calculate parameters such as the above-described risk value change amount and determine the priority based on the parameters.

[0093] Then, the output unit 14 generates and outputs vulnerability priority information D5 indicating the priority for each of the plurality of vulnerabilities (step S26). Note that the output unit 14 may include parameters such as the risk value change amount in the vulnerability priority information D5, or may include the parameters in the vulnerability priority information D5 instead of the priority. Further, the output unit 14 may further output asset risk information D3 indicating the result of the process in step S10, or may output asset risk information D3 indicating the risk values of the plurality of assets re-evaluated by the process in step S24.

[0094] In the above example, the input unit 11 acquires the vulnerability assessment information D4 after the logical configuration information D1 and the threat analysis information D2. However, the vulnerability assessment information D4 may be acquired at the same timing as the logical configuration information D1 and the threat analysis information D2. That is, the order in which the logical configuration information D1, the threat analysis information D2, and the vulnerability assessment information D4 are acquired by the input unit 11 may be any order.

[0095] Also, in the above example, the risk value evaluation process is performed in step S10, but this evaluation process may not be performed. For example, when the total of the re-evaluated risk values or the number of the maximum risk values, instead of the risk value change amount, is calculated as the above parameters by the priority determination unit 15, the risk value evaluation process may not be performed. In this case, in step S10, the input unit 11 acquires the logical configuration information D1 and the threat analysis information D2.

[0096] As described above, in the present embodiment, for each vulnerability, the risk value of the asset is re-evaluated based on the logical path corresponding to the vulnerability, and the priority of the countermeasure against the vulnerability is determined based on the re-evaluated risk value. Therefore, an appropriate priority for the vulnerability can be derived, and the safety of the device under evaluation 20 can be enhanced by taking countermeasures according to the priority. Also, since the priority of the countermeasure against the vulnerability is determined based on the risk values re-evaluated for each of the plurality of assets, an appropriate priority can be derived from the perspective of the plurality of assets, and the safety of the device under evaluation 20 can be effectively enhanced by taking countermeasures according to the priority. Further, for each vulnerability, since the priority of the vulnerability is determined based on the total of the risk values re-evaluated for each of the plurality of assets, the number of the maximum risk values, or the total of the risk value change amounts, an appropriate priority according to the purpose can be derived.

[0097] Also, the evaluation device 10a in the present embodiment can also be said to be the following device. That is, the evaluation device 10a is a device that evaluates an evaluation target device 20 including a plurality of physical components for executing processing according to a plurality of logical components, and includes an input unit 11, a path determination unit 12, a risk re-evaluation unit 13, and a priority determination unit 15. The input unit 11 acquires device information regarding the evaluation target device 20 and vulnerability evaluation information D4 indicating the vulnerability of at least one of the plurality of logical components. The path determination unit 12, for each vulnerability of at least one logical component indicated by the vulnerability evaluation information D4, based on the vulnerability and the device information, from outside the evaluation target device 20, until accessing an asset that is data or a function possessed by the evaluation target device 20, determines a logical path composed of an array of one or more logical components and a physical path composed of an array of one or more physical components corresponding to the logical path. The risk re-evaluation unit 13 evaluates the risk value of the asset for each vulnerability of at least one logical component based on the level of attack possibility for the determined physical path and logical path and the level of impact when the asset is infringed. The priority determination unit 15 determines the priority of countermeasures for each vulnerability of at least one logical component based on the evaluated risk value of the asset.

[0098] Thereby, for each vulnerability, the risk value of the asset is evaluated based on the logical path corresponding to the vulnerability, and the priority of countermeasures for the vulnerability is determined based on the evaluated risk value. Therefore, an appropriate priority for the vulnerability can be derived, and the security of the evaluation target device 20 can be enhanced by taking countermeasures according to the priority.

[0099] (Embodiment 3) FIG. 9 is a block diagram showing an example of the configuration of the evaluation device in the present embodiment.

[0100] The evaluation device 10b in this embodiment includes an input unit 11, a path determination unit 12, and an output unit 14, similar to the evaluation device 10 in Embodiment 1. Further, it also includes a usage situation identification unit 16 and a score calculation unit 17.

[0101] Also, the input unit 11 in this embodiment, similar to that in Embodiment 2, acquires not only the logical configuration information D1 and threat analysis information D2 but also vulnerability assessment information D4. The vulnerability assessment information D4 indicates, as a score value, the vulnerability of at least one logical component among the plurality of logical components included in the device under evaluation. Note that the score value is a CVSS score value.

[0102] The path determination unit 12 determines the logical paths of each of the plurality of assets, similar to Embodiments 1 and 2.

[0103] For each vulnerability of at least one logical component indicated by the vulnerability assessment information D4, the usage situation identification unit 16 identifies the CVSS score value of the vulnerability and the usage situation of the logical component corresponding to the vulnerability by the plurality of assets. When identifying the usage situation of the logical component, the usage situation identification unit 16 uses the logical paths of each of the plurality of assets determined by the path determination unit 12 to identify the usage situation.

[0104] For each vulnerability of at least one logical component indicated by the vulnerability assessment information D4, the score calculation unit 17 calculates, as a priority score value, the priority of the countermeasure against the vulnerability based on the CVSS score value of the vulnerability and the usage situation of the logical component corresponding to the vulnerability by the plurality of assets.

[0105] The output unit 14 generates vulnerability priority information D5 regarding the priority score value calculated for each vulnerability of at least one logical component indicated by the vulnerability assessment information D4 and outputs it to the outside of the evaluation device 10b.

[0106] FIG. 10 is a diagram for explaining the calculation of the priority score value.

[0107] For example, as shown in Fig. 10(a), the vulnerability assessment information D4 indicates the vulnerability D of the first OS 35, the vulnerability E of the virtualization infrastructure 31, and the vulnerability F of the USB driver 33. Specifically, the vulnerabilities D, E, and F are shown as CVSS score values. For example, the CVSS score value of the vulnerability D is "8.0", the CVSS score value of the vulnerability E is "4.0", and the CVSS score value of the vulnerability F is "5.0".

[0108] Similar to Embodiment 1 or 2, the route determination unit 12 determines the respective logical routes of the assets A, B, and C.

[0109] For each of the vulnerabilities D, E, and F indicated by the vulnerability assessment information D4, the usage status specifying unit 16 specifies the usage status of the logical components corresponding to the vulnerabilities by the assets A, B, and C. Specifically, the usage status specifying unit 16 specifies the usage status of the first OS 35 corresponding to the vulnerability D by the assets A, B, and C. For example, the first OS 35 exists only on the logical route leading to the asset A, and there is no first OS 35 on the logical routes leading to each of the assets B and C. Therefore, the usage status specifying unit 16 specifies the situation where the first OS 35 is used only by the asset A and not used by the assets B and C as the usage status of the first OS 35 corresponding to the vulnerability D. That is, the usage status specifying unit 16 specifies the number "1" of assets using the first OS 35 as the usage status of the first OS 35 corresponding to the vulnerability D. In other words, the usage status specifying unit 16 specifies the asset usage frequency "1" of the first OS 35 as the usage status.

[0110] Similarly, the usage specifying unit 16 specifies the usage of the virtualization infrastructure 31 corresponding to vulnerability E by assets A, B, and C. Specifically, the virtualization infrastructure 31 exists on the logical paths leading to each of assets A, B, and C. Therefore, the usage specifying unit 16 specifies the situation where the virtualization infrastructure 31 is used by assets A, B, and C as the usage of the virtualization infrastructure 31 corresponding to the vulnerability E. That is, the usage specifying unit 16 specifies the number "3" of assets using the virtualization infrastructure 31 as the usage of the virtualization infrastructure 31 corresponding to the vulnerability E. In other words, the usage specifying unit 16 specifies the asset usage frequency "3" of the virtualization infrastructure 31 as the usage situation.

[0111] Similarly, the usage specifying unit 16 specifies the usage of the USB driver 33 corresponding to vulnerability F by assets A, B, and C. Specifically, the USB driver 33 exists on the logical paths leading to each of assets B and C, and there is no USB driver 33 on the logical path leading to asset A. Therefore, the usage specifying unit 16 specifies the situation where the USB driver 33 is used by assets B and C and not used by asset A as the usage of the USB driver 33 corresponding to the vulnerability F. That is, the usage specifying unit 16 specifies the number "2" of assets using the USB driver 33 as the usage of the USB driver 33 corresponding to the vulnerability F. In other words, the usage specifying unit 16 specifies the asset usage frequency "2" of the USB driver 33 as the usage situation.

[0112] In this way, the usage specifying unit 16 specifies the usage of the logical component corresponding to the vulnerability by a plurality of assets as the number of assets using the logical component, that is, the asset usage frequency. Specifically, by the process of the usage specifying unit 16, as shown in (b2) of FIG. 10, the asset usage frequencies for each of vulnerability D, vulnerability E, and vulnerability F are specified.

[0113] For each of vulnerability D, vulnerability E, and vulnerability F, the score calculation unit 17 multiplies the CVSS score value of that vulnerability shown in (b1) of FIG. 10 by the asset usage frequency of that vulnerability shown in (b2) of FIG. 10. As a result, as shown in (b3) of FIG. 10, the score calculation unit 17 calculates the priority score value for each of vulnerability D, vulnerability E, and vulnerability F. In this way, the score calculation unit 17 calculates the priority score value by multiplying the CVSS score value by the asset usage frequency. Also, the score calculation unit 17 may determine a priority level for the priority score value of the vulnerability. The priority level is expressed, for example, by "low", "medium", or "high". For example, if the priority score value of the vulnerability is less than the third threshold, the score calculation unit 17 may determine the priority level "low" for that vulnerability. And if the priority score value of the vulnerability is equal to or greater than the third threshold and less than the fourth threshold, the score calculation unit 17 determines the priority level "medium" for that vulnerability, and if the priority score value of the vulnerability is equal to or greater than the fourth threshold, the score calculation unit 17 may determine the priority level "high" for that vulnerability. That is, the priority score value indicates a detailed priority, and the priority level indicates a general priority.

[0114] FIG. 11 is a flowchart showing an example of the processing operation of the evaluation device 10b.

[0115] First, the input unit 11 of the evaluation device 10b acquires the logical configuration information D1, threat analysis information D2, and vulnerability evaluation information D4 (step S11a). Next, the evaluation device 10b executes the processes of steps S12 and S13 in the same manner as in the first embodiment. Then, the usage situation specifying unit 16 specifies the asset usage frequency for each vulnerability indicated in the vulnerability evaluation information D4 as the usage situation (step S31). Next, the score calculation unit 17 calculates a priority score value by multiplying the CVSS score value of each vulnerability indicated in the vulnerability evaluation information D4 by the asset usage frequency of that vulnerability. Further, the score calculation unit 17 determines a priority level for the calculated priority score value (step S32). The output unit 14 generates vulnerability priority information D5 indicating the priority score value and the priority level calculated or determined by the score calculation unit 17 for each vulnerability and outputs it to the outside of the evaluation device 10b (step S33). Note that the output unit 14 may include only one of the priority score value and the priority level in the vulnerability priority information D5. Also, the evaluation device 10b may evaluate or re-evaluate the risk value of the asset in the same manner as in the first and second embodiments. That is, the evaluation device 10b may include a risk re-evaluation unit 13.

[0116] As described above, in this embodiment, the priority can be derived as a priority score value without using the risk value of the asset, and the degree of freedom in deriving the priority can be increased. Also, the more assets that use the logical component corresponding to the vulnerability, the higher the priority is derived for that vulnerability, so that an appropriate priority can be derived.

[0117] Also, the evaluation device 10b in the present embodiment can also be said to be the following device. That is, the evaluation device 10b is a device that evaluates an evaluation target device 20 including a plurality of physical components for executing processing according to a plurality of logical components, and includes an input unit 11, a path determination unit 12, and a score calculation unit 17. Further, the evaluation target device 20 has a plurality of assets that are data or functions respectively. The input unit 11 acquires device information regarding the evaluation target device 20 and vulnerability evaluation information D4 indicating the vulnerability of at least one of the plurality of logical components as a score value. The path determination unit 12 determines, for each vulnerability of at least one logical component indicated by the vulnerability evaluation information D4, a logical path composed of an array of one or more logical components from the outside of the evaluation target device 20 to access the asset for each asset based on the vulnerability and the device information. The score calculation unit 17 calculates, for each vulnerability of at least one logical component indicated by the vulnerability evaluation information D4, the priority of the countermeasure against the vulnerability as a priority score value based on the score value of the vulnerability and the usage status of the logical component corresponding to the vulnerability by the plurality of assets.

[0118] Thereby, the priority can be derived as a priority score value without using the risk value of the asset, and the degree of freedom in deriving the priority can be increased.

[0119] (Embodiment 4) In Embodiment 1, risk re-evaluation is performed by combining the physical path and the logical path. However, when the risk evaluation target function uses a virtualization infrastructure 31 such as Hypervisior or Docker, the physical configuration may be unknown or uncertain at the time of risk evaluation. In that case, the risk value may be individually evaluated in advance only by the logical path. The procedure in that case will be described below.

[0120] The evaluation device 10 of the present embodiment will be described with reference to FIG. 2.

[0121] The evaluation device 10 in this embodiment is a device that evaluates the safety of the evaluation target device 20 that executes processing according to a plurality of logical components, and evaluates the risk value of the assets evaluated by the threat analysis device as described above. Such an evaluation device 10 includes an input unit 11, a path determination unit 12, a risk re-evaluation unit 13, and an output unit 14.

[0122] The input unit 11 acquires logical configuration information D1 and threat analysis information D2 regarding the evaluation target device 20. The logical configuration information D1 indicates the logical configuration of the evaluation target device 20. The logical configuration can also be said to be a software configuration, and hierarchically defines the dependencies between software. Further, the logical configuration information D1 may indicate a software component list, that is, an SBOM (Software Bill Of Materials). The threat analysis information D2 indicates, for example, the risk value of each asset evaluated by the threat analysis device, the level of influence of each asset, and one or more attack paths.

[0123] The path determination unit 12 makes a determination using only logical paths. That is, based on the device information, the path determination unit 12 determines a logical path composed of an array of one or more logical components from outside the evaluation target device 20 to an asset that is data or a function possessed by the evaluation target device 20.

[0124] Note that the logical components are, for example, software. Also, the logical path is also called a logical path to an asset. Such a path determination unit 12 includes a separation setting identification unit 12a and a path combination unit 12b. The separation setting identification unit 12a identifies the separation state set in the logical configuration of the evaluation target device 20, that is, the separation state set in a plurality of logical components. The path combination unit 12b determines a logical path based on the identified separation state.

[0125] The risk reevaluation unit 13 evaluates the risk value of an asset based on the separation state between the logical path combined by the path coupling unit 12b and the outside. That is, the risk reevaluation unit 13 evaluates the risk value of the asset based on the level of attack possibility against the logical path determined by the path coupling unit 12b and the level of impact when the asset is infringed. In the present embodiment, since the risk value of the asset has been previously evaluated by the threat analysis device, the risk reevaluation unit 13 reevaluates the risk value of the asset evaluated by the threat analysis device. Note that if the risk value of the asset has not been previously evaluated by the threat analysis device, that is, if the risk value of the asset is not shown in the threat analysis information D2, the risk reevaluation unit 13 may evaluate the risk value instead of reevaluating it. Such a risk reevaluation unit 13 may be referred to as an evaluation unit.

[0126] The output unit 14 generates information indicating the risk value of the asset evaluated or reevaluated by the risk reevaluation unit 13 as asset risk information D3 and outputs it outside the evaluation device 10. Note that after the above risk reevaluation is performed, if the actual physical configuration to be assigned to the virtualization infrastructure is determined, the risk reevaluation may be performed again using the method described in Embodiment 1.

[0127] Thereby, even in a state where the physical path is unknown, the risk value based on the logical path can be derived. The derived risk value may be combined with the physical path later for risk reevaluation. An effect of shortening the risk reevaluation period in the derivative deployment to other physical configurations can be expected.

[0128] As described above, the evaluation device and the evaluation method according to one or more aspects of the present disclosure have been described based on each embodiment. However, the present disclosure is not limited to those embodiments. As long as the gist of the present disclosure is not deviated from, various modifications conceived by those skilled in the art applied to the above embodiments may also be included in the present disclosure. Also, a form constructed by combining components in a plurality of different embodiments may be included in the present disclosure.

[0129] For example, in Embodiment 3, the score calculation unit 17 may calculate a priority score according to not only the CVSS score value and the asset usage frequency but also the user, type, characteristics, etc. of the device 20 to be evaluated. The characteristics may be, for example, characteristics indicating whether the logical components can be updated or not.

[0130] Also, according to the vulnerability or the granularity of CVE shown in the vulnerability assessment information D4 in Embodiments 2 and 3, the accuracy of the priority determined for the vulnerability may be improved by determining a detailed logical path. For example, the logical path consists of an array of one or more logical components, and each of the one or more logical components may be software, a module included in the software, or a function. The detailed logical path may be a path including the module or the function.

[0131] Also, in Embodiments 1 to 4, the path combining unit 12b may determine a logical path using test result data such as coverage data obtained at the time of verification of the device 20 to be evaluated.

[0132] In each of the above embodiments, each component may be configured by dedicated hardware or may be realized by executing a software program suitable for each component. Each component may be realized by a program execution unit such as a CPU (Central Processing Unit) or a processor reading and executing a software program recorded on a recording medium such as a hard disk or a semiconductor memory. Here, the software for realizing the evaluation device and the like in each of the above embodiments is a computer program that causes a computer to execute each step of the flowcharts shown in FIGS. 5, 8, and 11.

[0133] Note that the following cases are also included in the present disclosure.

[0134] (1) The above-mentioned at least one device is specifically a computer system composed of, for example, a microprocessor, ROM, RAM, hard disk unit, display unit, keyboard, mouse, etc. A computer program is stored in its RAM or hard disk unit. By operating according to the computer program, the microprocessor enables the above-mentioned at least one device to achieve its function. Here, the computer program is composed of a combination of a plurality of instruction codes indicating instructions for the computer to achieve a predetermined function.

[0135] (2) Some or all of the components constituting the above-mentioned at least one device may be composed of a single system LSI (Large Scale Integration). A system LSI is a super multi-functional LSI manufactured by integrating a plurality of components on a single chip, and specifically, it is a computer system including a microprocessor, ROM, RAM, etc. A computer program is stored in the RAM. By operating according to the computer program, the microprocessor enables the system LSI to achieve its function.

[0136] (3) Some or all of the components constituting the above-mentioned at least one device may be composed of an IC card or a single module that is detachable from the device. The IC card or module is a computer system composed of a microprocessor, ROM, RAM, etc. The IC card or module may include the above-mentioned super multi-functional LSI. By operating according to the computer program, the microprocessor enables the IC card or module to achieve its function. This IC card or this module may have tamper resistance.

[0137] (4) The present disclosure may be the method described above. It may also be a computer program for realizing these methods by a computer, or a digital signal consisting of a computer program.

[0138] In addition, the present disclosure may be a computer program or a digital signal recorded on a computer-readable recording medium, such as a flexible disk, a hard disk, a CD (Compact Disc)-ROM, a DVD, a DVD-ROM, a DVD-RAM, a BD (Blu-ray (registered trademark) Disc), a semiconductor memory, etc. It may also be a digital signal recorded on these recording media.

[0139] In addition, the present disclosure may be a computer program or a digital signal transmitted via a telecommunication line, a wireless or wired communication line, a network represented by the Internet, data broadcasting, etc.

[0140] In addition, it may be implemented by another independent computer system by recording and transferring a program or a digital signal to a recording medium, or by transferring a program or a digital signal via a network or the like.

Industrial Applicability

[0141] The evaluation device of the present disclosure can be applied to, for example, a device or system for evaluating an ECU or the like incorporated in a vehicle or the like.

Explanation of Signs

[0142] 10, 10a, 10b Evaluation device 11 Input unit 12 Route determination unit 12a Separation setting specifying unit 12b Route combining unit 13 Risk re-evaluation unit (evaluation unit) 14 Output unit 15 Priority determination unit 16 Usage Status Specifying Section 17 Score Calculation Section 20 Device Under Evaluation 21 BT Interface 22 USB Interface 23 CAN Interface 24 Main Microcontroller 25 CAN Microcontroller 31 Virtualization Infrastructure 32 BT Driver 33 USB Driver 34 I2C Driver 35 First OS 36 Second OS 37 Container 38 First Function 39 Second Function 40 Third Function 90 External Device 91 Smartphone 92 Diag D1 Logical Configuration Information D2 Threat Analysis Information D3 Asset Risk Information D4 Vulnerability Assessment Information D5 Vulnerability Priority Information

Claims

1. An evaluation apparatus for evaluating an evaluation target device including a plurality of physical components for executing processes corresponding to a plurality of logical components, an input unit for acquiring device information regarding the evaluation target device; a path determination unit that determines, based on the device information, a logical path consisting of an array of one or more logical components from outside the evaluation target device to an access to an asset, which is data or a function of the evaluation target device, and a physical path consisting of an array of one or more physical components corresponding to the logical path; an evaluation unit that evaluates a risk value of the asset based on a determined level of attack possibility for the physical path and the logical path and a level of impact when the asset is violated; An evaluation device comprising:

2. The route determination unit is a separation setting specification unit that specifies a separation state set for the plurality of logical components; a path combining unit that combines the physical path and the logical path by determining the logical path based on the identified separation state and determining the physical path corresponding to the logical path, The evaluation unit evaluates a risk value of the asset based on the combined physical path and logical path. The evaluation device according to claim 1 .

3. The input unit further includes: acquiring vulnerability assessment information indicating a vulnerability of at least one of the plurality of logical components; The route determination unit further re-determining the physical path and the logical path based on each vulnerability of at least one logical component indicated by the vulnerability assessment information; The evaluation unit further comprises: reassessing a risk value of the asset based on the re-determined physical path and the re-determined logical path for each vulnerability of the at least one logical component; The evaluation device further comprises: a priority determination unit that determines a priority of a measure against each vulnerability of the at least one logical configuration element based on the reevaluated risk value of the asset; The evaluation device according to claim 1 .

4. the evaluation target device has a plurality of assets including the asset, For each of the plurality of assets, (a) the path determination unit re-determines the physical path and the logical path for the asset; (b) the evaluation unit re-evaluates a risk value of the asset based on the re-determined physical path and the re-logical path; The priority determination unit determining, for each vulnerability of the at least one logic component, the priority for the vulnerability based on the re-evaluated risk value for each of the plurality of assets; The evaluation device according to claim 3 .

5. The priority determination unit determining the priority for each vulnerability of the at least one logical component based on (a) a sum of risk values ​​reevaluated for each of the plurality of assets, (b) a number of risk values ​​that indicates a predetermined maximum value among the risk values ​​reevaluated for each of the plurality of assets, or (c) a sum of changes in the risk values ​​reevaluated for each of the plurality of assets; The evaluation device according to claim 4.

6. The input unit further includes: acquiring vulnerability assessment information indicating, as a score value, a vulnerability of at least one of the plurality of logical components; the evaluation target device has a plurality of assets including the asset, The route determination unit determines the logical route for each of the plurality of assets; The evaluation device further comprises: a score calculation unit that calculates, for each vulnerability of the at least one logical configuration element indicated by the vulnerability assessment information, a priority of a measure against the vulnerability as a priority score value based on the score value of the vulnerability and a usage status of the logical configuration element corresponding to the vulnerability by the plurality of assets; The evaluation device according to claim 1 .

7. The evaluation device further comprises: a usage status identification unit that identifies a usage status of a logical component corresponding to the vulnerability by the plurality of assets as a number of assets that use the logical component; The score calculation unit is calculating the priority score value by multiplying the score value by the number of assets; The evaluation device according to claim 6.

8. An evaluation device for evaluating an evaluation target that executes processing according to a plurality of logical components, an input unit for acquiring configuration information regarding the evaluation target; a route determination unit that determines a logical route consisting of an arrangement of one or more logical components from outside the evaluation target to accessing an asset that is data or a function of the evaluation target, based on the configuration information; an evaluation unit that evaluates a risk value of the asset based on the determined level of attack possibility for the logical path and the level of impact when the asset is violated; An evaluation device comprising:

9. 1. An evaluation method in which a computer evaluates an evaluation target device including a plurality of physical components for executing processes corresponding to a plurality of logical components, comprising: Acquire device information regarding the evaluation target device; Based on the device information, a logical path consisting of an array of one or more logical components from outside the evaluation target device to an asset, which is data or a function of the evaluation target device, is determined, and a physical path consisting of an array of one or more physical components corresponding to the logical path is determined; evaluating a risk value of the asset based on the determined level of attack probability for the physical path and the logical path and the level of impact when the asset is compromised; Evaluation method.

10. 1. An evaluation method in which a computer evaluates an evaluation target that executes processing according to a plurality of logical components, comprising: Obtaining configuration information regarding the evaluation target; Based on the configuration information, a logical path consisting of an arrangement of one or more logical components is determined from outside the evaluation target to access an asset, which is data or a function, possessed by the evaluation target; evaluating a risk value of the asset based on the determined level of attack possibility for the logical path and the level of impact when the asset is compromised; Evaluation method.

11. A program for evaluating an evaluation target device including a plurality of physical components for executing processes corresponding to a plurality of logical components, Acquire device information regarding the evaluation target device; Based on the device information, a logical path consisting of an array of one or more logical components from outside the evaluation target device to an asset, which is data or a function of the evaluation target device, is determined, and a physical path consisting of an array of one or more physical components corresponding to the logical path is determined; evaluating a risk value of the asset based on the determined level of attack probability for the physical path and the logical path and the level of impact when the asset is compromised; A program that causes a computer to do something.

12. A program for evaluating an evaluation target that executes processing according to a plurality of logical components, Obtaining configuration information regarding the evaluation target; Based on the configuration information, a logical path consisting of an arrangement of one or more logical components is determined from outside the evaluation target to access an asset, which is data or a function, possessed by the evaluation target; evaluating a risk value of the asset based on the determined level of attack possibility for the logical path and the level of impact when the asset is compromised; A program that causes a computer to do something.

Citation Information

Patent Citations

  • Vulnerability repair method, device and equipment and storage medium

    CN111147491A

  • A vulnerability driven hybrid test system for application programs

    CN112100050A

  • Network host node security risk assessment method based on host importance

    CN113779591A

  • Network defense system risk assessment method based on bypass attack simulation

    CN114124531A

  • Comprehensive risk assessment method and device integrating information security and function security

    CN116362543A