Setting rule generation device, setting rule generation method, information processing system, and program
The setting rule generation device and method address the impracticality of generating setting rules for access control in networks by registering specific attributes and reducing the number of combinations, resulting in a more efficient and practical approach.
Patent Information
- Application Number
- JP2023209722
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-12-12
- Publication Date
- 2025-06-24
AI Technical Summary
Existing policy setting support tools face impracticality in generating sample information for access control in networks due to the large number of network resources, resulting in an excessively large number of combinations for setting rules.
A setting rule generation device and method that register setting rule generation range information specifying attributes included in the setting rule, allowing the generation of setting rules based on this information and attribute information of network resources, thereby reducing the number of combinations.
The solution effectively reduces the number of generated setting rules, making the process more practical and manageable for networks with numerous resources.
Smart Images

Figure 2025093825000001_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to a setting rule generation device, a setting rule generation method, an information processing system, and a program.
Background Art
[0002] As related art, Patent Document 1 discloses a policy setting support tool. In Patent Document 1, a policy is used for access control to a file. In Patent Document 1, a policy means an access control list that defines users who can be accessed using a user ID (identifier) and a group ID for each access type such as reading and writing. When a user accesses a file via an application program, the OS (Operating System) collates the ID of the user who is the access request source and the ID of the group to which the user belongs with the access control list assigned to the file or directory to be accessed. The OS permits access only when the above user is included in the access control list.
[0003] The policy setting support tool described in Patent Document 1 creates a draft policy using sample information, association information, or access log information. Sample information is information that describes a policy for each type of software. Association information is information that describes information on programs with high usage frequency for each type of object. Access log information is information recorded by monitoring the operation of a program. The policy setting support tool displays the created draft policy. A user can confirm the created draft policy or edit the created draft policy using a user interface.
Prior Art Documents
Patent Documents
[0004]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0005] In Patent Document 1, sample information includes software name, object name, executable file name, user group name, and access type. Suppose the policy setting support tool described in Patent Document 1 is used for access control in a network. Then, sample information is generated for each combination of network resources to which access is permitted. Generally, a network has a large number of network resources. Therefore, in Patent Document 1, if sample information for access control in a network is to be automatically generated from an access log, the number of combinations becomes extremely large and is not practical.
[0006] One object of the present disclosure is to provide a setting rule generation device, a setting rule generation method, an information processing system, and a program that can reduce the number of generated setting rules when generating setting rules from attribute information.
Means for Solving the Problems
[0007] The setting rule generation device according to the first aspect of the present disclosure includes a rule generation range registration unit that registers setting rule generation range information including information specifying at least a part of one or more attributes included in a setting rule applied in a network, which is set according to policy information, and a setting rule generation unit that generates the setting rule based on the registered setting rule generation range information and attribute information of resources included in the network.
[0008] The information processing system according to the second aspect of the present disclosure includes the above-described setting rule generation device and a rule application device that performs predetermined control in the network according to the generated setting rule.
[0009] The setting rule generation method according to the third aspect of the present disclosure includes a computer registering setting rule generation range information including information specifying at least a part of one or more attributes included in a setting rule applied in a network, which is set according to policy information, and the computer generating the setting rule based on the registered setting rule generation range information and attribute information of resources included in the network.
[0010] The program according to the fourth aspect of the present disclosure is for causing a computer to execute a process including registering setting rule generation range information including information specifying at least a part of one or more attributes included in a setting rule applied in a network, which is set according to policy information, and generating the setting rule based on the registered setting rule generation range information and attribute information of resources included in the network.
Advantages of the Invention
[0011] The setting rule generation device, setting rule generation method, information processing system, and program according to the present disclosure can reduce the number of generated setting rules when generating setting rules from attribute information.
Brief Description of the Drawings
[0012]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
Figure 11
Figure 12
Embodiments for Carrying Out the Invention
[0013] Prior to the description of the embodiments of the present disclosure, the outline of the present disclosure will be described. FIG. 1 shows a schematic configuration example of an information processing system according to the present disclosure. The information processing system 10 includes a setting rule generation device 11 and a setting rule application device 15. The setting rule generation device 11 includes a rule generation range registration unit 12 and a setting rule generation unit 13.
[0014] The rule generation range registration unit 12 registers setting rule generation range information including information specifying at least a part of one or more attributes included in the setting rule. Here, the setting rule is a rule set according to policy information and applied in a network. The setting rule generation unit 13 generates a setting rule based on the registered setting rule generation range information and the attribute information of the resources included in the network. The setting rule application device 15 performs predetermined control in the network according to the setting rule generated by the setting rule generation device 11.
[0015] In the present disclosure, the setting rule generation range information includes information specifying at least a part of one or more attributes included in the setting rule. In this case, the setting rule generation unit 13 can create a combination of attributes from the attribute information for attributes not specified by the setting rule generation range information, and generate a setting rule. Therefore, the present disclosure can reduce the number of combinations of attributes in the setting rule compared to the case where the setting rule generation range information is not used, and can reduce the number of generated setting rules.
[0016] Hereinafter, embodiments of the present disclosure will be described in detail with reference to the drawings. Note that the following description and drawings are appropriately omitted and simplified for clarity of explanation. Also, in each drawing, the same elements and similar elements are denoted by the same reference numerals, and duplicate explanations are omitted as necessary.
[0017] FIG. 2 shows a configuration example of an information processing system according to the present disclosure. One embodiment will be described with reference to FIG. 2. The information processing system 100 shown in FIG. 2 includes a policy enforcement point (PEP) rule generation device 110 and a PEP rule application device 130. The information processing system 100 corresponds to the information processing system 10 shown in FIG. 1. The PEP rule generation device 110 corresponds to the setting rule generation device 11 shown in FIG. 1. The PEP rule application device 130 corresponds to the setting rule application device 15 shown in FIG. 1. In the present embodiment, it is assumed that the setting rule is a PEP rule that is an access control rule, and a predetermined control in the network is access control.
[0018] The PEP rule application device 130 implements access control in the network according to the PEP rules. The PEP rule application device 130 is implemented, for example, at a policy enforcement point that enforces access control according to an access control policy. The PEP rule generation device 110 generates the PEP rules used in the PEP rule application device 130. The PEP rule generation device 110 can be used for formulating access control policies or PEP rules for zero trust or microsegmentation.
[0019] The PEP rule generation device 110 and the PEP rule application device 130 can each be configured as a device having, for example, one or more memories and one or more processors physically. In the PEP rule generation device 110 and the PEP rule application device 130, one or more processors read a program from one or more memories and execute processing according to the read program.
[0020] The PEP rule generation device 110 includes a policy registration unit 111, a generation range information registration unit 112, a PEP rule generation unit 113, and an attribute information storage unit 114. The attribute information storage unit 114 stores the attribute information of each resource included in the network to be controlled. The attribute information (its value) of each resource is also simply called an attribute. Physically, the attribute information storage unit 114 is configured as a storage device such as a hard disk device or a Solid State Drive (SSD), for example. Note that the attribute information storage unit 114 does not necessarily have to be included in the PEP rule generation device 110. The attribute information storage unit 114 may be configured as cloud storage, for example.
[0021] The attribute information includes, for example, information regarding accesses that occurred in the past in the network. The attribute information can include not only information regarding actual accesses but also information regarding possible accesses. Information regarding accesses includes, for example, information on the network resource of the access source, information on the destination network resource, and information on the service type. Further, the attribute information includes information such as the address information of each network resource and information on the network to which it belongs. The above attribute information can be created, for example, from system logs, firewall setting information, and system configuration information.
[0022] FIG. 3 shows an example of the attribute information stored in the attribute information storage unit 114. In this example, the attribute information includes information indicating the source network (SrcNW), source node (Src node), destination network (DstNW), destination node (Dst node), service type, and presence or absence of encryption. In FIG. 3, the attribute value "ANY" indicates that it can take any value. For example, the attribute information includes information indicating that the service type of access from an arbitrary node in an arbitrary network to the node EWS in the network ICS_NW is OT-MANAGEMENT and the encryption is TRUE.
[0023] FIG. 4 shows another example of the attribute information. In this example, the attribute information includes the node name, IP (Internet Protocol) address, belonging network, and node type. For example, the attribute information includes information that the IP address of the asset with the node name "NICT_NTPsite" is "100.1.2.3", the network to which the asset belongs is "INTERNET", and the node type is "NTP-SV". The attribute information storage unit 114 stores the node name, IP address, belonging network, and node type for each asset included in the network, for example.
[0024] The policy registration unit 111 registers the policy information for access control in the PEP. The policy information indicates the rules of access control that serve as the criteria for the approval or disapproval of access control. The policy information may include, for example, the conditions of access control considered from the above attribute information. The policy information is manually input from the user to the policy registration unit 111, for example, using a user interface. The policy registration unit 111 registers the input policy information in a storage device (not shown). The policy registration unit 111 may generate policy information based on the attribute information stored in the attribute information storage unit 114 and the requirement information of the system, for example, using an AI (Artificial Intelligence) model.
[0025] Here, the policy information is broadly classified into ID-based policy information and attribute-based policy information. The ID-based policy information includes, for example, a combination of the ID of a specific network resource or information similar to the ID. As an example, the ID-based policy information includes information that defines the approval or disapproval of access for a combination of the user ID of the access source resource, the owner ID of the access destination resource, and an operation such as read or write. The PEP rule used in the PEP rule application device 130 can be considered as ID-based policy information.
[0026] The attribute-based policy information includes information not associated with the ID of a specific network resource. As an example, the attribute-based policy information includes information that defines the approval or disapproval of access for a combination of administrative authority, resource authority, and operation. In the present embodiment, the policy information registered by the policy registration unit 111 includes attribute-based policy information.
[0027] FIG. 5 shows an example of policy information. In the example shown in FIG. 5, the policy information includes, for example, information that unencrypted communication is not permitted. Further, the policy information includes information that communication from network A_SCADA to the Internet is not permitted. This information is created, for example, in accordance with a system requirement that communication from a specific node to the Internet is not permitted. Also, the policy information includes information that NTP-SV permits only NTP-based communication. This information is created, for example, in accordance with a system requirement that a specific server permits only communication of a specific protocol.
[0028] The generation range information registration unit 112 registers PEP rule generation range information indicating the generation range of PEP rules set according to the policy information. Here, the PEP rule can be considered as a rule obtained by converting the policy information into a form interpretable by the PEP rule application device 130. The PEP rule includes a combination of IDs of network resources for which access is permitted or access is denied. The PEP rule generation range information includes information specifying at least a part of one or more attributes included in the PEP rule. In other words, the PEP rule generation range information includes a part of the information indicating what kind of access is permitted or what kind of access is denied in the finally generated PEP rule. The PEP rule generation range information can be created from system configurations, settings of network devices such as firewalls and network access controls, or information such as logs, guidelines, operation policies, and monitoring condition policies. The generation range information registration unit 112 corresponds to the rule generation range registration unit 12 shown in FIG. 1.
[0029] Figure 6 shows an example of PEP rule generation range information related to network settings. The PEP rule generation range information shown in Figure 6 is also called network setting information. In Figure 6, the source network (SrcNW) indicates the network to which the access source node in access control belongs. The source IP address (SrcIP) indicates the IP address of the access source node. The destination network (DstNW) indicates the network to which the access destination node belongs. The destination IP address (DstIP) indicates the IP address of the access destination node. The service type indicates the service type of the access. The action indicates whether the access is permitted or not.
[0030] In this example, the network setting information includes information specifying at least one attribute among the access source resource, the destination resource, and the service type. The network setting information includes, for example, information that access of service type "GENERAL" is permitted from a node with an IP address of 10.50.10.120 in ICS_DMZ to a node with an IP address of 100.1.2.3 on the Internet. Also, the network setting information includes information that access of any service type is permitted from a node with any IP address in NW_MNG to a node with any IP address in NW_MNG. In this case, the network setting information specifies that the source network, that is, the access source network and the destination network are each NW_MNG. The ANY item is an item for which no attribute is specified in the network setting information and thus the attribute is indefinite.
[0031] FIG. 7 shows an example of PEP rule generation range information regarding attribute settings. The PEP rule generation range information shown in FIG. 7 is also called attribute setting information. The attribute setting information includes access control conditions and actions when those conditions are met. The attribute setting information includes, for example, information of access denial for the condition that communication is not encrypted. Also, the attribute setting information includes information that access is permitted when the source network and the destination network are the same and the service type is OT-CONTROL. In the example shown in FIG. 7, the attribute setting information includes information specifying attributes included in a conditional expression of access permission or access denial.
[0032] The PEP rule generation unit 113 generates a PEP rule, which is ID-based policy information, from the access control rules indicated by the above policy information. In the present embodiment, the PEP rule generation unit 113 generates a PEP rule based on the PEP rule generation range information registered by the generation range information registration unit 112 and the attribute information stored in the attribute information storage unit 114.
[0033] The PEP rule generation unit 113 generates a PEP rule, for example, by complementing attributes of a PEP rule not specified in the PEP rule generation range information with attributes included in the attribute information. For example, the PEP rule generation unit 113 acquires attribute information of network resources corresponding to the attributes specified in the PEP rule generation range information from the attribute information storage unit 114. The PEP rule generation unit 113 complements the attributes of the PEP rule not specified in the PEP rule generation range information with the acquired attribute information. The PEP rule generation unit 113 corresponds to the setting rule generation unit 13 shown in FIG. 1.
[0034] FIG. 8 shows an example of the generated PEP rules. In this example, the PEP rule generation range information, which is network configuration information, does not include items with indefinite attributes. The PEP rule generation unit 113 generates a PEP rule that permits access when there is an access of type GENERAL from 10.50.10.120 in the network ICS_DMZ to 100.1.2.3 on the Internet. In this case, the number (sample number) of PEP rules generated from one piece of PEP rule generation range information is one.
[0035] FIG. 9 shows another example of the generated PEP rules. In this example, in the PEP rule generation range information, which is network configuration information, the attribute information of the source network and the destination network is specified, but the attribute information of the items of the source IP address, the destination IP address, and the service type is not specified. In that case, the PEP rule generation unit 113 searches the asset storage unit 114 for assets whose affiliated network is NW_MNG and acquires the IP addresses of the searched assets. The PEP rule generation unit 113 acquires, for example, 172.18.99.1 and 172.18.99.10 as the IP addresses of the assets belonging to NW_MNG.
[0036] Also, the PEP rule generation unit 113 searches the attribute information storage unit 114 for communications where the source network and the destination network are NW_MNG and acquires the service types of the searched communications. The PEP rule generation unit 113 acquires, for example, the service types OT-MANAGEMENT, OT-CONTROL, and GENERAL. The PEP rule generation unit 113 generates a PEP rule in which the ANY item of the network configuration information is replaced with the acquired IP addresses and service types. In the example of FIG. 9, the number of combinations of the source IP address, the destination IP address, and the service type is 2×2×3. In this case, the PEP rule generation unit 113 generates 2×2×3 PEP rules from one piece of PEP rule generation range information.
[0037] FIG. 10 shows yet another example of the generated PEP rules. When access control is implemented in the permission list method, the PEP rule generation unit 113 acquires, from the attribute information storage unit 114, the attribute information of the source resource, the destination resource, and the service type based on the attribute information included in the conditional expression of access permission. When access control is implemented in the deny list method, the PEP rule generation unit 113 acquires, from the attribute information storage unit 114, the attribute information of the source resource, the destination resource, and the service type based on the attribute information included in the conditional expression of access denial. The permission list method is also called the pass list method. The deny list method is also called the block list method.
[0038] In the example of FIG. 10, the PEP rule generation unit 113 searches, in the attribute information storage unit 114, for communications in which the source network and the destination network are the same and the access type is OT-CONTROL based on the attribute information included in the conditional expression included in the attribute setting information. Here, assume that communications between nodes belonging to the network ICS_DMZ are searched as such communications. In that case, the PEP rule generation unit 113 acquires, from the attribute information storage unit 114, the attribute information of the source resource of the searched communication and the attribute information of the destination resource. The PEP rule generation unit 113 generates a PEP rule including the combination of the acquired attribute information as a PEP rule indicating access permission. When access control is in the deny list method, the PEP rule generation unit 113 generates a PEP rule including the combination of the acquired attribute information as a PEP rule indicating access denial.
[0039] Here, when the access control is based on the allow list method, the PEP rule generation unit 113 may generate combinations of attribute information in the PEP rule using the access denial conditional expression. For example, the PEP rule generation unit 113 may generate a PEP rule including attribute information that satisfies a conditional expression obtained by inverting the access denial conditional expression. When the access control is based on the allow list method, only access combinations that satisfy the access permission conditional expression are permitted, so it is not necessary to consider combinations of attribute information corresponding to the access denial conditional expression. When the access control is based on the deny list method, the PEP rule generation unit 113 may generate combinations of attribute information in the PEP rule using the access permission conditional expression. For example, the PEP rule generation unit 113 may generate a PEP rule including attribute information that satisfies a conditional expression obtained by inverting the access permission conditional expression.
[0040] The PEP rule application device 130 performs access control using the PEP rule generated by the PEP rule generation unit 113. A user such as a security officer may check or verify whether the PEP rule generated by the PEP rule generation unit 113 is appropriate before the PEP rule is used in the PEP rule application device 130. The user may input to the PEP rule application device 130 a PEP rule obtained by excluding inappropriate PEP rules and unnecessary PEP rules from the PEP rule generated by the PEP rule generation unit 113.
[0041] Subsequently, the operation procedure will be described. FIG. 11 shows the operation procedure in the PEP rule generation device 110. The operation procedure in the PEP rule generation device 110 corresponds to the setting rule generation method. The policy registration unit 111 registers the attribute information stored in the attribute information storage unit 114 and the policy information that can be considered from system requirements, etc. (step S1). The generation range information registration unit 112 registers PEP rule generation range information including information specifying at least a part of one or more attributes included in the created PEP rule (step S2).
[0042] The PEP rule generation unit 113 acquires attribute information not specified in the PEP rule generation range information from the attribute information storage unit 114 (step S3). The PEP rule generation unit 113 combines the PEP rule generation information and the acquired attribute information to generate a PEP rule (step S4). The generated PEP rule is used for access control in the PEP rule application device 130.
[0043] In the design of PEP, it is necessary to manually design the IP address, subnet or zone, protocol, port, and service type from the attribute information, and the work of PEP design is complicated. If we try to design automatically from the attribute information, the combination of attributes will become huge, and it is difficult to verify whether the PEP rule is appropriate. In addition, among the huge combinations, there may be combinations of attributes that cannot occur in the network, and it is also difficult to check the presence or absence of such combinations.
[0044] In this embodiment, the PEP rule generation unit 113 generates a PEP rule using PEP rule generation range information including information specifying at least a part of one or more attributes included in the PEP rule. In this case, the PEP rule generation unit 113 can reduce the number of combinations of attributes in the generated PEP rule compared to the case where the PEP rule generation range information is not used. In other words, the PEP rule generation unit 113 can narrow down the creation range of the PEP rule. The relationship of network resources in access control is often determined in advance like a policy. In this embodiment, by using such a relationship as the PEP rule generation range information and narrowing down the range of the PEP rule to be created, the PEP rule generation unit 113 can generate the PEP rule required by the user.
[0045] In the above-described embodiment, an example in which the setting rule is a PEP rule and access control based on the PEP rule is implemented in the PEP rule application device 130 has been described. However, the present disclosure is not limited thereto. The setting rule generated in the setting rule generation device according to the present disclosure may be a detection rule, a monitoring rule, a security policy, an access permission, a device setting, a firewall setting, or a rule set for web filtering.
[0046] Subsequently, the hardware configurations of the PEP rule generation device 110 and the PEP rule application device 130 will be described. FIG. 12 shows an example of the hardware configuration of a computer device or a network device that can be used as the PEP rule generation device 110 and the PEP rule application device 130. The computer device 300 shown in FIG. 11 includes one or more processors 301 and one or more memories 302. The processor 301 may be, for example, a microprocessor, an MPU (Micro Processing Unit), or a CPU (Central Processing Unit).
[0047] The memory 302 stores programs executed by the processor 301. The memory 302 is composed of a combination of a volatile memory and a non-volatile memory. The memory 302 may include storage located away from the processor 301. In that case, the processor 301 may access the memory 302 via an I / O (Input / Output) interface or a network (not shown).
[0048] When the above program is loaded into a computer, it includes a set of instructions or software code for causing the computer to perform one or more of the functions described in the embodiments. The program may be stored in a non-transitory computer-readable medium or a tangible storage medium and supplied to the computer device 300. By way of example and not limitation, the computer-readable medium or tangible storage medium includes random-access memory (RAM), read-only memory (ROM), flash memory, solid-state drive (SSD), or other memory technologies, Compact Disc (CD), digital versatile disc (DVD), Blu-ray (registered trademark) disc, or other optical disc storage, magnetic cassette, magnetic tape, magnetic disk storage, or other magnetic storage devices. The program may be transmitted on a transitory computer-readable medium or communication medium. By way of example and not limitation, the transitory computer-readable medium or communication medium includes electrical, optical, acoustic, or other forms of propagated signals.
[0049] In the present disclosure, the PEP rule generation device 110 and the PEP rule application device 130 do not necessarily have to be single devices respectively. The PEP rule generation device 110 and the PEP rule application device 130 may be configured using a plurality of physically separated devices. Also, the PEP rule generation device 110 and the PEP rule application device 130 do not necessarily have to be configured as individual devices. For example, the PEP rule generation device 110 and the PEP rule application device 130 may be configured as the same device.
[0050] The present disclosure has been described with reference to the embodiments above, but the present disclosure is not limited to the above-described embodiments. Various changes that can be understood by those skilled in the art can be made to the configuration and details of the present disclosure within the scope of the present disclosure.
[0051] The drawings are merely illustrative for explaining one or more embodiments. Each drawing may be associated with not only one specific embodiment but also one or more other embodiments. As can be understood by those skilled in the art, various features or steps described with reference to any one drawing can be combined with the features or steps shown in one or more other drawings to create, for example, embodiments that are not explicitly illustrated or described. Not all of the features or steps shown in any one drawing for explaining exemplary embodiments are necessarily essential, and some features or steps may be omitted. The order of the steps described in any drawing may be changed as appropriate.
[0052] Some or all of the above embodiments may be described as follows, but are not limited thereto.
[0053] [Appendix 1] A rule generation range registration unit that registers rule generation range information including information specifying at least a part of one or more attributes included in a setting rule applied in a network, which is set according to policy information; A setting rule generation device comprising: a setting rule generation unit that generates the setting rule based on the registered rule generation range information and the attribute information of resources included in the network.
[0054] [Appendix 2] The setting rule generation device according to Appendix 1, wherein the setting rule generation unit generates the setting rule by complementing the attributes of the setting rule not specified in the rule generation range information with the attributes included in the attribute information.
[0055] [Appendix 3] The setting rule generation device according to Appendix 2, wherein the setting rule generation unit acquires the attributes of network resources corresponding to the attributes specified in the rule generation range information from the attribute information, and complements the attributes of the setting rule not specified in the rule generation range information with the acquired attributes.
[0056] [Appendix 4] The setting rule is a rule for access control in the network, and the setting rule generation device according to any one of Appendices 1 to 3.
[0057] [Appendix 5] The setting rule generation range information includes information specifying at least one attribute among a resource of an access source, a resource of a destination, and a service type, and the setting rule generation device according to Appendix 4.
[0058] [Appendix 6] The setting rule generation range information includes information specifying an attribute included in a conditional expression of access permission or access rejection, and the setting rule generation device according to Appendix 4 or 5.
[0059] [Appendix 7] According to whether the access control is implemented in an allow list method or a deny list method, the setting rule generation unit, based on the attributes included in the conditional expression of access permission or the conditional expression of access rejection, acquires, from the attribute information, the attributes of the resource of the access source, the resource of the destination, and the service type, and generates a setting rule including a combination of the acquired attributes of the resource of the access source, the attributes of the resource of the destination, and the service type as a setting rule indicating access permission or access rejection, and the setting rule generation device according to Appendix 6.
[0060] [Appendix 8] When the access control is implemented in an allow list method, the setting rule generation unit generates a setting rule including an attribute that satisfies a conditional expression obtained by inverting the conditional expression of access rejection. When the access control is implemented in a deny list method, the setting rule generation unit generates a setting rule including an attribute that satisfies a conditional expression obtained by inverting the conditional expression of access permission, and the setting rule generation device according to Appendix 7.
[0061] [Appendix 9] The attribute information includes information for identifying a resource of an access source in the network, information for identifying a destination resource, and information for identifying a service type. The setting rule generation device according to any one of Appendices 1 to 8.
[0062] [Appendix 10] The attribute information includes address information of a resource in the network. The setting rule generation device according to any one of Appendices 1 to 9.
[0063] [Appendix 11] An information processing system including the setting rule generation device according to any one of Appendices 1 to 10, and a rule application device that performs predetermined control in the network according to the generated setting rules.
[0064] [Appendix 12] A computer registers setting rule generation range information including information specifying at least a part of one or more attributes included in a setting rule applied in a network, which is set according to policy information, A setting rule generation method in which the computer generates the setting rule based on the registered setting rule generation range information and attribute information of a resource included in the network.
[0065] [Appendix 13] Register setting rule generation range information including information specifying at least a part of one or more attributes included in a setting rule applied in a network, which is set according to policy information, A program for causing a computer to execute a process including generating the setting rule based on the registered setting rule generation range information and attribute information of a resource included in the network.
[0066] Some or all of the elements (e.g., configuration and function) described in Appendices 2 to 10 that are subordinate to Appendix 1 may be subordinate to Appendices 12 and 13 in the same subordinate relationship as Appendices 2 to 10. Some or all of the elements described in any appendix may be applied to various hardware, software, recording means for recording software, systems, and methods.
Description of Reference Numerals
[0067] 10: Information processing system 11: Setting rule generation device 12: Rule generation range registration unit 13: Setting rule generation unit 15: Setting rule application device 100: Information processing system 110: PEP rule generation device 111: Policy registration unit 112: Generation range information registration unit 113: PEP rule generation unit 114: Attribute information storage unit 130: PEP rule application device.
Claims
1. A rule generation range registration unit that registers setting rule generation range information including information specifying at least a part of one or more attributes included in a setting rule applied in a network, which is set according to policy information; A setting rule generation apparatus comprising: a setting rule generation unit that generates the setting rule based on the registered setting rule generation range information and attribute information of resources included in the network.
2. The setting rule generation apparatus according to claim 1, wherein the setting rule generation unit generates the setting rule by complementing attributes of the setting rule not specified in the setting rule generation range information with attributes included in the attribute information.
3. The setting rule generation apparatus according to claim 2, wherein the setting rule generation unit acquires attributes of network resources corresponding to the attributes specified in the setting rule generation range information from the attribute information, and complements the attributes of the setting rule not specified in the setting rule generation range information with the acquired attributes.
4. The setting rule generation apparatus according to any one of claims 1 to 3, wherein the setting rule is a rule for access control in the network.
5. The setting rule generation apparatus according to claim 4, wherein the setting rule generation range information includes information specifying at least one attribute among a resource of an access source, a resource of a destination, and a service type.
6. The setting rule generation apparatus according to claim 4, wherein the setting rule generation range information includes information specifying attributes included in a conditional expression for access permission or access rejection.
7. According to whether the access control is implemented in an allow list method or a deny list method, the setting rule generation unit acquires, from the attribute information, attributes of a resource of an access source, a resource of a destination, and a service type based on the attributes included in the conditional expression for access permission or the conditional expression for access rejection, and generates a setting rule including a combination of the acquired attributes of the resource of the access source, the resource of the destination, and the service type as a setting rule indicating access permission or access rejection. The setting rule generation apparatus according to claim 6.
8. When the access control is implemented in the permission list method, the setting rule generation unit generates a setting rule including an attribute that satisfies a conditional expression obtained by inverting the conditional expression for access rejection. When the access control is implemented in the rejection list method, the setting rule generation unit generates a setting rule including an attribute that satisfies a conditional expression obtained by inverting the conditional expression for access permission. The setting rule generation device according to claim 7.
9. The attribute information includes information for identifying a resource of an access source in the network, information for identifying a destination resource, and information for identifying a service type. The setting rule generation device according to any one of claims 1 to 3.
10. The attribute information includes address information of a resource in the network. The setting rule generation device according to any one of claims 1 to 3.
11. The setting rule generation device according to any one of claims 1 to 3, An information processing system including a rule application device that performs predetermined control in the network according to the generated setting rule.
12. A computer registers setting rule generation range information including information specifying at least a part of one or more attributes included in a setting rule applied in a network, which is set according to policy information. A setting rule generation method in which the computer generates the setting rule based on the registered setting rule generation range information and the attribute information of resources included in the network.
13. Register setting rule generation range information including information specifying at least a part of one or more attributes included in a setting rule applied in a network, which is set according to policy information. A program for causing a computer to execute a process including generating the setting rule based on the registered setting rule generation range information and the attribute information of resources included in the network.
Citation Information
Patent Citations
Policy setting support tool
JP2004192601A