Control method and management device

The control method and management device address the challenge of SBOM leakage by generating and transmitting altered or anonymized software component information, reducing the risk of data exposure and maintaining effective vulnerability analysis.

JP2025096920APending Publication Date: 2025-06-30PANASONIC AUTOMOTIVE SYST CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2023212916
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-12-18
Publication Date
2025-06-30

AI Technical Summary

Technical Problem

Existing detection systems are ineffective in preventing the leakage of Software Bill Of Materials (SBOM) when it is shared externally, as they are designed to manage internal data access and not external data transmission.

Method used

A control method and management device that generate and transmit irregular software component information by altering or anonymizing regular SBOM data, making it difficult for attackers to determine its credibility or extract valuable information.

Benefits of technology

The method reduces the risk of regular software component information leakage by making the transmitted data confusing or less informative to attackers, while still allowing for effective vulnerability analysis by external devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025096920000001_ABST
    Figure 2025096920000001_ABST
Patent Text Reader

Abstract

To provide a control method capable of reducing leakage risk of authorized software component information.SOLUTION: A control method includes: (a) a step of allowing a storage unit 10 to store an authorized SBOM 16; (b) a step of generating an unauthorized SBOM 18 corresponding to an SBOM which is obtained by changing at least a part of the authorized SBOM 16 on the basis the authorized SBOM 16 stored in the storage unit 10; and (c) a step of transmitting the unauthorized SBOM 18 generated in the (b) to an external device 6 via a network 8.SELECTED DRAWING: Figure 4
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to a control method and a management device.

Background Art

[0002] There is known a detection system for detecting leakage of parts list data (see, for example, Patent Document 1). In this detection system, for example, when a person in charge belonging to an organization has access rights to parts list data used in product design work, in response to a change in the work of the person in charge due to a personnel change within the organization, etc., access by the person in charge to the parts list data is restricted.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] By the way, in recent years, the importance of an SBOM (Software Bill Of Materials) showing a list of a plurality of software components constituting software has been increasing. For example, when developing software in an organization, in order to analyze the vulnerability of the software, the organization may provide an SBOM related to the software to an external vulnerability management server.

[0005] When providing the SBOM from an organization to the outside in this way, the risk of SBOM leakage becomes a problem. The above-described conventional detection system is applicable to cases where parts list data leaks within an organization, but cannot be applied to cases where an SBOM provided from an organization to the outside leaks.

[0006] Therefore, the present disclosure provides a control method and a management device capable of reducing the risk of leakage of regular software component information.

Means for Solving the Problems

[0007] A control method according to an aspect of the present disclosure is a control method in a management device that manages regular software component information indicating a list of a plurality of software components constituting software, including: (a) storing the regular software component information in a storage unit; (b) generating, based on the regular software component information stored in the storage unit, irregular software component information corresponding to software component information in which at least a part of the regular software component information is changed; and (c) transmitting the irregular software component information generated in (b) to an external device via a network.

[0008] These general or specific aspects may be implemented by a system, a method, an integrated circuit, a computer program, or a recording medium such as a computer-readable CD-ROM (Compact Disc-Read Only Memory), or may be implemented by any combination of a system, a method, an integrated circuit, a computer program, and a recording medium.

Advantages of the Invention

[0009] According to a control method and the like according to an aspect of the present disclosure, the risk of leakage of regular software component information can be reduced.

Brief Description of the Drawings

[0010]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Figure 12

Figure 13

Modes for Carrying Out the Invention

[0011] (Technology 1) A control method in a management device for managing regular software component information indicating a list of a plurality of software components constituting software, the method including: (a) storing the regular software component information in a storage unit; (b) generating, based on the regular software component information stored in the storage unit, irregular software component information corresponding to software component information obtained by changing at least a part of the regular software component information; and (c) transmitting the irregular software component information generated in (b) to an external device via a network.

[0012] According to Technique 1, based on the regular software component information stored in the memory unit, non-regular software component information corresponding to software component information in which at least a part of the regular software component information is changed is generated. Then, the generated non-regular software component information is transmitted to an external device via a network. As a result, even if the non-regular software component information provided from the management device to the external device is leaked to an attacker who performs hacking or the like, (i) the non-regular software component information does not include information required by the attacker, or (ii) it becomes difficult for the attacker to determine the credibility of the non-regular software component information. As a result, the risk of leakage of the regular software component information can be reduced.

[0013] (Technique 2) In the above (b), when at least one dependency exists among the plurality of software components in the regular software component information, the non-regular software component information corresponding to the software component information in which at least one dependency included in the regular software component information is eliminated is generated, according to the control method described in Technique 1.

[0014] According to Technique 2, in the non-regular software component information, at least one dependency among the plurality of software components included in the regular software component information is eliminated. As a result, in the non-regular software component information, the information regarding the dependencies among the plurality of software components becomes coarser. Here, the information regarding the dependencies among the plurality of software components is of low importance for vulnerability analysis in an external device (for example, a vulnerability management server), but is useful information for an attacker. Therefore, even if the non-regular software component information provided from the management device to the external device is leaked to an attacker, the attacker cannot know the detailed dependencies among the plurality of software components, so it becomes difficult to infer where each of the plurality of software components operates within the software. As a result, the risk of leakage of the regular software component information can be reduced without hindering the vulnerability analysis in the external device.

[0015] (Technology 3) The control method further includes: (d) transmitting the regular software component information stored in the storage unit to the external device via the network; (e) receiving regular response information for the regular software component information transmitted in (d) from the external device via the network; and (f) receiving irregular response information for the irregular software component information transmitted in (c) from the external device via the network. The control method according to Technology 1 or 2 includes these steps.

[0016] According to Technology 3, the software component information provided from the management device to the external device includes regular software component information transmitted in a regular session (i.e., a regular interaction between the management device and the external device) and irregular software component information transmitted in a dummy session (i.e., a dummy interaction between the management device and the external device). Therefore, even if the regular software component information and the irregular software component information provided from the management device to the external device are leaked to an attacker, it is difficult for the attacker to determine which software component information to trust. As a result, it is possible to cause confusion to the attacker and reduce the risk of leakage of the regular software component information.

[0017] (Technology 4) The control method further includes: (g) discarding the irregular response information received in (f). The control method according to Technology 3 includes this step.

[0018] According to Technology 4, by discarding unnecessary irregular response information, the storage capacity in the management device can be saved.

[0019] (Technology 5) In (b), at least a part of the regular software component information stored in the storage unit is tampered with, and the tampered regular software component information is generated as the irregular software component information. The control method according to any one of Technologies 1 to 4 includes this step.

[0020] According to Technique 5, the software component information provided from the management device to the external device is irregular software component information in which the management device has tampered with at least a part of the regular software component information. Therefore, even if the irregular software component information provided from the management device to the external device is leaked to an attacker, it is difficult for the attacker to know the content of the regular software component information. As a result, the attacker can be confused, and the risk of leakage of the regular software component information can be reduced.

[0021] (Technique 6) The control method further includes: (h) receiving, from the external device via the network, response information for the irregular software component information transmitted in (c); and (i) restoring the tampered information included in the response information received in (h) to the information before tampering. The control method according to Technique 5.

[0022] According to Technique 6, by restoring the tampered information included in the received response information to the information before tampering, for example, the management device can safely obtain the analysis result of the software vulnerability based on the restored response information.

[0023] (Technique 7) The regular software component information includes a plurality of name information respectively indicating the names of the plurality of software components. In (b), each of the plurality of name information included in the regular software component information stored in the storage unit is anonymized, and the anonymized regular software component information is generated as the irregular software component information. The control method according to any one of Techniques 1 to 6.

[0024] According to Technique 7, the software component information provided from the management device to the external device is non-regular software component information obtained by anonymizing each of a plurality of name information included in the regular software component information. Therefore, even if the non-regular software component information provided from the management device to the external device is leaked to an attacker, it is difficult for the attacker to identify the content of the regular software component information. As a result, the attacker can be confused, and the risk of leakage of the regular software component information can be reduced.

[0025] (Technique 8) The control method further includes: (j) receiving, from the external device via the network, response information for the non-regular software component information transmitted in (c); and (k) restoring each of the plurality of anonymized name information included in the response information received in (j) to the plurality of name information before anonymization. The control method according to Technique 7.

[0026] According to Technique 8, by restoring the plurality of anonymized name information included in the received response information to the plurality of name information before anonymization, for example, the management device can safely obtain the analysis result of the software vulnerability based on the restored response information.

[0027] (Technique 9) A management device that manages regular software component information indicating a list of a plurality of software components constituting software, including: a storage unit that stores the regular software component information; a generation unit that generates non-regular software component information corresponding to software component information obtained by changing at least a part of the regular software component information based on the regular software component information stored in the storage unit; and a communication unit that transmits the non-regular software component information generated by the generation unit to an external device via a network.

[0028] According to Technique 9, the generation unit generates non-standard software component information corresponding to software component information in which at least a part of the standard software component information is changed, based on the standard software component information stored in the storage unit. Then, the communication unit transmits the non-standard software component information generated by the generation unit to an external device via a network. As a result, even if the non-standard software component information provided from the management device to the external device is leaked to an attacker who performs hacking or the like, (i) the non-standard software component information does not include information required by the attacker, or (ii) it becomes difficult for the attacker to determine the credibility of the non-standard software component information. As a result, the risk of leakage of the standard software component information can be reduced.

[0029] Note that these general or specific aspects may be implemented in a system, a method, an integrated circuit, a computer program, or a recording medium such as a computer-readable CD-ROM, or may be implemented in any combination of a system, a method, an integrated circuit, a computer program, or a recording medium.

[0030] Hereinafter, embodiments will be specifically described with reference to the drawings.

[0031] Note that all of the embodiments described below show general or specific examples. The numerical values, shapes, materials, components, arrangement positions and connection forms of the components, steps, order of steps, etc. shown in the following embodiments are merely examples and are not intended to limit the present disclosure. In addition, among the components in the following embodiments, components not described in the independent claims indicating the most general concept are described as optional components.

[0032] (Embodiment 1) [1-1. Configuration of Management System] First, with reference to FIGS. 1 to 3, the configuration of the management system 2 according to Embodiment 1 will be described. FIG. 1 is a block diagram showing the configuration of the management system 2 according to Embodiment 1. FIG. 2 is an example showing an example of a regular SBOM 16 according to Embodiment 1. FIG. 3 is a diagram showing an example of an irregular SBOM 18 according to Embodiment 1.

[0033] As shown in FIG. 1, the management system 2 according to Embodiment 1 includes a management device 4 and an external device 6. The management device 4 and the external device 6 can communicate with each other via a network 8 such as the Internet.

[0034] The management device 4 is a device for managing a regular SBOM (an example of regular software component information), which is a list of a plurality of software components constituting software. The management device 4 is composed of, for example, a personal computer or the like, and is owned by an entity (such as a company, a group, an organization, and an individual) that develops software as a product.

[0035] Here, the "regular SBOM" is an SBOM (an example of software component information) that includes regular information (that is, information that has not been modified such as tampering) regarding a plurality of software components constituting software.

[0036] The management device 4 includes a storage unit 10, a generation unit 12, and a communication unit 14.

[0037] The storage unit 10 is a memory that stores the regular SBOM 16. The regular SBOM 16 is, for example, a data table as shown in FIG. 2(a). As shown in FIG. 2(a), the regular SBOM 16 is information showing the correspondence relationship between, for example, a component name (an example of name information), a supplier, a version, a creator, a hash, a UID (Unique Identifiers), and a relation.

[0038] The component name is the name of the component defined by the supplier. Note that a component is a concept that includes software (product) and a plurality of software components that make up the software. Also, the component name contains indentation information corresponding to the dependency relationship indicated by the relation described later.

[0039] The supplier is the name of the entity that developed the component.

[0040] The version is an identifier related to the version used to identify the component.

[0041] The creator is the name of the entity that created the SBOM of the component.

[0042] The hash is the hash value of the component.

[0043] The UID is an identifier used to identify the component.

[0044] The relation is information indicating the dependency relationship that a component is included in another component.

[0045] Although not shown in Fig. 2(a), the formal SBOM16 may further include a timestamp, which is information indicating the date and time when the SBOM was created.

[0046] In the example shown in Fig. 2(a), in the first row of the formal SBOM16, (a) the component name "Product α", (b) the supplier "Alice", (c) the version "1.1", (d) the creator "Alice", (e) the hash "0x123", (f) the UID "234", and (g) the relation "Primary" are stored.

[0047] Also, in the second line of the regular SBOM16, (a) component name "Component A", (b) supplier "Bob", (c) version "2.1", (d) creator "Bob", (e) hash "0x456", (f) UID "456", and (g) relation "Included in" are stored. Note that the indentation information stored together with "Component A" in the component name indicates the dependency that Component A is included in Product α.

[0048] Also, in the third line of the regular SBOM16, (a) component name "Component B", (b) supplier "Charlie", (c) version "3.1", (d) creator "Charlie", (e) hash "0x789", (f) UID "789", and (g) relation "Included in" are stored. Note that the indentation information stored together with "Component B" in the component name indicates the dependency that Component B is included in Product α.

[0049] Also, in the fourth line of the regular SBOM16, (a) component name "Component C", (b) supplier "Dave", (c) version "2.2", (d) creator "Dave", (e) hash "0x321", (f) UID "123", and (g) relation "Included in" are stored. Note that the indentation information stored together with "Component C" in the component name indicates the dependency that Component C is included in Component B.

[0050] That is, the regular SBOM16 shows that Supplier "Alice" developed the software (product) "Product α" using three software components: (i) "Component A" developed by Supplier "Bob", (ii) "Component B" developed by Supplier "Charlie", and (iii) "Component C" developed by Supplier "Dave".

[0051] In addition, as shown in Fig. 2(b), the relationships among product α, component A, component B, and component C in the regular SBOM 16 form a nested structure (tree structure) where product α includes component A, product α includes component B, and component B includes component C. This nested structure means that component A operates on product α, component B operates on product α, and component C operates on component B. That is, there is one dependency relationship, namely "component B includes component C", among the three software components, component A, component B, and component C in the regular SBOM 16. In this embodiment, the case where there is one dependency relationship among a plurality of software components in the regular SBOM 16 will be described, but it is not limited to this, and there may be two or more dependency relationships among the plurality of software components.

[0052] Returning to Fig. 1, based on the regular SBOM 16 stored in the storage unit 10, the generation unit 12 generates an irregular SBOM 18 (an example of irregular software component information) corresponding to an SBOM obtained by modifying at least a part of the regular SBOM 16. Specifically, the generation unit 12 generates an irregular SBOM 18 corresponding to an SBOM in which the dependency relationships among a plurality of software components included in the regular SBOM 16 are eliminated (that is, the nested structure of the plurality of software components is flattened).

[0053] Note that the generation unit 12 may generate the irregular SBOM 18 by overwriting the regular SBOM 16 stored in the storage unit 10, or may generate the irregular SBOM 18 by copying the regular SBOM 16 stored in the storage unit 10 and overwriting the copied regular SBOM 16. Further, the generation unit 12 may store the generated irregular SBOM 18 in the storage unit 10.

[0054] The irregular SBOM 18 is, for example, a data table as shown in Fig. 3(a). As shown in Fig. 3(a), similar to the regular SBOM 16, the irregular SBOM 18 is information indicating the correspondence relationship between, for example, a component name, a supplier, a version, a creator, a hash, a UID, and a relation.

[0055] In the example shown in FIG. 3(a), in the non - standard SBOM 18, the component name in the fourth line is different from that in the standard SBOM 16. Specifically, the indentation information stored together with "Component C" in the component name in the fourth line of the non - standard SBOM 18 indicates the dependency that Component C is included in Product α. As a result, the relationship among Product α, Component A, Component B, and Component C in the non - standard SBOM 18 is a flattened nested structure as shown in FIG. 3(b), that is, Product α includes Component A, and Product α includes Component B, and Product α includes Component C. That is, in the non - standard SBOM 18, the dependency "Component C is included in Component B" among multiple software components in the standard SBOM 16 is eliminated.

[0056] Returning to FIG. 1, when the analysis of the vulnerability of the software (product) is required, the communication unit 14 transmits the non - standard SBOM 18 generated by the generation unit 12 to the external device 6 via the network 8. Also, the communication unit 14 receives the response information from the external device 6 for the transmitted non - standard SBOM 18 via the network 8.

[0057] The external device 6 is a vulnerability management server arranged outside the management device 4. The external device 6 receives the non - standard SBOM 18 from the management device 4 via the network 8. Then, based on the received non - standard SBOM 18, the external device 6 analyzes the vulnerability of the software (product) using, for example, the Common Vulnerabilities and Exposures (CVE). Also, the external device 6 transmits the response information indicating the analysis result to the management device 4 via the network 8.

[0058] [1 - 2. Operation of the management system] Next, with reference to FIG. 4, the operation of the management system 2 according to Embodiment 1 (control method in the management device 4) will be described. FIG. 4 is a sequence diagram showing the operation flow of the management system 2 according to Embodiment 1.

[0059] As shown in FIG. 4, first, the storage unit 10 of the management device 4 stores the regular SBOM 16 (S101).

[0060] Next, the generation unit 12 of the management device 4 generates an irregular SBOM 18 based on the regular SBOM 16 stored in the storage unit 10 (S102).

[0061] Next, the communication unit 14 of the management device 4 transmits the irregular SBOM 18 generated by the generation unit 12 to the external device 6 via the network 8 (S103).

[0062] Next, the external device 6 receives the irregular SBOM 18 from the management device 4 via the network 8, and analyzes the vulnerability of the software (product) based on the received irregular SBOM 18.

[0063] Next, the external device 6 transmits response information indicating the analysis result to the management device 4 via the network 8 (S104). Although not shown, steps S103 and S104 may be repeatedly executed.

[0064] Next, the communication unit 14 of the management device 4 receives the response information from the external device 6 via the network 8.

[0065] [1-3. Effect] In the present embodiment, the SBOM provided from the management device 4 to the external device 6 is the irregular SBOM 18, not the regular SBOM 16. In the irregular SBOM 18, at least one dependency between a plurality of software components included in the regular SBOM 16 is eliminated. As a result, in the irregular SBOM 18, the information regarding the dependencies between the plurality of software components becomes coarser.

[0066] Here, information regarding the dependency relationships among a plurality of software components is of low importance for vulnerability analysis in the external device 6, but is useful information for an attacker who performs hacking or the like. Therefore, even if the unauthorized SBOM 18 provided from the management device 4 to the external device 6 leaks to the attacker, the attacker cannot know the detailed dependency relationships among the plurality of software components, making it difficult to speculate where each of the plurality of software components operates within the software (product).

[0067] As a result, the risk of leakage of the regular SBOM 16 can be reduced without hindering the vulnerability analysis in the external device 6.

[0068] (Embodiment 2) [2-1. Configuration of the Management System] With reference to FIGS. 5 and 6, the configuration of the management system 2A according to Embodiment 2 will be described. FIG. 5 is a block diagram showing the configuration of the management system 2A according to Embodiment 2. FIG. 6 is a diagram showing an example of the unauthorized SBOM 18A according to Embodiment 2. In this embodiment, the same reference numerals are assigned to the same components as in the above Embodiment 1, and the description thereof is omitted.

[0069] As shown in FIG. 5, in the management system 2A according to Embodiment 2, the configurations of the generation unit 12A and the communication unit 14A of the management device 4A are different from those in the above Embodiment 1.

[0070] Specifically, the generation unit 12A copies the regular SBOM 16 (refer to (a) of FIG. 2) stored in the storage unit 10, and generates the unauthorized SBOM 18A by changing a part of the copied regular SBOM 16.

[0071] As shown in FIG. 6, the second to fourth lines of the non-standard SBOM 18A are dummy information that has been changed from the second to fourth lines of the standard SBOM 16 respectively. That is, the non-standard SBOM 18A shows dummy information that the software (product) "Product α" was developed by the supplier "Alice" using three software components: (i) "Component D" developed by the supplier "Eve", (ii) "Component E" developed by the supplier "Charlie", and (iii) "Component F" developed by the supplier "Mike".

[0072] Further, the generation unit 12A dynamically generates the non-standard SBOM 18A, for example, at the timing of software (product) version upgrade. Also, each "version" stored in the non-standard SBOM 18A is updated to the latest information every time the generation unit 12A generates the non-standard SBOM 18A.

[0073] In this embodiment, the generation unit 12A generates one non-standard SBOM 18A for one standard SBOM 16, but it is not limited to this, and a plurality of different non-standard SBOM 18As may be generated for one standard SBOM 16.

[0074] Returning to FIG. 5, the communication unit 14A executes a normal session, which is a normal interaction between the management device 4A and the external device 6, and a dummy session, which is a dummy interaction between the management device 4A and the external device 6. In the normal session, the communication unit 14A (i) transmits the normal SBOM 16 stored in the storage unit 10 to the external device 6 via the network 8, and (ii) receives, via the network 8, normal response information, which is response information from the external device 6 for the transmitted normal SBOM 16. Also, in the dummy session, the communication unit 14A (iii) transmits the non-normal SBOM 18A generated by the generation unit 12A to the external device 6 via the network 8, and (iv) receives, via the network 8, non-normal response information, which is response information from the external device 6 for the transmitted non-normal SBOM 18A. Further, the communication unit 14A discards the non-normal response information received in the dummy session.

[0075] [2-2. Operation of the Management System] Next, with reference to FIG. 7, the operation of the management system 2A according to Embodiment 2 (control method in the management device 4A) will be described. FIG. 7 is a sequence diagram showing the operation flow of the management system 2A according to Embodiment 2.

[0076] As shown in FIG. 7, first, the storage unit 10 of the management device 4A stores the normal SBOM 16 (S201).

[0077] Next, the generation unit 12A of the management device 4A generates the non-normal SBOM 18A based on the normal SBOM 16 stored in the storage unit 10 (S202).

[0078] Next, the communication unit 14A of the management device 4A transmits the normal SBOM 16 stored in the storage unit 10 to the external device 6 via the network 8 (S203).

[0079] Next, the external device 6 receives the regular SBOM 16 from the management device 4A via the network 8, and analyzes the vulnerability of the software (product) based on the received regular SBOM 16. Next, the external device 6 transmits regular response information indicating the analysis result to the management device 4A via the network 8 (S204).

[0080] Next, the communication unit 14A of the management device 4A receives the regular response information from the external device 6 via the network 8.

[0081] Next, the communication unit 14A of the management device 4A transmits the irregular SBOM 18A generated by the generation unit 12A to the external device 6 via the network 8 (S205).

[0082] Next, the external device 6 receives the irregular SBOM 18A from the management device 4A via the network 8, and analyzes the vulnerability of the software (product) as a dummy based on the received irregular SBOM 18A. Next, the external device 6 transmits irregular response information indicating the analysis result to the management device 4A via the network 8 (S206).

[0083] Next, the communication unit 14A of the management device 4A receives the irregular response information from the external device 6 via the network 8. Next, the communication unit 14A discards the received irregular response information (S207).

[0084] In this embodiment, the regular session and the dummy session are each executed once, but the present invention is not limited to this, and the dummy session may be executed 1 to N times (N≥2). In this case, the order of executing the regular session and the dummy session may be random. For example, when the dummy session is executed 3 times in total, it may be executed in the order of "dummy session A ⇒ regular session A ⇒ dummy session B ⇒ dummy session C".

[0085] [2-3. Effects] In this embodiment, the SBOM provided from the management device 4A to the external device 6 is the regular SBOM 16 transmitted in a regular session and the irregular SBOM 18A transmitted in a dummy session. Therefore, even if the regular SBOM 16 and the irregular SBOM 18A provided from the management device 4A to the external device 6 are leaked to an attacker, it becomes difficult for the attacker to determine which SBOM to trust.

[0086] As a result, it is possible to cause confusion to the attacker and reduce the risk of leakage of the regular SBOM 16.

[0087] (Embodiment 3) [3-1. Configuration of the management system] With reference to FIGS. 8 and 9, the configuration of the management system 2B according to Embodiment 3 will be described. FIG. 8 is a block diagram showing the configuration of the management system 2B according to Embodiment 3. FIG. 9 is a diagram showing an example of the irregular SBOM 18B according to Embodiment 3. In this embodiment, the same components as those in the above Embodiment 1 are denoted by the same reference numerals, and the description thereof is omitted.

[0088] As shown in FIG. 8, in the management system 2B according to Embodiment 3, the configuration of the generation unit 12B of the management device 4B is different from that in the above Embodiment 1.

[0089] Specifically, the generation unit 12B generates the tampered regular SBOM 16 as the irregular SBOM 18B by tampering with and overwriting at least a part of the regular SBOM 16 (see (a) of FIG. 2) stored in the storage unit 10. That is, the generation unit 12B generates the poisoned SBOM, the irregular SBOM 18B, by so-called self-poisoning in which the management device 4B itself tampers with at least a part of the regular SBOM 16.

[0090] As shown in FIG. 9, in the non - standard SBOM 18B, the second line of the standard SBOM 16 is deleted, and the version "4.1" of the second line and the component name "Component F" of the third line in the non - standard SBOM 18B are dummy information changed from the version "3.1" of the third line and the component name "Component C" of the fourth line in the standard SBOM 16, respectively.

[0091] That is, the non - standard SBOM 18B shows dummy information that the software (product) "Product α" was developed by the supplier "Alice" using two software components: (i) "Component B" developed by the supplier "Charlie" and (ii) "Component F" developed by the supplier "Dave".

[0092] Also, when the communication unit 14 receives response information from the communication unit 14 for the non - standard SBOM 18B, the generation unit 12B restores (detoxifies) the tampered information included in the response information to the information before tampering.

[0093] [3 - 2. Operation of the management system] Next, with reference to FIG. 10, the operation of the management system 2B according to Embodiment 3 (control method in the management device 4B) will be described. FIG. 10 is a sequence diagram showing the operation flow of the management system 2B according to Embodiment 3.

[0094] As shown in FIG. 10, first, the storage unit 10 of the management device 4B stores the standard SBOM 16 (S301).

[0095] Next, the generation unit 12B of the management device 4B generates a non - standard SBOM 18B based on the standard SBOM 16 stored in the storage unit 10 (S302).

[0096] Next, the communication unit 14 of the management device 4B transmits the non - standard SBOM 18B generated by the generation unit 12B to the external device 6 via the network 8 (S303).

[0097] Next, the external device 6 receives the irregular SBOM 18B from the management device 4B via the network 8, and analyzes the vulnerability of the software (product) based on the received irregular SBOM 18B. Next, the external device 6 transmits response information indicating the analysis result to the management device 4B via the network 8 (S304).

[0098] Next, the communication unit 14 of the management device 4B receives the response information from the external device 6 via the network 8. Next, the generation unit 12B of the management device 4B restores the tampered information included in the response information received by the communication unit 14 to the information before tampering (S305). Thereby, the management device 4B can safely obtain the analysis result of the vulnerability of the software (product) based on the restored response information.

[0099] [3-3. Effect] In the present embodiment, the SBOM provided from the management device 4B to the external device 6 is an irregular SBOM 18B in which the management device 4B has tampered with at least a part of the regular SBOM 16 itself. Therefore, even if the irregular SBOM 18B provided from the management device 4B to the external device 6 is leaked to an attacker, it is difficult for the attacker to know the content of the regular SBOM 16.

[0100] As a result, it is possible to cause confusion to the attacker and reduce the risk of leakage of the regular SBOM 16.

[0101] (Embodiment 4) [4-1. Configuration of the management system] With reference to FIGS. 11 and 12, the configuration of the management system 2C according to Embodiment 4 will be described. FIG. 11 is a block diagram showing the configuration of the management system 2C according to Embodiment 4. FIG. 12 is a diagram showing an example of the irregular SBOM 18C according to Embodiment 4. In the present embodiment, the same components as those in the above Embodiment 1 are denoted by the same reference numerals, and the description thereof is omitted.

[0102] As shown in FIG. 11, in the management system 2C according to the fourth embodiment, the configuration of the generation unit 12C of the management device 4C is different from that of the first embodiment.

[0103] Specifically, the generation unit 12C generates the anonymized regular SBOM 16 as the irregular SBOM 18C by anonymizing and overwriting each of the plurality of component names and the plurality of versions included in the regular SBOM 16 (see FIG. 2(a)) stored in the storage unit 10. At this time, the generation unit 12C anonymizes, for example, each of the plurality of component names and the plurality of versions included in the regular SBOM 16 by hashing using a hash function.

[0104] As shown in FIG. 12, in the first row of the irregular SBOM 18C, a pseudonym "xxx" obtained by hashing the component name "Product α" and the version "1.1" in the first row of the regular SBOM 16 is stored. That is, the pseudonym "xxx" is the hash value obtained by hashing the component name "Product α" and the version "1.1".

[0105] Also, in the second row of the irregular SBOM 18C, a pseudonym "yyy" obtained by hashing the component name "Component A" and the version "2.1" in the second row of the regular SBOM 16 is stored. That is, the pseudonym "yyy" is the hash value obtained by hashing the component name "Component A" and the version "2.1".

[0106] Also, in the third row of the irregular SBOM 18C, a pseudonym "zzz" obtained by hashing the component name "Component B" and the version "3.1" in the third row of the regular SBOM 16 is stored. That is, the pseudonym "zzz" is the hash value obtained by hashing the component name "Component B" and the version "3.1".

[0107] In addition, in the fourth line of the non - standard SBOM 18C, the alias "www" is stored, which is the result of anonymizing the component name "Component C" and version "2.2" in the fourth line of the standard SBOM 16 by hashing. That is, the alias "www" is the hash value obtained by hashing the component name "Component C" and version "2.2".

[0108] In addition, when the communication unit 14 receives response information from the communication unit 14 for the non - standard SBOM 18C, the generation unit 12C restores the anonymized information (component name and version) included in the response information to the information before anonymization. In addition, the generation unit 12C restores the non - standard SBOM 18C stored in the storage unit 10 to the original standard SBOM 16 based on the database for restoration.

[0109] Note that in this embodiment, the generation unit 12C anonymizes a plurality of component names and a plurality of versions included in the standard SBOM 16, but it is not limited to this. At least a plurality of component names included in the standard SBOM 16 may be anonymized.

[0110] [4 - 2. Operation of the management system] Next, with reference to FIG. 13, the operation of the management system 2C (control method in the management device 4C) according to Embodiment 4 will be described. FIG. 13 is a sequence diagram showing the operation flow of the management system 2C according to Embodiment 4.

[0111] As shown in FIG. 13, first, the storage unit 10 of the management device 4C stores the standard SBOM 16 (S401).

[0112] Next, the generation unit 12C of the management device 4C generates a non - standard SBOM 18C based on the standard SBOM 16 stored in the storage unit 10 (S402).

[0113] Next, the communication unit 14 of the management device 4C transmits the non - standard SBOM 18C generated by the generation unit 12C to the external device 6 via the network 8 (S403).

[0114] Next, the external device 6 receives the non - regular SBOM 18C from the management device 4C via the network 8, and analyzes the vulnerability of the software (product) based on the received non - regular SBOM 18C. Then, the external device 6 transmits response information indicating the analysis result to the management device 4C via the network 8 (S404).

[0115] Next, the communication unit 14 of the management device 4C receives the response information from the external device 6 via the network 8. Then, the generation unit 12C of the management device 4C restores the anonymized information included in the response information received by the communication unit 14 to the information before anonymization (S405). Thereby, the management device 4C can safely obtain the analysis result of the vulnerability of the software (product) based on the restored response information.

[0116] Next, the generation unit 12C restores the non - regular SBOM 18C stored in the storage unit 10 to the original regular SBOM 16 using the restoration database (S406).

[0117] [4 - 3. Effect] In the present embodiment, the SBOM provided from the management device 4C to the external device 6 is the non - regular SBOM 18C in which a plurality of component names and a plurality of versions included in the regular SBOM 16 are anonymized respectively. Therefore, even if the non - regular SBOM 18C provided from the management device 4C to the external device 6 is leaked to an attacker, it is difficult for the attacker to identify the content of the regular SBOM 16.

[0118] As a result, it is possible to cause confusion to the attacker and reduce the risk of leakage of the regular SBOM 16.

[0119] (Modification Example 1) The first embodiment and the fourth embodiment may be combined. That is, the generation unit may generate a non - standard SBOM by resolving at least one dependency relationship among a plurality of software components included in the standard SBOM and anonymizing a plurality of component names and a plurality of versions included in the standard SBOM respectively. Thereby, the resistance to inference attacks by attackers can be enhanced.

[0120] (Modification Example 2) The second embodiment and the fourth embodiment may be combined. That is, the generation unit may anonymize a plurality of component names and a plurality of versions included in the standard SBOM respectively, and the communication unit may execute a normal session and a dummy session. Thereby, the resistance to aggregation attacks by attackers can be enhanced.

[0121] (Modification Example 3) The first embodiment and the second embodiment may be combined. That is, the generation unit may resolve at least one dependency relationship among a plurality of software components included in the standard SBOM, and the communication unit may execute a normal session and a dummy session. Thereby, the resistance to aggregation attacks by attackers can be enhanced.

[0122] (Modification Example 4) The first embodiment, the second embodiment, and the third embodiment may be combined. That is, the generation unit may tamper with at least a part of the standard SBOM, then resolve at least one dependency relationship among a plurality of software components included in the standard SBOM, and the communication unit may execute a normal session and a dummy session. Thereby, the resistance to aggregation attacks by attackers can be further enhanced.

[0123] (Modification Example 5) The first embodiment, the second embodiment, the third embodiment, and the fourth embodiment may be combined. That is, the generation unit may modify at least a part of the regular SBOM, eliminate at least one dependency relationship among a plurality of software components included in the regular SBOM, further anonymize a plurality of component names and a plurality of versions included in the regular SBOM, and the communication unit may execute a regular session and a dummy session. Thereby, the resistance to inference attacks and aggregation attacks by attackers can be maximized.

[0124] (Others) In addition to the above Modification Examples 1 to 5, any two or more of the first embodiment, the second embodiment, the third embodiment, and the fourth embodiment may be arbitrarily combined.

[0125] (Other Modification Examples) As described above, the control method and the management device according to one or more aspects have been described based on the above embodiments. However, the present disclosure is not limited to the above embodiments. Without departing from the spirit of the present disclosure, various modifications conceived by those skilled in the art applied to the above embodiments, or forms constructed by combining components in different embodiments may also be included within the scope of one or more aspects.

[0126] In each of the above embodiments, each component may be configured by dedicated hardware or may be realized by executing a computer program suitable for each component. Each component may also be realized by a program execution unit such as a CPU (Central Processing Unit) or a processor reading and executing a computer program recorded on a recording medium such as a hard disk or a semiconductor memory.

[0127] Also, part or all of the functions of the management device according to each of the above embodiments may be realized by a processor such as a CPU executing a computer program.

[0128] Some or all of the components constituting each of the above devices may be composed of an IC card or a single module that can be detached from each device. The IC card or the module is a computer system composed of a microprocessor, ROM, RAM, etc. The IC card or the module may include the above-described multifunctional LSI. When the microprocessor operates according to a computer program, the IC card or the module achieves its function. This IC card or this module may have tamper resistance.

[0129] The present disclosure may be the method shown above. It may also be a computer program for realizing these methods by a computer, or a digital signal including the computer program. Further, the present disclosure may be the computer program or the digital signal recorded on a computer-readable non-transitory recording medium such as a flexible disk, a hard disk, a CD-ROM, an MO, a DVD, a DVD-ROM, a DVD-RAM, a BD (Blu-ray (registered trademark) Disc), a semiconductor memory, etc. It may also be the digital signal recorded on these recording media. Further, the present disclosure may be the computer program or the digital signal transmitted via a telecommunication line, a wireless or wired communication line, a network represented by the Internet, data broadcasting, etc. Further, the present disclosure may be a computer system including a microprocessor and a memory, where the memory stores the above computer program and the microprocessor operates according to the computer program. Further, it may be implemented by another independent computer system by recording and transferring the computer program or the digital signal to the recording medium, or by transferring the computer program or the digital signal via the network or the like.

Industrial Applicability

[0130] The control method according to the present disclosure is applicable to, for example, a management system for exchanging a regular SBOM between a management device and an external device, and the like.

Explanation of Signs

[0131] 2, 2A, 2B, 2C Management system 4, 4A, 4B, 4C Management device 6 External device 8 Network 10 Storage unit 12, 12A, 12B, 12C Generation unit 14, 14A Communication unit 16 Regular SBOM 18, 18A, 18B, 18C Irregular SBOM

Claims

1. A control method in a management device for managing regular software component information indicating a list of a plurality of software components constituting software, comprising: (a) storing the regular software component information in a storage unit; (b) generating non-regular software component information corresponding to software component information in which at least a part of the regular software component information is changed, based on the regular software component information stored in the storage unit; (c) transmitting the non-regular software component information generated in (b) to an external device via a network. A control method.

2. In (b), when at least one dependency exists between the plurality of software components in the regular software component information, generating the non-regular software component information corresponding to the software component information in which at least one dependency included in the regular software component information is eliminated The control method according to claim 1.

3. The control method further comprises: (d) transmitting the regular software component information stored in the storage unit to the external device via the network; (e) receiving regular response information for the regular software component information transmitted in (d) from the external device via the network; (f) receiving non-regular response information for the non-regular software component information transmitted in (c) from the external device via the network. The control method according to claim 1 or 2.

4. The control method further comprises: (g) discarding the non-regular response information received in (f). The control method according to claim 3.

5. In (b), at least a part of the regular software component information stored in the storage unit is tampered with, and the tampered regular software component information is generated as the non-regular software component information. The control method according to claim 1 or 2.

6. The control method further comprises: (h) receiving response information for the non-regular software component information transmitted in (c) from the external device via the network; (i) restoring the tampered information included in the response information received in (h) to the information before tampering. The control method according to claim 5.

7. The regular software component information includes a plurality of name information items respectively indicating the names of the plurality of software components, and in (b), each of the plurality of name information items included in the regular software component information stored in the storage unit is anonymized, and the anonymized regular software component information is generated as the non-regular software component information. The control method according to claim 1 or 2.

8. The control method further includes: (j) receiving, from the external device via the network, response information for the non-regular software component information transmitted in (c); and (k) restoring each of the anonymized plurality of name information items included in the response information received in (j) to the plurality of name information items before anonymization. The control method according to claim 7.

9. A management device that manages regular software component information indicating a list of a plurality of software components constituting software, comprising a storage unit that stores the regular software component information, a generation unit that generates non-regular software component information corresponding to software component information obtained by changing at least a part of the regular software component information based on the regular software component information stored in the storage unit, and a communication unit that transmits the non-regular software component information generated by the generation unit to an external device via a network. Management device.

Citation Information

Patent Citations

  • Component chart leakage detection system, and component chart leakage detection method

    WO2014192078A1