Information processing system, information processing method, program, and recording medium
By generating history information linking software component updates with timing data, the system tracks software usage periods, addressing the inability to identify past vulnerabilities and enabling timely updates.
Patent Information
- Application Number
- JP2023220558
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-12-27
- Publication Date
- 2025-07-09
- Estimated Expiration
- 2043-12-27
AI Technical Summary
Existing management devices cannot identify when software with past vulnerabilities was used.
Generate history information indicating the change history of software components, including Software Bill Of Materials (SBOM), by associating software component information with timing information to track updates and identify usage periods.
Enables the identification of software usage periods even if vulnerabilities existed in the past, facilitating timely notifications and updates.
Smart Images

Figure 2025103273000001_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to an information processing system, an information processing method, a program, and a recording medium.
Background Art
[0002] The management device described in Patent Document 1 aims to identify locations in the system where abnormalities may occur. To achieve the above object, the management device stores configuration information indicating the configuration of each component of the system for each component of the system. The management device performs an operation of identifying a first component in which an abnormality has occurred and identifying a second component that is common to the identified first component from the stored configuration information.
[0003] In the above-described management device, in relation to the above-described operation, SBOM (Software Bill Of Materials), which is software configuration information, may include, for example, vulnerability information.
Prior Art Documents
Patent Documents
[0004]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0005] However, the above-described management device has a problem that, for example, even if software had a vulnerability in the past, it is impossible to identify when the software was used.
[0006] An object of the present disclosure is to provide an information processing system, an information processing method, a program, and a recording medium capable of identifying when software was used even if the software had a vulnerability in the past.
Means for Solving the Problems
[0007] To solve the above problems, the information processing system according to the present disclosure generates history information indicating the change history of software component information (including SBOM) regarding one or more software components constituting predetermined software based on the software component information and history timing information by a processing unit. The history timing information is information indicating the timing of one or more points in time from the generation time of the software component information to the storage time of the history information.
Effect of the Invention
[0008] According to the information processing system according to the present disclosure, even if the software had vulnerabilities in the past, it is possible to specify when the software was used.
Brief Description of the Drawings
[0009]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
Figure 11
Figure 12
Figure 13
Figure 14
Figure 15
Figure 16
Figure 17
Figure 18
Figure 19
Figure 20
Figure 21
Figure 22
Figure 23
Figure 24
Figure 25
Figure 26
Figure 27
Figure 28
Figure 29
Figure 30
Figure 31
Figure 32
Figure 33
Mode for Carrying Out the Invention
[0010] An embodiment of the information processing system JSS according to the present disclosure will be described.
[0011] 〈Embodiment 1〉 The information processing system JSS of Embodiment 1 will be described.
[0012] 〈Configuration of Embodiment 1〉 〈Configuration of Information Processing System JSS〉 FIG. 1 shows the configuration of the information processing system JSS of Embodiment 1.
[0013] As shown in FIG. 1, the information processing system JSS of Embodiment 1 includes terminals TM1 to TMm (m is an integer of 1 or more) and a server SV. The terminals TM1 to TMm and the server SV are interconnected via a network NW (for example, the Internet) as shown in FIG. 1.
[0014] The terminals TM1 to TMm are used by users US1 to USm who develop and use software SW to be managed by the server SV, for example. For example, terminal TM1 is used by user US1, terminal TM2 is used by user US2,..., and terminal TMm is used by user USm.
[0015] The server SV is used by the administrator KA. As shown in FIG. 1, the server SV stores the software SW, and also generates and stores history information RJ having configuration information KJ (in particular, component information included in the software SW (hereinafter also referred to as "software component information")) and history timing information (for example, time information JJ). The history timing information is timing information stored as history information, and in particular, can be timing information at one or more points in time from the generation time of the software component information (for example, configuration information KJ) to the storage time of the history information RJ (for example, information including at least a date, hereinafter also referred to as "time information JJ" in the description). More specifically, the history timing information can be, for example, the time when the software component information is generated by the processing unit SY(SV), the time when the software component information is acquired by the server SV (for example, when it is generated outside the server SV), the time when the software component information is stored in the server SV, the time when the history information is generated by the processing unit SY(SV), the time when the history information is stored in the server SV, and the like. When the server SV is logically configured (for example, a cloud server or the like), the administrator KA can operate the terminal TM to perform operations on the server SV.
[0016] Hereinafter, for ease of explanation and understanding, for example, a plurality of identical devices may be collectively referred to by one name. For example, the terminals TM1 to TMm may be collectively referred to as the terminal TM.
[0017] <Configuration of Terminal TM> FIG. 2 shows the configuration of the terminal TM according to Embodiment 1.
[0018] The terminal TM according to Embodiment 1 has, as shown in FIG. 2, an input / output unit NS(TM), a processing unit SY(TM), a storage unit KI(TM), and a communication unit TU(TM).
[0019] The input / output unit NS(TM) is used for the user US to input for changing, adding, deleting, etc. components (e.g., illustrated in FIG. 6) that make up the software SW in order to update the software SW, for example, and is also used for outputting the configuration of the software SW obtained from the server SV. The input / output unit NS(TM) is, for example, a touch panel, a keyboard, a mouse, a liquid crystal monitor, or a printer.
[0020] The processing unit SY(TM) performs, for example, processing related to the input for updating the software SW described above and the output of the configuration of the software SW described above. The processing unit SY(TM) also executes the software SW obtained by the user US as required by the user US.
[0021] The storage unit KI(TM) stores, for example, data necessary for the processing of the processing unit SY(TM).
[0022] The communication unit TU(TM) performs communication via the network NW, for example, transmits the updated software SW described above to the server SV, and receives the software SW managed by the server SV from the server SV.
[0023] 〈Configuration of Server SV〉 FIG. 3 shows the configuration of the server SV of Embodiment 1.
[0024] The server SV of Embodiment 1 has, as shown in FIG. 3, an input / output unit NS(SV), a processing unit SY(SV), a storage unit KI(SV), and a communication unit TU(SV).
[0025] The input / output unit NS(SV) is used, for example, to output the history information RJ of the software SW (e.g., shown in FIG. 1) in relation to the update of the software SW, and is also used to perform an input for adding supplementary information (e.g., bibliographic information) to the history information RJ. The input / output unit NS(TM) is, for example, a touch panel, a keyboard, a mouse, a liquid crystal monitor, or a printer. Note that, as described above, when the server SV is logically configured via a network (e.g., a cloud server, etc.), it may be replaced by the input / output unit NS provided in the terminal TM of the administrator KA.
[0026] The processing unit SY(SV) performs, for example, the processing related to the output of the above-described history information RJ and the input to the history information RJ. The processing unit SY(SV) also performs, as necessary, notification to the user US and license management of the software SW based on the history information RJ.
[0027] The storage unit KI(SV) stores, for example, the data necessary for the processing of the processing unit SY(SV).
[0028] The communication unit TU(SV) performs communication via the network NW, for example, receives the updated software SW from the user US, and transmits the software SW managed by the server SV to the terminal TM.
[0029] <Operation of Embodiment 1> FIG. 4 is a flowchart showing the operation of the information processing system JSS of Embodiment 1.
[0030] FIG. 5 is a time chart showing the operation of the information processing system JSS of Embodiment 1. The operation of the information processing system JSS of Embodiment 1 will be described with reference to the flowchart of FIG. 4 and the time chart of FIG. 5.
[0031] In the following, in order to facilitate explanation and understanding, the following is assumed. (1) That users US1 to US3 among users US1 to USm are involved in the development of the software SW (shown in FIG. 4) (2) The initial version of the software SW described above includes one or more components (for example, components A, B, C,..., W) (shown in FIG. 6). (3) History information RJ (shown in FIG. 18), in which configuration information KJ0 indicating the configuration of the initial version of the software SW (shown in FIG. 6) and time information JJ0 indicating the time t0 (12:34 on February 3, 2023) when the software SW (initial version) was saved (shown in FIG. 7) are linked to each other, is stored in the server SV.
[0032] Step ST11 (at time t1): The terminal TM1 transmits the software SW with "Component Dadd added" by the user US1, that is, the configuration information KJ1 (shown in FIG. 8), to the server SV.
[0033] Step ST12: When the server SV receives, that is, acquires, the software SW with "Component Dadd added", that is, the configuration information KJ1, it acquires time information JJ1 (shown in FIG. 9) indicating the time t1 "13:45 on March 4, 2023" from, for example, the clock in the information processing system JSS. The server SV further updates the history information RJ by linking the configuration information KJ1 and the time information JJ1 to each other (shown in FIG. 19).
[0034] Step ST13 (at time t2): The terminal TM2 transmits the software SW with "Component T changed to Component Tchg" by the user US2, that is, the configuration information KJ2 (shown in FIG. 10), to the server SV.
[0035] Step ST14: When the server SV receives the software SW with "Component T changed to Component Tchg", that is, the configuration information KJ2, it acquires time information JJ2 (shown in FIG. 11) indicating the time t2 "14:32 on April 5, 2023". The server SV further updates the history information RJ by linking the configuration information KJ2 and the time information JJ2 to each other (shown in FIG. 20).
[0036] Step ST15 (at time t3): The terminal TM3 transmits the software SW that has been "changed from component U to component Uchg" by the user US3, that is, the configuration information KJ3 (shown in FIG. 12), to the server SV.
[0037] Step ST16: When the server SV receives the software SW that has been "changed from component U to component Uchg", that is, the configuration information KJ3, it acquires the time information JJ3 (shown in FIG. 13) indicating the time "15:21 on May 6, 2023" at time t3. The server SV further updates the history information RJ by associating the configuration information KJ3 and the time information JJ3 with each other (shown in FIG. 21).
[0038] Step ST17 (at time t4): The terminal TM2 transmits the software SW that has been "changed from component Tchg1 to component Tchg2" by the user US2, that is, the configuration information KJ4 (shown in FIG. 14), to the server SV.
[0039] Step ST18: When the server SV receives the software SW that has been "changed from component Tchg1 to component Tchg2", that is, the configuration information KJ4, it acquires the time information JJ4 (shown in FIG. 15) indicating the time "16:10 on June 7, 2023" at time t4. The server SV further updates the history information RJ by associating the configuration information KJ4 and the time information JJ4 with each other (shown in FIG. 22).
[0040] Step ST19 (at time t5): The terminal TM1 transmits the software SW that has been "changed from component W to component Wchg" by the user US1, that is, the configuration information KJ5 (shown in FIG. 16), to the server SV.
[0041] Step ST20: When the server SV receives the software SW that has been "changed from component W to component Wchg", that is, the configuration information KJ5, it acquires the time information JJ5 (shown in FIG. 17) indicating the time "17:05 on July 8, 2023" at time t5. The server SV further updates the history information RJ by associating the configuration information KJ5 and the time information JJ5 with each other (shown in FIG. 23).
[0042] In the above example, the configuration for transmitting the configuration information KJ to the server SV is described. Instead of this, the configuration information of the software SW (particularly, software component information) may be used to analyze information related to the software SW (for example, hierarchical information of folders or hierarchical information of program sources) by the processing unit SY of the server SV, thereby constructing the configuration information KJ including the hierarchical component information. Further, the information related to the software may be transmitted from the terminal TM, or may be information read from the storage area of another computer (for example, a cloud server, etc.) through a predetermined path. The predetermined path may be, for example, read by the processing unit SY of the server SV or the terminal TM via a network or a wired cable (particularly, by granting access rights to the storage area of another computer), or may be temporarily stored in an external storage device such as a memory card, and then the external storage device may be connected to a computer such as the server SV accessible by the terminal TM and read, and thus may be stored in the storage unit KI of the server SV.
[0043] <Effect of Embodiment 1> As described above, in the information processing system JSS of Embodiment 1, every time the content of the software SW is updated (such as addition, change, deletion, etc.) by the users US1 to US3, the server SV generates the history information RJ by associating the configuration information KJ and the time information JJ with each other. Thereby, even if the software SW had a defect in the past (including defects such as vulnerabilities, bugs, crashes, etc., and license-related defects caused by the license side of the components that have received license permissions (for example, use outside the scope defined by the license, open source software ceasing to be open source, paid license expiration, etc.)), it is possible to identify when the software SW was used by checking and specifying the history information RJ.
[0044] For example, even if component Tchg1 has a vulnerability, as shown in FIG. 5, it is possible to identify that component Tchg1 is being used and the usage period SK is between time t2 and time t4, and more specifically, between "14:32 on April 5, 2023" and "16:10 on June 7, 2023".
[0045] <Variant Example 1-1> Information on whether components A to W, etc. included in software SW have vulnerabilities (hereinafter also referred to as "vulnerability information") may be received as input from the terminal TM of user US who develops software SW, and the vulnerability information may be stored in the storage unit KI of server SV. Alternatively, the vulnerability information may be generated by being independently analyzed by the processing unit SY of server SV and stored in the storage unit KI of server SV. Also, when a vulnerability database in which the vulnerability information of software SW is stored is publicly available (especially in the case of open source), the processing unit SY of server SV may access the vulnerability database via network NW (for example, the Internet) to collect (crawl) and store the vulnerability information.
[0046] Then, the processing unit SY of server SV compares the vulnerability information stored in the storage unit KI of server SV with the configuration information KJ included in the history information RJ (especially information regarding components A to W), and executes a process of identifying information indicating at least any one of the period during which the component corresponding to the vulnerability information was included, software information (including version information), and configuration information KJ (hereinafter also referred to as "vulnerability target information").
[0047] Note that, for the sake of easy explanation and understanding, vulnerable information has been described, but it is not limited to this. Any information (for example, the vulnerable information, defect information, license-related defect information, etc. as described above) may be used as long as it is information regarding defects of the software SW (especially, components A to W included in the software SW) stored in the storage unit KI of the server SV. That is, the processing unit SY of the server SV compares the defect information stored in the storage unit KI of the server SV with the configuration information KJ included in the history information RJ (especially, information regarding components A to W), and executes a process of specifying (generating) information (hereinafter, also referred to as "defect-corresponding information") indicating at least any one of the period or version in which the component corresponding to the defect information was included in the history information RJ and the configuration information KJ. Note that the "storage" of the defect information includes storage in any of the primary storage device (main memory), secondary storage device, cache memory, etc. included in the storage unit KI. For example, it may be storage by a registration process in response to a registration operation by the user US or the administrator KA, or temporary storage when acquired and referred to from an external database or the like.
[0048] <Effect of Modification Example 1-1> With the configuration of Modification Example 1-1, even if the software SW had defects in the past (including vulnerabilities, bugs, crashes, etc., and license-related defects caused by the licensee side of components licensed (for example, use outside the scope defined by the license, open-source software ceasing to be open-source, expiration of a paid license, etc.)), it is possible to specify the defect-corresponding information by the processing of the processing unit SY of the server SV.
[0049] <Modification Example 1-2> Further, the processing unit SY of the server SV, based on a defect corresponding designation process for designating at least one of the period or version in which the component corresponding to the defect information was included in the history information RJ or the configuration information KJ by a defect corresponding designation operation after an administrator KA or the like checked the history information RJ as in, for example, Embodiment 1, or based on the processing of the processing unit SY as in the above Modification 1-1, in response to the fact that defect corresponding information such as a period having a defect such as a vulnerability is specified (generated), may transmit, to the terminals TM1 to TMm, for example, a notification to the effect that "During the usage period SK (shown in FIG. 6), the software SW included the component Tchg1 having a defect." (that is, a notification regarding the usage period SK during which the component including the defect was used), a notification to the effect that "Prohibit the use of the software SW including the component Tchg1." (that is, a notification regarding the prohibition of the use of the software including the component having a defect), or a notification to the effect that "Recommend the use of the software SW including the component Tchg2 having no vulnerability." (that is, a notification regarding the recommendation of the use of the software including the component having no defect).
[0050] 〈Effect of Modification 1-2〉 With the configuration of Modification 1-2, by transmitting a notification regarding the software component having the specified defect to the terminal TM of the user US, the user US can smoothly recognize the defect.
[0051] 〈Modification 1-3〉 Further, the processing unit SY of the server SV may have importance information (which may be referred to as "influence degree indicating the influence degree") indicating the respective importance levels associated and stored in the storage unit KI of the server SV in at least one of the software component unit or the software SW unit.
[0052] The importance information (impact information) may, for example, accept an input operation from at least one of the user US or the administrator KA and set an arbitrary importance for each software component and / or for each software SW in the storage unit KI of the server SV, and / or execute a setting process for setting the importance by referring to importance condition information indicating the conditions for setting each importance by the processing unit SY of the server SV. Here, the conditions for setting each importance may be, for example, at least any one of the following six. (1) Whether at least any one of the target software SW or software components (hereinafter referred to as software components, etc.) is connected to the Internet (i.e., a condition based on connection relationship information), (2) Whether the target software component, etc. is connected to an area where access is restricted (i.e., a condition based on access restriction information), (3) Whether important data information (e.g., confidential information, customer information, personal information, credit card information, etc.) is included in the target software component, etc. (i.e., a condition based on important data information) (4) For what software environment (test environment, development environment, production environment, etc.) the target software component, etc. is intended (i.e., a condition based on software environment information) (5) Whether the target software component, etc. has access rights to other resources (computers, databases, networks, etc.) (i.e., a condition based on access right information) (6) What level is the threat level of the defect (especially vulnerability) associated with the software component itself (i.e., a condition based on defect threat level information)
[0053] Then, the processing unit SY performs a determination process of comparing importance information indicating the importance corresponding to the changed software component or the like (especially, the software component or the like in which the difference in the change specified in Embodiment 2 described later is larger than the reference) with the reference information, and determining that the importance is higher than the reference. Only when it is determined that the importance is higher than the reference, a notification (for example, a notification informing that a software component or the like with high importance has been changed) including information regarding the importance of the changed software component or the like may be transmitted (that is, the necessity of the notification may be determined based on the importance). At this time, one or more reference information is stored in the storage unit KI of the server SV. When two or more comparison results are obtained (for example, when the importance is set in four levels of Critical, High, Medium, and Low according to the conditions, if there is one reference, there are two comparison results of Critical or higher and High or lower, or two comparison results of High or higher and Medium or lower, etc., and if there are three references, each weight from Critical to Low becomes four comparison results), notification destination information corresponding to each comparison result may be set. That is, the notification destination information includes destination information (for example, an email address, etc.). For example, if there is one reference, when the importance of the changed software component or the like is Critical, a notification may be transmitted based on the destination information indicating the mailing list of all members of the group, and when it is High or lower, a notification may be transmitted based on the destination information indicating only one specific responsible person. In other words, the above notification may be transmitted to different notification destinations (for example, the mailing list or only one responsible person) or different notification ranges (for example, the mailing list and one responsible person, or only one responsible person) according to the comparison result.
[0054] Alternatively, instead of or in addition to the above, the processing unit SY may perform a determination process of comparing importance information indicating the importance corresponding to the software component etc. specified as the defect-corresponding information with the reference information, and determining that the importance is higher than the reference, and transmit the notification described in Modification 1-2 only when it is determined that the importance is higher than the reference (that is, the necessity of the above notification may be determined based on the importance). At this time, one or more pieces of reference information may be stored in the storage unit KI of the server SV, and when two or more comparison results are obtained, notification destination information corresponding to each comparison result may be set. That is, the notification destination information includes destination information (for example, an email address, etc.), and for example, if there is one reference, when the importance of the changed software component etc. is Critical, a notification may be transmitted based on the destination information indicating the mailing list of all members of the group, and when it is High or less, a notification may be transmitted based on the destination information indicating only one specific responsible person. In other words, the above notification may be transmitted to different notification destinations (for example, a mailing list or only one responsible person) or different notification ranges (for example, a mailing list and one responsible person or only one responsible person) according to the comparison result.
[0055] <Effect of Modification 1-3> With the configuration of Modification 1-3, it becomes possible to efficiently respond by checking the importance (impact) of the software component etc. (or the software component etc. in which a defect is identified) changed when the software update frequency is high. In particular, when performing a notification, it is possible to suppress the number of notifications by limiting it to the case where a predetermined importance (importance higher than the reference) is indicated.
[0056] <Embodiment 2> The information processing system JSS of Embodiment 2 will be described.
[0057] <Configuration of Embodiment 2> The information processing system JSS of Embodiment 2 has the same configuration as the configuration of the information processing system JSS of Embodiment 1 (illustrated in FIGS. 1, 2, and 3).
[0058] <Operation of Embodiment 2> The information processing system JSS of Embodiment 2 basically operates in the same manner as the information processing system JSS of Embodiment 1 (illustrated in FIGS. 4 and 5).
[0059] On the other hand, the information processing system JSS of Embodiment 2 is different from, or in addition to, the information processing system JSS of Embodiment 1 that stores history information RJ (illustrated in FIGS. 18 to 23) consisting of time information JJ and configuration information KJ. As shown in FIG. 24, it stores history information RJ consisting of time information JJ and difference information SJ. That is, it generates comparison result information (hereinafter also referred to as "difference information") indicating the result (difference) of comparing software component information stored at two time points with each other. The difference information SJ may be received, for example, from an input from the terminal TM and stored in the storage unit KI of the server SV, and / or the processing unit SY of the server SV may perform a comparison process (for example, character comparison by searching based on characters or image comparison by image analysis based on images, etc.) on the configuration information KJ in any of the forms of tree-shaped configuration information KJ (i.e., configuration information KJ indicating the relationship between software components), matrix-shaped configuration information KJ, and mutual relationship configuration information KJ, and the result of the comparison may be stored as difference information in the storage unit KI of the server SV.
[0060] In the history information RJ, as shown in FIG. 24, the time information JJ and the difference information SJ are mutually linked. For example, the time information JJ1 at time t1 and the difference information SJ1 at time t1 are mutually linked.
[0061] The difference information SJ of Embodiment 2, which replaces the configuration information KJ of Embodiment 1, indicates the difference between the software SW before and after the software SW is updated, that is, the difference between the configuration information KJ.
[0062] For example, the difference information SJ1 is the result of comparing the hierarchical configuration information KJ0 (illustrated in the upper part of FIG. 25) at time t0 indicated by the time information JJ0 with the hierarchical configuration information KJ1 (illustrated in the lower part of FIG. 25) at time t1 indicated by the time information JJ1. That is, it indicates the difference of "addition of component Dadd" (illustrated in FIGS. 24 and 25).
[0063] The difference information SJ1 also indicates the difference of "addition of component Dadd" (illustrated in FIGS. 24 and 26) between the matrix-shaped configuration information (hierarchy) KJ0(KS) (illustrated in the upper part of FIG. 26) at time t0 indicated by the time information JJ0 and the matrix-shaped configuration information (hierarchy) KJ1(KS) (illustrated in the lower part of FIG. 26) at time t1 indicated by the time information JJ1.
[0064] The difference information SJ1 further indicates the difference of "addition of component Dadd" (illustrated in FIGS. 24 and 27) between the configuration information (relationship) KJ0(KK) (illustrated in the upper part of FIG. 27) indicating the inter-component relationship (e.g., parent-child relationship) at time t0 indicated by the time information JJ0 and the configuration information (relationship) KJ1(KK) (illustrated in the lower part of FIG. 27) indicating the inter-component relationship at time t1 indicated by the time information JJ1.
[0065] <Effect of Embodiment 2> As described above, in the information processing system JSS of Embodiment 2, instead of the history information RJ in which the configuration information KJ and the time information JJ in Embodiment 1 are mutually associated, the history information RJ in which the difference information SJ and the time information JJ are mutually associated is generated. Thus, as in Embodiment 1, even if the software SW had vulnerabilities in the past, it becomes possible to identify when the software SW was used.
[0066] <Modification Example 2-1> Although the part name is described in the above difference information, instead of or in addition to this, a difference value corresponding to the amount of the difference may be associated. The difference value may be, for example, a value based on the number of differences. Or, the difference value may be a value obtained by multiplying the weighting coefficient set for each part by the number of differences.
[0067] <Effect of Modification Example 2-1> With the configuration of Modification Example 2-1, by associating a difference value corresponding to the amount of difference instead of or in addition to the part name as the difference information, it becomes possible to recognize changes more quantitatively as well as the differences in the software configuration. As a result, for example, operations such as "check whether the amount of difference after the change exceeds the reference value, and if it does, check whether there is a malfunction" become possible.
[0068] <Modification Example 2-2> Also, result condition information indicating conditions related to the comparison result may be set, and based on the comparison result information (difference value) and the result condition information (for example, a reference value is set and the difference value exceeds the reference difference value, etc.), a notification indicating that the conditions are met may be sent to the terminal TM.
[0069] <Effect of Modification Example 2-2> With the configuration of Modification Example 2-2, by sending a notification regarding software components having a difference amount equal to or greater than a predetermined reference to the terminal TM of the user US, it becomes possible for the user US to smoothly recognize changes in the software SW (particularly, changes with a large difference amount).
[0070] <Embodiment 3> The information processing system JSS of Embodiment 3 will be described.
[0071] <Configuration of Embodiment 3> The information processing system JSS of Embodiment 3 has the same configuration as the configuration of the information processing system JSS of Embodiment 1 (illustrated in FIGS. 1, 2, and 3).
[0072] <Operation of Embodiment 3> In the information processing system JSS of Embodiment 3, the input / output unit NS(TM) of the terminals TM1 to TMm (illustrated in FIG. 2) displays the configuration of the software SW in the form of the configuration information KJ11 to KJ4 (illustrated in FIGS. 28 to 31) instead of or in addition to the configuration information KJ (for example, the configuration information KJ0 illustrated in FIG. 6) of Embodiment 1.
[0073] In the aspect of the configuration information KJ11, as shown in FIG. 28, the components A to W that make up the software SW may be displayed separately as a main routine and a subroutine.
[0074] In the aspect of the configuration information KJ12, as shown in FIG. 29, the components A to W that make up the software SW may be displayed with the number of times used in the software SW appended.
[0075] In the aspect of the configuration information KJ13, as shown in FIG. 30, the components A to W that make up the software SW may be displayed separately as components with subroutines and components without subroutines.
[0076] In the aspect of the configuration information KJ14, as shown in FIG. 31, among the components A to W that make up the software SW, the required times T(A), T(B), T(C), T(D) of the components A, B, C, D that are the main routine, and the components (for example, the components S, T that make up the component A) that make up the components A, B, C, D may be displayed in time series.
[0077] <Effect of Embodiment 3> As described above, in the information processing system JSS of Embodiment 3, instead of or in addition to the display mode in the information processing system JSS of Embodiment 1, it is displayed in the display modes of the configuration information KJ11 to the configuration information KJ14. As a result, as in Embodiment 1, even if the software SW had a defect in the past, it is possible to specify when the software SW was used. Moreover, since the information processing system JSS of Embodiment 1 has better visibility in the display modes of the configuration information KJ11 to the configuration information KJ14, it is possible to perform the above specification more easily.
[0078] <Configuration by Hardware of Embodiments 1 to 3> FIG. 32 shows the hardware configuration of the information processing system JSS of Embodiments 1 to 3.
[0079] To perform the functions described above, the information processing system JSS according to Embodiments 1 to 3 includes a processing circuit SYO, and further includes an input circuit NYU and an output circuit SYU as necessary, as shown in FIG. 32.
[0080] The processing circuit SYO is dedicated hardware. The processing circuit SYO mainly realizes the functions of the processing unit SY(TM) of the terminal TM and the processing unit SY(SV) of the server SV (illustrated in FIGS. 2 and 3).
[0081] The processing circuit SYO is, for example, a single circuit, a composite circuit, a programmed processor, a parallel-programmed processor, an ASIC (Application Specific Integrated Circuit), an FPGA (Field Programmable Gate Array), or a combination thereof.
[0082] The input circuit NYU and the output circuit SYU exchange inputs and outputs related to the operation of the processing circuit SYO, for example, between the outside of the terminal TM and the server SV.
[0083] <Hardware Configuration Based on Software Realization of Embodiments 1 to 3> FIG. 33 shows the hardware configuration based on the software realization of the information processing system JSS according to Embodiments 1 to 3.
[0084] The information processing system JSS according to Embodiments 1 to 3 includes a processor PRO and a storage circuit KIO, and further includes an input circuit NYU and an output circuit SYU as necessary, as shown in FIG. 32.
[0085] The processor PRO is a CPU (Central Processing Unit, also referred to as a central processing unit, processing unit, arithmetic unit, microprocessor, microcomputer, DSP (Digital Signal Processing)) that executes programs. The processor PRO mainly realizes the functions of the processing unit SY(TM) of the terminal TM and the processing unit SY(SV) of the server SV.
[0086] The processor PRO realizes the above-described functions by software, firmware, or a combination of software and firmware. The software and firmware are described as a program PRG and stored in the memory circuit KIO.
[0087] The processor PRO realizes the above-described functions by reading out and executing the above-described program PRG from the memory circuit KIO. It can be said that the above-described program PRG mainly causes a computer to execute the procedures and methods of the processing unit SY(TM) of the terminal TM and the processing unit SY(SV) of the server SV.
[0088] Here, the memory circuit KIO is, for example, a non-volatile or volatile semiconductor memory such as RAM (Random Access Memory), ROM (Read Only Memory), flash memory, EPROM (Erasable Programmable Read Only Memory), EEPROM (Electrically Erasable Programmable Read-Only Memory), and magnetic disks, flexible disks, optical disks, compact disks, mini disks, DVDs (Digital Versatile Disc), etc.
[0089] Among the functions of the input / output unit NS(TM) to the communication unit TU(TM) of the terminal TM and the input / output unit NS(SV) to the communication unit TU(SV) of the server SV, some functions may be realized by the processing circuit SYO (shown in FIG. 32), and on the other hand, some other functions may be realized by the processor PRO (shown in FIG. 33).
[0090] As described above, the functions of the input / output unit NS(TM) to the communication unit TU(TM) of the terminal TM and the input / output unit NS(SV) to the communication unit TU(SV) of the server SV can be realized by hardware, software, firmware, or a combination thereof.
[0091] The input circuit NYU and the output circuit SYU exchange inputs and outputs related to the operation of the processor PRO, for example, with the outside of the terminal TM and the server SV.
[0092] <Exemplary Configuration> The information processing system, information processing system method, program, and recording medium according to the present disclosure have, for example, the following configuration.
[0093] [Item 1] By a processing unit, Based on software component information and history timing information regarding one or more software components constituting predetermined software, history information indicating a change history of the software component information is generated. The history timing information is information indicating the timing of one or more time points from the generation time point of the software component information to the storage time point of the history information. An information processing system. [Item 2] Further, by the processing unit, Based on the defect information stored in the storage unit and the history information, information indicating at least either the period during which the component corresponding to the defect information was included or the software component information is specified. The information processing system according to Item 1. [Item 3] Further, by the processing unit, At least any one of a notification regarding the usage period of the component using the component including the defect, a notification regarding the prohibition of use of the software including the component including the defect, or a notification regarding the recommendation of use of the software including the component not including the defect is transmitted to a predetermined terminal. The information processing system according to Item 2. [Item 4] Further, by the processing unit, Based on importance information set at least in either component unit or software component information unit, it is determined whether to transmit the notification. The information processing system according to Item 3. [Item 5] Generating comparison result information indicating the result of comparing software component information stored at two time points with each other The information processing system according to any one of Items 1 to 4 [Item 6] Based on the comparison result information and result condition information indicating conditions related to the result, sending a notification indicating that the conditions are met to a predetermined terminal The information processing system according to Item 5 [Item 7] The comparison result is difference value information based on the difference between software component information, and the condition includes that the difference value indicated by the difference value information exceeds a reference difference value The information processing system according to Item 6 [Item 8] The software component information is obtained by analyzing hierarchical information included in information related to software The information processing system according to any one of Items 1 to 7 [Item 9] The information related to the software is information read from the storage area of another computer The information processing system according to Item 8 [Item 10] By a processing unit Based on software component information and history timing information related to one or more software components constituting predetermined software, generating history information indicating a change history of the software component information The history timing information is information indicating the timing of one or more time points from the generation time point of the software component information to the storage time point of the history information. Information processing method [Item 10] By a processing unit Based on software component information and history timing information related to one or more software components constituting predetermined software, generating history information indicating a change history of the software component information The history timing information is information indicating the timing at one or more points in time from the generation time of the software component information to the storage time of the history information. Program.
Explanation of Signs
[0094] JSS Information Processing System TM Terminal SV Server US User KA Administrator NW Network SW Software RJ History Information KJ Configuration Information JJ Time Information
Claims
1. Based on software component information and history timing information regarding one or more software components that make up a predetermined software by a processing unit, generate history information indicating a change history of the software component information, wherein the history timing information is information indicating the timing of one or more points in time from the generation time of the software component information to the storage time of the history information. An information processing system.
2. The information processing system according to claim 1, wherein the processing unit further identifies information indicating at least one of a period during which a component corresponding to the defect information was included or software component information based on the defect information stored in the storage unit and the history information.
3. The information processing system according to claim 2, wherein the processing unit further transmits at least one of a notification regarding a usage period during which a component including the defect was used, a notification regarding prohibition of use of software including the component including the defect, or a notification regarding recommendation of use of software including a component not including the defect to a predetermined terminal.
4. The information processing system according to claim 3, wherein the processing unit further determines whether to transmit the notification based on importance information set in at least one of a component unit or a software component information unit.
5. Generate comparison result information indicating a result of comparing software component information stored at two points in time with each other. The information processing system according to claim 1.
6. Based on the comparison result information and result condition information indicating conditions related to the result, transmit a notification indicating that the conditions are met to a predetermined terminal. The information processing system according to claim 5.
7. The comparison result is difference value information based on the difference between software component information, and the condition includes that the difference value indicated by the difference value information exceeds a reference difference value. The information processing system according to claim 6.
8. The software component information is obtained by analyzing hierarchical information included in information regarding software. The information processing system according to any one of claims 1 to 7.
9. The information regarding the software is information read from a storage area of another computer. The information processing system according to claim 8.
10. By a processing unit Based on software component information and history timing information regarding one or more software components that constitute a predetermined software, history information indicating a change history of the software component information is generated. The history timing information is information indicating the timing of one or more points in time from the generation time of the software component information to the storage time of the history information. An information processing method.
11. By a processing unit, Based on software component information and history timing information regarding one or more software components that constitute a predetermined software, history information indicating a change history of the software component information is generated. The history timing information is information indicating the timing of one or more points in time from the generation time of the software component information to the storage time of the history information. A program.
Citation Information
Patent Citations
Management device, management method, and computer-readable storage medium
WO2023084671A1
Cited By
Information processing system, information processing method and program
JP7828691B1