Information processing system, information processing method, and program

The information processing system optimizes access control by specifying attribute types and selecting required logs, reducing unnecessary log operations and associated costs.

JP2025111958APending Publication Date: 2025-07-31NEC CORP
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024005918
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-01-18
Publication Date
2025-07-31

AI Technical Summary

Technical Problem

Existing access control systems incur unnecessary costs due to the operation of logs that are not essential for determining access availability, as they accumulate over time.

Method used

An information processing system that specifies access attribute types and selects necessary log types to derive their values, reducing the operation of unnecessary logs by using an attribute specifying unit and a selection unit to determine access control policies.

Benefits of technology

Reduces the operational costs associated with managing logs by only processing those necessary for access control, thereby optimizing resource access management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025111958000001_ABST
    Figure 2025111958000001_ABST
Patent Text Reader

Abstract

To provide an information processing system, an information processing method and a program, which contribute to reduction in cost of running a log that is required to use an access control policy.SOLUTION: An information processing system according to an embodiment of the present disclosure comprises: an attribute identification unit for identifying an access attribute type used to determine accessibility in the access control policy on the basis of the access control policy; and a selection unit for selecting a log type required to derive a value of the access attribute type identified by the attribute identification unit.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to an information processing system, an information processing method, and a program.

Background Art

[0002] Techniques for improving security by determining whether a user can access system resources and controlling the access have been evolving.

[0003] For example, Patent Document 1 discloses a log authentication server that performs user authentication of a user terminal. Here, when the log authentication server receives a network connection request from the user terminal, it determines whether the response sent from the user terminal satisfies the requested conditions based on the access log of the user of the user terminal.

Prior Art Documents

Patent Documents

[0004]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0005] As a means for determining whether access to a resource is possible, it is conceivable to use an access control policy. When an access control device uses an access control policy, the access control device refers to the logs necessary for access control and uses the information in the logs and the access control policy to determine whether access from the access subject is possible.

[0006] Access-related logs increase in volume over time. However, not all of the logs are necessarily required to determine the availability of access. Therefore, when an access control device uses an access control policy, it may also operate logs that are not originally necessary, increasing the cost incurred in log operation. Patent Document 1, which discloses log authentication technology, does not focus on this problem and thus cannot solve this problem.

[0007] One of the objectives that the embodiments of the present disclosure aim to achieve is to provide an information processing system, an information processing method, and a program that contribute to reducing the cost of operating logs necessary when using an access control policy. It should be noted that this objective is only one of the multiple objectives that the multiple embodiments disclosed herein aim to achieve. Other objectives or problems and novel features will be clarified from the description of this specification or the attached drawings.

Means for Solving the Problem

[0008] An information processing system according to one aspect includes an attribute specifying unit that specifies an access attribute type used to determine access availability in the access control policy based on the access control policy, and a selection unit that selects a log type necessary to derive the value of the access attribute type specified by the attribute specifying unit.

[0009] An information processing method according to one aspect is to specify an access attribute type used to determine access availability in the access control policy based on the access control policy, and select a log type necessary to derive the value of the specified access attribute type, an information processing method executed by a computer.

[0010] A program according to one aspect is Based on the access control policy, identify the types of access attributes used to determine access permission in the access control policy. Select the log types necessary to derive the values of the identified access attribute types. A program that causes a computer to perform the above.

Advantages of the Invention

[0011] The present disclosure can provide an information processing system, an information processing method, and a program that contribute to reducing the cost of operating logs required when using an access control policy.

Brief Description of the Drawings

[0012]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5A

Figure 5B

Figure 5C

Figure 5D

Figure 6A

Figure 6B

Figure 6C

Figure 7

Figure 8A

Figure 8B

Figure 8C

Figure 8D

Figure 8E

Figure 9A

Figure 9B

Figure 9C

Figure 9D

Figure 10

Figure 11

Figure 12

Mode for Carrying Out the Invention

[0013] Hereinafter, embodiments of the present disclosure will be described with reference to the drawings. Note that the following description and drawings in the embodiments are appropriately omitted and simplified for clarity of explanation. Also, in the present disclosure, unless otherwise specified, when "at least any one of a plurality of items" is defined for a plurality of items, the definition may mean any one item or any plurality of items including all items.

[0014] Each drawing referenced in the embodiments is merely an example for describing one or more embodiments. Each drawing may not relate to only one particular embodiment, but may also relate to one or more other embodiments. As will be understood by those skilled in the art, various features or steps described with reference to any one drawing can be combined with features or steps shown in one or more other drawings to create, for example, an embodiment not explicitly shown or described. Not all features or steps shown in any one drawing are necessarily required to describe an exemplary embodiment, and some features or steps may be omitted. The order of steps described in any drawing may be changed as appropriate.

[0015] Additionally, common definitions used throughout this disclosure are explained below.

[0016] [Definition explanation] In this disclosure, an "access resource" refers to any access target, such as an information asset, an application, a computer file, or a device to be accessed. Hereinafter, an "access resource" may also be referred to simply as a "resource." The accessing entity that accesses an access resource may be a user, or may be a non-human entity, such as a server or a process, that automatically performs the access.

[0017] In the present disclosure, an "access attribute" refers to any element that specifies the nature of an access when an access destination is accessed. Specific examples of elements include: -Various data from access sources -Various data of the destination Other data indicating the nature of the access It may include one or more arbitrary specific information (values) related to the nature of the access, such as the above. Hereinafter, the "access attribute" may also be simply referred to as the "attribute."

[0018] Specific examples of the various data (Subject Attributes) of the access source include any one or more of information on the access source's ID (IDentification), information on the end user, information on at least one of the access source's device or subsystem, information on the access source's IP (Internet Protocol) address, information on the port number, software name (e.g., application name), access authentication method, etc. Here, the information on the access source's ID includes any one or more of the access source's ID (e.g., end user ID), end user name, device ID, subsystem ID, application ID, end user authentication result (authentication history) of the access source ID, etc. The information on the end user includes any one or more of the end user's affiliation (organization), job title, job type, end user location (or location of the access source device), affiliation of the access source device, behavioral abnormality level of the end user or the access source device, etc. The information on the access source device includes any one or more of the OS (Operating System) and its version used by the access source device, manufacturer name, etc. The information about the IP address of the access source includes, for example, one or more of the IP address of the access source, the risk level of the IP address of the access source, etc. In the above, the OS version indicates a vulnerability in the access source device, and the behavioral abnormality level indicates the possibility of an attack. However, other elements of the access source device may be indicated as vulnerabilities in the access source device instead of (or in addition to) the OS version.

[0019] Specific examples of the various data (Object Attributes) of the destination include any one or more of the following: information about the destination's ID, information about the resource, the destination's address (e.g., IP address, web address, port number), information about the OS used by the destination device, and operation type. Information about the destination's ID includes any one or more of the destination's subsystem ID, resource ID, and the name of the resource ID owner. Information about the resource includes any one or more of the destination's organization (the organization that owns the resource), the type of resource requested, the creator, the creation date and time, and confidentiality. The confidentiality of a resource indicates the expected damage in the event of an attack. In the above, the OS version indicates a vulnerability in the destination device. However, other elements of the destination device may be indicated as vulnerabilities in the destination device instead of (or in addition to) the OS version.

[0020] Other specific examples of data indicating the nature of access include any one or more of the following: access history, frequency of requests from the access source ID to the resource ID, time of day (or time) of access, session key method, importance of the resource to the requesting subject, traffic level such as bandwidth usage, degree of network abnormality in access, traffic encryption strength, and various data related to authentication. Various data related to authentication include any one or more of various authentication methods (including, for example, information on authentication strength), device authentication results, application authentication results, various authentication times, and the number of various authentication failures. The importance of a resource to the requesting subject indicates usability regarding access, and bandwidth usage indicates the possibility of performance degradation when controlling multiple accesses. However, the elements listed above are merely examples, and elements indicating attributes are not limited to these.

[0021] In the present disclosure, "accessibility" is information indicating at least whether an action for access corresponds to authorization or denial, or the degree to which it corresponds to authorization or denial. For example, accessibility may be information indicating whether it corresponds to authorization or denial, or may be information indicating whether it corresponds to authorization, prohibition, or conditional authorization (additional authentication request). Accessibility may also be indicated as a numerical value within a predetermined range. In this case, a numerical value at one end of the predetermined range corresponds to authorization, a numerical value at the other end of the predetermined range corresponds to denial, and other numerical values indicate the degree of authorization or denial. However, the information indicated by "accessibility" is not limited to that shown above.

[0022] In this disclosure, "cost" refers to any constraint that arises in the operation of logs, such as time, capacity, or money. Examples of costs include the time required to acquire or refer to logs, the capacity required to store logs, or pay-per-use charges.

[0023] Embodiment 1 [Configuration Description] An example configuration of an information processing system will be described using Fig. 1. The information processing system 10 includes an attribute identification unit 11 and a selection unit 12, and each unit of the information processing system 10 is controlled by a hardware controller (not shown). Each unit of the information processing system 10 will be described below.

[0024] Based on the access control policy, the attribute specification unit 11 specifies the type of attribute (hereinafter referred to as the attribute type) used to determine whether or not access is permitted in the access control policy. That is, this attribute type is used in access control using the access control policy. The access control policy determines whether or not an access subject is permitted to access a resource. The access control policy may be, for example, a machine learning model or may be written on a rule basis. The attribute specification unit 11 may acquire the access control policy from either inside or outside the information processing system 10.

[0025] The attribute type may, for example, generally indicate a classification such as the above-mentioned "various data of the access source", "various data of the access destination", or "data indicating other access properties". Alternatively, as a subordinate concept, the attribute type may indicate the elements of the above specific examples of "various data of the access source", "various data of the access destination", or "data indicating other access properties".

[0026] The selection unit 12 selects the type of log (hereinafter referred to as the log type) necessary to derive the value of the attribute type specified by the attribute specification unit 11. Specific examples of the log type include any type of log such as a scan history, an EDR (Endpoint Detection and Response) log, an authentication history, and an access log.

[0027] In the selection, the selection unit 12 may select the log type corresponding to the attribute type specified by the attribute specification unit 11 by referring to, for example, a correspondence table in which the attribute type and the log type are associated. The correspondence table may be input by an administrator or the like, or may be automatically generated using machine learning or generative AI (Artificial Intelligence) or the like.

[0028] FIG. 2 shows an example of a correspondence table in which attribute types and log types are associated in a zero-trust architecture. Attribute type: For the vulnerability of the access source host, the usage log types: the logs of the agent installed on the host and the logs of the patch management server are associated. Attribute type: For the access history of the access source user and the access destination resource in the past X months, the usage log type: the access history of the server providing the resource in the past X months is associated. Attribute type: For the access history between the access source host and the access destination host in the past X months, the usage log types: the EDR logs of the access source host in the past X months, the EDR logs of the access destination host in the past X months, and the communication logs of the network devices on the path between the hosts in the past X months are associated. Attribute type: For the degree of abnormal behavior of the access source user, the logs of the authentication server (for example, directory, etc.) are associated. As an example, the selection unit 12 can select the log type corresponding to the attribute type specified by the attribute specifying unit 11 by referring to the correspondence table in FIG. 2.

[0029] As yet another example, the selection unit 12 may be implemented by a pre-trained AI model such as a neural network, a monotonic neural network, etc. This AI model is trained, for example, by inputting learning data including a plurality of sets of sample attribute types and information indicating the correct log types as correct labels. However, the generation engine may be implemented by an arbitrary algorithm instead of the AI model. As the algorithm, for example, probabilistic logic, fuzzy logic, linear regression, support vector machine, decision tree, monotonic regression, monotonic decision tree, etc. may be used.

[0030] Alternatively, instead of the correspondence table in which the attribute type and the log type are associated, a functional unit that outputs the log type according to the input attribute type may be provided. The selection unit 12 can select the log type corresponding to the attribute type specified by the attribute specifying unit 11 by using this functional unit.

[0031] Furthermore, the selection unit 12 may select additional information about the log related to the log type in order to further reduce the amount of log data required, as will be described in detail later.

[0032] [Flow description] 3 is a flowchart showing an example of a typical process of the information processing system 10, and this flowchart will be used to explain the process of the information processing system 10. Note that the details of each process are as described above, and therefore will not be explained again.

[0033] First, the attribute specification unit 11 specifies an attribute type used to determine whether or not access is permitted in the access control policy based on the access control policy (step S11: attribute specification step). Next, the selection unit 12 selects a log type required to derive the value of the attribute type specified by the attribute specification unit 11 (step S12: log type selection step).

[0034] [Effect description] As described above, the attribute specification unit 11 specifies the attribute type required in the access control policy, and the selection unit 12 selects the log type required to derive the value of the attribute type specified by the attribute specification unit 11. Therefore, the access control device does not need to operate logs other than the selected log when using the access control policy. Note that operation refers to any processing of data, such as acquiring, referencing, or storing data. Therefore, the information processing system 10 can reduce the costs incurred in operating logs.

[0035] The information processing system 10 may be configured as a single computer device, or may be configured as a distributed system having multiple computer devices configured to be able to communicate with each other. In a distributed system, the processing executed by the information processing system 10 can be shared and executed by multiple computer devices. In other words, the attribute identification unit 11 and the selection unit 12 may be distributed and installed on two or more computer devices.

[0036] As yet another example, some or all of the components of the information processing system 10 may be provided in a cloud server built on a cloud, or in other types of virtualized servers generated using virtualization technology, etc. Functions other than those provided in such servers are placed at the edge. For example, in a system that controls accessibility and selects communication paths at the access destination, the edge may be realized as a server device at the access destination.

[0037] In the following embodiments, specific examples of the information processing system described in embodiment 1 will be disclosed. However, the specific examples of the information processing system described in embodiment 1 are not limited to those shown below. Furthermore, the configurations and processes described below are merely examples and are not limited to these.

[0038] Embodiment 2 [Configuration Description] An example configuration of an information processing system will be described with reference to Fig. 4. The information processing system 20 includes an input unit 21, an attribute identification unit 22, a selection unit 23, a storage unit 24, and an output unit 25. Each unit of the information processing system 20 is controlled by a hardware controller (not shown).

[0039] The input unit 21 is configured with an input interface such as a touch panel, a keyboard, a mouse, etc. The administrator of the information processing system 20 operates the input unit 21 to input an access control policy to be processed.

[0040] The attribute specification unit 22 specifies the attribute type used for access control in the access control policy input from the input unit 21. For example, if the access control policy is written using an if then rule, the attribute specification unit 22 can specify the attribute type by listing the attributes that appear in this if statement. As another example, if the access control policy is expressed using a machine learning model, the attribute specification unit 22 can specify the attribute type required for access control by applying a method such as sensitivity analysis or SHAP (SHapley Additive exPlanations).

[0041] The selection unit 23 selects a log type required to derive a value of an attribute type based on the attribute type identified by the attribute identification unit 22. In this example, the selection unit 23 can select a log type according to the attribute type by referring to a correspondence table that indicates the relationship between the attribute type to be derived and the log type to be used for each attribute derivation method.

[0042] When identifying the log types, the selection unit 23 may finally select one or more log types from the identified log types that will reduce the required cost. Specifically, the selection unit 23 may derive log types whose required costs are within a predetermined rank in ascending order from the smallest to the largest, or may derive log types whose required costs are equal to or less than a predetermined threshold.

[0043] As another example, the selection unit 23 may finally select one or more log types using the accuracy required for the attribute used for access control. As one example, the selection unit 23 may derive one or more log types required from the viewpoint of the required accuracy, etc., using one or more parameters such as the required accuracy or reliability coefficient of the attribute that are separately provided.

[0044] Furthermore, the selection unit 23 may derive one or more log types by combining the above-described processes for both cost and accuracy.

[0045] The storage unit 24 stores a correspondence table to be referenced by the selection unit 23. The storage unit 24 may also store, as necessary, an input access control policy, information on a log selected by the selection unit 23, and the like.

[0046] 5A to 5D, the process in which the attribute specification unit 22 specifies the attribute type and the selection unit 23 selects the required log type based on the result will be described below.

[0047] 5A shows an example of an access control policy input from the input unit 21. In the access control policy, an action is executed to permit access when the conditions are met: user's job title == "management" and user's job title != "management" and the number of vulnerabilities in the host is less than 10. On the other hand, an action is executed to deny access under other conditions.

[0048] Fig. 5B shows an example of attribute types identified by the attribute identification unit 22. By analyzing the access control policy shown in Fig. 5A, the attribute identification unit 22 identifies the attribute types described in the conditions, "user's job title" and "number of vulnerabilities in the host," as attribute types to be used for access control, as shown in Fig. 5B.

[0049] 5C shows an example of a correspondence table showing the relationship between attribute types and log types stored in the storage unit 24. In the derivation methods 1 to 4, the following attribute types and log types are defined, respectively. (Derivation method 1) Attribute type to be derived: User's job title, Required log type: Device login history, Personnel information (Method 2) Attribute type to be derived: Host vulnerability, Required log type: Vulnerability scan information (Derivation method 3) Attribute type to be derived: User abnormality level, Required log type: Device operation history (Derivation method 4) Attribute type to be derived: Department to which the host belongs, Required log type: Asset ledger

[0050] FIG. 5D shows an example of the log type selected by the selection unit 23. The selection unit 23 refers to the correspondence table in FIG. 5C and selects the log types "Terminal login history", "Personnel information", and "Vulnerability scan information" corresponding to the attribute types "User's position" and "Number of host vulnerabilities" shown in FIG. 5B as shown in FIG. 5D.

[0051] Next, returning to FIG. 4, the description of the information processing system 20 will be continued. The output unit 25 outputs the log selected by the selection unit 23. For example, the output unit 25 may output the selected log by displaying it on a display unit or the like connected to the information processing system 20.

[0052] As another example, the output unit 25 may output an instruction to the PDP (Policy Decision Point) that determines the access control policy to judge whether access is permitted or not by deriving the access attribute using the selected log. Here, the PDP may derive the access attribute using the selected log when there is an access to be controlled, for example. Or, the PDP may set for the PEP (Policy Enforcement Point) what kind of access should be permitted or denied when there is a certain access based on the selected log. The PEP is, for example, a firewall device.

[0053] As yet another example, the output unit 25 may output an instruction to the PDP to use the method for deriving the attribute corresponding to the selected log and attribute. Alternatively, the output unit 25 may output an instruction to the log management system that manages the log to save the selected log. These examples will be described in detail below.

[0054] Next, with reference to FIGS. 6A to 6C, application examples of the information processing system 20 will be shown.

[0055] 6A shows a first example in which the information processing system 20 is applied. In step (1) in FIG. 6A, a user such as an administrator inputs an access control policy to the information processing system 20 using the input unit 21. In step (2), the information processing system 20 executes the above process based on the input access control policy, and the output unit 25 outputs the log to the display unit. In step (3), the user checks the displayed log and sets the log to be saved for access control in the log management system S1. In accordance with this setting, the log management system S1 can save the set logs among the logs generated during system operation, while deleting the logs that were not set.

[0056] Fig. 6B shows a second example in which the information processing system 20 is applied. In step (1) in Fig. 6B, a user such as an administrator uses the input unit 21 to input an access control policy to the information processing system 20 and the PDP. In step (2), the information processing system 20 executes the above-mentioned processing based on the input access control policy, and the output unit 25 outputs a log to the PDP. Here, the output unit 25 outputs the log used for access control to the PDP as an instruction.

[0057] The PDP includes an attribute estimation unit P11 and an approval / disapproval determination unit P12. When an access is made from an access source, the attribute estimation unit P11 references the log indicated by the instruction content from among past log data stored in a log database (DB). The log database stores logs about systems that are subject to access control (hereinafter also referred to as target systems). The attribute estimation unit P11 uses the referenced log to estimate the attributes of the access.

[0058] The authentication determination unit P12 determines whether to grant or deny access by applying the attributes estimated by the attribute estimation unit P11 to the access control policy input by the user using the input unit 21. In step (3), the authentication determination unit P12 sends the determination result to the PEP. The PEP is provided between the access source device and the target file F1, and controls whether access is permitted according to the determination result output by the authentication determination unit P12.

[0059] FIG. 6C shows a third example to which the information processing system 20 is applied. Regarding the description of the log management system S1, PDP, and PEP shown in FIG. 6C, the same description as that shown in FIGS. 6A and 6B will be omitted.

[0060] In step (1) in FIG. 6C, a user such as an administrator uses the input unit 21 to input an access control policy to the information processing system 20 and the PDP. In step (2), the information processing system 20 executes the above processing based on the input access control policy, and the output unit 25 outputs the log to the log management system S1. Here, the output unit 25 outputs, as an instruction, the log to be stored for use in access control to the log management system S1. In step (3), the log management system S1 acquires the necessary logs in the target system according to the instruction and stores them in the log DB. At this time, the log management system S1 does not necessarily store the logs that have not been instructed in the log DB.

[0061] As shown in FIG. 6B, the PDP includes an attribute estimation unit P11 and an authentication determination unit P12. In step (4), when there is an access from the access source, the attribute estimation unit P11 refers to the logs stored in the log DB. The attribute estimation unit P11 estimates the attributes of the access using the referred logs.

[0062] The authentication determination unit P12 determines whether to grant access by applying the attributes estimated by the attribute estimation unit P11 to the access control policy input by the user using the input unit 21. In step (5), the authentication determination unit P12 transmits the determination result to the PEP. The PEP controls whether access is permitted according to the determination result output by the authentication determination unit P12.

[0063] As described above, in each of the examples in FIGS. 6A to 6C, the destination to which the output unit 25 of the information processing system 20 outputs the log or the use of the log is different. However, at least any two of the application examples in FIGS. 6A to 6C may be combined and used. For example, assume a case where a user such as an administrator inputs an access control policy into the information processing system 20 using the input unit 21. At this time, the information processing system 20 can output the log used for access control as an instruction to the PDP (item (2) in FIG. 6B), and output the log to be stored for use in access control as an instruction to the log management system S1 (item (2) in FIG. 6C). Note that the application examples of the information processing system shown in FIGS. 6A to 6C can be similarly used in other embodiments. Also, the information processing system 20, the log management system S1, the PDP, and the PEP may belong to different systems or may constitute the same system.

[0064] [Description of Effects] By executing the above-described processing, the information processing system 20 can reduce the costs incurred in log operation for the reasons as shown in Embodiment 1.

[0065] Embodiment 3 In the following Embodiments 3 and 4, variations of the information processing system described in Embodiment 2 are disclosed. However, the variations of the information processing system shown in Embodiment 2 are not limited to those shown below.

[0066] [Description of Configuration] FIG. 7 shows a configuration example of an information processing system. The information processing system 30 includes an input unit 31, an attribute specifying unit 32, a selection unit 33, a storage unit 34, and an output unit 35 as components corresponding to those of the information processing system 20. Hereinafter, descriptions of points already described in Practical Form 2 will be omitted as appropriate.

[0067] Descriptions of the input unit 31 and the output unit 35 are omitted because they are the same as those of the input unit 21 and the output unit 25.

[0068] The attribute specifying unit 32 specifies the type of attribute to be used for access control in the access control policy input from the input unit 31. Here, the attribute specifying unit 32 specifies, for at least any one of each access subject, each resource, or a combination thereof, the type of attribute to be used for the access control to be estimated.

[0069] The selection unit 33 executes the following two processes. (i) For each type of attribute specified by the attribute specifying unit 32, the log type from which the type of attribute can be derived and the candidate for the acquisition location of the log type are specified by referring to the correspondence table stored in the storage unit 34. In the correspondence table, for each method of deriving an attribute, the type of attribute to be derived, the log type from which the type of attribute can be derived, and the candidate for the acquisition location are associated. (ii) Then, the selection unit 33 derives the final combination of the log types to be acquired based on the candidates for the acquisition locations of the specified log types. Note that the "acquisition location of the log type" indicates the range to which the log type applies (for example, the device to which the log type applies). Specific examples of the log type and its acquisition location will be described later in the description of FIG. 8C.

[0070] For example, the selection unit 33 may derive a combination such that at least any one of the log types to be acquired or their acquisition locations (hereinafter also referred to as log types, etc.) is reduced. Specifically, the selection unit 33 may derive a combination in which the number of log types, etc. is minimized based on the candidates for the acquisition locations of the specified log types, or may derive a combination in which the number of log types, etc. is equal to or less than a predetermined threshold value.

[0071] As another example, the selection unit 33 may derive a combination that reduces the cost required in the final combination of the log type and its acquisition location based on the candidates for the acquisition locations of the specified log types. Specifically, the selection unit 33 may derive a combination of the log type and its acquisition location that minimizes the cost required in the final combination of the log type and its acquisition location. Alternatively, the selection unit 33 may derive a combination of the log type and its acquisition location where the required cost is equal to or less than a predetermined threshold value.

[0072] Also, as another example, the selection unit 33 may calculate the log type and its acquisition location using the accuracy required for the attributes used for access control. As an example, the selection unit 33 may derive the log type and its acquisition location that are necessary from the perspective of the required accuracy or the like, using one or more parameters such as the required accuracy or the reliability coefficient of the attributes given separately.

[0073] Further, the selection unit 33 may derive the acquisition location of the log type by combining the above processes for both cost and accuracy.

[0074] The storage unit 34 stores a correspondence table in which, for at least any one of each access subject, each resource, or a combination thereof, a log type capable of deriving the attribute type thereof and the acquisition location of the log type are defined. However, instead of this correspondence table, a functional unit that outputs a log type according to the input attribute type may be provided for at least any one of each access subject, each resource, or a combination thereof. The selection unit 33 can select the log type corresponding to the attribute type specified by the attribute specifying unit 32 by using this functional unit.

[0075] Hereinafter, with reference to FIGS. 8A to 8E, a process in which the attribute specifying unit 32 specifies the attribute type and the selection unit 33 derives a required combination of log types according to the result will be shown.

[0076] FIG. 8A shows an example of an access control policy input from the input unit 31. In the access control policy, conditions and corresponding actions (permission or non - permission of access) are defined as follows. · Access from a host outside the IP (Internet Protocol) address range T ⇒ Not permitted · Other than the above, access from a host without vulnerabilities ⇒ Permitted for any resource · Other than the above, access from a host with vulnerabilities ⇒ Access is permitted if the abnormality level of the user is less than a certain value and the access destination is a resource with an access history in the past. · Other access ⇒ Not permitted

[0077] FIG. 8B shows an example of a set of attribute types to be estimated, specified by the attribute specifying unit 32. The set of attribute types is as follows. · Presence or absence of vulnerability of host A · Presence or absence of vulnerability of host B · … · Abnormality level of user C · Abnormality level of user D · … · Presence or absence of access history between host A and resource E · Presence or absence of access history between host A and resource F Note that FIG. 8B shows the case where the access is made from the IP address range T in FIG. 8A.

[0078] FIG. 8C shows an example of a correspondence table showing the relationship between the attribute types, log types, and their acquisition locations stored in the storage unit 34. In derivation methods 1 to 8, the following attribute types and log types are defined respectively. (Derivation method 1) Attribute type to be derived: Presence or absence of vulnerability of host A, Required log type and its acquisition location: Scan history of host A (Derivation method 2) Attribute type to be derived: Presence or absence of vulnerability of host A, Required log type and its acquisition location: EDR log of host A (Derivation method 3) Attribute type to be derived: Presence or absence of vulnerability of host B, Required log type and its acquisition location: Scan history of host B (Derivation Method 4) Attribute type to be derived: Presence or absence of vulnerability of Host B, required log type and its acquisition location: EDR log of Host B (Derivation Method 5) Attribute type to be derived: Degree of abnormality of User C, required log type and its acquisition location: Authentication history of User C (Derivation Method 6) Attribute type to be derived: Degree of abnormality of User D, required log type and its acquisition location: Authentication history of User D (Derivation Method 7) Attribute type to be derived: Presence or absence of access record between Host A and Resource E, required log type and its acquisition location: EDR log of Host A (Derivation Method 8) Attribute type to be derived: Presence or absence of access record between Host A and Resource E, required log type and its acquisition location: Access log of Resource E Here, the "required log type and its acquisition location: Scan history of Host A" in (Derivation Method 1) indicates that the log type is the scan history and the acquisition location is within the scope related to Host A. The same applies to the other Derivation Methods 2 to 8.

[0079] Figure 8D shows an example of the log type specified by the selection unit 33 and the candidates for the acquisition location of that log type in the above (i). The selection unit 33 specifies the information shown in Figure 8D by referring to the correspondence table shown in Figure 8C for each of the attribute types shown in Figure 8B. In Figure 8D, the following information is defined as the information on the log type and the candidates for its acquisition location. · Scan history of Host A · EDR log of Host A · Scan history of Host B · EDR log of Host B · Authentication history of User C · Authentication history of User D · EDR log of Host A · Access log of Resource E · EDR log of Host A · Access log of Resource F

[0080] FIG. 8E shows an example of the final combination of the log type and its acquisition location derived by the selection unit 33 based on the information shown in FIG. 8D in the above (ii). In FIG. 8E, the following content is defined as the information of the log type and its acquisition location. · EDR log of host A · EDR log of host B · Authentication history of user C · Authentication history of user D In this example, the selection unit 33 derives the information shown in FIG. 8E as a combination that minimizes the log type to be acquired based on the information shown in FIG. 8D.

[0081] Note that when the access is made from outside the IP address range T, access permission is set as an action, so the log for action control may not be stored. That is, in this case, the selection unit 33 does not need to obtain the information on the log type to be acquired.

[0082] Furthermore, for attributes that can be determined without referring to the log, the log for action control may not be stored. For example, as the attribute type, the network to which the access source host belongs and the network to which the access destination host belongs can be derived by the system by referring to the IP address or the like. Also, as the attribute type, the security level of the access destination resource can be derived by the system by referring to the label when the resource is labeled. In such cases, the selection unit 33 does not need to obtain the information on the log type to be acquired.

[0083] Hereinafter, specific examples of the processes (i) and (ii) of the attribute identification unit 32 will be further described. Generally, in step (i), the attribute identification unit 32 can convert the given access control policy into the following format. "Condition 1: (Condition 1_1 of attribute 1_1 and Condition 1_2 of attribute 1_2 and ··· Condition 1_m of attribute 1_m) Or Condition 2: (Condition 2_1 of Attribute 2_1 and Condition 2_2 of Attribute 2_2 and ··· Condition 2_n of Attribute 2_n) ··· Or Condition M: (Condition M_1 of Attribute M_1 and Condition M_2 of Attribute M_2 and ··· Condition M_o of Attribute M_o) is permitted when Here, M, m, n, and o are arbitrary natural numbers. Such a form is called the disjunctive normal form, and a method for converting any condition into this form is known. For example, the information processing system 30 represents, as a truth table, combinations of possible attribute values and the accessibility in each combination based on the access control policy. Then, for each combination of attribute values for which access is permitted in the truth table of the information processing system 30, the information processing system 30 expresses that each attribute takes that attribute value as a logical product, and further combines the logical products indicating those combinations with a logical sum to derive the form of the disjunctive normal form. However, the attribute specifying unit 32 may represent the given access control policy in the form of an arbitrary decision tree.

[0084] And the attribute specifying unit 32 executes the following processing for each of the above conditions A to M in step (ii). (iiA) Classify each attribute of each condition into an attribute Q that can be derived without using the log and an attribute R that is derived using the log. (iiB) Identify at least any one of the access subject, resource, or a combination thereof that satisfies the condition corresponding to attribute Q. (iiC) Add attribute R to the set of attributes to be estimated among the attributes for at least any one of the identified subject, resource, or a combination thereof.

[0085] Hereinafter, with reference to FIGS. 9A to 9D, an implementation example of the attribute specifying unit 32 will be further shown.

[0086] FIG. 9A shows an example of an access control policy input from the input unit 31. In the access control policy, a condition and a corresponding action (permission or non - permission of access) are defined as follows. · Access from a host with an IP address outside 192.168.1.0 / 24 ⇒ Not permitted · Access from a host without vulnerabilities, other than the above ⇒ Permitted for any resource · Access from a host with vulnerabilities, other than the above ⇒ If the abnormality level of the user is less than a certain value, access is permitted · Other access ⇒ Not permitted

[0087] Figure 9B shows an example in which the attribute identification unit 32 converts the access control policy of Figure 9A in the above step (i). The converted access control policy is shown in a format where access is permitted when either of the following (Condition A) or (Condition B) is satisfied. (Condition A) The IP address of the host belongs to outside 192.168.1.0 / 24 and The host has no vulnerability (Condition B) The IP address of the host belongs to outside 192.168.1.0 / 24 and The host has a vulnerability and The abnormality level of the user is less than a certain value

[0088] Figure 9C shows an example of the result in which the attribute identification unit 32 classifies each attribute of Condition A into an attribute that can be derived without using a log and an attribute that is derived using a log in the above step (ii). In Figure 9C, the following are defined. Attributes that can be derived without using a log ⇒ The IP address of the host Attributes derived using a log ⇒ The vulnerability of the host Also, although the description is omitted, the attribute identification unit 32 classifies each attribute of Condition B into an attribute that can be derived without using a log and an attribute that is derived using a log.

[0089] Fig. 9D shows an example of a set of attributes to be estimated, which are derived by the attribute specification unit 32 by performing the above (iiA) to (iiC) on the information in Fig. 9C. In Fig. 9D, the following are defined: Vulnerability of the host with IP address 192.168.1.1 Vulnerability of the host with IP address 192.168.1.2 … By doing so, the attribute specification unit 32 can reduce the number of attribute types to be specified and used for access control.

[0090] [Effect description] By performing the above-described processing, the information processing system 30 can reduce costs incurred in managing logs for the reasons described in the first embodiment. Furthermore, the information processing system 30 can identify log types required for access control by limiting the locations from which they are acquired. This makes it possible to further reduce the number of logs managed by the access control device, further enhancing the cost-reduction effect.

[0091] Embodiment 4 [Configuration Description] 10 shows an example of the configuration of an information processing system. The information processing system 40 includes, as components corresponding to the information processing system 20, an input unit 41, an attribute identification unit 42, a selection unit 43, a storage unit 44, and an output unit 45. Hereinafter, the points already explained in the second embodiment will be omitted as appropriate.

[0092] The explanation of the input unit 41, the attribute specification unit 42 and the output unit 45 is omitted because they are the same as the input unit 21, the attribute specification unit 22 and the output unit 25.

[0093] The selection unit 43 selects not only a log type required to derive a value of the attribute type based on the attribute type identified by the attribute identification unit 42, but also a period required for managing the log related to the log type (hereinafter also referred to as a required period). Here, the required period may be expressed as a length of time or as the number of times the log is managed (for example, referenced).

[0094] As a first example, the correspondence table stored in the storage unit 44 may define not only the relationship between the attribute type to be derived and the log type to be used, but also the period of the log required to derive the attribute type to be derived as the required period. In other words, the correspondence table stored in the storage unit 44 associates information on the attribute type, the log type to be used, and the required period. The selection unit 43 can select the required period by referring to the correspondence table.

[0095] Furthermore, the selection unit 43 may derive a combination of log types and their required periods that will reduce the required cost. Specifically, the selection unit 43 may derive a combination of log types and their required periods that will minimize the required cost. Alternatively, the selection unit 43 may derive a combination of log types and their required periods that will reduce the required cost to a predetermined threshold or less.

[0096] As a second example, the selection unit 43 may statistically calculate the log type and its required period using the accuracy required for the attribute used in access control. As an example, the selection unit 43 may determine the required number of samples using one or more parameters such as the required accuracy or reliability coefficient of the attribute that are separately provided, and derive the log period required to ensure the number of samples as the required period for the log type. The information processing system 40 may or may not have samples.

[0097] Furthermore, the selection unit 43 may derive the necessary period by combining the first example and the second example.

[0098] 11 shows an example of the correspondence table stored in the storage unit 44. In the derivation methods 1 to 3, the following attribute types, log types, and required periods are defined, respectively. (Method 1) Attribute type to be derived: Host vulnerability, Required log type: Vulnerability scan information, Required period: Last scan (Method 2) Attribute type to be derived: Host vulnerability, Required log type: Host EDR log, Required period: Last 6 months (Derivation Method 3) Attribute type to be derived: Access performance between hosts and resources in the past three months, Required log type: EDR logs of hosts, Required period: The most recent three months

[0099] [Description of the effect] By executing the above-described processing, the information processing system 40 can reduce the costs incurred in log operation for the reasons as shown in Embodiment 1. Furthermore, the information processing system 40 can limit and specify the required period for access control. As a result, it becomes possible to further reduce the logs operated by the access control device, and the effect of cost reduction can be further enhanced.

[0100] For example, in the example of FIG. 6C, in step (2), the output unit 25 outputs, as an instruction to the log management system S1, the logs to be stored for use in access control and the required period thereof. In step (3), the log management system S1 stores, in accordance with the instruction, the required logs in the target system in the log DB. At this time, when the required period regarding the instructed log type has elapsed, the log management system S1 deletes the logs related to that log type stored in the log DB. As a result, unnecessary logs are deleted, and costs can be reduced.

[0101] Embodiment 5 Furthermore, the information processing systems in Embodiments 2 to 4 can further execute the following processing. Hereinafter, the information processing system 20 of Embodiment 2 will be exemplified to explain the processing, but the same processing can also be realized by the information processing system 30 of Embodiment 3 and the information processing system 40 of Embodiment 4.

[0102] As described above, the correspondence table stored in the storage unit 24 shows the relationship between the attribute type to be derived and the required log type. Then, the selection unit 23 selects the log type corresponding to the attribute type for each attribute derivation method by referring to the correspondence table.

[0103] (A) At this time, if the selection unit 23 finds, as a result of referring to the correspondence table, multiple derivation methods capable of deriving the same attribute type (i.e., the required log type), it may adopt one derivation method from the multiple derivation methods that satisfies a predetermined cost condition. For example, the selection unit 23 may adopt, from the multiple log types, a log type with the smallest cost, or a log type with a cost equal to or less than a predetermined threshold. Here, the selection unit 23 may select one log type by referring to a table (hereinafter also referred to as Table 1) in which the log types and the costs corresponding to the log types are defined for each log type, and performing the above-mentioned determination process.

[0104] (B) Furthermore, when the selection unit 23 finds, as a result of referring to the correspondence table, multiple derivation methods capable of deriving the same attribute type, it may adopt one derivation method that satisfies a predetermined accuracy condition from among the multiple derivation methods. For example, the selection unit 23 may adopt, from among the multiple log types, a log type with the highest accuracy, or a log type with accuracy equal to or greater than a predetermined threshold. Here, the selection unit 23 may select one log type by referring to a table (hereinafter also referred to as Table 2) in which the log types and the corresponding accuracies are defined for each log type, and performing the above-mentioned determination process.

[0105] (C) Furthermore, when the selection unit 23 finds, as a result of referring to the correspondence table, multiple derivation methods capable of deriving the same attribute type, it may adopt from the multiple derivation methods a derivation method that satisfies the cost and accuracy conditions. For example, the selection unit 23 may adopt, from among the multiple log types, a log type with the highest accuracy among those whose costs are equal to or less than a predetermined threshold. Alternatively, the selection unit 23 may adopt, from among the multiple log types, a log type with the lowest cost among those whose accuracy is equal to or less than a predetermined threshold. Here, the selection unit 23 may select one log type by referring to Table 1 and Table 2 and performing the above-mentioned determination process.

[0106] The threshold values used in the above determinations (A) to (C) may be set by an administrator or the like. Also, the costs of the log types defined in Table 1 and Table 2 may be defined as different values or the same values for at least any one of each access subject, each resource, or a combination thereof.

[0107] At least one of Table 1 or Table 2 may be implemented by a pre-trained AI model. For example, instead of Table 1, an AI model may be set by inputting learning data including a plurality of sets of sample log types and information indicating the cost as the correct label. Also, instead of Table 2, an AI model may be set by inputting learning data including a plurality of sets of sample log types and information indicating the accuracy as the correct label. However, any algorithm other than the AI model may be used as an alternative to Table 1 or Table 2.

[0108] Furthermore, even for the same attribute type, the selection unit 23 may select different or the same ones among at least any one of the log type, the log acquisition location, or the log required period for at least any one of each access subject, each resource, or a combination thereof. For example, even when the selection unit 23 derives "host vulnerability" as the attribute type, it is possible to change the selected log type as follows according to the nature of the host. · Vulnerability information of hosts with UEM (Unified Endpoint Management) installed: Select the information collected by UEM as the log type · Vulnerability information of other hosts: Select the log of the patch distribution server as the log type

[0109] Furthermore, if, as a result of referring to the correspondence table, it is determined that a log type necessary for deriving a certain attribute type does not exist, the selection unit 23 may notify an administrator or the like of this fact. For example, a notification unit configured with either a display unit, a speaker, or the like is connected to the information processing system 20, and the selection unit 23 may output information indicating that a necessary log type does not exist to the notification unit. The notification unit notifies the administrator or the like of the information by executing either a screen display, a voice output, or the like.

[0110] The log type may be defined for each module that outputs a log (for example, an event log), or may be defined by a label (for example, an event ID) assigned to each log or by a log level (for example, error, warning, debug, etc.).

[0111] The above-described process can be similarly executed even when there is no correspondence table and the relationship between attribute types and log types is defined using an AI model or the like.

[0112] In the above-described embodiments, the present disclosure has been described as a hardware configuration, but the present disclosure is not limited to this. The present disclosure can also be realized by causing a processor in a computer to execute a computer program to perform the processing of each device constituting the information processing system described in each of the above-described embodiments.

[0113] 12 is a block diagram showing an example of the hardware configuration of an information processing device (i.e., a computer) that executes the processing of the system or device described in each embodiment. Referring to FIG. 12, an information processing device 90 includes a signal processing circuit 91, a processor 92, and a memory 93.

[0114] The signal processing circuit 91 is a circuit for processing signals in accordance with the control of the processor 92. The signal processing circuit 91 may include a communication circuit for receiving signals from a transmitting device.

[0115] The processor 92 is connected to the memory 93, and performs the processing of the device described in the above embodiment by reading and executing a computer program from the memory 93. As an example of the processor 92, one of a CPU (Central Processing Unit), an MPU (Micro Processing Unit), an FPGA (Field-Programmable Gate Array), a DSP (Demand-Side Platform), and an ASIC (Application Specific Integrated Circuit) may be used, or a plurality of these may be used in parallel.

[0116] The memory 93 is configured with a volatile memory, a nonvolatile memory, or a combination thereof. The memory 93 is not limited to one, and multiple memories may be provided. The volatile memory may be, for example, a RAM (Random Access Memory) such as a DRAM (Dynamic Random Access Memory) or an SRAM (Static Random Access Memory). The nonvolatile memory may be, for example, a ROM (Read Only Memory) such as a PROM (Programmable Random Only Memory) or an EPROM (Erasable Programmable Read Only Memory), a flash memory, or an SSD (Solid State Drive).

[0117] The memory 93 is used to store one or more instructions. Here, the one or more instructions are stored as programs in the memory 93. The processor 92 can perform the processes described in the above embodiments by reading and executing these programs from the memory 93.

[0118] The memory 93 may include memory built into the processor 92 in addition to memory provided outside the processor 92. The memory 93 may also include storage located away from the processors constituting the processor 92. In this case, the processor 92 can access the memory 93 via an I / O (Input / Output) interface.

[0119] As described above, one or more processors included in each information processing system in the above-described embodiments execute one or more programs including instructions for causing a computer to execute the algorithms described using the drawings. Execution of the programs enables the information processing described in each embodiment to be realized.

[0120] The program includes instructions or software code that, when loaded into a computer, causes the computer to perform one or more functions described in the embodiments. The program may be stored in a non-transitory computer-readable medium or a tangible storage medium. By way of example and not limitation, computer-readable media or tangible storage media include random-access memory (RAM), read-only memory (ROM), flash memory, solid-state drive (SSD) or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disk (DVD), Blu-ray disc or other optical disk storage, magnetic cassette, magnetic tape, magnetic disk storage or other magnetic storage devices. The program may also be transmitted on a transitory computer-readable medium or communication medium. By way of example and not limitation, transitory computer-readable media or communication media include electrical, optical, acoustic, or other forms of propagated signals. The transitory computer-readable medium or communication medium may provide the program to the computer via a wired communication path, such as electrical wires and optical fibers, or via a wireless communication path.

[0121] Some or all of the above embodiments may be described as follows, but are not limited thereto. (Appendix 1) An attribute specifying unit that specifies an access attribute type used to determine access permission in the access control policy based on the access control policy, and A selection unit that selects a log type necessary for deriving the value of the access attribute type specified by the attribute specifying unit. An information processing system. (Appendix 2) The selection unit further selects an acquisition location of the log related to the log type. The information processing system according to Appendix 1. (Appendix 3) The selection unit further selects a period required for the operation of the log related to the log type. The information processing system according to Appendix 1 or 2. (Appendix 4) The selection unit selects the log type based on the cost required for the operation of the log related to the log type. The information processing system according to any one of Appendices 1 to 3. [[ID= {27]] (Appendix 5) The selection unit selects the log type and the acquisition location based on the cost required for the operation of the log related to the log type. The information processing system according to Appendix 2. (Appendix 6) The selection unit selects the log type and the required period based on the cost required for the operation of the log related to the log type. The information processing system according to Appendix 3. (Appendix 7) The selection unit selects the log type based on the accuracy required for the log related to the log type. The information processing system according to any one of Appendices 1 to 6. (Appendix 8) The selection unit selects the log type and the acquisition location based on the accuracy required for the log related to the log type. The information processing system according to Appendix 2. (Appendix 9) the selection unit selects the log type and the required period based on accuracy required for the log related to the log type; 10. The information processing system of claim 3. (Appendix 10) an output unit that outputs an instruction to acquire a log related to the log type selected by the selection unit, An information processing system according to any one of appendices 1 to 9. (Appendix 11) an output unit that outputs an instruction to perform access control using the log related to the log type selected by the selection unit, An information processing system according to any one of appendices 1 to 10. (Appendix 12) the attribute specification unit specifies a host that is a target of access history information used in the access control policy based on the access control policy; the selection unit identifies the log of the host identified by the attribute identification unit as a log necessary for access control; 12. An information processing system according to any one of claims 1 to 11. (Appendix 13) Identifying an access attribute type used to determine whether or not to allow access based on the access control policy; selecting a log type necessary to derive the value of the identified access attribute type; A computer-implemented information processing method. (Appendix 14) Identifying an access attribute type used to determine whether or not to allow access based on the access control policy; selecting a log type necessary to derive the value of the identified access attribute type; A program that makes a computer do something.

[0122] Some or all of the elements (e.g., configurations and functions) described in Supplementary Notes 2 to 12 that are dependent on Supplementary Note 1 may also be dependent on Supplementary Notes 13 and 14 in the same dependency relationship as Supplementary Notes 2 to 12. Some or all of the elements described in any Supplementary Note may be applied to various hardware, software, recording means for recording software, systems, and methods.

[0123] Although the present disclosure has been described above with reference to the embodiments, the present disclosure is not limited to the above-described embodiments. Various modifications that can be understood by those skilled in the art can be made to the configuration and details of the present disclosure within the scope of the present disclosure. Furthermore, each embodiment can be combined with other embodiments as appropriate. [Explanation of symbols]

[0124] 10 Information Processing Systems 11 Attribute identification section 12 Selection section 20 Information Processing Systems 21 Input section 22 Attribute specification section 23 Selection section 24 Storage section 25 Output section 30 Information Processing Systems 31 Input section 32 Attribute specification section 33 Selection section 34 Storage section 35 Output section 40 Information Processing Systems 41 Input section 42 Attribute specification section 43 Selection section 44 Storage section 45 Output section

Claims

1. An attribute specifying unit that specifies an access attribute type used to determine access permission in the access control policy based on the access control policy, and A selection unit that selects a log type necessary for deriving the value of the access attribute type specified by the attribute specifying unit, An information processing system.

2. The selection unit further selects an acquisition location of a log related to the log type, The information processing system according to claim 1.

3. The selection unit further selects a period required for the operation of a log related to the log type, The information processing system according to claim 1.

4. The selection unit selects the log type based on the cost required for the operation of a log related to the log type, The information processing system according to claim 1 or 2.

5. The selection unit selects the log type based on the accuracy required for a log related to the log type, The information processing system according to claim 1 or 2.

6. The information processing system according to claim 1 or 2, further comprising an output unit that outputs an instruction to acquire a log related to the log type selected by the selection unit. The information processing system according to claim 1 or 2.

7. The information processing system according to claim 1 or 2, further comprising an output unit that outputs an instruction to perform access control using a log related to the log type selected by the selection unit. The information processing system according to claim 1 or 2.

8. The attribute specifying unit specifies a host targeted by access performance information used in the access control policy based on the access control policy, The selection unit specifies the log of the host specified by the attribute specifying unit as a log necessary for access control, The information processing system according to claim 1 or 2.

9. Specify the access attribute type used to determine access permission in the access control policy based on the access control policy, Select the log type necessary for deriving the value of the specified access attribute type, An information processing method executed by a computer.

10. Specify the access attribute type used to determine access permission in the access control policy based on the access control policy, Select the log type necessary for deriving the value of the specified access attribute type, A program that causes a computer to execute this.

Citation Information

Patent Citations

  • Method of and apparatus for measuring thermal expansion

    JP1978036262A