Information processing device and information processing method
The information processing apparatus simplifies the scanning of hierarchized resources in cloud services by propagating roles from a topmost authority account, allowing efficient detection of vulnerabilities in system environments.
Patent Information
- Application Number
- JP2024059828
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-04-02
- Publication Date
- 2025-08-01
AI Technical Summary
Scanning a system environment associated with hierarchized resources in cloud services is complicated and inefficient, making it difficult to detect vulnerable information.
An information processing apparatus and method that utilize a specific account with authority to operate at the topmost root of hierarchical resources, acquiring asset information, and identifying vulnerability information by propagating roles to lower-level resources using a configuration management tool.
Enables easy and efficient scanning of system environments with hierarchized resources by granting roles to lower-level resources, facilitating the detection of vulnerabilities.
Smart Images

Figure 2025113109000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to an information processing apparatus and an information processing method.
Background Art
[0002] Conventionally, a technique for detecting vulnerable information possessed by software has been known (for example, Patent Document 1).
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] By the way, in the cloud, cloud services that can use resources and assets such as virtual machines are also known. When an organization or the like uses such a cloud service, the resources to be used may be hierarchized. However, it may be complicated to scan the system environment associated with such hierarchized resources or detect vulnerable information.
[0005] Therefore, the present invention has been made to solve the above-described problems, and an object thereof is to provide an information processing apparatus and an information processing method that enable easy execution of scanning a system environment associated with hierarchized resources.
Means for Solving the Problems
[0006] In a target system having a system environment associated with hierarchical resources, based on a role propagated to resources at a predetermined level using a specific account having the authority to operate on the topmost root of the hierarchical resources, an acquisition unit that acquires asset information of the system environment associated with the resources at the predetermined level, and a control unit that identifies vulnerability information of the system environment associated with the resources at the predetermined level based on the asset information acquired by the acquisition unit. The acquisition unit acquires the authority to scan the system environment associated with the resources at the predetermined level by granting the role to the resources at the predetermined level. The resources at the predetermined level are information processing devices that are resources at a lower level than the root among the hierarchical resources.
[0007] In a target system having a system environment associated with hierarchical resources, based on a role propagated to resources at a predetermined level using a specific account having the authority to operate on the topmost root of the hierarchical resources, step A of acquiring asset information of the system environment associated with the resources at the predetermined level, step B of identifying vulnerability information of the system environment associated with the resources at the predetermined level based on the asset information acquired in step A, and step C of acquiring the authority to scan the system environment associated with the resources at the predetermined level by granting the role to the resources at the predetermined level. The resources at the predetermined level are information processing devices that are resources at a lower level than the root among the hierarchical resources, and this is an information processing method.
Effect of the Invention
[0008] According to the present invention, it is possible to provide an information processing apparatus and an information processing method that enable easy execution of scanning of a system environment associated with hierarchical resources.
Brief Description of the Drawings
[0009]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
DETAILED DESCRIPTION OF THE INVENTION
[0010] Hereinafter, embodiments will be described with reference to the drawings. In the following description of the drawings, the same or similar parts are denoted by the same or similar reference numerals.
[0011] However, it should be noted that the drawings are schematic, and the ratios of the dimensions and the like may be different from the actual ones. Therefore, specific dimensions and the like should be determined with reference to the following description. Of course, there may be portions where the relationships or ratios of the dimensions are different between the drawings.
[0012] [SUMMARY OF THE DISCLOSURE] In a target system having a system environment associated with hierarchical resources, based on a role propagated to resources at a predetermined level using a specific account having the authority to operate on the topmost root of the hierarchical resources, an acquisition unit that acquires asset information of the system environment associated with the resources at the predetermined level, and a control unit that identifies vulnerability information of the system environment associated with the resources at the predetermined level based on the asset information acquired by the acquisition unit. The acquisition unit acquires the authority to scan the system environment associated with the resources at the predetermined level by granting the role to the resources at the predetermined level. The resources at the predetermined level are resources at a lower level than the root among the hierarchical resources, and it is an information processing apparatus.
[0013] In a target system having a system environment associated with hierarchical resources, based on a role propagated to resources at a predetermined level using a specific account having the authority to operate on the topmost root of the hierarchical resources, step A of acquiring asset information of the system environment associated with the resources at the predetermined level, step B of identifying vulnerability information of the system environment associated with the resources at the predetermined level based on the asset information acquired in step A, and step C of acquiring the authority to scan the system environment associated with the resources at the predetermined level by granting the role to the resources at the predetermined level. The resources at the predetermined level are resources at a lower level than the root among the hierarchical resources, and it is an information processing method.
[0014] In the summary of the disclosure, the information processing apparatus acquires the authority to scan a system environment associated with resources at a predetermined hierarchy by granting a role that propagates to resources at the predetermined hierarchy using a specific account having the authority to operate the root, acquires asset information of the system environment associated with resources at the predetermined hierarchy based on the role that propagates to resources at the predetermined hierarchy, and identifies vulnerability information of the system environment associated with resources at the predetermined hierarchy based on the acquired asset information. According to such a configuration, by using a specific account having the authority to operate the root, since the role propagates to resources at the predetermined hierarchy, it is possible to easily execute scanning of the system environment associated with the hierarchical resources.
[0015] [Embodiment] (Information Processing System) Hereinafter, the information processing system according to the embodiment will be described. FIG. 1 is a diagram showing an information processing system 100 according to the embodiment.
[0016] As shown in FIG. 1, the information processing system 100 includes an information processing apparatus 10, a terminal 20, a system server 30, and a vulnerability server 40. The information processing apparatus 10, the terminal 20, the system server 30, and the vulnerability server 40 are connected by a network 200. Although not particularly limited, the network 200 may be configured by the Internet. The network 200 may include a local area network, may include a mobile communication network, and may include a VPN (Virtual Private Network).
[0017] The information processing apparatus 10 is an apparatus that scans, identifies, or manages software asset information and vulnerability information, and may be referred to as a vulnerability diagnosis apparatus. The information processing apparatus 10 may be provided by a provider of a service that scans, identifies, or manages vulnerability information and used by a user of the service. The software may be software that operates on the system server 30. Hereinafter, a system composed of software that is a target for scanning asset information may be referred to as a target system. The target system may be a system including one or more software. The one or more software may include OSS (Open Source Software). Details of the information processing apparatus 10 will be described later.
[0018] The terminal 20 is a terminal used by an administrator who manages the vulnerability of the target system. The terminal 20 may be a personal computer, a smartphone, or a tablet terminal. The terminal 20 may have a display unit 21. The display unit 21 may be composed of a display such as a liquid crystal panel, an organic EL (Electroluminescence) panel, or an LED (Light Emitting Diode).
[0019] The system server 30 is one or more servers (cloud servers) provided on the network 200 and is a server that constructs a target system in the cloud. The target system may be realized on a virtual server in a cloud computing environment. The cloud computing environment may be realized on a cloud platform provided by a cloud service provider. The cloud platform may be a platform that can use services such as a database, storage, and an application via the Internet. For example, the cloud platform may be Microsoft Azure (registered trademark) or the like.
[0020] Here, the target system is a system having a system environment associated with hierarchical resources. Hierarchical means that a plurality of resources constitute a hierarchical structure (hereinafter, a tree structure). Hierarchical means a relationship in which resources are nodes and the upper and lower levels of the nodes are defined. For example, hierarchical may mean a relationship in which there is a higher-level resource that bundles lower-level resources. Also, the resource (node) located at the topmost level that bundles a plurality of lower-level resources may be referred to as a root. The root may be referred to as an organization, a group, or an administrative group. Here, the root is a convergence point (root node) of the tree structure and is a top-level node (uppermost node) of the tree structure. That is, the tree structure starts branching from the root, and a plurality of lower-level resources hang from the root.
[0021] Resources located at the lowest level of the tree structure may be referred to as member accounts or projects. Member accounts or projects may be referred to as subscriptions or tenants, and hereinafter, these are collectively referred to as member accounts. A member account is a resource that can configure a system environment and associate assets to be used, and is distinguished from a user account composed of user identification information. Also, a resource that bundles a plurality of member accounts may be provided between the root located at the topmost level and the member account located at the lowest level. A resource that bundles a plurality of member accounts may be referred to as a unit. A unit may be referred to as a folder or a directory. That is, the tree structure is a structure having levels (hierarchies) of the root (organization or group) level, the unit (folder or directory) level, and the member account (subscription or project) level from top to bottom. Also, the member account may be an account created on a cloud computing environment other than the management account described later.
[0022] Specifically, in an organization such as a company, the stratification may include a mode of bundling a plurality of member accounts in units such as departments, and further bundling several department units in a root of a higher-level organization. According to such a configuration, a plurality of member accounts belonging to the organization can be bundled in units such as departments and efficiently managed centrally.
[0023] The vulnerability server 40 is an external server that manages software vulnerability information. The vulnerability server 40 may be composed of one or more servers. One or more vulnerability servers 40 may include a server connected to one or more external vulnerability information websites (databases) selected from external vulnerability information websites (databases) such as NVD (National Vulnerability Database), ICAT (IPA Cyber security Alert Service) Metabase, JVN (Japan Vulnerability Notes), JVN iPedia, and OSVDB (Open Source Vulnerability Database). One or more vulnerability servers 40 may include a server (for example, a security advisor) that stores the company's own vulnerability information provided independently by a software supplier.
[0024] (Information processing apparatus) Hereinafter, the information processing apparatus 10 according to the embodiment will be described. FIG. 2 is a diagram showing the information processing apparatus 10 according to the embodiment.
[0025] As shown in FIG. 2, the information processing apparatus 10 includes a transmission unit 11, a reception unit 12, a storage unit 13, and a control unit 14.
[0026] The transmission unit 11 may be composed of a communication module. The communication module may be a wireless communication module compliant with standards such as IEEE802.11a / b / g / n / ac / ax, LTE, 5G, and 6G, or may be a wired communication module compliant with standards such as IEEE802.3.
[0027] The transmission unit 11 may transmit a scan request for requesting a scan of resources to the system server 30. When the information processing apparatus 10 has acquired the right to scan resources, the target system permits the scan request from the transmission unit 11 (information processing apparatus 10). Each resource associated with the target system is provided with a role for assigning the right to scan resources to the transmission unit 11 (information processing apparatus 10) (that is, a role for permitting a scan request from the transmission unit 11 (information processing apparatus 10)), and in this case, transmits a scan response capable of specifying the asset information of the system environment associated with the resource to the information processing apparatus 10. The role includes a definition for permitting the information processing apparatus 10 to scan the system environment associated with the resource. Here, the role defines who has what kind of right with respect to the resource, and may be referred to as a policy. For example, the role defines that the right to scan the system environment associated with the resource is assigned to the user account for scanning associated with the user of the information processing apparatus 10. Thereby, the information processing apparatus 10 acquires the right to scan resources. Here, the acquisition of the scan right by the information processing apparatus 10 may refer to assigning a role for permitting the scan by the information processing apparatus 10 to the resource.
[0028] Here, the role is propagated to the resources at a predetermined layer of the hierarchical resources using a specific account having the right to operate the root located at the top layer of the hierarchical resources. The resources at the predetermined layer may include resources (member accounts) located at the bottom layer of the tree structure. At least the member accounts are associated with the system environment to be scanned by the information processing apparatus 10. Note that the method of propagating the role will be described later (see FIGS. 3 to 6).
[0029] The receiving unit 12 may be composed of a communication module. The communication module may be a wireless communication module compliant with standards such as IEEE802.11a / b / g / n / ac / ax, LTE, 5G, 6G, etc., or may be a wired communication module compliant with standards such as IEEE802.3.
[0030] In response to a scan request, the receiving unit 12 receives a scan response from the system server 30 (a resource with a role assigned) that can identify the asset information of the system environment.
[0031] Here, the asset includes all system environments, entities, and services that can be managed on the cloud platform, and may include, for example, virtual machines, virtual networks, storage accounts, web applications, databases, etc. The asset may include policies and roles assigned by IAM (Identity and Access Management), etc.
[0032] The asset information may include an application library, a host, a container image, etc.
[0033] The application library may be a set of applications included in the system environment. The application library may include the names and versions of the applications. The application may be read as software or as a program.
[0034] The host may include the name and configuration of the device (terminal, router, server, etc.) that constructs the system environment. The host may include the name of the account associated with the system environment.
[0035] The container image may be an image generated by building a container file. A container may be generated by running a container image. The container may include middleware (MW) and an application provided on the middleware, on the premise that an OS is provided on a physical server and a container engine is provided on the OS. The container image may include the name and version of the application. The application may be read as software or as a program.
[0036] The storage unit 13 is composed of a storage medium such as an SSD (Solid State Drive) or an HDD (Hard Disk Drive), and stores various information.
[0037] First, the storage unit 13 stores a predetermined file (hereinafter referred to as a template) used for role propagation by a configuration management tool that manages the configuration of the target system. Role propagation may be role assignment and replacement. Here, role propagation means that a role that is valid when assigned to a specific resource is inherited and assigned to a resource located in the lower hierarchy of that resource and becomes valid. A template is a file that describes in code resources such as roles created on a cloud computing environment by a configuration management tool, and is a design document for resources. The resources created by the template may be referred to as stacks.
[0038] The configuration management tool is a tool that cooperates with a system in a cloud computing environment and automatically constructs resources such as roles for that system using a template, and may be referred to as an orchestrator. The template is composed of a text file in JSON format or YAML format, and the configuration information of the resources to be constructed may be described in code. The resources constructed by the configuration management tool may include at least a role (for example, Read Only by the information processing apparatus 10) that permits the information processing apparatus 10 to scan the system environment associated with the resources. In other words, the template may include a description regarding a role that assigns to the information processing apparatus 10 the authority to scan the system environment associated with the resources.
[0039] Roles are managed by IAM and may be assigned to resources such as member accounts. IAM assigns to the resources a role that permits the information processing apparatus 10 to perform the processing necessary for vulnerability scanning by the information processing apparatus 10. Thereby, the information processing apparatus 10 can execute the processing necessary for vulnerability scanning of the target system by cooperating with the target system. That is, when the information processing apparatus 10 transmits a scan request, the scan request is permitted based on the role assigned to the resources, so that the asset information of the system environment associated with the resources can be obtained.
[0040] Although not particularly limited, IAM is a function that assigns operation authorities (roles) of resources to cloud services and applications, and is a function capable of assigning the authority to permit scanning of the system environment associated with the resources. The roles assigned by IAM may not include authorities such as creation of resources, deletion of resources, confirmation of billing information regarding the target system, and acquisition of the structure of resources.
[0041] Second, the storage unit 13 stores identification information for identifying the role assigned to the resource. The identification information may be acquired from the system server 30. The identification information for identifying the role may be any name or symbol that can uniquely identify the role, such as a resource name or a resource ID, and is acquired from the second target system. In addition to the identification information for identifying the role, the storage unit 13 may store a scan credential issued from the target system and a user account (scan user account) used for scanning. The propagation of the role in the target system and the storage of the identification information for identifying the role may mean the cooperation between the information processing apparatus 10 and the target system. By the cooperation between the information processing apparatus 10 and the target system, the information processing apparatus 10 can scan the system environment associated with the resource to which the role is assigned, using the scan user account. The cooperation may be API cooperation, as described in Modification Example 1 below.
[0042] Third, the storage unit 13 stores a vulnerability database (hereinafter, vulnerability DB) that stores vulnerability information in association with at least a part of the information included in the asset information (for example, the name of software, etc.). The vulnerability DB may store information based on the vulnerability information received from the vulnerability server 40. The vulnerability DB may store information obtained by extracting various information from the vulnerability information received from the vulnerability server 40. Further, the vulnerability DB may store information input and registered by the user himself / herself from other websites such as security-related news sites and blogs, and may modify the vulnerability information acquired from the vulnerability server 40. Thereby, it is possible to collect information not published on external vulnerability information websites such as NVD and accumulate it in the vulnerability DB, and even if the information on the vulnerability information site is incorrect due to misinformation or the like, correct information can be accumulated in the vulnerability DB.
[0043] The control unit 14 may include at least one processor. The at least one processor may be constituted by a CPU (Central Processing Unit), an MPU (Micro Processing Unit), a GPU (Graphics Processing Unit), one or more Integrated Circuits, one or more Discrete Circuits, and combinations thereof.
[0044] The control unit 14 identifies vulnerability information of the system environment associated with resources of a predetermined hierarchy based on the asset information acquired from the system server 30 (resources with roles assigned). Here, the control unit 14 may identify vulnerability information of the system environment associated with resources of a predetermined hierarchy based on the vulnerability information stored in the storage unit 13 (vulnerability DB).
[0045] As described above, the asset information may include an application library, a host, a container image, and the like. Therefore, based on the asset information, the vulnerability information of the system environment can be identified.
[0046] In an embodiment, the receiving unit 12 and the control unit 14 may constitute an acquisition unit that acquires asset information of a system environment associated with a resource at a predetermined level based on a role propagated to the resource at the predetermined level using a specific account having the authority to operate the top root of the hierarchical resource in a target system having a system environment associated with the hierarchical resource. The receiving unit 12 and the control unit 14 acquire the authority to scan the system environment associated with the resource at the predetermined level by granting a role to the resource at the predetermined level. The control unit 14 may constitute a control unit that identifies vulnerability information of a system environment associated with a resource at a predetermined level based on the asset information acquired by the acquisition unit. The storage unit 13 may constitute a storage unit that stores a template used for role propagation by a configuration management tool. The storage unit 13 may constitute a storage unit that stores identification information for identifying a role assigned by a configuration management tool.
[0047] (Operation Example 1) Hereinafter, Operation Example 1 according to the embodiment will be described. In Operation Example 1, a case where the target system is a first target system will be exemplified. The first target system is constructed in a first cloud computing environment. By granting a role to a resource, the authority to scan the resource is assigned to the information processing apparatus 10 (for example, a scanning user account). Here, the scanning user account is a user account (for example, a set of an ID and a password) associated with the information processing apparatus 10, which is issued so that the information processing apparatus 10 can scan the first target system in the first computing environment.
[0048] In the first cloud computing environment, when a role is assigned to a certain resource, the role is automatically propagated to resources at a lower level than the certain resource.
[0049] In Operation Example 1, the following options can be considered as the role propagation method.
[0050] In Option 1-1, as shown in FIG. 3, when a role is assigned to a root, the role is automatically propagated and assigned to resources in the lower-level hierarchy subordinate to the root. That is, the role is automatically propagated to resources AAA, BBB, CCC (units), and further automatically propagated to resources AAA#1, AAA#2, BBB#1, BBB#2, CCC#1, CCC#2 (member accounts), respectively.
[0051] That is, when a role is assigned to a resource in the upper-level hierarchy (here, the root), the same role is inherited and assigned to resources in the lower-level hierarchy subordinate thereto (here, units and member accounts). Thus, if scan authority by the information processing apparatus 10 is assigned to a resource in the upper-level hierarchy by a role, the same scan authority will also be assigned by the information processing apparatus 10 to resources in the lower-level hierarchy.
[0052] In Option 1-2, as shown in FIG. 4, when a role is assigned to unit AAA, the same role is automatically propagated and assigned to resources in the lower-level hierarchy subordinate to unit AAA. That is, the role is automatically propagated to member accounts AAA#1, AAA#2. Note that in Option 1-2, the role does not propagate to units BBB, CCC, and resources (member accounts) in their lower-level hierarchies.
[0053] Although not particularly limited, Operation Example 1 may be considered as a reference example for Operation Example 2. In Option 1-1, when there is a user account having the authority to manage the entire hierarchical resources, such a user account may be considered as an example of a specific account.
[0054] As described above, in Operation Example 1, when the target system is constructed in the first cloud computing environment, the information processing apparatus 10 obtains the authority to scan by the automatic propagation of the role from the role assigned to the resource in the upper-level hierarchy higher than the predetermined level.
[0055] (Operation Example 2) Hereinafter, operation example 2 according to the embodiment will be described. In operation example 2, a case where the target system is the second target system will be exemplified. The second target system is constructed in a second cloud computing environment. By assigning a role to a resource, the authority to scan the resource is assigned to the information processing apparatus 10 (for example, a scan user account corresponding to the information processing apparatus 10).
[0056] In the second cloud computing environment, unlike the first cloud computing environment, even if a role is assigned to a certain resource, the same role is not automatically propagated and assigned to the resources at a lower hierarchy than that resource.
[0057] Under such a premise, in operation example 2, a specific account having the authority to operate the root of the highest hierarchy of the hierarchical resources is used. The specific account may be a management account which is a specific resource provided separately from the hierarchical resources. Here, the management account, like the member account, is one of the resources, can constitute a system environment, and can link and hold the assets used in the management account. In operation example 2, a configuration management tool for managing the configuration of the second target system may be used.
[0058] In operation example 2, the following options can be considered as the role propagation method.
[0059] In Option 2-1, as shown in FIG. 5, the management account and the configuration management tool are coordinated.
[0060] Subsequently, the template stored in the information processing apparatus 10 is acquired by the user, and the template acquired by the user is uploaded to the configuration management tool. The configuration management tool instructs the management account to propagate and execute the template from the root to the resources under the root. As a result, the template propagates to a lower hierarchy than the root, and the roles described in the template are assigned to the resources in the lower hierarchy. The configuration management tool instructs the management account to provide information (routing information) specifying the entry point and path for propagating the template. The template may include information regarding the party to which the right to scan resources is assigned (for example, information identifying the user account for scanning). Here, the user account for scanning is a user account (for example, a set of ID and password) associated with the information processing apparatus 10, which is issued for the information processing apparatus 10 to scan the second target system in the second computing environment.
[0061] In Option 2-1, the routing information may be information specifying all resources under the root (for example, the identifier of the resource), or information specifying resources under the resources of AAA, BBB, and CCC. As a result, the roles described in the template are propagated and assigned to the units AAA, BBB, and CCC, and are respectively propagated and assigned to the member accounts AAA#1, AAA#2, BBB#1, BBB#2, CCC#1, and CCC#2. Also, the routing information may be information (for example, the identifier of the resource) specifying the entry point (for example, the root) for propagating the template, and the role can be propagated and assigned to all resources under the root.
[0062] Although not particularly limited, the routing information may be described in the template.
[0063] Furthermore, in Option 2-1, a role may be assigned to the management account which is one of the resources. Similar to the member accounts, the role may be assigned to the management account using a template by the configuration management tool. The template for assigning a role to the management account may be the same as the template for assigning a role to the member accounts. As a result, the information processing apparatus 10 acquires the authority to scan the asset information (Asset X, Asset Y) associated with the management account which is a specific resource different from the hierarchical resources.
[0064] In Option 2-2, as shown in FIG. 6, the management account and the configuration management tool are coordinated.
[0065] Subsequently, the template stored in the information processing apparatus 10 is acquired by the user, and the template acquired by the user is uploaded to the configuration management tool. The configuration management tool instructs the management account to propagate and execute the template from the root to the resources in the hierarchy under the root. As a result, the template is propagated and assigned to the lower hierarchy than the root, and the role described in the template is assigned to the resources in the lower hierarchy. The configuration management tool instructs the management account with information (route information) specifying the entry and route for propagating the template. The template may include information regarding the party to which the authority to scan the resources is assigned (for example, information identifying the scanning account).
[0066] In Option 2-2, the route information may be information specifying the resources under the unit AAA among the subordinates of the root. As a result, the role described in the template is propagated to the unit AAA, propagated to the member accounts AAA#1 and AAA#2, and assigned.
[0067] Although not particularly limited, the route information may be described in the template.
[0068] Furthermore, in Option 2-2, a role may be assigned to the management account. Similar to the member account, the role may be assigned using a template by the configuration management tool. The template for assigning a role to the management account may be the same as the template for assigning a role to the member account. Thereby, the information processing apparatus 10 acquires the authority to scan the asset information (Asset X, Asset Y) associated with the management account, which is a specific resource different from the hierarchical resources.
[0069] As described above, in Operation Example 2, when the target system is constructed in the second cloud computing environment, the information processing apparatus 10 uses the configuration management tool that manages the configuration of the target system, and by propagating the role to the resources at a predetermined level, acquires the authority to scan.
[0070] In Operation Example 2, the information processing apparatus 10 acquires the asset information of the system environment associated with the resources at a predetermined level based on the role assigned to the resources at the predetermined level, and based on the acquired asset information, identifies the vulnerability information of the system environment associated with the resources at the predetermined level. In addition to this, the information processing apparatus 10 may acquire the asset information of the system environment associated with the specific account based on the role assigned to the specific account, and based on the acquired asset information, identify the vulnerability information of the system environment associated with the specific account.
[0071] In Operation Example 2, the units AAA, BBB, and CCC may or may not be associated with an account or a system environment. That is, in Operation Example 2, at least the scanning (acquisition of asset information, identification of vulnerability information) of the system environment associated with the management account and the system environment associated with the member account may be executed.
[0072] Operation Example 2 differs from Operation Example 1 in that, since the role does not automatically propagate to the resources in the lower-level hierarchy, the process of propagating the role to the resources in the lower-level hierarchy is realized by using a specific account that has the authority to operate on the root.
[0073] Operation Example 2 differs from Operation Example 1 in that the acquisition of the asset information of the system environment associated with the specific account and the identification of the vulnerability information of the system environment associated with the specific account are executed.
[0074] (Information Processing Method) Hereinafter, the information processing method according to the embodiment will be described. FIG. 7 is a diagram showing the information processing method according to the embodiment. Hereinafter, Operation Example 2 described above will be mainly described.
[0075] As shown in FIG. 7, in step S10, the information processing apparatus 10 outputs a template stored in the information processing apparatus 10. The output of the template may be a download and re-reading of the template by the administrator of the second target system or the user of the information processing apparatus 10.
[0076] In step S11, the administrator of the second target system instructs the execution of the template using the configuration management tool. When the template is executed, the role described in the template propagates to the hierarchical resources that make up the second target system. The method of role propagation is as described above (see FIGS. 5 and 6).
[0077] In step S12, the information processing apparatus 10 stores the identification information for identifying the role. The identification information for identifying the role may be a name or symbol that can uniquely identify the role, such as a resource name or a resource ID, and is acquired from the second target system. Also, the identification information for identifying the role is stored in the information processing apparatus 10 by the administrator of the second target system or the user of the information processing apparatus 10. The information processing apparatus 10 and the second target system cooperate by the processes of step S11 and step 12.
[0078] In step S20, the information processing apparatus 10 transmits information requesting vulnerability information of an application assumed to be used in the second target system to the vulnerability server 40.
[0079] In step S21, the information processing apparatus 10 receives vulnerability information from the vulnerability server 40.
[0080] In step S22, the information processing apparatus 10 stores the vulnerability information in the vulnerability DB. The information processing apparatus 10 may store in the vulnerability DB information extracted from the vulnerability information received from the vulnerability server 40. As described above, the information stored in the vulnerability DB may be modified by the user.
[0081] In step S30, the information processing apparatus 10 uses the scan user account to transmit a scan request for the resource with a role assigned thereto to the system server 30. The scan request may include identification information for identifying the role and may include a credential issued for the scan.
[0082] In step S31, the information processing apparatus 10 receives, as a response to the scan request, a scan response that can identify the asset information of the system environment from the system server 30.
[0083] In step S32, the information processing apparatus 10 acquires the asset information of the system environment corresponding to the resource with a role assigned thereto based on the scan response. As described above, the asset information may include an application library, a host, a container image, and the like.
[0084] In step S33, the information processing apparatus 10 refers to the vulnerability DB based on the asset information to identify the vulnerability information of the system environment corresponding to the resource with a role assigned thereto.
[0085] (Function and Effect) In the embodiment, the information processing apparatus 10 acquires the authority to scan a system environment associated with resources at a predetermined hierarchy by granting a role that propagates to the resources at the predetermined hierarchy using a specific account having the authority to operate the root, and acquires asset information of the system environment associated with the resources at the predetermined hierarchy based on the role that propagates to the resources at the predetermined hierarchy, and specifies vulnerability information of the system environment associated with the resources at the predetermined hierarchy based on the acquired asset information. According to such a configuration, by using a specific account having the authority to operate the root, since the role propagates to the resources at the predetermined hierarchy, it is possible to easily execute the scanning of the system environment associated with the hierarchical resources. For example, even when the target system is constructed in an environment such as a second cloud computing environment where the role does not automatically propagate to the lower-level resources, it is possible to easily grant the role to the lower-level resources, acquire the authority to scan, and specify the vulnerability information of the lower-level resources.
[0086] In the embodiment, when the target system is a second target system constructed in a second cloud computing environment (that is, an environment where the role does not automatically propagate to the lower-level resources), the role is propagated by the configuration management tool. In such a case, the information processing apparatus 10 may store a template used for the propagation of the role. According to such a configuration, it is possible to reduce the labor of the user of the second target system to prepare the template, and since the information processing apparatus 10 knows the identification information for identifying the role, the cooperation with the second target system is also easy. Further, even in a plurality of cloud computing environments (multi-cloud environment) with different environments such as the first cloud computing environment and the second cloud computing environment, it is possible to grant a role to the lower-level resources and scan them in an appropriate manner according to the environment.
[0087] In an embodiment, when the target system is a second target system constructed in a second cloud computing environment (i.e., an environment where roles are not automatically propagated and assigned to lower-layer resources), by using the management account and the configuration management tool in cooperation, only by executing the template twice using the same template, it becomes possible to scan both the resources outside the hierarchical structure (management account) and the member accounts at the lower level of the hierarchical structure.
[0088] [Modification Example 1] Hereinafter, Modification Example 1 of the embodiment will be described. Hereinafter, the differences from the embodiment will be mainly described.
[0089] In Modification Example 1, after a role is assigned to a resource, the information processing apparatus 10 may obtain asset information of the system environment by cooperation of an application programming interface (hereinafter referred to as API cooperation) within the range permitted by the role. Specifically, the information processing apparatus 10 may obtain asset information of the system environment associated with the resource to which the role is assigned by API cooperation. In this case, the information processing apparatus 10 may obtain the execution authority of the API by the role assigned to the hierarchical resource.
[0090] The range permitted by the role may include the processing content related to the scan of the system environment, and it may be within the range necessary for the scan of the system environment. For example, the range permitted by the role may include the acquisition of a snapshot of the system environment. On the other hand, the range permitted by the role may be permissions unnecessary for the scan, such as the creation of resources, the deletion of resources, the confirmation of billing information such as the usage amount related to the target system, and the acquisition of the structure of resources, and may not include relatively strong permissions.
[0091] In Modification Example 1, the information processing apparatus 10 may create and acquire a snapshot of the system environment associated with the resource to which a role is assigned, as asset information of the system environment associated with the resource to which a role is assigned. In such a case, the information processing apparatus 10 stores the snapshot in a dedicated area, and after identifying the vulnerability information of the system environment associated with the resource to which a role is assigned, the information processing apparatus 10 may delete the snapshot of the system environment associated with the resource to which a role is assigned.
[0092] In Modification Example 1, the scan result of the system environment (the scan response described above) may include a snapshot of the system environment. The snapshot may be information extracted from the states of source code, files, directories, database files, etc. at a certain point in time.
[0093] [Modification Example 2] Hereinafter, Modification Example 2 of the embodiment will be described. Hereinafter, the differences from the embodiment will be mainly described.
[0094] In Modification Example 2, the information processing apparatus 10 may identify the priority of the vulnerability information of the system environment. The target for identifying the priority may include the vulnerability information of the system environment associated with the hierarchical resources. Furthermore, the target for identifying the priority may include the vulnerability information of the system environment associated with a specific account.
[0095] Specifically, the information processing apparatus 10 may specify the priorities of the asset information of the first system environment and the vulnerability information of the second system environment based on at least any one of information indicating the level of vulnerability set by a third-party organization, information indicating whether it is accessible from the outside, information indicating whether the impact on operations due to an attack on the vulnerability is large, information indicating whether attack code for the vulnerability is circulating, and information indicating whether exploitation of the vulnerability has been confirmed. The information indicating the level of vulnerability set by a third-party organization may be information indicating the level of software vulnerability (hereinafter, score value). For example, the score information may be a score value (e.g., Base Score) defined by CVSS (Common Vulnerability Scoring System).
[0096] For example, in the information processing apparatus 10, the control unit 14 determines the priority for executing countermeasures against the vulnerability corresponding to the specified vulnerability information. The process of determining the priority for dealing with vulnerability information may be referred to as triage. The priority may be referred to as Level.
[0097] As shown in FIG. 8, Level may be represented in five levels from Level 0 to Level 4. The larger the value of Level, the higher the priority for executing countermeasures against the vulnerability. The vulnerabilities may be narrowed down in the order of Level 0 to Level 4.
[0098] Level 0 includes vulnerabilities among all vulnerabilities whose score value (e.g., Base Score defined by CVSS) is less than the threshold. It may be considered that the vulnerabilities of Level 0 are those for which countermeasures do not particularly need to be executed.
[0099] Vulnerabilities above Level 1 may include vulnerabilities with a score value equal to or above the threshold. Level 1 vulnerabilities are those obtained by excluding vulnerabilities above Level 2 from vulnerabilities above Level 1. Level 1 vulnerabilities may be determined to be vulnerabilities for which countermeasures are to be implemented through regular maintenance (e.g., once a month), and the priority for addressing Level 1 vulnerabilities is higher than that of Level 0 vulnerabilities.
[0100] Vulnerabilities above Level 2 may include vulnerabilities in system environments that are accessible from the outside among vulnerabilities above Level 1. Level 2 may include vulnerabilities in system environments where the impact on operations when under attack is significant among vulnerabilities above Level 1. Level 2 vulnerabilities are those obtained by excluding vulnerabilities above Level 3 from vulnerabilities above Level 2. Level 2 vulnerabilities may be determined to be vulnerabilities for which countermeasures should be implemented within the first deadline (e.g., within two weeks), and the priority for addressing Level 2 vulnerabilities is higher than that of Level 1 vulnerabilities.
[0101] Vulnerabilities above Level 3 may include vulnerabilities in which attack codes are circulating among vulnerabilities above Level 2. Level 3 vulnerabilities are those obtained by excluding Level 4 vulnerabilities from vulnerabilities above Level 3. Level 3 vulnerabilities may be determined to be vulnerabilities for which countermeasures should be implemented within a second deadline shorter than the first deadline (e.g., within one day), and the priority for addressing Level 3 vulnerabilities is higher than that of Level 2 vulnerabilities.
[0102] Level 4 vulnerabilities may include vulnerabilities in which attacks have actually been observed and exploitation has been confirmed among vulnerabilities above Level 3. Level 4 vulnerabilities may be determined to be vulnerabilities for which countermeasures should be implemented within a third deadline shorter than the second deadline (e.g., immediately), and the priority for addressing Level 4 vulnerabilities is higher than that of Level 3 vulnerabilities. In other words, the priority of Level 4 vulnerabilities is the highest.
[0103] Information indicating that an exploitation of a vulnerability has been confirmed may be obtained from a vulnerability server 40 (e.g., Known Exploited Vulnerabilities Catalog).
[0104] In order to implement the above-described triage, it may be expressed that the information processing apparatus 10 executes the following processes.
[0105] First, for a vulnerability corresponding to the vulnerability information of the specified system environment, the information processing apparatus 10 determines, based on at least any one of information indicating the level of the vulnerability set by a third-party organization, information indicating whether the system environment is externally accessible, information indicating whether the impact on the business due to an attack on the vulnerability is large, information indicating whether an attack code for the vulnerability is circulating, and information indicating whether an exploitation of the vulnerability has been confirmed, the priority of the vulnerability information of the system environment.
[0106] Second, when the vulnerability information of the system environment is specific vulnerability information and the system environment is externally accessible, the control unit 14 sets the highest priority (Level 4 shown in FIG. 8) as the priority of the vulnerability information of the system environment. Specific vulnerability information is vulnerability information for which an exploitation of the vulnerability corresponding to the vulnerability information of the system environment has been confirmed.
[0107] Third, when the control unit 14 specifies that an attack code for the vulnerability corresponding to the vulnerability information of the specified system environment is circulating based on the vulnerability information of the specified system environment, the control unit 14 sets the first priority (Level 3 shown in FIG. 8) as the priority of the vulnerability information of the system environment. When the vulnerability information of the system environment is specific vulnerability information and the system environment is externally accessible, the control unit 14 sets the second priority (Level 4 shown in FIG. 8), which is higher than the first priority, as the priority of the vulnerability information of the system environment. Specific vulnerability information is vulnerability information for which an exploitation of the vulnerability has been confirmed.
[0108] Fourthly, based on the vulnerability information of the identified system environment, the control unit 14 identifies that attack codes for vulnerabilities corresponding to the vulnerability information of the system environment are circulating, and when the system environment is accessible from the outside, sets the third priority level (a level of Level 3 or higher shown in FIG. 8) as the priority of the vulnerability information of the system environment. When the vulnerability information of the system environment is identified vulnerability information and the system environment is not accessible from the outside, the control unit 14 sets the fourth priority level (Level 2 shown in FIG. 8), which is lower than the third priority level, as the priority of the vulnerability information of the system environment. Identified vulnerability information is vulnerability information for which the exploitation of the vulnerability has been confirmed.
[0109] [Modification Example 3] Hereinafter, Modification Example 3 of the embodiment will be described. Hereinafter, the differences from the embodiment will be mainly described.
[0110] In Modification Example 3, an alert regarding the support of software included in the asset information will be described. Generally, software maintenance and support end after a certain period has elapsed since the end of software sales. Here, software maintenance and support include software updates for vulnerability countermeasures, inquiry response, and maintenance response in the event of a failure. The date when software support ends may be referred to as the EOL (End of Life) date. Software that has passed the EOL date will not have patches applied even when vulnerabilities are discovered, increasing the risk of attacks. Therefore, from a security perspective, users usually need to take actions such as software version upgrades or switching to another software before the EOL date is reached.
[0111] Under such a premise, the information processing apparatus 10 (storage unit 13) may store a master DB that stores the information shown in FIG. 9. As shown in FIG. 9, the master DB may store information that associates an ID, software name, related information, EOL date, first identifier (e.g., CPE), and second identifier (e.g., purl).
[0112] The ID is an identifier used to identify software in the information processing apparatus 10. The ID may be associated with at least one of two or more first identifiers and second identifiers in a one-to-many relationship (for example, "PAxxxx" and "PBxxxx" associated with "XXXX"). The ID may be associated with at least one of one first identifier and one second identifier in a one-to-one relationship (for example, "PAyyyy" associated with "YYYY").
[0113] The software name is the name of the software corresponding to the ID, and may be a specific name of the software. Also, when two or more first identifiers or second identifiers are associated with the ID, the software name may be a comprehensive name including each software indicated by the two or more first identifiers or second identifiers.
[0114] The related information is information related to the software corresponding to the ID. The related information may include the release date of the software, etc.
[0115] The EOL date is the date when the support for the software ends, and is information provided by the software supplier, etc. The EOL date may be managed for each ID or software name.
[0116] The first identifier and the second identifier may be extracted from the vulnerability information received from the vulnerability server 40. The extracted first identifier and second identifier are associated with the ID or name of the master DB that manages the EOL date, etc.
[0117] The information processing apparatus 10 (control unit 14) refers to the master DB and outputs an alert regarding software based on the EOL date when the support for the software ends. Specifically, the information processing apparatus 10 acquires at least one of the first identifier and the second identifier of the software included in the asset information based on the scan result of the asset information of the system environment. The control unit 14 uses at least one of the first identifier and the second identifier of the software as a search key to acquire the specific name and the EOL date of the software from the master DB, and outputs an alert based on the EOL date. More specifically, the control unit 14 specifies the specific name of the corresponding software using at least one of the first identifier and the second identifier of the software as a search key. Thereafter, the control unit 14 acquires the EOL date corresponding to the specified specific name. Also, the control unit 14 may directly acquire the corresponding EOL date using at least one of the first identifier and the second identifier of the software as a search key. The alert may be visually displayed in the EOL date column of the master DB. The alert may be output step by step according to the remaining days until the EOL date. The remaining days may be read as the priority for executing measures against the end of support.
[0118] The search key used for searching the EOL date is not limited to the first identifier (for example, CPE (Common Platform Enumeration)) and the second identifier (for example, purl (Package URL)), and may be an identifier or name that can identify the software. Therefore, the master DB may associate at least one of the first identifier, the second identifier, and the name of the software included in the asset information with the date when the support for the software ends. The information processing apparatus 10 may specify the date when the support for the software ends based on at least one of the first identifier, the second identifier, and the name of the software, and output an alert regarding the software based on the date when the support for the software ends.
[0119] For example, the information processing apparatus 10 may output an alert indicating that support will end six months after the EOL date six months before the EOL date, may output an alert indicating that support will end three months after the EOL date three months before the EOL date, or may output an alert indicating that support has ended at the timing when the EOL date arrives. The information processing apparatus 10 may output an alert indicating that support has ended after the EOL date.
[0120] Note that the EOL date may be referred to as the EOS (End of Support) date or the EOSL (End of Service Life) date. Further, it may be read as the EOS (End of Sale) date indicating the end of sale of the service or the EOE (End of Engineering) date indicating the end of technical support.
[0121] (Operations and Effects) In Modification Example 3, an alert regarding the software included in the asset information is output based on the EOL date when the support for the software of the information processing apparatus 10 ends. According to such a configuration, for the software for which support ends, it is possible to appropriately execute measures such as version upgrading of the software included in the asset information and software changes.
[0122] [Other Embodiments] Although the present invention has been described by the above-described embodiments, it should not be understood that the discourse and drawings forming a part of this disclosure limit this invention. Various alternative embodiments, examples, and operation techniques will be apparent to those skilled in the art from this disclosure.
[0123] In the above-described disclosure, the system environment may include software, programs, applications, components, and hardware that constitute the system environment. The software may include software managed by a package management tool (package manager). The system environment may include assets. The system environment may be read as assets.
[0124] In the above disclosure, when a resource is associated with a system environment (such as an asset), it may be read as the system environment or the asset. When a resource is associated with an account, it may be read as the account.
[0125] In the above disclosure, a role may be considered as the authority, function, or role that permits the scanning of a system environment when a scan request is received from the information processing apparatus 10.
[0126] In the above disclosure, the vulnerability information may include not only information regarding vulnerabilities such as usage defects and bugs in software, programs, applications, components, etc., but also security-related information such as mistakes in the settings of cloud services and setting leaks.
[0127] Although not particularly mentioned in the above disclosure, a program for causing a computer to execute each process performed by the information processing apparatus 10 may be provided. Further, the program may be recorded on a computer-readable medium. By using a computer-readable medium, it is possible to install the program on a computer. Here, the computer-readable medium on which the program is recorded may be a non-transitory recording medium. The non-transitory recording medium is not particularly limited, and may be, for example, a recording medium such as a CD-ROM or a DVD-ROM.
[0128] Alternatively, a chip constituted by a memory that stores a program for executing each process performed by the information processing apparatus 10 and a processor that executes the program stored in the memory may be provided.
[0129] [Appendix] A first feature is that, in a target system having a system environment associated with hierarchical resources, based on a role of propagating to resources at a predetermined level using a specific account having the authority to operate on the top root of the hierarchical resources, an acquisition unit that acquires asset information of the system environment associated with the resources at the predetermined level, and a control unit that identifies vulnerability information of the system environment associated with the resources at the predetermined level based on the asset information acquired by the acquisition unit. The acquisition unit acquires the authority to scan the system environment associated with the resources at the predetermined level by granting the role to the resources at the predetermined level. The resources at the predetermined level are resources at a lower level than the root among the hierarchical resources, and it is an information processing device.
[0130] A second feature is that, in the first feature, the specific account is an administrative account which is a specific resource provided separately from the hierarchical resources, and it is an information processing device.
[0131] A third feature is that, in the first feature or the second feature, the acquisition unit acquires the authority to scan by using a configuration management tool that manages the configuration of the target system, and by propagating the role to the resources at the predetermined level, and it is an information processing device.
[0132] A fourth feature is that, in the third feature, it includes a storage unit that stores a template used for propagating the role by the configuration management tool, and it is an information processing device.
[0133] A fifth feature is that, in the third feature or the fourth feature, it includes a storage unit that stores a predetermined file used for propagating the role by the configuration management tool, and it is an information processing device.
[0134] The sixth feature is that in at least any one of the first to fifth features, the acquisition unit acquires asset information of the system environment associated with the specific account based on the role assigned to the specific account, and the control unit identifies vulnerability information of the system environment associated with the specific account, which is an information processing apparatus.
[0135] The seventh feature is that in the sixth feature, the role is assigned to the specific account using a configuration management tool that manages the configuration of the target system, which is an information processing apparatus.
[0136] The eighth feature is that in at least any one of the first to seventh features, the acquisition unit acquires asset information of the system environment associated with the resources of the predetermined layer by the cooperation of the application programming interface within the range permitted by the role, which is an information processing apparatus.
[0137] The ninth feature is that in at least any one of the first to eighth features, when the target system is constructed in the first cloud computing environment, the acquisition unit automatically obtains the role propagation from the role assigned to the resources of the upper layer than the predetermined layer to obtain the permission to scan, and when the target system is constructed in the second cloud computing environment, the acquisition unit uses a configuration management tool that manages the configuration of the target system to obtain the permission to scan by the role propagation to the resources of the predetermined layer, which is an information processing apparatus.
[0138] The tenth feature is that in at least any one of the first to ninth features, the acquisition unit acquires a snapshot of the system environment associated with the resources of the predetermined layer as the asset information of the system environment associated with the resources of the predetermined layer, which is an information processing apparatus.
[0139] The 11th feature is that in the 10th feature, after the control unit identifies the vulnerability information of the system environment associated with the resources of the predetermined layer, the control unit deletes the snapshot of the system environment associated with the resources of the predetermined layer. This is an information processing apparatus.
[0140] The 12th feature is that in at least any one of the 1st to 11th features, it includes a storage unit that stores vulnerability information in association with at least some of the information included in the asset information. The control unit is an information processing apparatus that identifies the vulnerability information of the system environment associated with the resources of the predetermined layer based on the vulnerability information stored in the storage unit.
[0141] The 13th feature is that in at least any one of the 1st to 12th features, the control unit is based on at least any one of the information indicating the level of vulnerability set by a third-party organization, the information indicating whether it is accessible from the outside, the information indicating whether the impact on the business due to an attack on the vulnerability is large, the information indicating whether the attack code for the vulnerability is circulating, and the information indicating whether the exploitation of the vulnerability has been confirmed. This is an information processing apparatus that identifies the priority of the vulnerability information of the system environment associated with the resources of the predetermined layer.
[0142] The 14th feature is that in at least any one of the 1st to 13th features, it includes a storage unit that stores in association at least any one of the first identifier, the second identifier, and the name of the software included in the asset information and the date when the support for the software ends. The control unit identifies the date when the support for the software ends based on at least any one of the first identifier, the second identifier, and the name of the software, and outputs an alert regarding the software based on the date when the support for the software ends. This is an information processing apparatus.
[0143] Feature 14 is an information processing method in a target system having a system environment associated with hierarchical resources, comprising: Step A of obtaining asset information of the system environment associated with the resources at a predetermined level based on a role of propagating to the resources at the predetermined level using a specific account having the authority to operate on the top root of the hierarchical resources; Step B of identifying vulnerability information of the system environment associated with the resources at the predetermined level based on the asset information obtained in Step A; and Step C of obtaining the authority to scan the system environment associated with the resources at the predetermined level by assigning the role to the resources at the predetermined level, wherein the resources at the predetermined level are resources at a lower level than the root among the hierarchical resources.
Description of Reference Numerals
[0144] 10… Information processing device, 11… Transmission unit, 12… Reception unit, 13… Storage unit, 14… Control unit, 20… Terminal, 30… System server, 40… Vulnerability server, 100… Information processing system, 200… Network
Claims
1. In a target system having a system environment associated with hierarchical resources, based on a role to be propagated to resources at a predetermined hierarchy using a specific account having the authority to operate the top root of the hierarchical resources, an acquisition unit that acquires asset information of the system environment associated with the resources at the predetermined hierarchy; A control unit that identifies vulnerability information of the system environment associated with the resources at the predetermined hierarchy based on the asset information acquired by the acquisition unit; and The acquisition unit acquires the authority to scan the system environment associated with the resources at the predetermined hierarchy by granting the role to the resources at the predetermined hierarchy; The resources at the predetermined hierarchy are information processing apparatuses that are resources at a lower hierarchy than the root among the hierarchical resources.
2. The information processing apparatus according to claim 1, wherein the specific account is an administrative account that is a specific resource provided separately from the hierarchical resources.
3. The information processing apparatus according to claim 1, wherein the acquisition unit acquires the authority to scan by using a configuration management tool that manages the configuration of the target system and propagating the role to the resources at the predetermined hierarchy.
4. The information processing apparatus according to claim 3, further comprising a storage unit that stores a predetermined file used for propagating the role by the configuration management tool.
5. The information processing apparatus according to claim 3, further comprising a storage unit that stores identification information for identifying the role assigned by the configuration management tool.
6. The acquisition unit acquires asset information of the system environment associated with the specific account based on the role assigned to the specific account; The control unit identifies vulnerability information of the system environment associated with the specific account, the information processing apparatus according to claim 1.
7. The information processing apparatus according to claim 6, wherein the role is assigned to the specific account by using a configuration management tool that manages the configuration of the target system.
8. The information processing apparatus according to claim 1, wherein the acquisition unit acquires asset information of the system environment associated with the resources at the predetermined hierarchy by cooperation of an application programming interface within the range permitted by the role.
9. The acquisition unit When the target system is built in a first cloud computing environment, the role is automatically propagated from the role assigned to resources in a higher layer than the predetermined layer to obtain the permission to scan. The information processing apparatus according to claim 1, wherein when the target system is built in a second cloud computing environment, the role is propagated to the resources in the predetermined layer by using a configuration management tool that manages the configuration of the target system, thereby obtaining the permission to scan.
10. The information processing apparatus according to claim 1, wherein the acquisition unit acquires a snapshot of the system environment associated with the resources in the predetermined layer as asset information of the system environment associated with the resources in the predetermined layer.
11. The information processing apparatus according to claim 10, wherein the control unit deletes a snapshot of the system environment associated with the resources in the predetermined layer after identifying vulnerability information of the system environment associated with the resources in the predetermined layer.
12. It includes a storage unit that stores vulnerability information in association with at least a part of the information included in the asset information. The information processing apparatus according to claim 1, wherein the control unit identifies vulnerability information of the system environment associated with the resources in the predetermined layer based on the vulnerability information stored in the storage unit.
13. The control unit is based on at least any one of information indicating the level of vulnerability set by a third party organization, information indicating whether it is accessible from the outside, information indicating whether the impact on business due to an attack on the vulnerability is large, information indicating whether an attack code for the vulnerability is circulating, and information indicating whether the exploitation of the vulnerability has been confirmed. The information processing apparatus according to claim 1, which identifies the priority of the vulnerability information of the system environment associated with the resources in the predetermined layer.
14. It includes a storage unit that stores in association at least any one of a first identifier, a second identifier, and a name of software included in the asset information and the date when the support for the software ends. The control unit identifies the date when the support for the software ends based on at least any one of the first identifier, the second identifier, and the name of the software, and outputs an alert regarding the software based on the date when the support for the software ends. The information processing apparatus according to claim 1.
15. In a target system having a system environment associated with hierarchical resources, step A of obtaining asset information of the system environment associated with the resources of a predetermined hierarchy based on a role of propagating to the resources of the predetermined hierarchy using a specific account having the authority to operate the top root of the hierarchical resources; Step B of identifying vulnerability information of the system environment associated with the resources of the predetermined hierarchy based on the asset information obtained in step A; Step C of obtaining the authority to scan the system environment associated with the resources of the predetermined hierarchy by granting the role to the resources of the predetermined hierarchy. The resources of the predetermined hierarchy are resources of a lower hierarchy than the root among the hierarchical resources. An information processing method.
Citation Information
Patent Citations
Embedded mechanism for platform vulnerability assessment
JP2008165794A
Cited By
AI agent control apparatus for dynamically intercepting tools based on risk evaluation and asynchronously freezing and thawing cognitive states and method using the same
KR102982822B1